Privacy Policy
The protection of your personal data is important to us. Below we inform you about how we process your data when you use the Shipman platform, in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing is: Redstone IT GmbH Potsdamer Platz 10 10785 Berlin Germany Email: contact@evuno.ai Managing Director: Niklas Heinze
2. General information on data processing
We process personal data of our users only insofar as this is necessary to provide a functional platform as well as our content and services. As a logistics and warehouse-management (WMS) application, Shipman processes data on behalf of our business customers in order to operate their fulfillment, inventory and shipping workflows. Processing of personal data takes place regularly only with the consent of the data subject or where processing is permitted by statutory provisions.
3. Hosting and server log files
Our infrastructure is operated on servers located in Germany. With every access to the platform, the system automatically collects technical data from the requesting device: IP address, date and time of access, the page or endpoint accessed, the HTTP status code and the amount of data transferred. This data is stored in server log files. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in ensuring the security, stability and proper operation of the service. Log data is deleted as soon as it is no longer required for these purposes.
4. Cookies
Shipman uses only technically necessary cookies. These comprise a session cookie for authentication (keeping you signed in), a cookie storing your language preference, and a cookie storing your theme preference (light/dark). We do not use tracking cookies, third-party analytics or advertising cookies, and we do not track your usage behaviour. The legal basis for the use of these strictly necessary cookies is Art. 6 (1) (f) GDPR and § 25 (2) TTDSG.
5. Contacting us
If you contact us by email, the data you provide (e.g. your name, email address and the content of your message) will be processed in order to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR where your request relates to a contract, and otherwise Art. 6 (1) (f) GDPR (our legitimate interest in responding to enquiries). This data is deleted once your enquiry has been finally dealt with, unless statutory retention obligations apply.
6. User account and use of the application
To use Shipman, a user account is required. When you register and use the platform, we process account data (such as username, email address and assigned role) as well as the operational data you enter into the system (e.g. orders, products, storage locations, shipments and related records). This data is processed to provide the contractually agreed services. The legal basis is Art. 6 (1) (b) GDPR (performance of the contract). Within multi-tenant operation, each customer's data is strictly isolated from that of other customers at the database level.
7. Legal bases for processing
We process personal data on the following legal bases under Art. 6 (1) GDPR: (a) consent, where you have given it; (b) performance of a contract or pre-contractual measures, in particular for providing the platform and managing your account; (c) compliance with a legal obligation, e.g. statutory retention periods; and (f) our legitimate interests, such as the security and proper operation of the service, provided your interests do not override them.
8. Storage duration
We store personal data only for as long as is necessary for the respective purpose. Account and operational data is retained for the duration of the contractual relationship and deleted within a reasonable period thereafter, unless statutory retention obligations require longer storage. Invoicing and accounting data is retained for the statutory periods (generally up to ten years). Server log data is deleted promptly once it is no longer needed for security purposes.
9. Order processing
Where we process personal data on behalf of our business customers, we act as a processor within the meaning of Art. 28 GDPR. In such cases, a separate data processing agreement (DPA) governs the type, scope and purpose of the processing, the technical and organisational measures and the rights and obligations of the parties. We engage carefully selected sub-processors only where necessary to operate the service (in particular for hosting in Germany) and bind them to data protection obligations equivalent to our own.
10. Data security
We employ appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, manipulation and unauthorised access. All data transmissions are encrypted using current TLS standards (SSL/TLS), recognisable by the lock symbol in your browser. Access to data is restricted by role-based permissions and authentication. Our measures are continuously reviewed and adapted to technological developments.
11. Your rights
You have the following rights with regard to your personal data: the right of access (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), to data portability (Art. 20 GDPR), and the right to object to processing carried out on the basis of Art. 6 (1) (f) GDPR (right to object under Art. 21 GDPR). Where processing is based on consent, you may withdraw that consent at any time with effect for the future (Art. 7 (3) GDPR). To exercise your rights, please contact us at contact@evuno.ai.
12. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. The authority responsible for us is: Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte fuer Datenschutz und Informationsfreiheit) Friedrichstr. 219 10969 Berlin www.datenschutz-berlin.de