Privacy policy
This is a translation for your convenience. In case of doubt, the German version is legally binding.
Last updated: 5. September 2026
This policy describes which data we process when you use PrivadiOffice, why we do so and what rights you have. It applies to office.privadi.de and the software behind it.
1. Who is responsible
Privadi, Martin Schröder Ernst-Kromayer-Straße 28 06112 Halle (Saale) Telefon: 0155/65699969 E-Mail: info@privadi.net
There is no data protection officer; the legal requirements for appointing one are not met.
2. The most important point first
PrivadiOffice deliberately separates two kinds of data.
Your own data — your account, your company details, your settings. We are responsible for this, and this policy is about it.
The data of your customers and employees that you enter into PrivadiOffice. You are responsible for this. We only store it for you and do not look into it. This is governed by the data processing agreement.
There is no access in PrivadiOffice through which we could look into our users' customer data, and none will be built. If you need help and we have to look into your account, this is only possible if you expressly and temporarily allow it. Every such access is logged.
3. Where the data is stored
On a server in Germany, operated by STRATO AG, Pascalstraße 10, 10587 Berlin. The connection is encrypted (TLS). No transfer to countries outside the EU takes place.
A data processing agreement pursuant to Art. 28 GDPR is in place with the server provider.
4. When the website is accessed
When the site is accessed, technical details transmitted by your browser are processed: the address requested, the time, the amount of data transferred, the referring page, browser and operating system identifiers, and the IP address. This is technically necessary to deliver the page and serves the security of operations.
The legal basis is Art. 6(1)(f) GDPR. These logs are deleted after 7 days at the latest.
5. Visitor counting without cookies
We count visits to the home page ourselves. We only store the date, the page requested and — if available — the page a visitor came from.
Not stored: IP address, identifiers of any kind, cookies or other features that would allow a visitor to be recognised. Nothing is stored on or read from your device. No profiling takes place.
No external service such as Google Analytics is used. The legal basis is Art. 6(1)(f) GDPR.
The same count also covers the brand website privadi.com and the brokerage portal privadi.de, both operated by the same controller. The figures are held here together and are distinguished only by a prefix before the page address. Here too, no IP addresses and no identifiers are stored.
6. Cookies
PrivadiOffice sets one technically necessary cookie: the session cookie for signing in. Without it you could not log in. It contains no advertising or analytics features.
How long it is valid is your choice when signing in. Without the “Stay signed in” checkbox, PrivadiOffice signs you out after one hour without activity. With it, the sign-in stays valid for up to 30 days and is extended with every visit. “Sign out” and deleting your browser data end it at any time; the checkbox only applies to the browser or app where you set it.
There are no advertising cookies and no third-party cookies. That is why no cookie banner appears.
7. Your account
For an account we process: email address, password (only as a hash, never in plain text), name, company details, address, contact details, tax number and VAT ID, bank details for printing on invoices, your settings, and the time of registration and of last use.
The legal basis is Art. 6(1)(b) GDPR — performance of the contract.
Optional, for the tax estimate: if you enter tax calculation details in the settings — legal form, your municipality's trade tax rate, joint assessment with a partner, other income, church tax rate — these are stored in your account. They serve solely to show you a rough tax figure inside the program. The calculation runs on our server; no transfer to tax authorities, tax advisers or any other third party takes place. These details are voluntary; without them the program uses standard assumptions. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time by clearing the fields.
Retention: for the duration of the contract. After the subscription ends, your account and content remain for another three months; during that time you can download your data, all other functions are locked. After that, account and content are deleted automatically and irreversibly — we remind you by email 14 days and one day beforehand. If you delete your account yourself, this happens immediately after your confirmation by email. Excepted are records subject to statutory retention periods — invoices issued to you must be kept for up to ten years.
8. One account for PrivadiOffice and the brokerage portal (businesses)
The brokerage portal at privadi.de and PrivadiOffice are operated by the same controller (see item 1) and have kept one shared account for businesses since 4 September 2026: you sign in to both services with the same email address and the same password. There is no redirection. Private customers of the portal have no PrivadiOffice account; we receive no data about them.
