Kristmann Engineering
Legal

Privacy Policy — Service Partner

This privacy policy covers the Service Partner app, not this website — the separate website privacy policy applies to that. It describes which personal data is processed in the app and in the services behind it. Last updated: 16 September 2026.

1. Data Controller

The controller for the operation of the app under the GDPR is: Julius Kristmann Ufgaustraße 3 76532 Baden-Baden Germany Email: julius@kristmann.de Phone: +49 176 63362759 No data protection officer has been appointed. Roles: where service/trade companies use the app, those companies are the controllers for their end customers' and employees' data, and Julius Kristmann acts as a processor under an Art. 28 GDPR data processing agreement.

2. Overview and Scope

Service Partner is an app for managing service operations (jobs, scheduling, customers, on-site documentation, invoicing and optional vehicle/location management). Users are administrators, managers, technicians and the end customers of each organization. This policy describes how personal data is processed in the app and its backend services.

3. Personal Data We Process

Customer data: name, address, phone, email, appliance/equipment details, job site coordinates, job and problem descriptions, photos/videos of the site, voice-note transcriptions, signatures, ratings, and invoice/payment data. Employee data (technicians, managers): name, contact details, address where applicable, role and organization, qualifications, hourly rate, check-in/out times, live location and location history (where GPS tracking is enabled, see section 5), geofence events, device identifiers for push notifications, and audit/log data. Special categories (Art. 9 GDPR): site photos and free-text notes may incidentally contain health-related or other sensitive information. Such content should only be captured where necessary for the job.

4. Purposes and Legal Bases

We process data to carry out service jobs, schedule and dispatch, document visits, issue invoices and to provide and secure the app. Legal bases are in particular Art. 6(1)(b) GDPR (contract), (c) (legal obligations, e.g. tax retention), (f) (legitimate interests in secure, reliable operation) and, where required, (a) (consent). For employee data, § 26 BDSG also applies. Consent can be withdrawn at any time with future effect.

5. Location and Employee Data (GPS Tracking)

The app may process technicians' location: (a) a live position shown on the job map and (b) — where the organization enables it — a location history used to produce mileage logs. Fixed vehicle trackers (Teltonika devices via the Flespi/Gurtam provider) may also supply positions. Employee location tracking is employee-data processing under § 26 BDSG / Art. 88 GDPR. App GPS is only activated once the organization has enabled the feature and the person has consented; consent can be withdrawn in the settings at any time. Workplace use generally requires an appropriate legal basis/agreement (e.g. a works agreement) and informing the employees; this is the responsibility of the respective organization.

6. Recipients and Processors

We use carefully selected providers (processors under Art. 28 GDPR): • Supabase — database, authentication and file storage hosting (EU region, Ireland). • Anthropic (Claude API, USA) — AI features: rewriting notes (the note text is transmitted), the assistant for appliance questions (the question and matching excerpts from the manuals uploaded by the organization are transmitted), checklist generation (appliance data is transmitted) and text extraction from uploaded manuals and documents (the file is transmitted as PDF or image). All AI features are optional and run only when a user triggers them; the manual search itself runs at Supabase in the EU without an external provider. • Firebase Cloud Messaging (Google) — delivery of push notifications; a device token and the title and text of each notification are transmitted. • Sentry — error/crash diagnostics only; screenshots are disabled. Active only when a DSN is configured. • Maps/geocoding/routing: OpenStreetMap, Nominatim, Photon (Komoot, EU), OSRM, Overpass API (OpenStreetMap data for postcode areas and the company search) and swisstopo (api3.geo.admin.ch, Swiss postcode areas) — address/coordinate queries are sent. When you start navigation, the app hands the destination address to the maps app you choose (Apple Maps, Google Maps or Waze). • IP geolocation (ip-api.com, ipwho.is, ipapi.co) — desktop/web fallback only; the IP address is transmitted. • OpenWeatherMap (USA) — weather lookups by coordinates. • Flespi/Gurtam — telematics middleware for vehicle trackers (if used). • Resend (USA) — sending invoice emails (if used). Optional services, used only if the organization explicitly enables them: SMS (Twilio), payments (Stripe), calendar (Google/Microsoft), CRM/accounting/ERP integrations (e.g. HubSpot, Xero, SAP). A processing agreement must be in place for each active service. Speech recognition (dictation): the app uses the operating system's speech recognition and, wherever the device supports it for the selected language (iOS, iPadOS and macOS with the language pack installed; Android 12 or later with offline recognition), explicitly requests on-device processing; audio then does not leave the device. If offline recognition is unavailable, and in the browser version, the app says so when dictation starts and uses the speech recognition of the operating system or browser; audio may then be transmitted to its provider (Apple or Google) and processed under that provider's privacy terms. The app does not store dictation audio; only the recognized text is inserted.

7. International Transfers

Some providers (incl. Anthropic, Sentry, OpenWeatherMap, Resend, Twilio, Stripe, Google (push notifications, calendar), Microsoft and, for dictation without offline recognition, Apple or Google as providers of the system speech recognition) process data in the USA or other third countries. Such transfers rely on appropriate safeguards, in particular the EU Standard Contractual Clauses (Art. 46 GDPR) or an adequacy decision (EU-US Data Privacy Framework) where applicable.

8. Retention and Deletion

We keep personal data only as long as necessary for the stated purposes or as required by law: • Raw GPS location history (track_points): 3 months. • Geofence events: 90 days. • Audit/log data: 90 days. • Invoice and payment data: up to 10 years (German tax/commercial law). • Job, visit and media data: for the duration of the business relationship or while warranty/dispute matters remain. Accounts can be deleted in the settings (see section 10). Personal data is then deleted or anonymized; records subject to a retention obligation (e.g. invoices) are kept in anonymized form.

9. App Permissions

Depending on the feature, the app requests: location (job map, check-in, optional background trip recording), camera (photos/videos of equipment and work), photo library (selecting existing images), microphone and speech recognition (dictating notes) and notifications. Permissions can be revoked at any time in the device system settings.

10. Your Rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to certain processing (Art. 21). You can withdraw consent at any time with future effect. You can delete your account in the app (Settings › Security & Privacy › Delete account). To exercise other rights, contact us using the details in section 1. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

11. Data Security

Data is transmitted encrypted (TLS/HTTPS). On the device, credentials are stored in the platform secure store (iOS Keychain / Android EncryptedSharedPreferences); the local database resides in a non-user-visible app directory and is encrypted with a per-installation key kept in the device's secure store. Server-side access is restricted per organization and role via row-level security.

12. No Advertising, No Tracking

The app uses no advertising IDs, no profiling for advertising and no analytics/tracking services such as Google Analytics. It sets no first-party cookies. AI features serve only to assist with handling jobs.

13. Children

The app is intended for businesses and their staff and customers, not for children. We do not knowingly collect data from children.

14. Changes to This Policy

We update this policy when processing or the legal framework changes. The current version is always available in the app.

15. Contact

For privacy questions, contact us at: julius@kristmann.de (see also section 1).