1. Controller
The controller responsible for the processing of personal data on this site and in the LagerFlow application is the operator named in our Imprint. For any privacy-related question, write to support@aarondigitalservices.com.
2. What data we collect
- Account data: name, email, hashed password, workspace name, business category, role.
- Operational data: the merchants, products, orders, invoices, lots, payments, and related records you create inside your workspace.
- Technical data: IP address, user agent, request timestamps, session identifiers — used for security, abuse prevention, and basic operation of the service.
- Email delivery: when LagerFlow sends transactional email (verification, password reset, invoices), the recipient address and delivery metadata are processed by our email provider.
3. Why we process it (legal bases)
- Performance of contract (Art. 6(1)(b) GDPR): to provide the workspace, mobile apps, ordering flow, and invoicing you signed up for.
- Legitimate interest (Art. 6(1)(f) GDPR): to keep the service secure, prevent abuse, and improve reliability.
- Legal obligation (Art. 6(1)(c) GDPR): retaining billing and tax-relevant records where required by law.
4. Sub-processors
We use the following sub-processors to run LagerFlow:
- Vercel Inc. — application hosting and edge network.
- Neon — managed PostgreSQL database.
- Vercel Blob — file storage for product images, signatures, and APK delivery.
- Resend — transactional email delivery.
Where any sub-processor is located outside the EU/EEA, we rely on Standard Contractual Clauses and the supplementary safeguards their terms provide.
5. Retention
Account and operational data is retained for the lifetime of your workspace and for a reasonable period afterwards to honor accounting obligations. You can request deletion at any time; we will delete or anonymize data not subject to a legal retention requirement.
6. Your rights
Under GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure (Art. 17), where no legal retention applies;
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- lodge a complaint with a supervisory authority.
To exercise these rights, contact support@aarondigitalservices.com.
7. Cookies
LagerFlow uses only first-party cookies that are strictly necessary for authentication and session management. We do not use third-party advertising cookies on the application. Marketing pages may load privacy-friendly analytics; if introduced, we will list them here before going live.
8. Changes
We will update this policy when our processing changes. Material changes will be announced inside the application and by email when relevant. The “Last updated” date at the top reflects the current version.