Privacy and data protection

Privacy Policy

How Servicify handles personal data for enquiries, accounts, orders, website projects and security.

Version
2026-08-06
Effective date
Published

Data we use

Types of personal data we collect and how we handle it.

Why we use it

Purposes and legal bases for our processing.

Your choices

Rights you have and how to exercise them.

Contact

How to reach us about privacy and data.

Our role with your data

Servicify as controller

For our own services, website and direct business operations.

We determine purposes and means of processing.

Servicify as processor

When we build and host customer websites on your behalf.

We process data on your instructions.

1. About this notice

This Privacy Policy explains how Servicify handles personal data when you visit our website, contact us, request a website concept, create or use an account, place or manage an order, work with us on a website project, request support, or exercise a privacy right.

Personal data means information relating to an identified or identifiable person. This notice applies to Servicify's own processing as a controller. When we process personal data contained in a customer's website or project only on that customer's documented instructions, the customer normally acts as controller and Servicify acts as processor or subprocessor under the applicable agreement and data processing terms.

2. Who is responsible for your data

The controller for the processing described in this policy is:

Legal name: FOP Ovcharenko Yuriy Valentynovych Registration details: Individual entrepreneur registered in Ukraine; taxpayer identification number 2820218979. Postal address: 129B Oleksandra Polia Avenue, Dnipro, 49055, Ukraine. Privacy contact: support@servicify.ai

3. Personal data we handle

When you contact us or request concepts, we process your name, email, business description and the additional project information and files you choose to provide. These may include your business website, audience, goals, requirements, contact details, feedback and supplied content. Required form fields are identified on the form; without them we cannot assess the request.

The concept request is saved for administrator review. Its fields and attachment count are included in an email notification; uploaded file bodies are not attached to that notification. Submitting the form does not create an order or start automatic generation.

When you use an account or demo, we process the account, authentication, access and security information needed for that function. Requests to our servers can contain IP addresses, browser details, timestamps and technical errors. Abuse controls use IP-derived keyed identifiers; these are pseudonymous, not necessarily anonymous.

If you explicitly check a domain on Modules & Pricing, the entered domain is sent to our Central service and then to Namecheap. The provider request uses our server's authentication and IP address, not your visitor IP as its caller address. Our quota records contain a timestamp and a keyed caller identifier, not the entered domain or raw IP. This check does not register, reserve or buy a domain.

We receive information directly from you, your authorised representative and the technical services described here. Business information from a website or other public source may also be relevant when you supply it as context for a requested concept; public availability does not remove personal-data protection. This notice does not authorise an unrelated outreach campaign or unrestricted public-source profiling.

If you later enter a service agreement, the agreed service may require project, approval, contract, handover, support and legally required accounting records. Online checkout and payment collection are currently disabled. 2Checkout is planned but not integrated and does not currently receive data through a Servicify checkout. Do not send payment-card details in our forms or email.

Please do not send sensitive personal information, government identifiers or children's data unless we have expressly agreed a lawful need and safeguards. Use fictional data in the isolated demo; do not enter real customer records, passwords, confidential information or production credentials.

4. Why we use personal data and our legal bases

Where the GDPR applies, we distinguish the following purposes and bases:

• Answer an enquiry and assess a requested concept: steps you request before a contract, or our legitimate interest in answering a business representative's enquiry where the individual is not personally the contracting party.

• Preserve requested configuration and preferences, provide a demo or authenticated access, and perform an explicit domain check: provide the requested function; where this is not a necessary contractual step, our legitimate interest in operating a usable service. The browser-storage purposes are explained in section 6.

• Protect forms, accounts, infrastructure and provider capacity: our legitimate interest in preventing abuse, controlling access and investigating security incidents.

• Provide and support agreed website work: contract performance where you are the contracting party; otherwise our legitimate interest in communicating with authorised business contacts. Processing a customer's own website data on instructions is addressed separately in section 5.

• Handle privacy rights and comply with applicable legal requirements: the relevant legal obligation. Handle complaints and legal claims: the applicable obligation or our legitimate interest in establishing, exercising or defending a claim.

We use only data needed for the relevant purpose and consider the effect of legitimate-interest processing on individuals. You may object as described in section 11. A necessary-storage exemption is separate from the legal basis for processing personal data; it is not an exemption merely because a technology is first-party.

No analytics or advertising service is currently used on our own website. Optional marketing or tracking is not authorised by this notice. Any future activity requiring consent must explain its purpose and provide the appropriate choice before it begins. Selecting Understood on the storage notice is not consent.

Future payment processing will be explained before checkout is introduced. This notice does not activate payment collection or create a new payment, cancellation or refund term.

