Privacy Policy
Last updated: 21 July 2026 · Effective: 21 July 2026
- Who we are
- Controller vs. Processor — our dual role
- Account data we collect (controller)
- Tenant business data (processor)
- Legal basis for processing
- Sub-processors
- Data retention
- Backup rules
- Log retention
- Cookies & tracking
- Your rights (Art. 15–21 GDPR)
- International transfers
- Security measures
- Breach notification
- Changes to this policy
- Contact & DPO
1. Who we are
Golden Inventory is a multi-tenant inventory management SaaS operated by Serhii Korsunenko (Golden Inventory, "we", "us", "our"), reachable at support@inventory-system.com. The service is hosted at inventory-system.com.
For GDPR purposes the lead supervisory authority is the Berlin Data Protection Authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit), as we are based in Berlin, Germany.
2. Controller vs. Processor — our dual role
We act in two distinct capacities under the GDPR:
- Controller (Art. 4(7)) for account data: user registration, authentication, IP addresses in access logs, Gumroad license-to-org mappings, and visitor analytics on our public landing pages. We determine the purposes and means of this processing ourselves.
- Processor (Art. 4(8)) for tenant business data: the parties (customers, vendors), documents, payments, stock movements, serial/lot numbers, vehicle/VIN data in the assets module, technician and waiter attribution records, Shopify/WooCommerce-imported customer records, webhook payloads, and document PDFs that you enter into your organization account. We process this data solely on your documented instructions as the controller of your own tenant data.
This policy covers both roles. Section 3 describes controller processing; section 4 describes processor processing. If you are a tenant (a business using Golden Inventory), you are the controller of your own business data and must have your own lawful basis for the personal data you enter — we provide an Art. 28 DPA template for this relationship.
3. Account data we collect (controller)
| Category | Examples | Purpose |
|---|---|---|
| Identity | Email address, full name (optional), Google account ID (if Google Sign-In used) | Account creation, authentication, password reset |
| Authentication | Hashed password, refresh token hashes, email verification tokens | Secure login, session management |
| Billing | Gumroad license key, subscription status, plan tier, payment amounts (no full card numbers — Gumroad is the merchant of record) | Plan enforcement, license linking |
| Usage metadata | IP address, User-Agent string, Referer header, visit timestamps | Security, abuse prevention, visitor analytics (landing pages only) |
| Support | Contact form submissions (name, email, company, message) | Customer support, sales inquiries |
We do not collect or process special categories of personal data (Art. 9 GDPR) as a controller. We do not make automated decisions with legal or similarly significant effects (Art. 22).
4. Tenant business data (processor)
When you use Golden Inventory as a business, you may enter personal data about your own customers, vendors, employees, and other parties. This data belongs to you — you are the controller. We process it on your behalf and on your documented instructions (the agreement you accept when creating an organization, supplemented by our Data Processing Agreement).
Personal data that may appear in tenant business data:
- Parties: customer/vendor/employee names, contact details (phone, email, address), tax IDs (VAT numbers)
- Documents: invoice/sales-order/purchase-order/estimate lines with party references, document PDFs with party names and addresses
- Payments: payment records linked to party accounts, terminal references
- Assets module: vehicle registration plates, VINs, meter readings linked to customer assets
- Labor lines: technician names on work orders and invoices
- Restaurant mode: waiter attribution on table tabs, server assignments
- E-commerce connectors: Shopify/WooCommerce-imported customer names, addresses, order history
- Webhook payloads: data you configure us to forward to your endpoints
Not in scope of personal data: item master data (SKUs, barcodes, descriptions), stock quantities, bill-of-material structures, tax code definitions, and Plausible analytics (cookieless, no personal data).
5. Legal basis for processing
As controller, we process account data on the following bases:
- Contract performance (Art. 6(1)(b)): account registration, authentication, plan enforcement, license verification, support responses.
- Legitimate interests (Art. 6(1)(f)): security logging (IP addresses), abuse prevention, aggregated visitor analytics on our landing pages, service improvement. You may object to legitimate-interest processing at any time (see section 11).