The account is held here at PrivadiOffice. When a business registers as a partner in the portal, its account is created here; the name, email address, password, company name and the time of consent to the terms, the privacy policy and the data processing agreement are transmitted. We store the password only as a hash, never in plain text. Each time you sign in to the portal, the portal passes your email address and password to PrivadiOffice for verification; changes to the password or email address made in the portal are carried out here and apply to both services.
If you sign in here with a business account that previously existed only in the portal, PrivadiOffice verifies the password with the portal and creates the shared account at that moment; the portal transmits the name and company name. A business from the portal receives the Equip plan; we ask for consent to the data processing agreement on the first visit.
The Sign in with PrivadiOffice button in the portal remains: if you click it, we confirm to the portal via a signed token (valid for 60 seconds, redeemable once) that you are signed in here; email address, name and booked plan are transmitted, not the password. Sub-accounts for staff cannot use this route.
If your business has a partner account in the portal, PrivadiOffice shows you in the overview the number of open tenders, enquiries and awarded jobs from the portal; for this PrivadiOffice queries the portal with your email address, and the portal returns numbers only, no customer data. All transfers take place exclusively within the same server; the data do not leave it. This is not a disclosure to third parties. Both services keep separate data holdings for their content. The legal basis is Article 6(1)(b) GDPR.
Deletion: item 7 applies to the shared account. When your account is deleted here — at your request or automatically three months after the end of the subscription — your access, quotes, messages and data releases in the portal are deleted in the same step, and your business is no longer visible to anyone there. Your business entry and your documents are then kept in the portal for three years so that claims arising from brokered jobs can still be settled, and are then deleted automatically (details in the portal's privacy policy, item 7). There is no separate cancellation.
9. Sending email
If you send invoices or quotes from PrivadiOffice, this runs via the outgoing mail server of your own email provider, which you enter in the settings. The message therefore comes from you, not from us. Your credentials are stored encrypted in your account.
If you do not enter a mailbox of your own, then since 29 August 2026 we send the message via our own sender noreply@privadi.net instead. Your company name appears as the sender and replies from your customers go to your company address. In doing so our email provider processes your customer's name and address and the attached invoice; to that extent it is our processor. We do not store the messages.
Only for system messages concerning you personally — such as the link to reset your password — do we use our own sender.
If you set up a recurring invoice, the invoice is created automatically on the day you specify and — if you have set it that way — goes to the stored customer without further action. For this, a time-controlled process runs on the server once a day to check which series are due. No data is processed beyond what a manually sent invoice involves; only the trigger is the clock instead of your click. You remain responsible for the sending.
Since 29 August 2026 the program asks for the recipients before sending. The address stored with the customer is pre-filled; you can change it for this one email, add further addresses or send a copy to yourself. These addresses are used only for this delivery and are not stored — an address is changed permanently only with the customer record.
10. Data of your customers and employees
What you record in PrivadiOffice about your customers and employees is processed by us exclusively on your behalf and according to your instructions. A data processing agreement pursuant to Art. 28 GDPR applies between you and us, which you conclude on registration and can view at any time.
Important for you: towards your customers and employees, you are the controller. You must therefore inform them that you process their data — your own privacy policy covers this, not ours.
For each employee you can file documents under „Documents“ that are generated from their master data — employment contract and personnel form. They are stored as text in your account, on the same server as your other data, and are not viewed by us. If you delete the employee, their documents are deleted along with them; you can remove individual documents at any time. How long you must retain personnel records follows the tax and social security periods that apply to you as the employer — that is your decision, not ours.
If you use time tracking, you process your employees' working hours: the start and end of each assignment, the site it is assigned to, the hours calculated from this, and every subsequent change with its time and author. The change log is not an extra but follows from your recording obligation under § 17 MiLoG. The monthly payroll preparation for your tax adviser and the labour cost preview are based on the same data; once a month has been closed, it can no longer be changed unnoticed.
You also record absences: holiday, sick leave, unpaid leave and public holidays, each with a period, the state of the request and a free-text note. If your employees report something themselves through their personal access, the entries are created there. The fact that someone was ill on particular days is health data within the meaning of Art. 9 GDPR. You collect it as the controller and only in so far as you need it for continued pay, holiday planning and your recording obligations; for us as processor, Art. 9(2)(b) GDPR applies together with the data processing agreement. Diagnoses do not belong in the note field — none of these purposes require them.
