KontoCSV Plugin Privacy Notice
Version 1.0 · effective 6 October 2026 · applies to the KontoCSV plugin and MCP connection used from ChatGPT and Codex.
This plugin-specific notice supplements the full KontoCSV Privacy Policy. For the German privacy policy, see Datenschutzerklärung.
1. Controller and scope
Controller: Tom Abraham, Riemekestraße 118, 33102 Paderborn, Germany. Contact: support@kontocsv.de.
This notice covers personal data processed by KontoCSV when a user connects the KontoCSV plugin and invokes its tools from ChatGPT or Codex. The ChatGPT or Codex host separately processes the user's account, conversation and host-side data under its own terms and privacy policy.
2. Categories of personal data processed
- Account and authorization data: the connected KontoCSV account identifier, account email where associated with the KontoCSV account, and authentication or authorization metadata required to establish and secure the connection.
- User-provided financial documents: bank, card or payment statement PDFs, transaction CSV files, filenames and document metadata, and the financial data contained in those files, such as transaction dates, amounts, descriptions, balances, account identifiers and currencies.
- Conversion and account data: requested export format, inspection and conversion status, generated accounting export, and the connected KontoCSV account's existing credit balance or reservations needed to determine whether a requested conversion can run.
- Technical and security data: request timestamps, network and device metadata needed to operate and secure the service, and technical error or security log data.
3. Purposes of processing
- Authenticate and authorize the connected KontoCSV account.
- Import and inspect the bank statement or transaction CSV chosen by the user.
- Prepare and, only when authorized, execute the requested accounting conversion using existing KontoCSV credits.
- Return conversion status and the requested accounting export.
- Prevent abuse, protect account and service security, diagnose technical failures and provide support.
KontoCSV does not use plugin data for advertising and does not sell personal data.
4. Categories of recipients and service providers
Personal data is disclosed only as necessary to provide the user-requested plugin function. Depending on the operation, recipients may include:
- ChatGPT or Codex host: the host transmits the user's authorized tool request to KontoCSV and receives the tool result needed to present the requested response.
- Supabase: authentication, database, job data and private object storage in the EU region used by KontoCSV.
- Vercel: hosting and server-side functions for the KontoCSV web and MCP interface.
- Render: operation of the KontoCSV backend and document-processing jobs in Frankfurt.
- Google Cloud Storage and Google Vertex AI / Gemini: temporary document processing and AI-assisted extraction in the configured Frankfurt region.
- Technical security providers: limited technical error metadata may be processed by services such as Sentry. Uploaded financial document contents are not sent to error-monitoring services.
The full provider and international-transfer information is maintained in the full Privacy Policy.
5. Data retention timelines
| Data | Retention |
|---|---|
| Uploaded source files, conversion files, document chunks, intermediate processing formats and conversion jobs | Automatically deleted no later than 7 days after upload or creation; processing copies may be deleted earlier. |
| Server and security logs | 30 days |
| KontoCSV account and session data | Retained while needed for the account or active session and removed when the account is deleted or the applicable session is removed, subject to mandatory legal retention. |
| Contract and invoice records created outside the plugin | Up to 10 years where required by German commercial or tax law. The plugin itself does not create payment-card transactions or checkout sessions. |
6. User controls
- A user can stop using or disconnect the KontoCSV plugin in ChatGPT, preventing future plugin calls until it is connected again.
- KontoCSV account holders can export their account data and delete their account from the KontoCSV dashboard.
- Users can request access, rectification, erasure, restriction, portability or objection by contacting support@kontocsv.de.
- Preparing or inspecting a conversion does not itself spend credits. Conversion tools that spend existing credits require the user-authorized conversion flow.
7. Security and legal basis
Data is transmitted over encrypted connections and processed only for the purposes described above. The principal legal basis for account and conversion processing is Art. 6(1)(b) GDPR; security and service-stability processing may rely on Art. 6(1)(f) GDPR. Additional details, including safeguards for service providers, are stated in the full KontoCSV Privacy Policy.
8. Changes to this notice
KontoCSV updates this notice when the plugin's processing, recipients or retention rules materially change. The effective date at the top identifies the current version.