BWPM TRACK
Last updated: 23 July 2026

Privacy information

1. Controller

BWPM Boardwalk Projektmanagement GmbH
Hahntrapp 1, 20457 Hamburg, Germany
Email: track@bwpm.de

2. Scope and data categories

BWPM TRACK processes account and contact data, project roles, project and construction records, uploaded files and photos, communications, audit events, security information and technical log data. The exact scope depends on the modules used in a project.

3. Purposes and legal bases

Data is processed to provide user accounts and contracted project functions, document construction activity, coordinate participants, secure and troubleshoot the service, send requested notifications and meet legal retention duties. Depending on the situation, processing is based on contract performance, legal obligations, legitimate interests in secure and efficient operation, or consent where expressly requested.

4. Storage location: Finland

All server-side customer data is stored exclusively in Finland. This includes application and database content, file attachments, photos, logs and backups. Finland is a member of the European Union, so storage is subject to EU data-protection law and the GDPR. The Finnish location provides reliable infrastructure, short European data routes and data residency within the EU.

5. Recipients and processors

Access is limited by project roles. Technical service providers receive data only where required for hosting, email delivery, maintenance or support and are contractually bound where required. When a B2B subscription is placed, PayPal receives the data required to create and administer the recurring payment. PayPal processes payment-account and transaction data under its own privacy information. BWPM TRACK stores the PayPal subscription and transaction identifiers, payment status, invoice data and webhook events, but no PayPal password or payment credentials. Customer data is not sold and is not used for advertising profiles.

6. Artificial-intelligence help

The optional help assistant receives only the question entered by the user, limited conversation history, the current page name and selected help text. It does not automatically receive project records. Depending on the configured provider, the request may be processed outside the EU; users must therefore not enter confidential project data. The wiki describes the current provider and boundaries.

7. Cookies and local storage

Essential session cookies support sign-in, CSRF protection and language selection. Local storage remembers the selected system, light, dimmed or dark appearance. A preference cookie remembers acknowledgement of the cookie notice. These technologies are not used for advertising.

8. Matomo usage statistics

The self-hosted Matomo service at matomo.bwpm.org measures aggregated use without analytics cookies, user IDs or browser fingerprinting. Query parameters and fragments are removed from current and referring addresses before transmission. Generic page titles are used. Matomo necessarily receives the IP address for the connection; IP anonymisation must be enabled before storage. Raw visit records are scheduled for deletion after no more than 180 days.

9. Retention and security

Data is retained for the duration of the account or project and afterwards only as long as contractual, evidentiary or statutory duties require. Backup rotation and technical logs may lead to limited delayed deletion. Measures include role-based access, two-factor authentication for privileged roles, protected downloads, audit trails, backups and regular system checks.

10. Rights

Subject to the legal requirements, data subjects may request access, rectification, erasure, restriction, portability or object to processing. Consent may be withdrawn for the future. Complaints may be submitted to a competent data-protection authority. Requests can be sent to the controller above.

11. Matomo objection

You can disable or enable usage measurement for this browser below.

Checking current setting…