5. Customer website data and our processor role

The customer controls the purposes and means of processing personal data on the customer's website. If Servicify hosts, administers, troubleshoots, backs up, or otherwise accesses that data on the customer's documented instructions, Servicify acts as processor. If the customer is itself a processor, Servicify may act as subprocessor.

That processing is governed by the applicable Order/SOW and data processing addendum, including the subject matter, duration, purposes, data categories, data subjects, security measures, subprocessors, assistance, return or deletion, and any international-transfer mechanism. After a no-maintenance handover, Servicify is not described as an ongoing processor unless it still hosts, backs up, monitors, supports, or can access the data.

The customer remains responsible for its own privacy notice, lawful bases, collection choices, instructions, and responses to its website users. A request about data controlled by a Servicify customer may need to be referred to that customer.

6. Cookies and similar technologies

Our own public and customer surfaces use browser storage for requested functions, security and continuity:

• Session cookies maintain form security and authenticated access. Their duration depends on the relevant session. A remember-me cookie may be set by a login flow that offers that choice; the configured duration is 14 days. Logging out or clearing cookies can end access earlier.

• The servicify_locale cookie remembers an explicit language choice for about one year. Explicit reselection renews it; an ordinary visit does not. A language preference does not imply that every language has published translated content.

• The pricing configurator uses sessionStorage, under servicify.modulesPricing.estimate.v2, to keep package, module and hosting/domain-source choices through navigation and reload in the same tab. It can write the initial configuration after a successful automatic estimate response, before you change a selection. The requested domain and its availability result are not saved in that record.

• The Visual Editor stores its selected device profile in sessionStorage. This keeps the chosen view after a reload without changing the website's published content.

• An isolated demo uses the __Host-servicify_demo_resume cookie and an authentication session. The resume lifetime is tied to the demo and can renew during demo workspace/editor activity, with a configured idle window of about 30 minutes. Ordinary public-page visits do not extend it. Cookie expiry and server-side data cleanup are distinct.

• Understood stores only the notice version in the servicify_storage_notice cookie for up to 180 days. It is shared across servicify.ai and its subdomains, including future subdomains that use this notice. It contains no personal identifier and grants no account access or consent. A localStorage fallback (or sessionStorage if needed), servicify.storageNotice.ack, contains the notice version and an expiry time. Reading the acknowledgement does not renew it. An older local acknowledgement can be migrated when its original site is revisited, within a limited migration period. Expiry, a materially changed notice version, cleared or blocked storage, private browsing or a different browser/profile can make the notice appear again. If storage is blocked, dismissal may last only for the current page.

SessionStorage normally ends with the tab's session; browser restore features can affect this. You can manage cookies and browser storage in your browser. Blocking storage may affect login, form protection and remembered choices. The Privacy Policy footer link keeps this explanation available.

We do not currently use analytics or advertising cookies. Namecheap domain checks are server-to-server requests initiated by your click, not a provider script or embed. 2Checkout is not integrated. Any future third-party technology must be assessed on its actual purpose and behaviour; payment functionality does not automatically exempt all provider technologies from consent requirements.

7. Who receives personal data

Namecheap provides our hosting and Namecheap Private Email. Hosting supports our website, database, private request files and technical operations. Private Email handles our correspondence and form-notification messages. Namecheap's published hosting terms describe its processor role for hosted customer data; its own account administration and legal obligations are also governed by its privacy terms.

Namecheap also receives the domain you explicitly ask us to check. We do not send it your contact-form contents or use your visitor IP as the provider caller address in that check.

Namecheap's Private Email terms permit security screening that may involve OpenAI moderation. They separately describe an optional AI Assistant for email text. Those provider capabilities are not evidence that a particular Servicify message has been processed by them. We do not describe email delivery as excluding all downstream automated processing.

We do not manually distribute customer information to additional outside tools or recipients as part of our current practice. This does not exclude the hosting, email and domain-provider processing described above, or disclosure required by law. 2Checkout is a planned recipient only; no Servicify checkout currently sends it data. If the processing changes, the relevant information must be updated before that change is introduced.

Authorised Servicify personnel use the information for the stated purposes. Disclosure to authorities or professional advisers may be necessary for a specific legal obligation or claim; this is not a statement that such a disclosure has occurred.

8. Where data is processed

Servicify operates from Ukraine and uses Namecheap, a US provider, for hosting, Private Email and the explicit domain check described above. Namecheap's published datacentre information locates Private Email in Phoenix, United States. These services involve processing outside the European Economic Area.

Namecheap publishes a data processing addendum for covered hosting services, including standard contractual clauses for applicable EU transfers: https://www.namecheap.com/legal/universal/data-processing-addendum/. This describes the provider's contractual framework; it is not a claim that every service or onward transfer has been individually verified.

