top of page
ChangeCanvasLogo.png

PRIVACY AND DATA MANAGEMENT

Last updated: 2 September 2026

 

This Privacy Policy explains how personal data is processed in connection with the Change Canvas website and the Change Canvas application. It is intended to provide transparent information in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and other applicable data-protection law.

 

1. Controller

Frank Waible

Sommergasse 109

69469 Weinheim

Germany

Email: mail@frankwaible.de

Data protection contact: Frank Waible

 

2. Scope of this Privacy Policy

This Privacy Policy applies to the Change Canvas website and to the Change Canvas application. The website and the app involve different processing activities. The website is operated using Wix Studio; the app is designed as a local-first workspace in which project content is stored primarily on the user's device.

 

3. General Categories of Personal Data

Depending on how you use the website or app, the following categories of personal data may be processed:

  • contact data, such as name, email address and other information submitted in a contact request;

  • usage and technical data, such as IP address, device and browser information, access times and technical logs;

  • content data that you voluntarily enter into the Change Canvas app;

  • project, assessment, workshop and action-board information stored locally within the app;

  • consent and cookie-preference information relating to the website; and

  • limited operational metadata generated when Digital Coach functionality is used.

 

4. Purposes and Legal Bases of Processing

We process personal data only where a legal basis under the GDPR applies. Depending on the relevant processing activity, the legal basis may include: consent (Art. 6(1)(a) GDPR); performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR); compliance with legal obligations (Art. 6(1)(c) GDPR); and our legitimate interests (Art. 6(1)(f) GDPR), in particular the secure and efficient operation of the website, app and related services.

 

5. Change Canvas Website

 

5.1 Website hosting and technical operation

The Change Canvas website is created and operated using Wix Studio. When you access the website, technical data may be processed as necessary to deliver the website securely and reliably. This may include IP addresses, device and browser information, request data and security-related information. Such processing may be carried out by Wix and its subprocessors in accordance with the applicable contractual and data-protection arrangements.

 

5.2 Contact requests

If you contact us by email or through a website form, we process the information you provide in order to respond to your request. The legal basis is Art. 6(1)(b) GDPR where the communication relates to a contract or pre-contractual request, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.

 

6. Cookies and Consent Management

The website may use cookies and similar technologies. Cookies are small data files stored in, or accessed through, a visitor's browser. They may be required for essential website functions or, subject to consent, used for functional, analytics or marketing purposes.

 

Change Canvas uses the Usercentrics for Wix consent solution available through the Wix Privacy Center. When the consent banner is active, only essential cookies and scripts are intended to load before a visitor makes a choice. Non-essential categories, such as functional, analytics or marketing technologies, are activated only after the required consent has been obtained. Visitors may accept all categories, reject non-essential categories, or manage individual preferences through the consent interface. Consent choices may be changed later through the privacy/cookie settings mechanism made available on the website.

 

The precise cookies and technologies used can change when website functionality is added, removed or updated. For this reason, the current cookie categories, providers, purposes and storage periods should be taken from the live consent-management interface and its website scan, rather than from a static legacy cookie list in this Privacy Policy.

Certain third-party applications or custom code may require separate configuration to ensure that non-essential technologies are blocked until consent is obtained. We therefore review the website's consent configuration when such functionality is introduced.

 

7. Analytics and Marketing Technologies

Analytics or marketing technologies are used only where they have actually been enabled for the website and, where legally required, only after the visitor has provided consent through the consent-management platform. This Privacy Policy does not state that Google Analytics or any other specific analytics service is in use unless that service has been activated. The live cookie/consent settings provide the current information about enabled technologies.

 

8. International Data Transfers

Where personal data is transferred to a country outside the European Union or European Economic Area, an appropriate transfer mechanism under Chapter V GDPR is used where required. Depending on the recipient, this may include an adequacy decision of the European Commission, the European Commission's Standard Contractual Clauses, or another legally

recognized safeguard.

For transfers to participating organizations in the United States, the EU-U.S. Data Privacy Framework may provide an adequacy basis where the recipient is validly certified under that framework. The former EU-U.S. Privacy Shield is not relied upon. Where the Data Privacy Framework does not apply, another lawful transfer mechanism must be used where required.

9. Change Canvas App – Local-First Data Processing

Change Canvas is designed as a local-first workspace for organizational change. Project information is not sent to an AI service merely because it is entered or saved in the app.

