# Privacy Policy Last updated: 2026-09-16 This Privacy Policy explains how personal data is processed when using savien, our website and our B2B SaaS application. ## 1. Controller The controller within the meaning of the General Data Protection Regulation (GDPR) is Davis Gabriels Kalnozols, trading under the business name “savien”, Meierberger Str. 14, 31737 Rinteln, Germany (“savien”). Email: privacy@savien.io ## 2. Data Protection Officer No Data Protection Officer has been appointed because there is no statutory obligation to appoint one. The relevant provisions are Art. 37 GDPR and Section 38 German Federal Data Protection Act (BDSG). We have assessed each of the grounds set out there and documented the outcome internally in writing; we will provide that documentation to the supervisory authority on request. The assessment is repeated at least annually and whenever circumstances change, in particular if at least 20 persons are regularly and permanently involved in automated processing of personal data, if a data protection impact assessment becomes necessary, or if a new feature evaluates the behaviour of natural persons. Privacy requests may be sent to privacy@savien.io. ## 3. Purpose of savien savien is a B2B platform for collaboration between merchants, suppliers and their employees. The application supports in particular: - Registration, login, roles and team management. - Supplier and customer connections. - Product catalogues, items, prices and stock information. - Orders, deliveries, shipments, goods receipts and returns. - Comments, documents, notifications and email templates. - Billing and subscription management. - Optional ERP integration, currently in particular BillBee. - Support, security, error analysis, platform operations and misuse prevention. ## 4. GDPR Roles For data we process ourselves to provide and manage the service, we act as controller within the meaning of Art. 4(7) GDPR. This includes in particular account, contract, billing, support, security, website and operational data. For content and business data that customers process in savien for their own supply chain processes, we generally act as processor within the meaning of Art. 28 GDPR. Details are governed by our Data Processing Agreement. Customers remain responsible for their own content and the lawfulness of their processing, in particular for data relating to their employees, suppliers, merchants, contact persons and other business partners. Where customers invite other companies or users to savien, they must ensure that the invitation and transmitted data are lawful. Pure company data is not personal data. It may become personal data where it relates to identified or identifiable natural persons, such as contact persons, sole proprietors, roles, email addresses or communication content. ## 5. Categories of Personal Data Depending on usage, we process the following categories: - Master data: name, company, role, customer number, language, time zone. - Contact data: email address, telephone number, business address. - Authentication data: user ID, password hash, login status, email verification, MFA status, session data. - Team and permission data: roles, invitations, company assignment, platform administrator status. - Waitlist and consent data: email address, language, consent and notice version, status, consent, confirmation, withdrawal and deletion timestamps, and hashed confirmation and unsubscribe tokens. - Contract and billing data: plan, subscription status, Stripe customer ID, invoice and payment information. - Supply chain and order data: suppliers, merchants, items, SKUs, prices, orders, shipments, tracking, received quantities, discrepancies, returns. - Communication data: comments, notifications, email templates, contact form and support requests. - Documents and files: uploaded order, delivery, product or other B2B documents and metadata. - Integration data: BillBee username, API credentials, SKU mappings and API test results. - Usage and security data: IP address, user agent, timestamps, logs, error data, audit events and rate-limit data. - Technical data: cookies, session cookies, local storage data, device and browser information, performance and web-vitals data. ## 6. Purposes and Legal Bases ### Account, Authentication and Security Purpose: registration, login, email verification, password reset, MFA, session management, role checks, protection against misuse. Legal basis: Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(f) GDPR for legitimate security interests, Art. 6(1)(c) GDPR for legal obligations. ### Provision of the B2B Platform Purpose: management of merchant/supplier relationships, orders, catalogues, shipments, documents, comments and notifications. Legal basis: Art. 6(1)(b) GDPR where we provide contractual services; Art. 28 GDPR where we process customer data on behalf of the customer. ### Team Management and Invitations Purpose: inviting employees, suppliers and merchants, assigning them to company accounts and permissions, and preventing abusive repeat sends. Legal basis: Art. 6(1)(b) GDPR for pre-contractual steps and Art. 6(1)(f) GDPR for the requested B2B collaboration, secure access management and misuse prevention. Where an organisation enters a business email address, that address comes from the inviting organisation rather than directly from the data subject. The first message states the source, specific purpose, data categories, roles, legal