Legal
Privacy Policy
Servolia LLC — Last updated: August 2026
1. Who we are
Servolia LLCis a limited liability company registered in the State of Wyoming, USA, trading as Servolia (“Servolia”, “we”, “us”). We build websites, AI receptionists, booking systems and client portals for service businesses in Europe and the US.
For anything in this policy, or to exercise any right described in section 8, write to hello@servolia.com. We answer privacy requests within 30 days.
2. The two roles we act in
As controller — for people who visit servolia.com, request a free audit, subscribe to our list, or hold a client account with us. We decide why and how that data is used, and this policy governs it.
As processor— for the enquiries our clients' own customers submit on a site we built and host for them (for example a patient messaging a dental practice's AI receptionist). There, our clientis the controller and decides the purpose; we process on their documented instructions, under our agreement with them. If you contacted a business through a site we operate and want your data removed, you may write to us and we will act on that business's instruction, or you can contact them directly.
Clients acting as controllers can request a written data-processing agreement from us at any time at hello@servolia.com.
3. What we collect
On servolia.com:
- Audit and contact forms: your name, email, business name, website URL, and your message.
- Newsletter: your email address, if you opt in.
- Client accounts: your business details, billing records, the intake information you provide, and messages you exchange with us in the portal.
- Our own site assistant: what you type into it, so we can answer and follow up.
- Analytics and advertising: pages viewed, referrer, approximate location, device and browser — and, if you accept them, cookies and pixels (section 7).
On a client's site that we operate (as processor):
- What a visitor writes to the AI receptionist, and the reply, with timestamps.
- Booking and contact submissions: name, phone, email, reason for the visit, preferred time.
- Page-visit statistics for that site.
Please do not send sensitive details through a chat or contact form. Those channels are for arranging an appointment, not for describing a medical condition, diagnosis or treatment. We ask our clients to configure their assistants accordingly, and we do not ask visitors health questions. Where a visitor volunteers such information anyway, it is stored with the rest of that conversation and treated with the same protections, and it can be deleted on request.
4. Why we use it, and our legal basis
- To answer your enquiry and send the audit you asked for — legitimate interest in responding to someone who contacted us.
- To deliver, host and support a service you bought — performance of our contract with you.
- To take payment, invoice, and keep accounting records — contract, and legal obligation.
- Marketing emails — your consent, withdrawable at any time from the link in every email.
- Analytics and advertising cookies — your consent, given through the cookie banner and withdrawable at any time.
- Security, fraud prevention and service reliability — legitimate interest in keeping the service safe and available.
5. Who processes data for us
We never sell personal data. We share it only with the providers that make the service run, each under its own agreement and privacy terms:
- Vercel — website and application hosting.
- Supabase — the database holding enquiries, accounts and conversations.
- Anthropic and Cloudflare — the AI models that generate assistant replies. Conversation text is sent to them to produce an answer.
- Stripe — payments, subscriptions and invoices. Card details are entered directly with Stripe and never reach our servers.
- Resend — transactional and marketing email delivery.
- Telegram — internal alerts to our own team when an enquiry arrives.
- Google Analytics 4 and Google Places — site analytics, and business look-ups.
- Meta — advertising measurement via the Meta Pixel and the Conversions API. Where we send conversion events from our server, contact details are hashed first and cannot be read back.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
6. International transfers
Servolia LLC is established in the United States, and several providers above process data in the United States or other countries outside the European Economic Area and the United Kingdom. Where data leaves the EEA or the UK, the transfer is made under the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism offered by that provider, together with the technical measures described in section 9. You may ask us for details of the mechanism used for a specific provider.
8. How long we keep it
- Enquiries that do not become clients: up to 24 months.
- Client records, contracts and invoices: up to 10 years, to meet accounting and tax obligations.
- Conversations and enquiries on a client's site: for as long as their plan is active, then 60 days after it ends, during which we export the data to them on request. After that it is deleted, unless they instruct otherwise.
- Marketing list: until you unsubscribe.
9. Security
Data is encrypted in transit. Access to production systems is restricted, protected by two-factor authentication, and rate-limited against brute force. Card details never touch our servers. No online service can promise absolute security, but if a breach ever affected your data we would notify you and the competent authority as the law requires.
10. Your rights
If you are in the EEA or the UK you have the right to access your data, correct it, have it deleted, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out. Write to hello@servolia.com and we will respond within 30 days, free of charge.
You also have the right to lodge a complaint with your national data protection authority — in France, the CNIL (cnil.fr); in the UK, the ICO (ico.org.uk). We would rather you came to us first so we can put it right.
11. Changes
We update this policy when what we do changes. The date at the top always reflects the current version, and material changes are announced to clients by email.