PortalPilot

Privacy Policy

Last updated: September 6, 2026

1. Data controller

NordScope, a Finnish sole trader (toiminimi), Y-tunnus 3148476-5, owner-operator Peter Sterkenburg ("we", "us", "our"), is the data controller for the personal data collected through this application. Contact us at privacy@portalpilot.io for any data protection inquiries.

2. Data we collect

We collect the following categories of personal data:

  • Account data: Email address, password (encrypted), full name
  • HubSpot portal metadata: Portal ID, portal name, property definitions (names, types, labels, descriptions, usage statistics, group assignments)
  • Record sample data: During analysis, we access a sample of property values (up to 1,000 records per object type: contacts, companies, deals, tickets) to compute fill rates, value distributions, and data quality scores. Samples are processed in memory, and the immediate response may include detailed diagnostics. Persisted cached analysis removes HubSpot user identities and raw cross-object mismatch examples. Analysis history stores scores and counts.
  • Lead data: Email address for newsletter subscribers
  • Usage data: Analysis history, property actions, timestamps
  • User-provided service content: Annotations, discussions, notifications, dependency contact details, and export recipient email addresses
  • Security and diagnostic data: IP addresses, user agents, session identifiers, login attempts, audit events, and performance telemetry
  • Payment data: Transaction records processed by Mollie (we do not store card details)

3. Legal basis for processing

We process your data based on:

  • Contract (Art. 6(1)(b) GDPR): Processing necessary to provide our analysis services, including accessing HubSpot portal data via OAuth
  • Consent (Art. 6(1)(a) GDPR): For email marketing and optional analytics
  • Legitimate interest (Art. 6(1)(f) GDPR): For service improvement, security monitoring, and fraud prevention
  • Legal obligation (Art. 6(1)(c) GDPR): For tax and financial record-keeping

4. How we use your data

  • To analyze your HubSpot property configuration and data quality
  • To compute fill rates and value distributions from record samples processed in memory
  • To provide health scores, AI readiness assessments, and recommendations
  • To generate AI-powered property suggestions and descriptions
  • To send service-related communications
  • To send marketing emails (only with your consent)
  • To improve our services

5. Data retention

We retain your data only as long as necessary for the purposes described. Cached analysis is retained for no more than 365 days, and analysis history defaults to 180 days. Specific retention periods:

Data typeRetention period
Account dataDuration of service + 30 days
Cached analysisNo more than 365 days
Analysis history180 days by default
Source record samplesProcessed in memory; no separate source-record store
Audit logs90 days
Payment records7 years (Finnish tax law)
Lead email addressesUntil unsubscribe

You can request deletion at any time.

6. Data sharing

We share data only with the following service providers:

  • Mollie B.V.: Payment processing (PCI DSS compliant, Netherlands, EU)
  • Your HubSpot portal: PortalPilot accesses your own HubSpot portal via OAuth as your authorised integration; HubSpot is not a service provider engaged by us. Where API requests are processed depends on your portal's data residency setting (EU or US). For US-hosted portals, transfers are covered by the EU-US Data Privacy Framework.
  • Mistral AI: AI-powered suggestions, descriptions, and embeddings use Mistral's EU regional API endpoint. API inputs are not used to train Mistral models by default. Zero Data Retention is a separate opt-in account setting, and PortalPilot does not claim it is enabled without account-level evidence.
  • Lettermint B.V.: Transactional email delivery (Netherlands, EU). Processes email addresses and email template content for account notifications, analysis reports, team invitations, and authentication emails. GDPR compliant, EU-hosted. No email content is stored by Lettermint beyond delivery.
  • healthchecks.io: Dead-man's-switch monitoring for our status page probe (Hetzner Falkenstein, Germany, EU). Receives only a probe-OK signal on every successful probe run; no PII, no portal data, no customer data is transmitted. Sends an email alert to our operations inbox if the probe stops reporting.

Self-hosted infrastructure: Our database (Supabase), analytics (Plausible), and public status page (Kener) are self-hosted on our own servers at Hetzner in Finland, EU. They are not third-party SaaS services; we control the infrastructure directly. The status page additionally processes subscriber email addresses (only for users who opt in to incident notifications) and per-subscriber unsubscribe tokens, both stored in the self-hosted Kener database.

We do NOT sell your personal data.

7. Your rights (GDPR)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a machine-readable format
  • Object: Object to processing based on legitimate interests
  • Withdraw consent: Unsubscribe from marketing at any time

To exercise these rights, contact us at privacy@portalpilot.io or use the data export feature in your dashboard. We will respond within 30 days as required by GDPR.

