Service IT / Privacy Policy
Privacy Policy
Controller and contact
Controller: Service IT, sole proprietorship operated by Serhii Yanov, Paul-Gossen-Str. 89, 91052 Erlangen, Germany. Contact: s@st-in.eu, +49 9131 9185513, +38 063 405 0291.
Use the same contact for privacy requests, consent withdrawal, objection and questions about project data.
Scope
This policy applies to website visits, contact forms, email, phone or messenger communication, livechat, Telegram and WhatsApp bot communication, customer portal usage, support, project work, invoices and business service requests.
When Service IT processes personal data only on behalf of a customer, the customer remains the controller and a data processing agreement or project-specific agreement controls the processing.
Data categories
We may process contact data, account and company data, communication content, project requirements, technical logs, IP address, device and browser data, language settings, consent records, billing and payment references, support tickets, screenshots, files, call notes and data from systems connected during agreed project work.
Please do not send special-category data, payment card data, passwords, secrets or third-party personal data unless it is necessary and covered by an agreement.
Purposes
We process data to answer requests, prepare offers, conclude and perform contracts, deliver software development, Telegram bots, CRM, ERP and Odoo integrations, maintain website and server security, provide customer support, document agreed work, issue invoices, comply with legal obligations, defend legal claims and improve our services.
Legal bases
Depending on the case, processing is based on GDPR Art. 6(1)(b) for contract steps and service delivery, Art. 6(1)(f) for legitimate interests such as security, support and business communication, Art. 6(1)(c) for legal obligations, and Art. 6(1)(a) for consent-based processing such as optional analytics or certain marketing communication.
Electronic marketing messages are sent only where legally permitted, for example with consent or another valid basis under applicable anti-spam rules, including UWG § 7 where German law applies.
Cookies and similar technologies
Essential cookies are used for website operation, security, language, session and consent storage. Optional analytics, marketing or embedded third-party cookies are used only where enabled and, where required, only after your consent.
Details, cookie names, purposes, retention and withdrawal options are available at /cookie-policy.
Recipients and processors
Data may be processed by hosting and infrastructure providers, Odoo/CRM systems, email and communication providers, analytics and consent tools, payment and accounting providers, tax or legal advisers, subcontractors, AI or automation providers where required for the project, and public authorities where legally required.
Processors are used only within the required scope and, where GDPR requires it, under data processing agreements.
International transfers
If providers or project systems outside the EU/EEA are used, we apply appropriate safeguards where required, such as adequacy decisions, EU Standard Contractual Clauses, contractual limits, provider review and retention controls.
Retention
We keep personal data only as long as needed for the stated purposes, contract performance, support, security, accounting and tax retention duties, limitation periods and defense of legal claims.
Contact requests that do not lead to a project are deleted or minimized when they are no longer needed. Project and invoice data may be retained for statutory commercial and tax periods.
Your rights
You may request access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time for future processing.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
AI-assisted processing and automated decisions
Where useful, we may use AI-assisted or rule-based tools, including language models, CRM tools, translation, summarization, search and drafting tools, to classify incoming requests, summarize project information, translate messages, prepare draft replies, search internal knowledge, detect technical issues and support service delivery.
These tools may process data submitted through forms, chat or livechat, email, messengers, phone notes, customer systems or project systems only for the stated purposes and under human responsibility.
We do not use this website to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects for a person within the meaning of GDPR Article 22. If a project would involve such decisions, it requires a separate legal basis, safeguards, human intervention and the right to contest the decision.
For AI systems covered by Regulation (EU) 2024/1689, the Artificial Intelligence Act, prohibited, high-risk, transparency-only and low-risk uses are classified before implementation. Users are informed when they interact directly with AI where required.
Messenger and bot channels
If you contact us through Telegram, WhatsApp or another messenger, we process your username or number, message content, metadata visible to us, bot interaction data and support history to answer the request and provide the service.
The messenger platform provider may process additional data under its own terms and privacy policy.
Security
We use TLS where available, role-based access, backups, logging, account separation and operational security measures appropriate to the project. No internet service can be guaranteed to be risk-free.
Related legal documents
Last updated
30.07.2026