Your delivery data is stored in Germany and belongs to you.

Where your data lives, who has access to it and how you get it back at any time: all covered by contract. The documents are ready to download and sign.

  • Data processing agreement under Article 28 GDPR
  • IONOS data centres, ISO 27001
Photo and text recognition on your device

Sunventory, data centres in Germany

IONOS and Hetzner, two subprocessors
Tenant separation, access per site
Daily backups, retained for 35 days
Export at any time as PDF, CSV or ZIP

Documents

Everything your review needs.

Seven documents, downloadable directly. No form, no registration and no need to ask us. All documents are in German.

Data processing agreement

The agreement under Article 28 GDPR, ready to sign.

  • Roles clarified: you are the controller, we are the processor.
  • Instructions, control rights and audits agreed in writing.
  • Deletion at the end of the contract, written confirmation on request.

Annex 1: Technical and organisational measures

The measures under Article 32 GDPR in detail.

  • Physical access, system access, data access and separation, evidenced per control class.
  • Tenant separation at application and database level.
  • Encryption, logging and backup regime.

Annex 2: Subprocessors

Two entries, both in Germany. No third-country transfer.

  • IONOS for hosting, Hetzner for the encrypted backup.
  • Service, place of processing and legal basis named.
  • Changes announced 30 days ahead in writing, with a right to object.

Service level agreement

What we commit to, and how it is measured.

  • 99.5 percent monthly availability, with the formula.
  • Incident classes P1 to P3 with fixed response times.
  • Maintenance windows, service hours and reporting channel bindingly agreed.

Deletion policy and retention periods

When which data disappears again.

  • Period, start of period and deletion routine per data class.
  • Export window of 30 days after the end of the contract.
  • Backups overwritten after 35 days at the latest.

Security and hosting, overview

Two pages for the first review.

  • Hosting, architecture and access control at a glance.
  • Document recognition on the device, no AI cloud service.
  • Position on ISO 27001 and NIS2.

Supplier self-disclosure

Your supplier form, already filled in.

  • Master data, register and payment details.
  • Statements on information security and data protection.
  • For vendor set-up and supplier qualification.

At a glance

The short version of the documents.

Four answers about what is available for download above. Every statement is backed by contract, in the data processing agreement and its annex on technical and organisational measures.

Where the data lives.

Data centres in Germany: IONOS for hosting, Hetzner for the encrypted off-site backup. Two subprocessors, no US cloud, no third country.

Who can see it.

Access is tied to the site, and the tenant structure separates customers. Quantities are captured, not prices.

What stays on the device.

Text recognition runs on the phone. No delivery note photo and no recognised text goes to an AI service.

How you get out.

Export is self-service, in open formats. The continuity commitment is part of the contract.

Frequently asked questions

Who on our project sees which data?

Access is tied to the site. Staff see the projects they are assigned to and no others. Between customers, the tenant structure separates data at application and database level. Within a project, the operational staff of subcontractors also see the bill of materials. That is intentional: the EPC buys the material and the EPC provides the bill of materials.

How do we get our data back if we switch providers?

At any time and without asking us. Export is self-service and covers deliveries, bills of materials, check status and the original photos, as PDF, CSV or ZIP. Open formats, no proprietary storage, no lock-in. This continuity commitment is part of the contract.

Does Sunventory train AI models on our delivery notes?

No. Text recognition runs exclusively on the phone, with Apple Vision on iOS and Google ML Kit on Android. No delivery note photo and no recognised text goes to third parties or to an AI cloud service. The apps contain no analytics, advertising or tracking SDKs.

Does a photo of a delivery note hold up in a dispute?

That depends on the individual case. Sunventory documents traceably who captured which delivery when and who confirmed it, and supplies the original photo. We do not use a qualified electronic signature or a qualified timestamp. What you get is complete, exportable documentation.

Do we need a data processing agreement, and is one available?

Yes, under Article 28 GDPR, ready to download and sign, with the annex on technical and organisational measures and the subprocessor list. There are two subprocessors, both in Germany: IONOS SE in Montabaur for hosting and Hetzner Online GmbH for the encrypted off-site backup. We announce any planned change at least 30 days in advance in writing, with a right to object.

Our client is a KRITIS operator. What does that mean for us?

Sunventory itself is not a regulated entity under the NIS2 directive. Where supply-chain requirements apply, we support you with incident notification within 24 hours, documented processes and contractual security commitments in the data processing agreement and the service level agreement.

What happens in the event of a data breach?

We notify you without undue delay, at the latest 24 hours after becoming aware, following a documented process. The notification duties under Articles 33 and 34 GDPR towards the supervisory authority and data subjects rest with you as the controller. We supply the information you need for that.

Documents reviewed. Now the app.

Thirty minutes, live on a project like yours: bill of materials, capture on delivery, export of the proof. No slides, no preparation.

Questions from IT or procurement.

Questions about hosting, data processing or deletion periods are answered by the managing director personally, not by a support mailbox.

Write to us

Two pages for a first review.

Hosting, architecture, access control and the position on ISO 27001 and NIS2, compact enough to forward internally.

Open the overview (German)