Draft — review with your attorney before publishing. This text describes how the platform works today; it is not legal advice and makes no compliance claim. The operator clears this notice by setting legal.attorneyReviewed to true in platform settings.
Legal
Privacy policy
How ServiVolt (the "platform") handles data about the companies that use it, their staff, and visitors to this website. Last updated September 2026.
1. Who this covers
This policy covers three groups of people:
- Visitors to this website (the platform’s own pages, including the sign-up and contact forms).
- Company users: owners, office staff and technicians of an HVAC company (a “company”) that has an account on the platform.
- Company customers: the people whose details a company stores in its account. For that data the company is the controller and the platform is its processor; the company’s own privacy notice governs how it collects and uses it. Each company’s public website has its own privacy page for that purpose.
2. What we collect
From visitors
- What you type into the sign-up form (company name, your name, email, phone, password) and the contact-sales form (name, company, email, phone, team size, message).
- Technical data: IP address and browser user agent, recorded with form submissions for rate limiting and abuse prevention, and by Cloudflare as traffic passes through it.
From company users
- Account details: name, email, phone, role, password (stored only as an argon2id hash).
- Session records: IP address, user agent, sign-in time; failed sign-in attempts and lockouts.
- Audit trail: the privileged actions you take in the account, with time, entity and a summary.
- Billing contact and subscription status. Card details are entered on Stripe-hosted pages and never reach our servers.
- Provider credentials you choose to store (for example Twilio or SMTP), encrypted at rest.
From company customers (on the company’s behalf)
- Names, addresses, phone numbers, email, equipment and service history, estimates, invoices and payment records (amount and method only).
- Consent records: what the customer agreed to, the wording, the source, IP address and time.
- When a company enables it: call recordings, transcripts and AI receptionist conversation logs.
3. How we use it
- To provide the service: run the company’s account, website, phone features, documents and notifications.
- To keep it secure: rate limiting, bot checks, lockouts, audit logging, fraud and abuse prevention.
- To bill: subscriptions, usage metering (voice and AI minutes, SMS, email, storage, numbers) and receipts through Stripe.
- To support you: replying to contact-sales and support messages, and — only with a recorded reason — accessing a company’s account through an audited impersonation session.
- To improve the platform using aggregate, non-identifying usage and health metrics. We do not sell personal data and do not use company customer data to train models.
The legal basis for each use (contract, legitimate interest, consent, legal obligation) is to be confirmed by the operator’s counsel for the jurisdictions the platform serves.
4. Who we share it with
Only the providers needed to run the service, listed with what they receive on the Data handling page: Cloudflare, Twilio, OpenAI, Stripe, the SMTP provider, optional Discord webhooks and Google Fonts a company chooses, and the hosting provider of the server. We also disclose data when the law requires it or to protect the platform, its companies and their customers from harm. We do not sell personal data.
5. Cookies
- One session cookie when you sign in: httpOnly, secure, SameSite=Lax, valid for up to 14 days. Deleting it signs you out.
- Cloudflare may set cookies needed to deliver traffic securely.
- Cloudflare Turnstile, when enabled on a form, runs a bot check in your browser.
- We do not use advertising or cross-site tracking cookies on the platform’s own pages.
6. Retention
Account and company data is kept for the life of the company’s account. After cancellation it is kept for a retention window of 30 days so it can be exported or reactivated, then permanently deleted by a scheduled task. Shorter periods apply to sessions, tokens, rate-limit counters, webhook events, exports, recordings and transcripts; the full table is on the Data handling page. Backups are kept for 14 days. Audit logs are not automatically deleted.
7. Security
Each company’s data is isolated at the database and application layer; secrets are encrypted at rest; passwords are hashed with argon2id; sessions are revocable; webhooks are signature-checked; the platform sits behind Cloudflare. The controls, and which are in place versus planned (multi-factor authentication is planned), are described on the Security page. No system is perfectly secure; if we learn of a breach affecting you, we will notify affected companies and, where required, individuals and regulators, within the timelines the law sets.
8. Your choices and rights
- Company users can edit their profile and change their password in the account, and an owner can deactivate users and revoke sessions.
- Companies can export every table as CSV or a full ZIP at any time, and can request deletion by cancelling.
- Company customers should direct access, correction and deletion requests to the company that holds their record; the company has the tools to fulfil them, and we assist the company where needed.
- Visitors who sent a contact-sales message can ask for it to be deleted using the contact address below.
Depending on where you live you may have further rights (access, portability, objection, complaint to a supervisory authority). We will honour them as the applicable law requires.
9. Changes and contact
We will post changes to this policy here with a new “last updated” date and, for material changes, notify company owners by email. Questions and requests: the contact form.
This document describes how the platform works today and is provided for review. It is not legal advice and does not claim compliance with any specific law or standard.