8. Data security

We implement appropriate technical and organizational measures including encryption at rest (AES-256) and in transit (TLS 1.2+), role-based access controls, and regular security assessments. HubSpot OAuth tokens are stored encrypted and never exposed to the client.

9. Local storage and preferences

We use browser local storage and tab-scoped session storage for the following data:

  • Authentication state: Supabase session data is kept in local storage until session expiry, sign-out, or browser storage clearing.
  • Impersonation identity: The admin support tool keeps the selected user and portal in session storage until impersonation stops, admin access is unavailable, or the tab closes.
  • Generated descriptions: AI-generated property descriptions stay in session storage until they are cleared in the workflow or the tab closes.
  • OAuth state: The connection nonce and return route stay in session storage until the relevant callback completes, the flow expires, or the tab closes.
  • Task content: Tasks created from dashboard recommendations remain in local storage until browser storage is cleared.
  • Preferences: Theme, onboarding, consent, and analysis-view settings remain in local storage until changed or cleared.

Authentication state is sent with authenticated requests, and OAuth state is returned during the connection flow. You can clear browser-held data through your browser settings.

10. Website analytics

We use a self-hosted instance of Plausible Analytics to understand how visitors use our website. Plausible is a privacy-focused, open-source analytics tool that:

  • Does not use cookies: no tracking cookies are set
  • Does not collect personal data: no IP addresses, device fingerprints, or persistent identifiers are stored
  • Is fully self-hosted: on our EU servers (Hetzner, Finland), with no data sent to third parties
  • Collects only aggregate metrics: page views, referral sources, browser type, and country (derived from IP, then immediately discarded)

The legal basis for this processing is legitimate interest (Art. 6(1)(f) GDPR). Since Plausible does not use cookies or collect personal data, no consent is required under the ePrivacy Directive.

11. International transfers

All our core infrastructure is located within the European Economic Area (EEA):

  • Application and database: Hetzner, Finland (EU)
  • AI processing: Mistral AI, Paris, France (EU)
  • Analytics: Self-hosted Plausible, Hetzner, Finland (EU)
  • Payments: Mollie B.V., Netherlands (EU)
  • Transactional email: Lettermint B.V., Netherlands (EU)
  • Public status page (self-hosted): Kener, Hetzner, Finland (EU)
  • Status page monitoring (dead-man's-switch): healthchecks.io, Hetzner Falkenstein, Germany (EU)

PortalPilot accesses your HubSpot portal via API on your instruction. Whether this constitutes an international transfer depends on your portal's data residency setting. If your portal uses HubSpot's EU data hosting, API traffic may remain within the EEA. If your portal is US-hosted, the transfer is covered by the EU-US Data Privacy Framework, under which HubSpot is certified.

12. HubSpot marketplace compliance

As a HubSpot ecosystem application, we comply with:

  • HubSpot's Acceptable Use Policy
  • HubSpot's App Partner Program Agreement
  • HubSpot's Developer Terms and API Use Policy

We process HubSpot data only as authorized through the OAuth consent flow and for the purposes described in this policy. We only request OAuth scopes necessary for the service's functionality. Users are also bound by HubSpot's own Terms of Service when using HubSpot data through our service.

13. Data deletion requests

You can request complete data deletion by:

  • Emailing privacy@portalpilot.io
  • Using the "Delete My Data" button in your account settings
  • Disconnecting your HubSpot portal (removes all portal data)

When HubSpot notifies us of a data deletion request (GDPR compliance), we remove any associated data within 24 hours.

14. AI data processing

Our AI-powered features are processed by Mistral AI (Paris, France, EU). When you use them, your data is:

  • Sent through Mistral's EU regional API endpoint
  • API inputs are not used to train Mistral models by default
  • Zero Data Retention is a separate opt-in account setting; PortalPilot does not claim it is enabled without account-level evidence
  • Processed to generate the requested AI feature output
  • For most features, limited to property metadata (names, descriptions, types) and aggregate statistics
  • Deal-risk analysis can send up to six deal records with business fields such as deal ID, name, amount, stage, close date, and risk flags
  • Processed entirely within the EU (no data leaves the EEA for AI processing)

15. Children's privacy

Our service is designed for business professionals and is not directed at children. We do not knowingly collect personal data from children under 16 years of age (per GDPR) or 13 years of age (per COPPA). If we become aware that we have collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@portalpilot.io.

16. Changes to this policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email (if you have an account) and by posting a prominent notice on our website at least 30 days before the changes take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy. The "Last updated" date at the top of this page indicates when the policy was last revised.

17. Contact and complaints

For privacy inquiries: privacy@portalpilot.io
You also have the right to lodge a complaint with your local data protection authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).