- Consent (Art. 6(1)(a)): Meta Pixel on landing pages (optional, gated behind the cookie consent banner). You may withdraw consent at any time via the cookie settings link in the page footer.
- Legal obligation (Art. 6(1)(c)): retention of invoice data where required by commercial/tax law (e.g. §147 AO / GoBD in Germany — 10 years for invoices and booking records), cooperation with supervisory authorities.
As processor, we process tenant business data on the basis of your instructions (Art. 28(3)(a) GDPR) as documented in the DPA.
6. Sub-processors
We use the following sub-processors to deliver the service. Each has signed their own DPA with us (or we have accepted their standard DPA/AVV in their respective panels):
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Hetzner Online GmbH | VPS hosting (application server + database) | EU (Germany / Finland) | All account and tenant business data |
| Scaleway / OVH | Encrypted off-site backup storage (pgBackRest + restic) | EU (France) | Encrypted database backups (client-side AES-256-CBC) |
| nocdirect (Josef) | SMTP mail relay for transactional emails | US (TX) — EU SCCs in place via cPanel agreement | Email address, email content (verification, password reset, contact form) |
| Gumroad, Inc. | Payment processing (Merchant of Record), subscription management, EU VAT handling | US — EU SCCs in place (Gumroad DPA) | Email, license key, subscription status, payment amounts |
We will notify tenants of any new sub-processor at least 14 days before engagement, with the opportunity to object on reasonable data-protection grounds. The current list is also maintained in the DPA Annex.
7. Data retention
| Data category | Retention period | Basis |
|---|---|---|
| User account | Until deletion request or 2 years after last login | Contract + legitimate interest |
| Tenant business data | Until org deletion by tenant admin, or 30 days after subscription ends (grace period for export) | Processor — tenant instruction |
| Invoices & booking records | 10 years from end of calendar year (GoBD §147 AO for DE tenants) | Legal obligation — tenant's retention duty |
| Server access logs (with IPs) | 14 days (nginx), 30 days (application) | Security / abuse prevention |
| Backups | 30-day rolling retention (daily incrementals + weekly fulls) | Disaster recovery |
| Gumroad webhook events | Duration of subscription + 90 days | Billing audit trail |
8. Backup rules
To ensure service continuity, we maintain encrypted backups of the application database:
- Storage location: EU-owned and EU-located storage only (Hetzner Storage Box for primary backups, Scaleway/OVH object storage for secondary copies).
- Encryption: All backups are encrypted client-side (AES-256-CBC) before transmission. Storage providers cannot access plaintext data.
- Retention: 30-day rolling retention — daily incremental backups plus weekly full backups. Backups older than 30 days are automatically purged.
- Restore testing: A restore test is performed monthly to verify integrity and recoverability.
- Erasure requests and backups: When you request deletion of personal data, we erase it from the live database immediately. Because backups are encrypted at rest and retained for a maximum of 30 days, any residual copies age out automatically within that window. We do not perform surgical editing of backup archives; instead, we re-apply erasure instructions after any restore to ensure no deleted data re-enters the live system. This practice is stated transparently here so you can make an informed decision.
9. Log retention
- nginx access logs: Retained for 14 days, then auto-rotated (logrotate, daily rotation, 14 keep). IP addresses in access logs are truncated after rotation.
- Application logs: Retained for 30 days (RotatingFileHandler, 10 MB × 5 files). Application logs may contain IP addresses for error diagnosis and abuse prevention.
- Database visitor log (
visitor_logtable): IP + User-Agent retained for 90 days for aggregated analytics, then purged by a nightly cron job.
10. Cookies & tracking
The Golden Inventory application itself is cookieless. We use no analytics, no tracking pixels, and no third-party scripts inside the authenticated app — your business data stays between you and the server.
