Privacy policy
Only the controller's postal address is still open — it will be set once the company is formally registered (see the legal notice). Everything else here, including the list of processors, is complete and kept up to date automatically.
Controller
Servezia, represented by Edgar Baumann and Max Schwetje. Postal address: see the legal notice. Contact: hallo@servezia.com.
Scope
It applies to this website. For processing inside the application our customers use, those businesses are the controllers; we act on their instructions there. That is governed by the data processing agreement with each business, not by this policy.
Purposes and legal basis
These pages are static. There is no sign-up, no advertising script, no tracking pixel and no embedded third-party content. We process only what secure operation of the website and a reply to your enquiry require.
- Server logs: truncated IP address, timestamp, requested path, transfer size, user agent. Legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
- Emails you send us: your details, to answer your enquiry (Art. 6(1)(b) and (f) GDPR).
Contact by email
This website deliberately has no contact form, only an email address. A form would need its own endpoint, spam protection and consent handling — and would be the only place this website accepts personal data. If you write to us, we process your message to answer it and delete it once it is resolved and no retention obligation applies.
Cookies
This website sets no cookies and therefore needs no consent banner. Your selection in the pricing configurator stays in the page's working memory and never leaves your browser; it does not even survive a page reload. Fonts are served from our own server — no connection to Google Fonts or any other third-party server.
Hosting
This website and the application our customers use run exclusively on Google Cloud, in a region within the European Union (Milan). No data is transferred to third countries. Google is engaged as a processor for running that infrastructure — details are set out in our data processing agreement with Google.
Sub-processors
Depending on which modules a customer business books with us, further sub-processors are added on top of the hosting infrastructure. This table is not maintained by hand; it is rendered directly from the same module catalogue the product itself uses. The moment a module needs an outside service, that entry appears here automatically. A hand-typed list would go wrong exactly when a new module with a new provider ships — deriving the table this way rules that out.
| Module | Sub-processor | Purpose |
|---|---|---|
| Buchhaltungsexport | Buchhaltungsanbieter (DATEV, lexoffice) | payment processing |
| Telefon-KI | Google Cloud (Dialogflow, Speech-to-Text) | communication |
| 3D-Raumaufnahme | Google Cloud (GPU-Verarbeitung) | jobs and quotes |
| KI-Aufmaß | Google Cloud Vertex AI | jobs and quotes |
| KI-Betriebsassistent | Google Ireland Limited | operations |
| Tourenplanung | Google Maps Platform | operations |
| Meta Platforms Ireland | communication | |
| SMS | SMS-Versanddienst | communication |
| Online-Zahlung | Zahlungsdienstleister | payment processing |
Module names are carried in the catalogue in German only, the same way the product itself names them — shown here unchanged rather than translated and potentially inaccurate.
Retention
Server logs are kept briefly and then deleted automatically. We delete emails to us once the enquiry is resolved and no statutory retention duty applies. Inside the application our customers use, retention periods are set by that business as the controller.
Your rights
You have the following rights against the controller:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
To exercise any of these, an email to hallo@servezia.com is enough.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement (Art. 77 GDPR). This applies regardless of where we are based.