Privacy Policy
Last updated: [DATE] · Effective from: [DATE]
This Privacy Policy explains how Ptolemy Technologies Ltd (“Servano”, “we”, “us”) collects, uses and protects personal data when you use servano.io and the Servano platform (the “Service”).
We are committed to processing personal data lawfully, transparently and in accordance with Regulation (EU) 2016/679 (GDPR).
1. Two different roles
Servano handles personal data in two distinct capacities. The distinction matters because different rules apply.
We are the controller for data about you as our customer: your account details, billing information, support conversations, and how you use the dashboard. This policy governs that data.
We are a processor for data inside the applications you host with us: whatever your own users submit to your sites, apps and databases. You remain the controller of that data. We process it only on your documented instructions, under the Data Processing Agreement (DPA) available at servano.io/legal/dpa. We do not access, analyse or use your application data for any purpose of our own.
2. Who we are
Controller:
Ptolemy Technologies Ltd
[REGISTERED OFFICE ADDRESS], London, United Kingdom
Registered in England and Wales, company number [COMPANY NUMBER]
Director: Evangelos Sampanis
[VAT NUMBER — if registered]
Contact for privacy matters: privacy@servano.io
We have not appointed a Data Protection Officer, as we do not meet the criteria in Art. 37 GDPR. Privacy enquiries are handled directly by the address above.
EU representative (Art. 27 GDPR): as we are established outside the European Union but offer services to data subjects in the EU, we have appointed the following representative for matters relating to EU data protection law:
[EU REPRESENTATIVE NAME]
[EU REPRESENTATIVE ADDRESS]
[EU REPRESENTATIVE EMAIL]
You may contact either us or our representative in relation to your rights under the GDPR.
3. What we collect and why
3.1 Account data
What: name, email address, password hash, company name (optional), team membership.
Why: to create and operate your account, authenticate you, and communicate about the Service.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Retention: for the life of your account, then 30 days after deletion.
3.2 Billing data
What: billing name and address, VAT number, subscription plan, invoice history, payment method token.
Why: to charge you, issue compliant invoices, and meet tax obligations.
Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
Retention: invoices and related records are kept for the statutory retention period applicable to us ([X] years), even after account deletion.
We never see or store full card numbers. Card data is collected and stored directly by Stripe (see §6).
3.3 Technical and usage data
What: IP address, browser and device information, pages visited in the dashboard, deployment and build logs, resource usage metrics.
Why: to operate and secure the platform, detect abuse, enforce plan limits, and troubleshoot.
Legal basis: contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in keeping the Service secure and functional.
Retention: access and security logs for 90 days; aggregated usage metrics for 24 months; build logs for 30 days.
3.4 Support communications
What: the content of emails and support tickets you send us.
Why: to answer you and improve our documentation.
Legal basis: contract and legitimate interests.
Retention: 24 months from the last message in the thread.
3.5 Website analytics
We do not use any website analytics or visitor-tracking scripts on servano.io. No third-party analytics provider receives data about your visit, and no analytics identifiers are stored on your device.
If this ever changes, we will ask for your consent first (Art. 6(1)(a)) and update this policy.
4. Cookies
We use only what is strictly necessary to run the Service:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you logged in | Session / 30 days if “remember me” |
| CSRF token | Protects against cross-site request forgery | Session |
| Cookie preference | Remembers your choices, if any are offered | 12 months |
These are exempt from consent requirements under Art. 5(3) of the ePrivacy Directive because they are strictly necessary for a service you have requested. We do not use advertising, retargeting or third-party tracking cookies.
5. Where your data is stored
All customer data and all hosted application data is stored on servers located in the European Union. Our production infrastructure is in Frankfurt, Germany. We do not replicate customer data outside the EU.
Ptolemy Technologies Ltd is established in the United Kingdom. Data at rest — your account data and all hosted application data — remains on servers in the European Union at all times. Administrative and support access from the United Kingdom takes place under the European Commission’s adequacy decision for the UK of 28 June 2021, as extended, which recognises the United Kingdom as providing an adequate level of data protection.
If that adequacy decision lapses or is annulled, we will implement Standard Contractual Clauses without interruption to the Service and update this policy accordingly.
6. Sub-processors
We use a small number of carefully selected providers. Each is bound by a data processing agreement.
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| [HOSTING PROVIDER] | Server infrastructure | Frankfurt, Germany (EU) | N/A — within EU |
| Stripe Payments Europe, Ltd. | Payment processing, invoicing | Ireland (EU) | N/A — within EU |
| Cloudflare, Inc. | DNS, DDoS protection, CDN | EU edge / global | EU SCCs + Data Privacy Framework |
| Resend | Transactional email delivery | [LOCATION] | [SCCs if outside EU] |
| [ERROR MONITORING, IF USED] | Error tracking | [LOCATION] | [BASIS] |
An up-to-date list is maintained at servano.io/legal/subprocessors. We will notify customers by email at least 30 days before adding or replacing a sub-processor, and you may object as set out in the DPA.
7. Who else sees your data
We do not sell personal data. We do not share it for advertising. We disclose it only:
- to the sub-processors listed above, strictly to operate the Service;
- to professional advisers (accountants, lawyers) under confidentiality;
- where required by law, court order, or a valid request from a competent authority — and only to the extent legally required. Where we are permitted to notify you of such a request, we will;
- in the event of a merger, acquisition or asset sale, in which case you will be notified before your data becomes subject to a different privacy policy.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- erasure of your data, subject to our legal retention duties (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- data portability — receive your data in a structured, machine-readable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21);
- withdraw consent at any time, where processing is based on consent (Art. 7(3)), without affecting prior lawful processing.
To exercise any of these, email privacy@servano.io. We respond within one month, extendable by two further months for complex requests, in which case we will tell you why.
Right to complain: you may lodge a complaint with your local supervisory authority. If you are in the European Economic Area, that is the authority of your country of residence or place of work. Our supervisory authority in the United Kingdom is the Information Commissioner’s Office (ico.org.uk).
9. Security
We apply appropriate technical and organisational measures, including:
- encryption in transit (TLS 1.2+) for all connections to the Service;
- encryption at rest for databases and backups;
- key-based SSH access only, with password authentication disabled on all production systems;
- host firewalls and automated intrusion prevention;
- least-privilege access — production access is limited to personnel who need it;
- automatic security updates on all production systems;
- daily encrypted backups held in the EU, with tested restore procedures;
- isolation between customer workloads at the container level.
No system is perfectly secure. We do not claim otherwise.
Breach notification: where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify affected customers without undue delay where the risk is high.
10. Data deletion
You may delete your account at any time from the dashboard. On deletion:
- your applications, databases and files are destroyed within 30 days;
- backups containing your data are overwritten within 35 days on the standard backup rotation;
- account and technical data is erased within 30 days;
- billing records are retained for the statutory period (§3.2).
We can provide a written confirmation of deletion on request.
11. Children
The Service is not directed at children. You must be at least 16 years old, or the age of digital consent in your country, to create an account. We do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@servano.io and we will delete it.
12. Changes to this policy
We may update this policy. If changes are material, we will notify account holders by email at least 30 days before they take effect. The “last updated” date at the top always reflects the current version. Previous versions are available on request.
13. Contact
Privacy enquiries: privacy@servano.io
Postal: Ptolemy Technologies Ltd, [REGISTERED OFFICE ADDRESS], London, United Kingdom
Abuse reports: abuse@servano.io