Privacy Policy
How Servn collects, protects, processes, and respects your data across ServnCore, ServnAssist, ServnCapture, and connected services.
1. Overview & Scope
Servn, a product by Evecture Tech (“Servn”, “we”, “us”, or “our”), provides an integrated artificial intelligence operating system for service businesses, including customer relationship management (ServnCore), conversational voice and messaging agents (ServnAssist), interactive lead capture funnels (ServnCapture), and performance-driven websites (Servn Websites).
This Privacy Policy describes our practices concerning personal data collected when you visit our website at servn.co, access or subscribe to our SaaS platform, interact with our AI agents, or communicate with businesses that utilize Servn software.
2. Information We Collect
We collect information in three main categories depending on your interaction with Servn:
A. Information You Provide Directly
- Account & Profile Details: Name, business name, work email address, telephone number, business address, industry, trade license details, and administrative login credentials.
- Billing & Transaction Information: Payment card numbers, billing addresses, and payment history processed securely via our PCI-DSS Level 1 compliant payment gateway.
- Demo & Inquiries: Contact information, company size, monthly lead volume, and specific feature requests submitted via our web forms.
B. Customer Data Processed on Behalf of Subscribers (Service Businesses)
When our subscribers deploy Servn to manage their business operations, Servn acts as a Data Processor / Service Provider under applicable data privacy laws:
- Lead & Customer Records (ServnCore): Contact information, service addresses, project estimates, booking notes, invoice history, and job status.
- Conversational Data (ServnAssist): Audio recordings, real-time audio streams, speech-to-text transcripts, SMS/MMS messages, caller IDs, call duration, timestamp, and AI conversation summaries.
- Interactive Quote Responses (ServnCapture): Roof square footage, solar utility bill estimates, HVAC equipment age, zip codes, budget ranges, and customer-uploaded project photos.
C. Information Collected Automatically
- Device & Telemetry Data: IP address, browser type and version, operating system, referrer URL, pages visited, time spent on pages, and interaction telemetry.
- Cookies & Local Storage: Essential session cookies, authentication tokens, and privacy preference flags.
3. How We Process & Use Data
We utilize the collected information for the following legitimate business purposes:
Delivering AI Operations
Powering automated inbound call answering, customer inquiry triage, automatic scheduling, and real-time lead qualification.
CRM Synchronization
Consolidating calls, texts, web captures, and job updates into a single unified customer timeline inside ServnCore.
Platform Security & Reliability
Preventing fraudulent activity, blocking spam or malicious telephony traffic, and enforcing acceptable use standards.
Service Communications
Sending critical account alerts, invoice receipts, system uptime announcements, and customer support resolutions.
4. AI & Machine Learning Guarantee
Enterprise AI Privacy Protection
Modern AI systems require uncompromising privacy standards. Servn adheres to strict zero-retention and zero-training protocols with all underlying AI inference vendors:
5. Voice, SMS & TCPA Compliance
Because Servn powers automated telephony, voice transcription, and two-way SMS messaging, compliance with telecommunication regulations is fundamental:
- Telephone Consumer Protection Act (TCPA): Subscribers utilizing ServnAssist are contractually responsible for ensuring they have obtained prior express written consent before initiating automated outreach to consumers.
- Call Recording Disclosures: Servn provides automated, configurable voice announcements (e.g., “This call is recorded for quality and scheduling purposes”) to satisfy two-party consent jurisdictions.
- 10DLC & A2P Carrier Compliance: All SMS campaigns sent through Servn are registered with The Campaign Registry (TCR). Automated opt-out keywords (
STOP,UNSUBSCRIBE,CANCEL) are handled automatically by the system.
6. Sub-processors & Third Parties
We partner with industry-leading infrastructure, telecommunications, and security vendors who meet rigorous SOC2 Type II, ISO 27001, and GDPR compliance standards:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| MongoDB Atlas / AWS | Encrypted Cloud Database & Hosting | United States / Global Regions |
| Twilio / Telnyx | Telephony, Voice WebSockets, SMS/MMS Routing | United States |
| Resend | Transactional Email & Lead Notifications | United States |
| Stripe | PCI-DSS Compliant Payment Processing | United States |
| Enterprise AI Inference Providers | Conversational AI, Speech-to-Text, LLM Processing | United States (Zero Retention) |
7. Data Security & Storage
We implement comprehensive technical and organizational safeguards designed to protect personal data against accidental loss, unauthorized access, destruction, and alteration:
- Encryption in Transit: All HTTP and WebSocket connections enforce TLS 1.3 encryption with strict HSTS headers.
- Encryption at Rest: All database records, backups, and audio recordings are encrypted using industry-standard AES-256 encryption.
- Tenant Isolation: Customer databases are logically separated with strict row-level and organization-level security boundaries.
- Continuous Monitoring: Real-time intrusion detection, rate limiting, automated DDoS mitigation, and 24/7 logging.
8. Retention & Deletion
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, or as required by statutory accounting, tax, and legal obligations.
Upon termination of a subscriber subscription, customer data is maintained for a 30-day grace period to allow data export, after which all customer records, audio transcripts, and related backups are permanently purged from active systems.
9. Your Rights (GDPR & CCPA/CPRA)
Depending on your geographical jurisdiction, you possess specific legal rights regarding your personal information:
- Right to Access / Know: Request a copy of the personal information we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal records.
- Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your personal data.
- Right to Restrict or Object: Object to processing of personal data for direct marketing or profiling.
- Right to Data Portability: Obtain your records in a structured, machine-readable JSON or CSV format.
- Right to Non-Discrimination: We will never deny services, charge different rates, or provide degraded service for exercising privacy rights.
To exercise any of these rights, email us directly at [email protected]. We respond to all verified consumer requests within 30 days.
11. International Data Transfers
Servn operates primarily within the United States. If you access our platform from outside the United States, your information may be transferred to and processed in facilities located in the U.S. We implement Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection safeguards.
12. Contact & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy or our security standards, please contact our Data Protection Team:
Servn Technologies
Attn: Data Protection Officer & Legal Counsel
Email: [email protected] or [email protected]
Website: https://servn.co
Ready to build a better service business?
Capture more leads. Respond faster. Close more customers. Spend less time on repetitive work.