For information about the safeguards applicable to your data and how to obtain a copy, contact support@servicify.ai. Visiting the site or selecting Understood is not consent to an international transfer.

9. How long we keep personal data

For enquiries that do not become orders, we have adopted a retention period of six calendar months after the last meaningful contact. This covers enquiry and contact-form details, supplied files and related correspondence. Active discussions, agreed orders or projects, and records still required for a specific legal obligation or justified legal hold are excluded while that need continues; an exception is not a reason for indefinite retention. Applying this period requires a review of contact history and any exclusion. Automated scheduled deletion is not yet enabled. Removing an application record does not itself remove related mailbox or backup copies. You can ask about or request deletion of your data using the contact in section 14.

For account and project records, relevant factors include the duration of the service, the work and support still required, agreed handover or return instructions, and applicable legal, accounting or claims requirements. Security and support records must be assessed against the incident or request they document. Technical log rotation is not a universal retention period for all personal data.

Browser-storage durations are described in section 6. Domain quota records have a logical 24-hour expiry. Cleanup is bounded and occurs during later requests, so expired records can remain longer during inactivity. They do not contain the queried domain or raw IP.

Recovery and change-backup copies can contain earlier data and are separate from working records. Erasure from an active record does not mean every recovery copy is erased immediately. A complete production backup, retention and verified recovery programme is still being prepared for project launch; existing recovery copies already exist. This does not suspend privacy rights or other applicable retention duties.

10. How we protect personal data

Current controls include HTTPS, authenticated administrative access, private storage for uploaded request files, form-security checks and bounded abuse controls. Access is restricted through application and operating-system permissions.

Existing recovery and change-backup tools are not a guarantee of complete production recovery. No internet service can guarantee absolute security. Where a personal-data breach requires notification, the applicable controller or processor duties apply.

11. Your privacy rights

Where the GDPR applies, and subject to its conditions and exceptions, you may ask us to:

• confirm whether we process your personal data and provide access to it;

• correct inaccurate or incomplete data;

• erase data;

• restrict processing;

• provide eligible data in a portable format;

• stop processing based on a particular situation where the basis is a legitimate interest or public task;

• stop direct marketing at any time;

• withdraw consent at any time where processing relies on consent, without affecting processing already carried out lawfully;

• obtain the safeguards-related information available for a restricted international transfer;

• not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where law permits it with required safeguards.

To make a request, contact support@servicify.ai. We may ask for information reasonably needed to verify identity and protect another person's data. Under the GDPR, we normally respond within one month. The period may be extended by up to two additional months for a complex request or multiple requests, but we will explain an extension within the first month. Rights may not apply in every circumstance, and we will explain a lawful refusal or limitation.

If Servicify handles the relevant data only for a customer as processor, we will direct the request to that customer or assist the customer as required by the applicable agreement and law.

12. Automation and human review

Software validates forms, filters abuse, controls authentication and request rates, and retrieves domain availability when you ask for it. These controls can reject or limit a technical request. A concept submission does not automatically create an order or start generation. Contact support@servicify.ai if a technical restriction prevents a genuine request.

Servicify uses software-assisted design and development, with review before delivery. Our current practice is not to manually send customer information to additional external tools, as explained in section 7. Namecheap's email security processing is a separate provider flow described there.

The technical controls described here operate requests and access; they do not decide a customer's contractual rights or obligations. Any future use of solely automated decision-making with legal or similarly significant effects would require specific information about its purpose, logic, effects and safeguards before introduction.

13. Changes to this policy

During development, before project launch or binding customer use, we may update the current edition. After launch or binding use, changes are published as a new edition and previous applicable editions remain preserved. Updates do not rewrite the policy or contract evidence attached to an existing order.

The current policy remains available through the footer. The policy and contract versions applicable to an order are retained with its order evidence; a link to the current policy does not replace that record.

14. Contact and complaints

Privacy requests: support@servicify.ai General enquiries: info@servicify.ai Project support: use the authenticated Customer Workspace or support@servicify.ai Postal contact: 129B Oleksandra Polia Avenue, Dnipro, 49055, Ukraine.

You may lodge a complaint with the data-protection supervisory authority in the place of your habitual residence, place of work, or place of the alleged infringement where the GDPR provides that right. Contact details for EEA supervisory authorities are available from the European Data Protection Board at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. You may contact us first, but doing so is not a condition of complaining to an authority.

Related pages: Terms & Conditions (/terms), Refunds & Cancellation (/refund-cancellation), Delivery & Fulfilment (/delivery-fulfilment), and Contact (/contact).

Current version Archive Same-release language