Privacy policy

This is a courtesy translation – the German version is legally binding.

1. Controller

Sveov e.K.
Owner: Patrik Piszkor
Sonnenfeld 39
83395 Freilassing, Germany
Email: sve@sveov.com · Phone: +49 177 2150782

2. What Sveov Forms does

Sveov Forms is a form backend: website operators embed our endpoint URL into their forms; we receive, store and forward the submitted data on their behalf. For the data of form senders, the respective website operators are the controllers within the meaning of the DSGVO – we act as a processor (DPA contract).

3. Data we process

3.1 For form submissions (on behalf of the website operator)

Legal basis: Art. 6 (1) (b) DSGVO (processing the request) or consent under Art. 6 (1) (a) DSGVO via the checkbox in the form. Storage period: until deleted by the operator or automatically after the retention period set by the operator.

3.2 For registered users (operator accounts)

Legal basis: Art. 6 (1) (b) DSGVO (performance of contract).

4. Cookies

We only use technically necessary cookies (session, CSRF protection, short-lived status messages, language preference). No tracking or marketing cookies, no third-party analytics. A cookie banner is therefore not required.

5. Email delivery

We send notifications and confirmations via Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (Amazon SES). Sending takes place exclusively via the AWS region eu-central-1 (Frankfurt am Main, Germany). A data processing agreement including EU standard contractual clauses is in place with AWS. Delivery status is logged for evidence purposes and deleted after 90 days.

6. Hosting

This application runs on servers in Germany operated by Tube-Hosting (owner: Ferdinand Zink), Schlesierstr. 7, 97631 Bad Königshofen, Germany. A data processing agreement is in place with the provider. Server log files (IP address, time, requested URL) are kept for a maximum of 14 days for operational security.

7. Payment processing (Premium)

Premium subscriptions are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Payment data (e.g. card numbers) is entered directly with Stripe and never reaches our servers. Stripe retains billing data for the statutory retention periods (§ 257 HGB, § 147 AO).

8. Optional captcha services

Website operators can enable a captcha service per form (Cloudflare Turnstile, hCaptcha or Google reCAPTCHA). The respective provider then processes data of the form sender. The operator is obliged to disclose this in their own privacy policy. We recommend Cloudflare Turnstile as the most privacy-friendly option.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Registered users can run data export and account deletion directly in the dashboard under "Account". Form senders should contact the operator of the respective website; we support them with the built-in DSGVO tools (export & deletion per person).

Right to complain: you may lodge a complaint with a data protection supervisory authority, e.g. the Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach.

10. Data security