Times and absences remain stored until you delete the employee. Which retention periods apply to you — two years for the records under § 17 MiLoG, for example — follows from your own obligations as an employer.
Since 29 August 2026 the program records two further points in time for each invoice: when it was last printed and when it was sent to your customer by email. Both describe your own action and are not additional information about your customer; they appear in the preview panel next to the invoice list and are deleted together with the invoice.
If you change a recorded payment or undo it, the program records that too: the time, the account that was signed in, and the previous value. This is not an evaluation of your behaviour but the traceability that proper accounting principles require for corrections. These entries are deleted together with the invoice.
Since 29 August 2026 you can also record customer payments in instalments. For each payment the program stores the amount, the date received, the payment method (cash, bank, card or other), an optional note and the account that recorded it. This information relates to your customer's payment behaviour and is deleted together with the invoice. For your own expenses the program additionally stores the payment date and payment method; that concerns your business, not your customers.
Since 30 August 2026 there is a cash book. It holds your own cash transactions with date, type, amount, tax rate, purpose, receipt reference and running balance; where an entry arose from a customer payment, the invoice number is shown with it. This concerns your business; no new information about your customer is added. Note: cash entries are never changed and never deleted — a correction is added as a separate counter-entry, as German bookkeeping law requires. The cash book is deleted only together with your account.
Also since 30 August 2026 you can record that a customer owes the VAT themselves under the reverse charge rule, and store the validity of their exemption certificate. Both are tax details about your business partner that you need in order to issue a correct invoice; they are deleted together with the customer.
Customer app (since 4 September 2026, password sign-in since 5 September 2026): Your customers can sign in to a dedicated app and see their appointments, the invoices you released and news there. To sign in they enter their customer number, their email address and a password of their own choosing. They set the first password via a one-time link that we send to exactly the email address stored for them in your account; the same route applies to a forgotten password. For this we store the time of sign-in, the time the password was set and check values of the password, the link and the session — never the password and never the link itself. Failed attempts are counted in memory for a few minutes to prevent guessing. As the company you can open the app from your overview in the view of one of your customers; you only see data you are responsible for anyway. We do not record how often a customer opens the app or whether they looked at an invoice. You remain responsible for this data; we process it on your behalf.
Appointment messages and advertising (since 5 September 2026): When a customer books an appointment we send a message to you in your name; when you confirm or decline, a message goes to the customer. If you have connected your calendar, we write a confirmed appointment with the customer's name and contact details into that calendar. Customers with an account in the app can also receive news by email; the default is “yes” and relies on section 7(3) of the German Unfair Competition Act (advertising for your own similar services to existing customers). Every customer can switch this off in the app at any time, every message contains an unsubscribe link, and we record the time of any objection. You remain responsible for content and sending.
Appointment reminders (since 5 September 2026): Before a confirmed appointment we send up to two reminders to your customer in your name — one week and one day beforehand, depending on your settings. The message contains the date and time as well as the appointment as an attached calendar file. A time-controlled process runs on the server once a day for this; for each appointment we record which reminder has already been sent so that nobody is contacted twice.
11. Disclosure to third parties
We do not sell data and do not pass it on for advertising purposes. Disclosure only takes place to service providers necessary for operations who work on our behalf — currently only our server provider — and where we are legally obliged to do so.
Calendar connection (since 4 September 2026, optional): If you connect your Apple Calendar (iCloud) in the settings, we store your Apple ID and the app-specific password created for it at Apple in encrypted form in your account. The server uses it to retrieve the entries of the calendar you selected from Apple Inc. and to create booked appointments there; in doing so, your customer's name, contact details and requested time end up in your calendar at Apple. Apple is your provider here, not ours — Apple's terms apply to data protection in your Apple account. If you disconnect, we delete Apple ID and password from your account immediately; the entries in your calendar remain at Apple.
12. Your rights
You have the right at any time to:
- access the data stored about you (Art. 15 GDPR)
- rectification of incorrect data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- receive your data in a common format (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
An informal message to info@privadi.net is sufficient.
You may also lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg.
13. Changes to this policy
If something changes in PrivadiOffice that affects how data is handled, we update this policy in the same step and raise the date above. Logged-in users then see a marker next to the „Privacy“ entry in the software until they have opened the policy once.