Privacy policy
This is a translation for your convenience. In case of doubt, the German version is legally binding.
Last updated: 25. August 2026
This policy describes which data we process when you use PrivadiOffice, why we do so and what rights you have. It applies to office.privadi.de and the software behind it.
1. Who is responsible
Privadi, Martin Schröder Ernst-Kromayer-Straße 28 06112 Halle (Saale) Telefon: 0177/480 90 10 E-Mail: info@privadi.net
There is no data protection officer; the legal requirements for appointing one are not met.
2. The most important point first
PrivadiOffice deliberately separates two kinds of data.
Your own data — your account, your company details, your settings. We are responsible for this, and this policy is about it.
The data of your customers and employees that you enter into PrivadiOffice. You are responsible for this. We only store it for you and do not look into it. This is governed by the data processing agreement.
There is no access in PrivadiOffice through which we could look into our users' customer data, and none will be built. If you need help and we have to look into your account, this is only possible if you expressly and temporarily allow it. Every such access is logged.
3. Where the data is stored
On a server in Germany, operated by STRATO AG, Pascalstraße 10, 10587 Berlin. The connection is encrypted (TLS). No transfer to countries outside the EU takes place.
A data processing agreement pursuant to Art. 28 GDPR is in place with the server provider.
4. When the website is accessed
When the site is accessed, technical details transmitted by your browser are processed: the address requested, the time, the amount of data transferred, the referring page, browser and operating system identifiers, and the IP address. This is technically necessary to deliver the page and serves the security of operations.
The legal basis is Art. 6(1)(f) GDPR. These logs are deleted after 7 days at the latest.
5. Visitor counting without cookies
We count visits to the home page ourselves. We only store the date, the page requested and — if available — the page a visitor came from.
Not stored: IP address, identifiers of any kind, cookies or other features that would allow a visitor to be recognised. Nothing is stored on or read from your device. No profiling takes place.
No external service such as Google Analytics is used. The legal basis is Art. 6(1)(f) GDPR.
6. Cookies
PrivadiOffice sets one technically necessary cookie: the session cookie for signing in. Without it you could not log in. It contains no advertising or analytics features.
How long it is valid is your choice when signing in. Without the “Stay signed in” checkbox, PrivadiOffice signs you out after one hour without activity. With it, the sign-in stays valid for up to 30 days and is extended with every visit. “Sign out” and deleting your browser data end it at any time; the checkbox only applies to the browser or app where you set it.
There are no advertising cookies and no third-party cookies. That is why no cookie banner appears.
7. Your account
For an account we process: email address, password (only as a hash, never in plain text), name, company details, address, contact details, tax number and VAT ID, bank details for printing on invoices, your settings, and the time of registration and of last use.
The legal basis is Art. 6(1)(b) GDPR — performance of the contract.
Optional, for the tax estimate: if you enter tax calculation details in the settings — legal form, your municipality's trade tax rate, joint assessment with a partner, other income, church tax rate — these are stored in your account. They serve solely to show you a rough tax figure inside the program. The calculation runs on our server; no transfer to tax authorities, tax advisers or any other third party takes place. These details are voluntary; without them the program uses standard assumptions. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time by clearing the fields.
Retention: for the duration of the contract. After the subscription ends, your account and content remain for another three months; during that time you can download your data, all other functions are locked. After that, account and content are deleted automatically and irreversibly — we remind you by email 14 days and one day beforehand. If you delete your account yourself, this happens immediately after your confirmation by email. Excepted are records subject to statutory retention periods — invoices issued to you must be kept for up to ten years.
8. Sending email
If you send invoices or quotes from PrivadiOffice, this runs via the outgoing mail server of your own email provider, which you enter in the settings. The message therefore comes from you, not from us. Your credentials are stored encrypted in your account.
Only for system messages concerning you personally — such as the link to reset your password — do we use our own sender.
If you set up a recurring invoice, the invoice is created automatically on the day you specify and — if you have set it that way — goes to the stored customer without further action. For this, a time-controlled process runs on the server once a day to check which series are due. No data is processed beyond what a manually sent invoice involves; only the trigger is the clock instead of your click. You remain responsible for the sending.
9. Data of your customers and employees
What you record in PrivadiOffice about your customers and employees is processed by us exclusively on your behalf and according to your instructions. A data processing agreement pursuant to Art. 28 GDPR applies between you and us, which you conclude on registration and can view at any time.
Important for you: towards your customers and employees, you are the controller. You must therefore inform them that you process their data — your own privacy policy covers this, not ours.
For each employee you can file documents under „Documents“ that are generated from their master data — employment contract and personnel form. They are stored as text in your account, on the same server as your other data, and are not viewed by us. If you delete the employee, their documents are deleted along with them; you can remove individual documents at any time. How long you must retain personnel records follows the tax and social security periods that apply to you as the employer — that is your decision, not ours.
If you use time tracking, you process your employees' working hours: the start and end of each assignment, the site it is assigned to, the hours calculated from this, and every subsequent change with its time and author. The change log is not an extra but follows from your recording obligation under § 17 MiLoG. The monthly payroll preparation for your tax adviser and the labour cost preview are based on the same data; once a month has been closed, it can no longer be changed unnoticed.
You also record absences: holiday, sick leave, unpaid leave and public holidays, each with a period, the state of the request and a free-text note. If your employees report something themselves through their personal access, the entries are created there. The fact that someone was ill on particular days is health data within the meaning of Art. 9 GDPR. You collect it as the controller and only in so far as you need it for continued pay, holiday planning and your recording obligations; for us as processor, Art. 9(2)(b) GDPR applies together with the data processing agreement. Diagnoses do not belong in the note field — none of these purposes require them.
Times and absences remain stored until you delete the employee. Which retention periods apply to you — two years for the records under § 17 MiLoG, for example — follows from your own obligations as an employer.
10. Disclosure to third parties
We do not sell data and do not pass it on for advertising purposes. Disclosure only takes place to service providers necessary for operations who work on our behalf — currently only our server provider — and where we are legally obliged to do so.
11. Your rights
You have the right at any time to:
- access the data stored about you (Art. 15 GDPR)
- rectification of incorrect data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- receive your data in a common format (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
An informal message to info@privadi.net is sufficient.
You may also lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg.
12. Changes to this policy
If something changes in PrivadiOffice that affects how data is handled, we update this policy in the same step and raise the date above. Logged-in users then see a marker next to the „Privacy“ entry in the software until they have opened the policy once.