Privacy Policy

Last updated: 21 July 2026 · Effective: 21 July 2026

1. Who we are

Golden Inventory is a multi-tenant inventory management SaaS operated by Serhii Korsunenko (Golden Inventory, "we", "us", "our"), reachable at support@inventory-system.com. The service is hosted at inventory-system.com.

For GDPR purposes the lead supervisory authority is the Berlin Data Protection Authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit), as we are based in Berlin, Germany.

2. Controller vs. Processor — our dual role

We act in two distinct capacities under the GDPR:

This policy covers both roles. Section 3 describes controller processing; section 4 describes processor processing. If you are a tenant (a business using Golden Inventory), you are the controller of your own business data and must have your own lawful basis for the personal data you enter — we provide an Art. 28 DPA template for this relationship.

3. Account data we collect (controller)

CategoryExamplesPurpose
IdentityEmail address, full name (optional), Google account ID (if Google Sign-In used)Account creation, authentication, password reset
AuthenticationHashed password, refresh token hashes, email verification tokensSecure login, session management
BillingGumroad license key, subscription status, plan tier, payment amounts (no full card numbers — Gumroad is the merchant of record)Plan enforcement, license linking
Usage metadataIP address, User-Agent string, Referer header, visit timestampsSecurity, abuse prevention, visitor analytics (landing pages only)
SupportContact form submissions (name, email, company, message)Customer support, sales inquiries

We do not collect or process special categories of personal data (Art. 9 GDPR) as a controller. We do not make automated decisions with legal or similarly significant effects (Art. 22).

4. Tenant business data (processor)

When you use Golden Inventory as a business, you may enter personal data about your own customers, vendors, employees, and other parties. This data belongs to you — you are the controller. We process it on your behalf and on your documented instructions (the agreement you accept when creating an organization, supplemented by our Data Processing Agreement).

Personal data that may appear in tenant business data:

Not in scope of personal data: item master data (SKUs, barcodes, descriptions), stock quantities, bill-of-material structures, tax code definitions, and Plausible analytics (cookieless, no personal data).

As controller, we process account data on the following bases:

As processor, we process tenant business data on the basis of your instructions (Art. 28(3)(a) GDPR) as documented in the DPA.

6. Sub-processors

We use the following sub-processors to deliver the service. Each has signed their own DPA with us (or we have accepted their standard DPA/AVV in their respective panels):

Sub-processorPurposeLocationData processed
Hetzner Online GmbH VPS hosting (application server + database) EU (Germany / Finland) All account and tenant business data
Scaleway / OVH Encrypted off-site backup storage (pgBackRest + restic) EU (France) Encrypted database backups (client-side AES-256-CBC)
nocdirect (Josef) SMTP mail relay for transactional emails US (TX) — EU SCCs in place via cPanel agreement Email address, email content (verification, password reset, contact form)
Gumroad, Inc. Payment processing (Merchant of Record), subscription management, EU VAT handling US — EU SCCs in place (Gumroad DPA) Email, license key, subscription status, payment amounts

We will notify tenants of any new sub-processor at least 14 days before engagement, with the opportunity to object on reasonable data-protection grounds. The current list is also maintained in the DPA Annex.

7. Data retention

Data categoryRetention periodBasis
User accountUntil deletion request or 2 years after last loginContract + legitimate interest
Tenant business dataUntil org deletion by tenant admin, or 30 days after subscription ends (grace period for export)Processor — tenant instruction
Invoices & booking records10 years from end of calendar year (GoBD §147 AO for DE tenants)Legal obligation — tenant's retention duty
Server access logs (with IPs)14 days (nginx), 30 days (application)Security / abuse prevention
Backups30-day rolling retention (daily incrementals + weekly fulls)Disaster recovery
Gumroad webhook eventsDuration of subscription + 90 daysBilling audit trail

8. Backup rules

To ensure service continuity, we maintain encrypted backups of the application database:

9. Log retention

10. Cookies & tracking

The Golden Inventory application itself is cookieless. We use no analytics, no tracking pixels, and no third-party scripts inside the authenticated app — your business data stays between you and the server.

On our public landing pages only:

11. Your rights (Art. 15–21 GDPR)

As a data subject, you have the following rights regarding your account data (controller processing):

For tenant business data, direct your requests to the tenant (your service provider) who is the controller. We assist tenants in fulfilling data subject requests as required by Art. 28(3)(e) GDPR — see the DPA for the procedure.

To exercise any of these rights, email us at support@inventory-system.com. We respond within 30 days (Art. 12(3)). Verification of identity may be required. You also have the right to lodge a complaint with your local supervisory authority.

12. International transfers

All primary processing (application server, database, primary backups) happens on servers in the European Union (Germany / Finland via Hetzner; France via Scaleway/OVH). Two sub-processors operate outside the EU:

We do not transfer tenant business data (documents, parties, stock) outside the EU.

13. Security measures

14. Breach notification

In the event of a personal data breach, we will:

15. Changes to this policy

We will post changes on this page and, for material changes affecting account data, notify account holders by email at least 14 days in advance. Continued use after the effective date constitutes acceptance. For material changes affecting processor obligations, we follow the DPA amendment procedure.

16. Contact & supervisory authority

Data Protection Officer (not required by law for our size, but designated voluntarily):
Serhii Korsunenko
support@inventory-system.com
Berlin, Germany

You have the right to lodge a complaint with a supervisory authority. The lead authority for Golden Inventory is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
www.datenschutz-berlin.de