bases, recipients, retention and rights. The notice sent is recorded as version `art14-de-v1-2026-07-30`. The link is valid for seven days; unaccepted invitation data is scheduled for automatic deletion on day eight. No more than two send events are permitted. Recipients may object to the invitation and further reminders through the unsubscribe link. Open invitations are then blocked and scheduled for deletion. A non-reversible hash of the normalised email address may be retained under Art. 6(1)(f) GDPR to the extent required to honour the objection and prevent further invitations. ### Billing and Payment Management Purpose: subscription management, checkout, payment processing, invoices, fraud and misuse prevention. Legal basis: Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR for statutory commercial and tax obligations, Art. 6(1)(f) GDPR for receivables management and misuse prevention. ### Email Communication Purpose: transactional emails, security emails, invitations, password reset, notifications and support responses. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. Marketing emails are sent only in accordance with Section 7 German Unfair Competition Act, in particular with consent or within legally permissible existing-customer communication. ### Launch Waitlist Purpose: a one-off product launch notification. We process the email address, language, consent version `launch-notification-v1-2026-07-30`, status and timestamps, and hashed confirmation and unsubscribe tokens. The legal basis is consent under Art. 6(1)(a) GDPR. After sign-up, a confirmation email is sent. Only entries confirmed within 48 hours may receive the launch notice; unconfirmed entries are automatically deleted when the confirmation window expires. Consent may be withdrawn at any time through the unsubscribe link. Confirmed entries are retained for no more than 365 days and no more than 30 days after the launch notice is sent; withdrawal makes deletion due immediately. ### Contact Form, Support and Customer Communication Purpose: handling demo, sales, support, privacy, security or legal requests. Legal basis: Art. 6(1)(b) GDPR for pre-contractual or contractual communication and Art. 6(1)(f) GDPR for general request handling and documentation. ### Support, Error Analysis and Operations Purpose: support handling, troubleshooting, auditing, monitoring, security, backup and recovery. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. ### Vercel Analytics and Speed Insights Purpose: measuring views of allowlisted public pages, technical performance and web vitals. The components load only after express analytics consent. The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR. The technical allowlist comprises home, pricing, contact, public legal documents and public documentation. Dashboard, admin, authentication, setup, API and invitation routes are excluded. Query strings and URL fragments are removed; email addresses, tokens, user, order, invitation and reference numbers are not submitted. ### Internal Usage Statistics Purpose: analysing which parts of the application are used, in order to prioritise development and operations. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in developing the platform in line with actual demand. Collection takes place exclusively on the server. No information is stored on or read from your terminal equipment, so Section 25 TDDDG does not apply and no consent is obtained. We record only views of dashboard routes by signed-in users, namely: - the **route shape** rather than the concrete address. Identifiers are replaced with placeholders before storage, so `/dashboard/buyer/orders/9f3c...` becomes `/dashboard/buyer/orders/[id]`, - the user ID, in order to determine the number of distinct users, - the timestamp. Query strings and URL fragments are discarded entirely. Browser prefetch requests are not counted. Public pages are not covered. The data is deleted automatically after 90 days. You may object to this processing under Art. 21 GDPR; please contact privacy@savien.io. ### Optional Integrations Purpose: connection with third-party providers such as BillBee, synchronisation of SKUs and stock levels. Legal basis: Art. 6(1)(b) GDPR and Art. 28 GDPR where we act on behalf of the customer. Activation is performed by the customer. ### Legal Obligations and Enforcement Purpose: statutory retention, responding to authority requests, enforcing and defending legal claims. Legal basis: Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. ## 7. Recipients and Service Providers We use service providers that process personal data on our instructions, on the basis of their own statutory obligations or as independent controllers. These include in particular: - Supabase: authentication, PostgreSQL database, storage, realtime. - Vercel: hosting, deployment, edge/serverless infrastructure, logs, Web Analytics, Speed Insights. - Stripe: payment processing, subscription management, invoices; depending on the processing, Stripe may also act as independent controller. - Resend: transactional email delivery. - BillBee: optional ERP integration where activated by the customer; depending on configuration, BillBee may act as independent controller or processor of the customer. - Further technical service providers as listed in the current Subprocessor List. The current [Subprocessor List](/en/subprocessors) is permanently available. Personal data may also