CameleonProCameleonPro

Privacy Policy

Effective date: March 6, 2026 · Last updated: March 6, 2026

CameleonPro UG (haftungsbeschränkt) (“CameleonPro”, “we”, “us”, or “our”) is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, and share personal data when you use our field service management platform, websites, and mobile applications (collectively, the “Services”).

CameleonPro is a B2B SaaS platform that enables organizations to manage their field service operations. Organizations (“Subscribers”) use CameleonPro to coordinate fieldworkers and serve their own customers.

1. Data Controller and Data Processor

When you are a Subscriber (organization): CameleonPro acts as the data controller for account registration, billing, and platform usage data. For data that Subscribers input into the platform about their customers and fieldworkers, CameleonPro acts as a data processor on behalf of the Subscriber (the data controller).

When you are an end customer or fieldworker: Your organization (the Subscriber) is the data controller. CameleonPro processes your data on their behalf under our Data Processing Agreement.

Contact (Data Protection):
CameleonPro UG (haftungsbeschränkt)
Email: privacy@cameleonpro.com

2. Personal Data We Collect

The categories of personal data we collect depend on your role in the platform:

2.1 Organization Owners & Managers

2.2 Fieldworkers

2.3 End Customers

3. Legal Bases for Processing

We process personal data under the following legal bases (GDPR Article 6(1)):

PurposeLegal Basis
Providing the platform servicesPerformance of contract (Art. 6(1)(b))
Processing paymentsPerformance of contract (Art. 6(1)(b))
Sending service notifications (booking updates, invoices)Performance of contract (Art. 6(1)(b))
Fieldworker GPS tracking during active assignmentsLegitimate interest (Art. 6(1)(f)) — service delivery and safety
Platform security, fraud preventionLegitimate interest (Art. 6(1)(f))
Analytics and platform improvementLegitimate interest (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))
NPS surveys and feedback requestsConsent (Art. 6(1)(a))
Tax and financial record-keepingLegal obligation (Art. 6(1)(c))

4. How We Use Your Data

5. GPS and Location Data

CameleonPro collects GPS location data from fieldworkers' mobile devices. This is a sensitive category that we handle with particular care:

6. Data Retention

Data CategoryRetention Period
Account and profile dataDuration of account + 30 days after deletion
Booking and service historyDuration of subscription + 12 months
Chat messages and discussionsDuration of subscription + 6 months
GPS/location traces90 days after booking completion
Invoices and financial records10 years (German tax law — AO §147, HGB §257)
Notification history12 months
Server logs and security events12 months
Push notification tokensUntil token refresh or account deletion

When a Subscriber cancels their subscription, we retain their data for 30 days to allow for reactivation or data export. After this period, data is permanently deleted in accordance with the schedule above, except where longer retention is required by law.

7. Sub-Processors

We use the following third-party services to provide and support the platform. Each sub-processor processes data only as necessary for its stated purpose:

Sub-ProcessorPurposeData ProcessedLocation
StripePayment processingName, email, payment card details, transaction amountsEU / US (SCCs)
Keycloak (self-hosted)Authentication and identity managementEmail, name, credentials, session tokensEU
Firebase / Google CloudPush notifications (FCM)Device tokens, notification contentEU / US (SCCs)
MapboxMapping and geocodingAddresses, GPS coordinatesUS (SCCs)
Brevo (Sendinblue)Transactional email deliveryEmail addresses, email contentEU (France)
CloudinaryImage hosting and transformationProfile photos, uploaded images, compliance documentsEU / US (SCCs)
STRATO AGInfrastructure (PostgreSQL, application servers, web hosting)All platform dataEU (Germany)

We will notify Subscribers at least 30 days before adding a new sub-processor, giving them the opportunity to object.

8. International Data Transfers

CameleonPro's primary infrastructure is hosted within the European Union. Where data is transferred to sub-processors outside the EU/EEA, we rely on:

9. Your Rights Under GDPR

Depending on your role, you have the following rights regarding your personal data:

For Subscribers (organization owners): Exercise your rights by contacting us at privacy@cameleonpro.com.

For end customers and fieldworkers: Your organization (the Subscriber) is the data controller. Please contact your organization directly to exercise your rights. We will assist the Subscriber in fulfilling your request.

We respond to all data subject requests within 30 days, in accordance with GDPR Article 12(3).

10. Cookies and Local Storage

Our web applications use cookies and browser local storage for the following purposes:

CategoryPurposeExamples
EssentialAuthentication, session management, security, CSRF protectionKeycloak session cookies, JWT tokens, tenant context
FunctionalUser preferences, language selection, UI stateDark mode preference, sidebar state, selected locale
AnalyticsUsage tracking and platform improvementGoogle Analytics 4 (if enabled by Subscriber)
MarketingCampaign trackingMeta Pixel (if enabled by Subscriber)

Essential cookies are required for the platform to function and cannot be disabled. Analytics and marketing cookies are only activated with your consent via our cookie preference banner.

11. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

12. Children's Privacy

CameleonPro is a business platform not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@cameleonpro.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify Subscribers of material changes at least 30 days before they take effect via email or in-platform notification. Continued use of the Services after changes become effective constitutes acceptance of the updated policy.

14. Contact and Supervisory Authority

For questions, concerns, or to exercise your data protection rights:

CameleonPro UG (haftungsbeschränkt)
Data Protection Contact
Email: privacy@cameleonpro.com

You also have the right to lodge a complaint with the German federal data protection authority:

BfDI (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit)
Graurheindorfer Str. 153, 53117 Bonn, Germany
Website: www.bfdi.bund.de

Cookie Preferences

We use cookies to enhance your experience. Essential cookies are required for the platform to function. You can choose to enable analytics and marketing cookies.