Privacy policy
1. Controller
Silas Nutz
trading as Mandavo Softwareentwicklung
Daimlerstraße 50, 74211 Leingarten, Germany
hello@mandavotech.com
We have not appointed a data protection officer because we are currently not legally required to do so (in particular no obligation under § 38 BDSG). For privacy questions, please contact the address above directly.
2. What Mandavo Synthetic Datasets does — and does not do
Mandavo Synthetic Datasets is an online shop for synthetic invoice machine-learning datasets. After registration and e-mail verification you can download a free sample tier; paid tiers are purchased once via Stripe and delivered as release ZIP files. We do not operate a search engine, image archive, subscription SaaS dashboard, or OAuth social login on this product.
3. Categories of personal data
- Account data: e-mail address, password in hashed form (scrypt), optionally name and company, timestamps of registration, e-mail confirmation and login, accepted terms version.
- Purchase data: purchased tier, Stripe checkout session and payment identifiers, amount, currency, purchase timestamp, entitlement to download the corresponding release.
- Download events: which tier was downloaded and when, stored in security/event logs with a pseudonymised IP address.
- Security and event logs: logins, failed login attempts, password changes, checkout and purchase events, withdrawal notices — each with timestamp and pseudonymised IP address.
- Server access logs: IP address, time, requested address, status code, browser type — for security and error analysis.
- Session data: session identifier (hashed), expiry time, browser type, pseudonymised IP address.
- Billing data for paid tiers: Stripe customer identifier, payment status, invoices. Payment details (card number, IBAN) are processed exclusively by Stripe; we do not receive them.
- Communication: the content of your e-mails to us (support, withdrawal) and transactional e-mails we send to you (verification, purchase confirmation, password reset).
4. Purposes and legal bases
4.1 Providing the website, security
When you visit, we process technical data (IP address, time, page requested, browser type) to deliver content and protect the service against misuse (rate limiting, bot protection). Legal basis: Art. 6 (1) (f) GDPR (secure operation).
4.2 Account, login, downloads
We process account data and sessions to perform the contract (Art. 6 (1) (b) GDPR) and to prevent misuse (Art. 6 (1) (f) GDPR). The free sample tier is available only after e-mail verification.
4.3 Dataset purchases and delivery
We process purchase and entitlement data so you can buy a tier once and download the release ZIP. By consenting at checkout you expressly agree that delivery of the digital content begins before the withdrawal period ends and you confirm loss of the right of withdrawal once delivery begins (§ 356 (6) BGB; see withdrawal policy). Legal basis: Art. 6 (1) (b) GDPR.
4.4 Transactional e-mails (Postmark)
For e-mail confirmation, password reset, purchase confirmations and receipts for withdrawal we use Postmark (ActiveCampaign, LLC, USA). Only the recipient address and message content are transmitted; open and click tracking is disabled. Legal basis: Art. 6 (1) (b) and (f) GDPR. We do not send marketing e-mails without your separate consent.
4.5 Billing and payment (Stripe)
Paid tiers are processed via Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA). Stripe processes payment and invoice data as an independent controller for payment processing and partly as a processor for us; we receive customer identifiers, payment status and invoices. Checkout takes place on Stripe's pages; we do not load Stripe scripts on our pages. Legal basis: Art. 6 (1) (b) GDPR; for tax retention Art. 6 (1) (c) GDPR. Privacy notice: stripe.com/privacy.
4.6 Bot protection (Cloudflare Turnstile, optional)
We currently do not use an external bot protection service. Should we enable Cloudflare Turnstile at registration, technical browser data and the IP address would be transmitted to Cloudflare, Inc. (USA) (Art. 6 (1) (f) GDPR); we will update this policy accordingly.
4.7 Hosting
The service is operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (EU). Database, logs and backups are located there. Legal basis: Art. 6 (1) (b) and (f) GDPR.
4.8 Withdrawal
Notices submitted via the withdraw from purchase form are logged with timestamp, account identifier and a short notice excerpt; the full text is e-mailed to you and to us. Legal basis: Art. 6 (1) (b) and (c) GDPR.
4.9 Obligation to provide data
Without an e-mail address we cannot provide an account or deliver downloads. Without payment details at Stripe, no paid tier can be purchased. Name and company are voluntary.
5. Recipients and processors
| Recipient | Purpose | Location / safeguard |
|---|---|---|
| Hetzner Online GmbH | Hosting, database, backups | EU (Germany/Finland), processing under Art. 28 GDPR |
| Postmark (ActiveCampaign, LLC) | Transactional e-mails | USA — EU-U.S. Data Privacy Framework, additionally standard contractual clauses |
| Stripe Payments Europe Ltd. / Stripe, Inc. | One-time payments, invoices | Ireland / USA — EU-U.S. Data Privacy Framework, additionally standard contractual clauses |
| Cloudflare, Inc. (only if Turnstile is enabled) | Bot protection at registration | USA — EU-U.S. Data Privacy Framework, additionally standard contractual clauses |
6. Transfers to third countries
Where Postmark, Stripe or Cloudflare process data in third countries, we rely — to the extent applicable to us — on the EU-U.S. Data Privacy Framework for certified providers, otherwise or additionally on the EU Commission's standard contractual clauses (2021) and supplementary measures.
7. Cookies and local storage
We use only technically necessary first-party storage (§ 25 (2) no. 2 TDDDG); there are no advertising or tracking cookies and no analytics services are embedded.
datasets_session— login session (httpOnly, Secure), up to 30 days.datasets_csrf— protection against cross-site request forgery, 30 days.
8. Retention periods
- Account data: until the account is deleted (possible at any time in the account area); residual copies in backups for up to 30 days.
- Purchase and entitlement records: for the duration of your account plus statutory limitation periods where claims may arise.
- Security and event logs: 12 months; withdrawal notices until the expiry of statutory limitation periods (3 years).
- Server access logs: 14 days, longer in case of security incidents where necessary.
- Password reset and e-mail verification tokens: until used or expired (typically 48 hours for verification, 2 hours for password reset).
- Billing data and invoices: 10 years pursuant to § 147 AO / § 257 HGB (at Stripe and in our accounting).
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). Please send requests to hello@mandavotech.com. You can delete your account yourself in the account area.
You have the right to lodge a complaint with a supervisory authority. The authority responsible for our registered office in Baden-Württemberg is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart, Germany (baden-wuerttemberg.datenschutz.de).
10. No automated decision-making
We make no automated decisions with legal effect within the meaning of Art. 22 GDPR.
11. Changes
We adapt this policy when processing activities, service providers or the legal situation change and publish the current version at datasets.mandavotech.com/privacy.