This privacy policy explains which personal data we (the "controller") process, for what purposes and to what extent, when you use our online offering at lavesy.de and the Lavesy application.
Controller
Henry MankeAn der Eveke 358511 LüdenscheidDeutschlandEmail: mail@lavesy.deOverview of processing
We process inventory data (e.g. names, addresses), contact data (e.g. email addresses), content data (e.g. entries in the application), usage data (e.g. pages visited, interest in content) and meta/communication data (e.g. device information, IP addresses) of customers, prospects, visitors and users of the online offering. Purposes are the provision of our contractual services, security measures, reach measurement and the administration of the service.
Relevant legal bases
- Performance of a contract (Art. 6(1)(b) GDPR): providing the Lavesy service, account management, billing.
- Legal obligation (Art. 6(1)(c) GDPR): commercial and tax retention duties.
- Legitimate interests (Art. 6(1)(f) GDPR): security, cookieless reach measurement, usability improvement (masked session recordings on the public pages), defence of legal claims.
- Consent (Art. 6(1)(a) GDPR): only where we ask for it explicitly (e.g. optional communications).
In addition to the GDPR, the German Federal Data Protection Act (BDSG) and the German TTDSG apply.
Security measures
We take appropriate technical and organisational measures in accordance with Art. 32 GDPR, including transport encryption (TLS), access controls, role-based permissions inside the application, audit logging and hosting on servers in the EU.
Transfers of personal data and international transfers
Data is transferred to service providers only where necessary for providing the service (see the list of subprocessors). Processing takes place in the EU; where a provider may transfer data to third countries (e.g. Stripe to the USA), this is based on the EU standard contractual clauses and/or an adequacy decision (EU–US Data Privacy Framework).
Storage and deletion
We delete personal data as soon as the purpose of processing no longer applies and no statutory retention periods require storage. Customers can export their data at any time and permanently delete their account, including all data, in the account settings (Art. 17 GDPR).
Rights of data subjects
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), as well as the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). To exercise your rights, contact us at mail@lavesy.de.
Business services (accounts, billing)
We process the data of our customers to provide the contractual services: account data (email address, password hash, company name where provided), plan and billing data, and the content customers store in the application (items, stock, suppliers, documents). Payment processing for paid plans is handled by Stripe; we do not store full payment card details ourselves. Legal bases: performance of a contract, legal obligations, legitimate interests.
Automated document processing (OCR and optional AI extraction)
A core part of the service is processing documents that users upload into the application (e.g. supplier invoices, delivery notes). We run optical character recognition (OCR) on our own infrastructure and extract structured fields (e.g. invoice number, amounts, line items); the results are reviewed and confirmed by authorised users before they are applied (human review). Optionally, extraction can be assisted by AI services. This AI-assisted extraction is disabled by default and only takes effect once a tenant enables it and provides their own API key. When enabled, the document content required for the analysis is transmitted to the respective AI provider (OpenAI or Anthropic), which may involve a transfer to a third country (USA) on the basis of the EU standard contractual clauses. Legal bases: performance of a contract (Art. 6(1)(b) GDPR) and legitimate interests (Art. 6(1)(f) GDPR).
Provision of the online offering and web hosting
The application is hosted on servers in the EU. When you access our services, the web server processes connection data (IP address, timestamp, requested resource, user agent) in server log files for the purposes of stability, security and abuse prevention; log files are deleted on a short rotation. Legal basis: legitimate interests.
Use of cookies
We only use technically necessary cookies (sign-in session, security, settings such as language and theme). These require no consent (§ 25(2) TTDSG). We do not use marketing or third-party tracking cookies, which is why no cookie consent banner is required.
Contact and enquiry management
When you contact us (e.g. by email), we process the information you provide to handle the enquiry. Legal bases: performance of a contract / pre-contractual measures and legitimate interests.
Web analytics, monitoring and optimisation
For reach measurement we exclusively use the open-source software Umami, which we operate on our own infrastructure. No analytics data is shared with third parties and no third-party services (such as Google Analytics) are used. Umami works without cookies and without comparable access to information on your device; no cross-device profiles are created. IP addresses are not stored — they are only processed transiently to derive a daily-rotating, non-reversible pseudonym and a coarse geographic region. Browsers with the "Do Not Track" setting enabled are excluded from measurement. As no cookies are set and no information is stored on or read from the device, no consent is required (§ 25(2) TTDSG); processing is based on our legitimate interests (Art. 6(1)(f) GDPR).
Session recordings and heatmaps (Umami Replays): on the public pages of our website (never in the logged-in application) we record usage interactions such as mouse movements, clicks and scrolling to improve usability and to generate aggregated heatmaps. Form inputs and text content are masked in your browser before transmission (strict masking); the recordings contain no clear-text data. Recordings are stored on our own infrastructure, are not shared with third parties and are automatically deleted after 30 days. Browsers with "Do Not Track" enabled are never recorded. Legal bases: legitimate interests (Art. 6(1)(f) GDPR); § 25(2) TTDSG.
Error monitoring
To detect and fix technical errors we use self-hosted error tracking (GlitchTip) on our own EU infrastructure. Error reports may contain technical metadata (browser, operating system, stack traces); they are not shared with third parties. Legal basis: legitimate interests.
Presence on social networks
We maintain profiles on social networks (e.g. LinkedIn, Instagram, TikTok) to communicate with users there. When you visit those profiles, the terms and privacy policies of the respective operators apply; data may be processed outside the EU. We receive at most aggregated statistics from these platforms.
Plug-ins and embedded content
Our online offering does not embed third-party content that transmits personal data to external providers (fonts, scripts and media are served from our own infrastructure).
For the complete, authoritative wording — including further sections that may apply — please refer to the German Datenschutzerklärung.