
This policy explains which personal data we process when operating Servidence, for which purposes and on which legal basis. It applies to visitors of our website and to users of the application.
Last updated: September 2026 · This English version is provided for convenience. In case of discrepancies, the German version of this privacy policy prevails.
The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
ingenious Labs
Christian Proch
Rosenweg 3A
35447 Reiskirchen
Deutschland
Email: info@servidence.de
Privacy contact: datenschutz@servidence.de
No data protection officer has been appointed. For any privacy-related question and to exercise your rights, please contact us at datenschutz@servidence.de.
For the data arising from the contractual relationship with us (such as your user account, your organisation data and billing), we are the controller under the GDPR. For the content that users enter into Servidence themselves (in particular customer data, orders, repair items and uploaded files), the respective organisation (for example the repair shop) is the controller; we process this data on their behalf and on their instructions as a processor under Art. 28 GDPR. If you are a customer of such an organisation and have questions about your data, please contact that organisation first.
We process personal data for the following purposes:
Depending on how you use the service, we process in particular the following categories:
We do not process or store complete payment data such as credit card numbers; these are processed exclusively by our payment service provider (see section 8).
Servidence stores only what is necessary to operate the service and to remember settings you have chosen yourself. We do not use analytics, audience measurement, tracking or marketing technologies, and we embed no tracking pixels or third-party scripts. In detail:
Beyond this we use no session storage, no IndexedDB, no cache storage and no service worker.
Under section 25(2) no. 2 of the German TDDDG, storage and access do not require consent where they are strictly necessary for us to provide the service you have expressly requested. The entries listed above serve sign-in, language delivery and display settings you selected yourself. Because we use no optional tracking or marketing technologies, we deliberately do not display a consent banner. Should we use such services in the future, we will obtain your consent beforehand and update this policy.
We use carefully selected service providers, with whom data processing agreements under Art. 28 GDPR are in place:
These providers may also process personal data outside the European Union. In such cases we base the transfer on appropriate safeguards, in particular the European Commission's standard contractual clauses, where this is required. Further recipients may be public authorities where we are legally obliged to provide information.
We access the content of your organisation only when there is a specific reason to do so, and only to the extent necessary for support, error analysis, security or technical operation.
We currently do not send newsletters. If we send you product information or a newsletter in the future, we will do so only on the basis of your consent or where legally permitted. You may object or unsubscribe at any time.
We store personal data for as long as it is necessary for the purposes described. After your user account or organisation has been deleted, personal data is generally deleted or anonymised, unless statutory retention obligations apply, such as commercial and tax retention periods for invoices and accounting records. Data may persist in technical backups for a limited period of up to 30 days before those backups are overwritten in the regular cycle.
You have the following rights regarding personal data concerning you:
A message to datenschutz@servidence.de is sufficient to exercise your rights. If your request concerns data that an organisation entered into Servidence, we will refer you to the responsible organisation (see section 3).
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de).
Anyone signing up for product updates provides their email address and expressly consents to receiving occasional messages about Servidence. Sign-up uses double opt-in: after the address is entered we send an email containing a confirmation link, and consent only takes effect once that link is clicked. We store the email address, the chosen language, the wording and version of the consent text, and the times of the request, the confirmation and any later unsubscribe. The legal basis is your consent under Article 6(1)(a) GDPR, and for the procedure itself our legitimate interest in a verifiable sign-up process under Article 6(1)(f) GDPR. Product update emails are sent only after double opt-in and only to confirmed addresses in the matching language. Every product update email contains an unsubscribe link. For accountability we store send logs with recipient address, send status, timestamp, and technical error messages. Sending uses Brevo (see above) as individual transactional emails, not as a marketing campaign. Servidence does not evaluate opens or clicks of these emails on a personal basis and does not set its own tracking links or open pixels. Brevo may process technical delivery events and, where applicable, aggregated or anonymised events; tracking per contact there only occurs with recorded consent, and contacts with unknown consent are not tracked. Servidence does not collect a tracking consent for product updates. You can withdraw your consent to receive messages at any time, using the unsubscribe link in every message or in your account settings. After a withdrawal the entry is kept as a record of the unsubscribe; without confirmation an entry is never used for sending.
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.
Servidence is not directed at children or adolescents. We do not knowingly collect personal data from minors.
We take technical and organisational measures to protect your data against loss, misuse and unauthorised access. These include encrypted transmission (TLS), strict separation of different organisations' data at database level, a role-based access model, time-limited access links for files, and storage of credentials exclusively with the authentication service used. Complete payment data never reaches our systems.
We update this privacy policy when the processing or the legal framework changes, for example when new features or service providers are added. The version published on this page applies.