be disclosed to authorities, courts, tax advisers, legal advisers or other recipients where legally required or necessary to enforce rights. ## 8. International Data Transfers savien can be used worldwide. Personal data may therefore be processed outside the EU/EEA, in particular where service providers, support processes or users are located outside the EU/EEA. For international transfers, we use appropriate safeguards under Chapter V GDPR, in particular: - Adequacy decisions of the European Commission, where available. - EU Standard Contractual Clauses pursuant to Art. 46 GDPR. - Additional technical and organisational safeguards where required. - The EU-US Data Privacy Framework where a US provider is certified accordingly. Customers processing data from other jurisdictions in savien are responsible for reviewing local transfer and privacy requirements to the extent they go beyond EU/German law. ## 9. Retention Periods We store personal data only as long as necessary for the respective purposes. - Account data: for the duration of the user account and thereafter according to statutory obligations or legitimate interests. - Invoices and accounting records: generally eight years; commercial and business correspondence generally six years, where the statutory requirements apply. - Customer data in the platform: while the customer uses the service or until deletion under the contract/DPA. - Unaccepted invitation data: valid for seven days and scheduled for automatic deletion on day eight; a necessary objection hash may remain for longer. - Launch waitlist: unconfirmed for no more than 48 hours; confirmed for no more than 365 days and no more than 30 days after the launch notice; withdrawals are scheduled for deletion immediately. - Error and security logs: only for the period required for operations, evidence and misuse prevention; the specific system period is maintained in the internal deletion policy. - Backups containing customer data after contract end: blocked from further use and overwritten or deleted in the regular cycle, no later than 90 days, unless a statutory retention obligation applies. - Support and contact requests: as long as required for handling, traceability and legal interests. Specific periods may vary depending on contract, plan, backup configuration and statutory obligations. ## 10. Cookies, Local Storage and Similar Technologies savien uses technically necessary cookies and similar storage technologies, in particular for login, session, security, language settings and service delivery. Access to information on terminal devices in Germany is governed in particular by Section 25 TDDDG. Technically necessary storage may rely on Section 25(2) No. 2 TDDDG. Where we use non-essential cookies, analytics, marketing or tracking technologies, we obtain prior consent where legally required. The current inventory and permanent withdrawal route are set out in the [Cookie and Storage Notice](/en/cookies). ## 11. Security We implement technical and organisational measures pursuant to Art. 32 GDPR, in particular access controls, role and permission models, encryption, row-level security, private storage buckets for documents, MFA support, logging, backups and remediation processes. A [public security overview and access process for the detailed TOMs](/en/toms) are permanently available. ## 12. Data Subject Rights Data subjects have the following rights under the GDPR, among others: - Access under Art. 15 GDPR. - Rectification under Art. 16 GDPR. - Erasure under Art. 17 GDPR. - Restriction of processing under Art. 18 GDPR. - Data portability under Art. 20 GDPR. - Objection under Art. 21 GDPR. - Withdrawal of consent with effect for the future. - Complaint to a supervisory authority under Art. 77 GDPR. Requests may be sent to `privacy@savien.io`. Where we process data on behalf of a customer, we generally forward requests to the relevant customer or assist the customer in handling them. ## 13. Right to Lodge a Complaint Data subjects have the right to lodge a complaint with a data protection supervisory authority. The competent authority may in particular be the authority at the controller's place of establishment or the data subject's place of residence. For savien at its Rinteln location, the following authority may be relevant: Der Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony) Postfach 221, 30002 Hannover, Germany Visitor address: Prinzenstraße 5, 30159 Hannover, Germany Phone: +49 511 120-4500 Email: poststelle@lfd.niedersachsen.de Website: [www.lfd.niedersachsen.de](https://www.lfd.niedersachsen.de) The authority provides its own online complaint form and asks that it be used in preference to other channels. ## 14. Obligation to Provide Data Certain data is required for registration, contract conclusion, platform use and billing. Without this data, we may be unable to provide savien in whole or in part. ## 15. Automated Decision-Making We do not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Art. 22 GDPR. Automated notices, prioritisation, alerts or status calculations serve platform functionality and can be reviewed by users. ## 16. Minors savien is directed at businesses and professional users. Use by minors is not intended. ## 17. Changes to this Privacy Policy We may update this Privacy Policy if features, service providers or legal requirements change. The current version will be made available in the application or on the website.