Privacy statement
Draft version — not yet legally reviewed. This text is a first draft and may still change before publication.
0. What this statement does and does not cover
Servandum ([Patxaran Holding B.V.], "we") operates the Servandum dataroom platform, including its white-label edition Annona Dataroom. This statement covers the personal data we process as controller: account data, authentication and usage data, billing data, and the platform-level activity log.
It does not cover the documents and data a customer (an organisation with a tenant account) shares with stakeholders inside a data room. For that processing, the customer is the controller and Servandum is the processor, as set out in the data processing agreement between Servandum and that customer. If you are a stakeholder in a data room with a question about documents, NDA acceptance, or your activity there, please contact that data room's administrator — not Servandum.
1. Who is responsible
[Patxaran Holding B.V.], trading as Servandum, registered office in [place], trade register number [KvK number], is the controller under the GDPR for the processing described in this statement.
Questions about this statement or your data: [privacy@servandum.nl — to be set up; until then info@annona.nl]. Suspected vulnerabilities: security@annona.nl.
2. What data, for what purpose, on what basis
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data (name, business email, language preference) | Creating and managing the account, signing in | Performance of a contract / legitimate interest | While the account exists; +[30] days |
| Authentication and security data (IP address, sessions, TOTP status) | Enabling sign-in, preventing misuse | Legitimate interest (security) | Session until end + revocation; log [90] days |
| Platform activity log (who did what at platform/tenant level — not data room content) | Accountability, abuse prevention | Legitimate interest | [provisionally 24 months] |
| Billing and payment data (company name, address, VAT number; card data held by Stripe) | Invoicing, bookkeeping | Performance of a contract / legal obligation | 7 years (statutory retention) |
| Support correspondence (email to info@/security@) | Handling questions and reports | Legitimate interest | As needed, +[12] months |
Data room content is explicitly excluded — see §0.
3. Cookies
We place only functional cookies: a session cookie (secured, httpOnly/secure/SameSite) and a language-preference cookie. No tracking, marketing, or analytics cookies, and therefore no cookie banner — every cookie is strictly necessary for the service to function.
4. Who we share data with
| Recipient | Role | Location / safeguard |
|---|---|---|
| Scaleway SAS (FR) | Hosting, database, storage | EU (Amsterdam) |
| Resend (Plus Five Five, Inc., US) | Transactional email | US; EU SCCs + EU-U.S. Data Privacy Framework |
| Stripe Payments Europe, Ltd. (IE) | Invoicing and payments | EU [to be verified] |
| Google Ireland Ltd. | Sign-in for platform administrators (Google Workspace) | EU/US [to be verified] |
We do not sell personal data. Parties that process only data room content (such as Anthropic for optional AI features) are the customer's responsibility — see the data processing agreement, Annex 3.
5. International transfers
Resend (US) involves a transfer outside the EEA, covered by EU standard contractual clauses and the EU-U.S. Data Privacy Framework. For the other recipients, processing within the EEA is the starting point.
6. Security
Our technical and organisational measures are described in our security documentation (encryption in transit and at rest, role-based and database-enforced authorisation, an immutable activity log). Suspected vulnerability: security@annona.nl.
7. Your rights
You have the right to access, rectify, erase, restrict processing, object, and data portability. For account and platform data, the platform offers self-service: a GDPR export and erasure by anonymisation, via your profile or — for administrators — tenant management. For data inside a data room, contact that data room's administrator (see §0).
You may lodge a complaint with the Dutch Data Protection Authority or your own supervisory authority.
8. Automated decision-making
We do not make decisions about you based solely on automated processing. The platform's optional AI features work on document content on the customer's behalf and are advisory: a human administrator confirms every outcome.
9. Changes
Each version carries a version number and date and is published on this page. In the event of a material change, we proactively notify tenant administrators.
10. Contact
[privacy@servandum.nl — to be set up; until then info@annona.nl] · security@annona.nl for vulnerabilities.