On our public landing pages only:
- Essential (always on): a session-localStorage key (
gi_lang) to remember your language preference; a consent cookie (gi_consent) to remember your tracking preferences. Neither contains personal data nor is sent to any server. - Optional — Meta Pixel: with your consent, we load a Meta (Facebook) conversion pixel for ad attribution. It sets third-party cookies. Consent is collected via a banner on first visit, stored in localStorage, and can be changed at any time via the "Cookie settings" link in the page footer.
- Plausible Analytics: we use Plausible (EU-hosted, cookieless, no personal data) for aggregated visit counts. Plausible does not set cookies, does not fingerprint visitors, and is exempt from consent requirements under ePrivacy Directive interpretation. It is always on.
11. Your rights (Art. 15–21 GDPR)
As a data subject, you have the following rights regarding your account data (controller processing):
- Access (Art. 15): request a copy of your personal data.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): request deletion of your data ("right to be forgotten"), subject to legal retention obligations (e.g. invoices under GoBD §147). Where erasure is restricted by law, we restrict processing instead (Art. 18). For tenant business data, party anonymization is used instead of hard-deletion where invoices are under legal retention: we overwrite name/contact fields with placeholders while preserving document numbers and amounts for tax audit purposes.
- Restriction (Art. 18): request restricted processing while a dispute is pending.
- Portability (Art. 20): receive your data in a structured, machine-readable format (JSON/XLSX).
- Objection (Art. 21): object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds.
- Withdraw consent (Art. 7(3)): withdraw cookie/tracking consent at any time via the "Cookie settings" link in the footer. Withdrawal does not affect the lawfulness of processing before withdrawal.
For tenant business data, direct your requests to the tenant (your service provider) who is the controller. We assist tenants in fulfilling data subject requests as required by Art. 28(3)(e) GDPR — see the DPA for the procedure.
To exercise any of these rights, email us at support@inventory-system.com. We respond within 30 days (Art. 12(3)). Verification of identity may be required. You also have the right to lodge a complaint with your local supervisory authority.
12. International transfers
All primary processing (application server, database, primary backups) happens on servers in the European Union (Germany / Finland via Hetzner; France via Scaleway/OVH). Two sub-processors operate outside the EU:
- nocdirect (US): SMTP relay for transactional email. EU Standard Contractual Clauses are in place via the hosting provider's data processing terms.
- Gumroad (US): payment processing and subscription management. Gumroad's DPA includes EU Standard Contractual Clauses. Only email, license key, and payment metadata are shared — no tenant business data.
We do not transfer tenant business data (documents, parties, stock) outside the EU.
13. Security measures
- All traffic encrypted in transit (TLS 1.3, HSTS).
- Passwords hashed with bcrypt; refresh tokens hashed with SHA-256 at rest.
- Database access restricted to the application via internal Docker network (no public port).
- Rate limiting on authentication endpoints (SlowAPI).
- Immutable audit log for billing webhook events.
- Org-scoped data isolation: every tenant query is filtered by
org_idat the database level; cross-tenant data access is architecturally prevented (no shared tenant-data tables). - Nightly database backups, encrypted client-side, stored in EU locations.
- Monthly restore tests.
- Admin access restricted to verified admin email addresses via JWT.
14. Breach notification
In the event of a personal data breach, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware (Art. 33 GDPR), where the breach is likely to result in a risk to individuals' rights and freedoms.
- Notify affected data subjects without undue delay (Art. 34) where the breach is likely to result in a high risk.
- Notify affected tenants (as our controllers) without undue delay so they can meet their own Art. 33/34 obligations.
15. Changes to this policy
We will post changes on this page and, for material changes affecting account data, notify account holders by email at least 14 days in advance. Continued use after the effective date constitutes acceptance. For material changes affecting processor obligations, we follow the DPA amendment procedure.
16. Contact & supervisory authority
Data Protection Officer (not required by law for our size, but designated voluntarily):
Serhii Korsunenko
support@inventory-system.com
Berlin, Germany
You have the right to lodge a complaint with a supervisory authority. The lead authority for
Golden Inventory is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
www.datenschutz-berlin.de