9.1 Data stored on your device

Projects, Canvas responses, workshop results, Action Board entries, assessments, settings and locally generated results are stored in the app's local data store on the user's device.

Leadership self-assessment entries are maintained separately from project data and remain available on that device unless the user chooses to export or otherwise share them.

9.2 Digital Coach requests

A request is transmitted only when the user actively chooses to use a Digital Coach function and submits the request. Before transmission, the app applies the privacy settings configured for the relevant project.

Names entered in the Stakeholder Analysis are not intended to be transmitted to the AI service. Instead, a generated stakeholder identifier and the relevant assessment context are used. For affected persons, groups rather than individual names are transmitted. Depending on the configured privacy settings, additional information such as financial information, company names, project names and specified terms may be removed or protected before transmission.

The protected context is sent to the Change Canvas backend for the purpose of generating the requested response. Digital Coach functionality requires an internet connection and may involve processing by the AI provider configured through the Change Canvas backend.

9.3 Backend processing

The current Change Canvas backend is designed so that prompts, project content and AI-generated results are not intentionally stored in a Change Canvas application database or file. Requests to the configured OpenAI Responses API are made with storage disabled at the API-request level. The Change Canvas backend is designed not to intentionally log request content, prompts or generated results.

Limited operational metadata may nevertheless be processed or logged for security, reliability and troubleshooting purposes, for example request identifiers, timestamps and error information. Separate infrastructure providers, including hosting or reverse-proxy providers, may apply their own technical logging and retention practices. Those practices are subject to the relevant provider arrangements and should be reviewed as the production infrastructure evolves.

9.4 User control and deletion

Users can use the data-management functions in the app settings to manage project privacy settings, delete an individual project or delete all locally stored projects. Deleting a project removes the locally stored project records and dependent data associated with that project, subject to the technical operation of the device and any user-created exports or backups.

Use of the Digital Coach is optional. Workshop notes and Canvas work can remain local without submitting an AI request.

10. Apple TestFlight and Diagnostics

During beta testing, Apple may make standard TestFlight diagnostic information available to the developer, such as crash reports, device information and session-related metrics. Such processing is performed through Apple's TestFlight service and is subject to Apple's applicable terms and privacy information.

11. Recipients and Processors

Personal data is disclosed to service providers or other recipients only where this is necessary for the operation of the website or app, for performance of contractual obligations, to comply with legal obligations, on the basis of consent, or where another lawful basis applies. Where a service provider processes personal data on our behalf as a processor, the processing is governed by the requirements of Art. 28 GDPR.

 

12. Data Retention

Personal data is retained only for as long as necessary for the purpose for which it was processed, unless a longer retention period is required by law. Statutory retention obligations, in particular under German commercial and tax law, remain unaffected. Where processing is based on consent, data is no longer processed for the consent-based purpose after consent is withdrawn, unless another legal basis applies.

 

13. Security

We implement appropriate technical and organizational measures in accordance with Art. 32 GDPR, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of natural persons. No method of transmission or storage can provide absolute security.

 

14. Your Rights under the GDPR

Subject to the statutory requirements, data subjects may have the following rights:

  • right of access (Art. 15 GDPR);

  • right to rectification (Art. 16 GDPR);

  • right to erasure (Art. 17 GDPR);

  • right to restriction of processing (Art. 18 GDPR);

  • right to data portability (Art. 20 GDPR);

  • right to object to processing based on legitimate interests (Art. 21 GDPR);

  • right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR); and

  • right to lodge a complaint with a competent data-protection supervisory authority (Art. 77 GDPR).

15. Right to Object

Where personal data is processed on the basis of Art. 6(1)(f) GDPR, you have the right, on grounds relating to your particular situation, to object at any time to such processing in accordance with Art. 21 GDPR. Where personal data is processed for direct-marketing purposes, you may object to such processing at any time.

 

16. Changes to this Privacy Policy

We may amend this Privacy Policy where changes to the Change Canvas website, app, technical infrastructure or applicable law make an update necessary. The current version will be made available through the Change Canvas website.

 

17. Contact

For questions concerning this Privacy Policy, the processing of personal data, or the exercise of data-subject rights, please contact:

 

Frank Waible
Email: mail@frankwaible.de

bottom of page