Servidence

Privacy Policy

This policy explains which personal data we process when operating Servidence, for which purposes and on which legal basis. It applies to visitors of our website and to users of the application.

Last updated: September 2026 · This English version is provided for convenience. In case of discrepancies, the German version of this privacy policy prevails.

1. Controller

The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

ingenious Labs
Christian Proch
Rosenweg 3A
35447 Reiskirchen
Deutschland

Email: info@servidence.de
Privacy contact: datenschutz@servidence.de

2. Data protection officer and privacy contact

No data protection officer has been appointed. For any privacy-related question and to exercise your rights, please contact us at datenschutz@servidence.de.

3. Roles: our own processing and processing on behalf

For the data arising from the contractual relationship with us (such as your user account, your organisation data and billing), we are the controller under the GDPR. For the content that users enter into Servidence themselves (in particular customer data, orders, repair items and uploaded files), the respective organisation (for example the repair shop) is the controller; we process this data on their behalf and on their instructions as a processor under Art. 28 GDPR. If you are a customer of such an organisation and have questions about your data, please contact that organisation first.

4. Purposes of processing

We process personal data for the following purposes:

  • Providing, operating and improving Servidence
  • Creating and managing the user account, including sign-in and session management
  • Managing organisations and team members, including invitations and roles
  • Customer management within the application
  • Managing orders and repair items
  • Storing and providing uploaded files, including deliberately sharing selected files with customers via status links
  • Creating test reports, repair reports, cost estimates and PDF documents
  • Sending emails required to operate the service, such as confirmations and status messages
  • Handling subscription and payment
  • Support, error analysis, security and abuse prevention

5. Categories of personal data

Depending on how you use the service, we process in particular the following categories:

  • Contact data such as name and email address
  • Organisation data such as display name, address, contact details and logo
  • User and sign-in data such as email address, role and session information
  • Customer and order data that users enter themselves
  • Device and repair data such as type, manufacturer, model, serial number and problem description
  • Uploaded files and their metadata such as file name, type, size and time; selected files may be deliberately shared with customers by the organization via status links
  • Technical usage and log data such as IP address, time, requested address and browser information generated when our servers are accessed
  • Payment administration data such as Stripe customer ID, subscription ID, status, price ID and term

We do not process or store complete payment data such as credit card numbers; these are processed exclusively by our payment service provider (see section 8).

6. Legal bases

  • Art. 6(1)(b) GDPR: performance of the user agreement and pre-contractual measures, for example for the account, application features and billing.
  • Art. 6(1)(f) GDPR: legitimate interests in secure, stable and abuse-free operation, in error analysis and support, and in asserting or defending legal claims.
  • Art. 6(1)(c) GDPR: compliance with legal obligations where applicable, such as commercial and tax retention requirements.
  • Art. 6(1)(a) GDPR: consent, where we ask you for it, for example for product information or a newsletter. You may withdraw consent at any time with effect for the future.

7. Cookies and local browser storage

Servidence stores only what is necessary to operate the service and to remember settings you have chosen yourself. We do not use analytics, audience measurement, tracking or marketing technologies, and we embed no tracking pixels or third-party scripts. In detail:

Sign-in session cookie (name starts with “sb-” and ends with “-auth-token”)
Stores the credentials of your session. Signing in is not possible without this cookie. It is renewed while you are active and deleted when you sign out.
NEXT_LOCALE (cookie)
Remembers the interface language being served (value “de” or “en”). Session cookie, contains no identifier.
servidence-theme (local storage)
Remembers your appearance choice (“System” follows your device setting, alongside “Light” and “Dark”) so the page loads without a colour flash.
servidence.orders.new.afterCreate (local storage)
Remembers where you want to go after creating an order. It is only stored if you actively change the selection.

Beyond this we use no session storage, no IndexedDB, no cache storage and no service worker.

Under section 25(2) no. 2 of the German TDDDG, storage and access do not require consent where they are strictly necessary for us to provide the service you have expressly requested. The entries listed above serve sign-in, language delivery and display settings you selected yourself. Because we use no optional tracking or marketing technologies, we deliberately do not display a consent banner. Should we use such services in the future, we will obtain your consent beforehand and update this policy.

8. Service providers and recipients

We use carefully selected service providers, with whom data processing agreements under Art. 28 GDPR are in place:

  • Supabase: operation of the database, authentication and file storage.
  • Vercel: hosting and delivery of the application as well as technical logs.
  • Stripe: handling of subscription and payment. You enter payment details directly with Stripe; we only receive and store the administration data listed in section 5.
  • Brevo: sending emails required to operate the service and, where applicable, future product information.

These providers may also process personal data outside the European Union. In such cases we base the transfer on appropriate safeguards, in particular the European Commission's standard contractual clauses, where this is required. Further recipients may be public authorities where we are legally obliged to provide information.

9. Access by us for support and operations

We access the content of your organisation only when there is a specific reason to do so, and only to the extent necessary for support, error analysis, security or technical operation.

10. Product information and newsletter

We currently do not send newsletters. If we send you product information or a newsletter in the future, we will do so only on the basis of your consent or where legally permitted. You may object or unsubscribe at any time.

11. Retention and deletion

We store personal data for as long as it is necessary for the purposes described. After your user account or organisation has been deleted, personal data is generally deleted or anonymised, unless statutory retention obligations apply, such as commercial and tax retention periods for invoices and accounting records. Data may persist in technical backups for a limited period of up to 30 days before those backups are overwritten in the regular cycle.

12. Your rights

You have the following rights regarding personal data concerning you:

  • Access to the processed data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

A message to datenschutz@servidence.de is sufficient to exercise your rights. If your request concerns data that an organisation entered into Servidence, we will refer you to the responsible organisation (see section 3).

13. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de).

Product updates by email

Anyone signing up for product updates provides their email address and expressly consents to receiving occasional messages about Servidence. Sign-up uses double opt-in: after the address is entered we send an email containing a confirmation link, and consent only takes effect once that link is clicked. We store the email address, the chosen language, the wording and version of the consent text, and the times of the request, the confirmation and any later unsubscribe. The legal basis is your consent under Article 6(1)(a) GDPR, and for the procedure itself our legitimate interest in a verifiable sign-up process under Article 6(1)(f) GDPR. Product update emails are sent only after double opt-in and only to confirmed addresses in the matching language. Every product update email contains an unsubscribe link. For accountability we store send logs with recipient address, send status, timestamp, and technical error messages. Sending uses Brevo (see above) as individual transactional emails, not as a marketing campaign. Servidence does not evaluate opens or clicks of these emails on a personal basis and does not set its own tracking links or open pixels. Brevo may process technical delivery events and, where applicable, aggregated or anonymised events; tracking per contact there only occurs with recorded consent, and contacts with unknown consent are not tracked. Servidence does not collect a tracking consent for product updates. You can withdraw your consent to receive messages at any time, using the unsubscribe link in every message or in your account settings. After a withdrawal the entry is kept as a record of the unsubscribe; without confirmation an entry is never used for sending.

14. No automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

15. Intended audience

Servidence is not directed at children or adolescents. We do not knowingly collect personal data from minors.

16. Data security

We take technical and organisational measures to protect your data against loss, misuse and unauthorised access. These include encrypted transmission (TLS), strict separation of different organisations' data at database level, a role-based access model, time-limited access links for files, and storage of credentials exclusively with the authentication service used. Complete payment data never reaches our systems.

17. Changes to this policy

We update this privacy policy when the processing or the legal framework changes, for example when new features or service providers are added. The version published on this page applies.