Skip to main content

Privacy Policy

Transparency and Data Protection

This Privacy Policy explains how personal data is processed in connection with this platform, the tenant-specific services offered through it, and the technical operation provided by Maped Solutions.

Overview

Protecting personal data is important to us. This Privacy Policy explains which party is responsible for which processing activity, for which purposes personal data is processed, and what rights users have.

Contact the Controller

Roles and data protection responsibilities

Role of the respective client

Where personal data is processed for the initiation, performance, and administration of the specific service offered, the respective client will generally be the controller. This includes, in particular, the operational handling of users, service requests, appointments, work orders, customer communication, invoicing, and similar service-related processes.

Role of Maped Solutions as technical operator

Maped Solutions technically operates the platform and supports secure operation, authentication, infrastructure, abuse prevention, and protective measures. Depending on the specific processing activity, Maped Solutions may act as a processor, an independent controller, or, where legally justified, a joint controller. It would therefore be inaccurate to describe every processing activity on the platform as being carried out exclusively on the client's instructions.

Identity and contact details

The following contact details identify the parties relevant for data protection in connection with this platform and the offered services.

Controller for the offered services

For the service relationship with end users, the responsible business shown below is generally the controller.

Business / Brand
Havenova
Legal name
TODO Havenova Legal Name
Address
TODO Havenova Legal Address
Phone
+49 000 000000

Technical platform operator

The following operator is responsible for the technical operation, security, and infrastructure of the platform.

Legal name
TODO Operator Legal Name
Represented by
TODO Operator Representative

Global accounts and service-specific profiles

The platform may use a central base account structure so that the same person can authenticate across multiple services or clients. However, separate relationships and profiles are maintained within each individual service. A profile for one service is therefore not automatically identical to all other uses of the platform.

Purposes and Legal Bases

Personal data is processed exclusively for lawful and clearly defined purposes.

Categories of Data

Depending on platform usage, the following data may be processed:

Third-Party Service Providers

This overview refers to technical providers that may be required to operate the platform (e.g., hosting, infrastructure, data storage, email delivery).

No providers are used for analytics or marketing.

Third-Party Service Providers
ProviderPurposeRegionPrivacy Policy
VercelFrontend hosting and operations, technical logsGlobal (region-dependent)Privacy Policy
Cloudflare R2Storage and delivery of static assetsGlobal (region-dependent)Privacy Policy
RenderBackend hosting, technical logsGlobal (region-dependent)Privacy Policy
MongoDB AtlasDatabase hostingGlobal (region-dependent)Privacy Policy
SendGridEmail deliveryGlobal (region-dependent)Privacy Policy

Security Measures

Appropriate technical and organizational measures pursuant to Art. 32 GDPR are implemented, including encrypted passwords, secure data transmission (HTTPS/TLS), role-based access control, and firewall/CDN protection.

Cookies and comparable technologies

This platform currently uses only strictly necessary cookies and comparable technical storage and access technologies. Where such technologies are required for authentication, security, session control, language settings, or other strictly necessary functions, they are used to ensure the secure operation of the platform. No analytics, marketing, or tracking technologies are implemented on this platform.

View Cookie Policy

Your Rights

Data subjects have the following rights under the GDPR:

Requests concerning the offered services should generally be addressed to the responsible business shown on this page. Maped Solutions may provide technical assistance in handling requests, in particular where they relate to platform-wide authentication, security, or account administration. Identification may be required, and responses are generally provided, or technically supported, within one month.

Deletion of a service-specific account

If you delete your account for a specific service or client, the related service-specific profile will generally be deleted and the active relationship with that service will be ended or deactivated. Any underlying base account structure used for authentication, or other active relationships with other clients or services, will generally remain unaffected. Where other functional domains still require minimal residual data, for example for invoicing, legal documentation, evidentiary purposes, or statutory retention obligations, only the data necessary for that separate purpose will be retained. Such residual data will not be used to recover or reactivate the deleted profile.

Data Retention

Personal data is retained only for as long as necessary for the relevant purpose. If a service-specific profile is deleted, that profile and the related active service relationship will generally be removed or deactivated. Where other functional domains require minimal snapshots or residual records for legal, evidentiary, documentation, or billing purposes, only that purpose-bound data will be kept for the required retention period. Such residual data is not sufficient to reconstruct the deleted profile.

The specific storage duration depends in particular on:

Once these purposes cease to apply, data will be deleted or, where possible, anonymized.

Additional Information under Art. 13 GDPR

International Data Transfers

If personal data is processed outside the EEA, this occurs exclusively with appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission. Where necessary, supplementary technical, contractual, or organizational measures are implemented to ensure an adequate level of data protection.

Changes to this Privacy Policy

This Privacy Policy may be updated where legal requirements, technical services, or actual processing activities change.

Legal References