Privacy policy

Version 2026-09-25-legal. This policy explains how personal data is processed when you use Mandavo Synthetic Datasets (datasets.mandavotech.com). GDPR = EU General Data Protection Regulation.

1. Controller

Silas Nutz
trading as Mandavo Softwareentwicklung
Daimlerstraße 50, 74211 Leingarten, Germany
hello@mandavotech.com

We have not appointed a data protection officer because we are currently not legally required to do so (in particular no obligation under § 38 BDSG). For privacy questions, please contact the address above directly.

2. What Mandavo Synthetic Datasets does — and does not do

Mandavo Synthetic Datasets is an online shop for synthetic invoice machine-learning datasets. After registration and e-mail verification you can download a free sample tier; paid tiers are purchased once via Stripe and delivered as release ZIP files. We do not operate a search engine, image archive, subscription SaaS dashboard, or OAuth social login on this product.

3. Categories of personal data

4. Purposes and legal bases

4.1 Providing the website, security

When you visit, we process technical data (IP address, time, page requested, browser type) to deliver content and protect the service against misuse (rate limiting, bot protection). Legal basis: Art. 6 (1) (f) GDPR (secure operation).

4.2 Account, login, downloads

We process account data and sessions to perform the contract (Art. 6 (1) (b) GDPR) and to prevent misuse (Art. 6 (1) (f) GDPR). The free sample tier is available only after e-mail verification.

4.3 Dataset purchases and delivery

We process purchase and entitlement data so you can buy a tier once and download the release ZIP. By consenting at checkout you expressly agree that delivery of the digital content begins before the withdrawal period ends and you confirm loss of the right of withdrawal once delivery begins (§ 356 (6) BGB; see withdrawal policy). Legal basis: Art. 6 (1) (b) GDPR.

4.4 Transactional e-mails (Postmark)

For e-mail confirmation, password reset, purchase confirmations and receipts for withdrawal we use Postmark (ActiveCampaign, LLC, USA). Only the recipient address and message content are transmitted; open and click tracking is disabled. Legal basis: Art. 6 (1) (b) and (f) GDPR. We do not send marketing e-mails without your separate consent.

4.5 Billing and payment (Stripe)

Paid tiers are processed via Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA). Stripe processes payment and invoice data as an independent controller for payment processing and partly as a processor for us; we receive customer identifiers, payment status and invoices. Checkout takes place on Stripe's pages; we do not load Stripe scripts on our pages. Legal basis: Art. 6 (1) (b) GDPR; for tax retention Art. 6 (1) (c) GDPR. Privacy notice: stripe.com/privacy.

4.6 Bot protection (Cloudflare Turnstile, optional)

We currently do not use an external bot protection service. Should we enable Cloudflare Turnstile at registration, technical browser data and the IP address would be transmitted to Cloudflare, Inc. (USA) (Art. 6 (1) (f) GDPR); we will update this policy accordingly.

4.7 Hosting

The service is operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (EU). Database, logs and backups are located there. Legal basis: Art. 6 (1) (b) and (f) GDPR.

4.8 Withdrawal

Notices submitted via the withdraw from purchase form are logged with timestamp, account identifier and a short notice excerpt; the full text is e-mailed to you and to us. Legal basis: Art. 6 (1) (b) and (c) GDPR.

4.9 Obligation to provide data

Without an e-mail address we cannot provide an account or deliver downloads. Without payment details at Stripe, no paid tier can be purchased. Name and company are voluntary.

5. Recipients and processors

RecipientPurposeLocation / safeguard
Hetzner Online GmbHHosting, database, backupsEU (Germany/Finland), processing under Art. 28 GDPR
Postmark (ActiveCampaign, LLC)Transactional e-mailsUSA — EU-U.S. Data Privacy Framework, additionally standard contractual clauses
Stripe Payments Europe Ltd. / Stripe, Inc.One-time payments, invoicesIreland / USA — EU-U.S. Data Privacy Framework, additionally standard contractual clauses
Cloudflare, Inc. (only if Turnstile is enabled)Bot protection at registrationUSA — EU-U.S. Data Privacy Framework, additionally standard contractual clauses

6. Transfers to third countries

Where Postmark, Stripe or Cloudflare process data in third countries, we rely — to the extent applicable to us — on the EU-U.S. Data Privacy Framework for certified providers, otherwise or additionally on the EU Commission's standard contractual clauses (2021) and supplementary measures.

7. Cookies and local storage

We use only technically necessary first-party storage (§ 25 (2) no. 2 TDDDG); there are no advertising or tracking cookies and no analytics services are embedded.

8. Retention periods

9. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). Please send requests to hello@mandavotech.com. You can delete your account yourself in the account area.

You have the right to lodge a complaint with a supervisory authority. The authority responsible for our registered office in Baden-Württemberg is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart, Germany (baden-wuerttemberg.datenschutz.de).

10. No automated decision-making

We make no automated decisions with legal effect within the meaning of Art. 22 GDPR.

11. Changes

We adapt this policy when processing activities, service providers or the legal situation change and publish the current version at datasets.mandavotech.com/privacy.