1. Who we are and the scope of this notice
Serberus is the operating name used by the provider identified in a customer's order form. This notice covers the marketing site, application, public intake, quote, booking, tracking and payment pages, and related support interactions.
The provider's legal name, address, Privacy Officer title and contact details will be published here before general commercial availability. Until then, privacy questions should be submitted through the support channel identified in the applicable account or order form.
2. Our role
Serberus is responsible for information it collects directly to create, secure, administer, and support business accounts. A Serberus customer usually controls the customer, prospect, worker, technician, and job information it enters or collects through its forms.
When a business controls the information, Serberus processes it to provide the service and may direct an access, correction, or deletion request to that business.
3. Information we handle
The information depends on how Serberus is configured and which workflows a business uses.
- Account and business data, including names, email addresses, phone numbers, roles, authentication records, business identity, trade, settings, and connected-service status.
- Customer and work data, including contact details, addresses, language, intake answers, service requests, quotes, prices, schedules, job notes, status, ETA, feedback, invoices, payments, credits, and service agreements.
- Workforce and fleet data, including technician assignments, shifts, PTO, status, location used for dispatch where enabled, timesheets, hourly labour cost, vehicle, fuel, odometer, registration, insurance, and maintenance records.
- Communications and media, including SMS and email threads, inbound and outbound message records, attachments, job photos, signatures, deficiency reports, consent events, and audit history.
- Financial and operational data, including catalogue pricing, taxes, promotions, expenses, job profitability, revenue reports, project budgets, and import or export files.
- Device, usage, security, and diagnostic data needed to operate and protect the service. The current marketing site does not include custom advertising pixels or non-essential analytics cookies.
4. Why we use information
We use information to provide and secure the service, authenticate users, operate configured intake, quoting, scheduling, dispatch, communications, billing and recovery workflows, maintain audit records, connect enabled providers, provide support, prevent abuse, diagnose errors, and meet legal duties.
Marketing messages are sent only with a valid legal basis and must include the required identification and opt-out choices.
5. Automation and AI
Rule-based workflows can calculate a quote from a business catalogue, decide whether a request requires assessment, show availability from shifts and capacity, assign an eligible technician, prepare customer communications, create a draft invoice, and propose recovery options. The business chooses the relevant rules and remains responsible for reviewing consequential results.
When a user chooses an AI rewrite or briefing feature, the draft text or intake and job context needed for that request may be sent to OpenAI to produce the result. Users should not submit information that is unnecessary for the task. Automated results may be corrected, rejected, or reviewed by an authorized person.
6. When information is shared
Information is shared with authorized users of the relevant business and with providers needed to deliver configured features. Confirmed provider categories currently include Cloudflare, Render, Supabase, Clerk, Resend, Twilio, Stripe, Intuit QuickBooks, Google Routes, Open-Meteo, Sentry, and OpenAI. A provider is used only where its related feature applies or is enabled.
Information may also be disclosed when required by law, to protect people or the service, to investigate abuse, or as part of a corporate transaction with appropriate protections. Serberus does not sell personal information.
7. Processing outside Quebec
Some service providers may process information outside Quebec. Verified processing locations, contractual protections, and required privacy impact assessments must be completed and documented before commercial launch. We will update this notice when that review is complete.
8. Retention and deletion
Information is intended to be kept only as long as needed for the service, the customer's documented instructions, security, dispute handling, and legal obligations. A category-specific schedule for account, customer and job, financial, message and media, consent, audit, security, and backup data must be approved before commercial launch.
Deletion may be delayed where law requires retention, a legitimate dispute is active, or information remains in protected recovery systems for a limited cycle.
9. Safeguards
Serberus uses reasonable administrative, technical, and contractual safeguards appropriate to the information and risk. Current controls include organization-scoped access, configurable roles, password hashing, session invalidation, optional SMS two-factor authentication, rate limits, encrypted integration secrets, signed webhook validation, private photo storage with time-limited links, hashed public tokens, security headers, logging, and error monitoring.
No system can promise absolute security. Customers must configure roles carefully, protect credentials, and promptly report suspected unauthorized access through their support channel.
10. Rights and choices
Depending on the law and our role, a person may request access, correction, deletion, consent withdrawal, data portability where applicable, or human review of an exclusively automated decision. Identity may need to be verified and lawful exceptions may apply.
End customers and workers should usually contact the business that collected their information first. Account holders can use their Serberus support channel. A direct Privacy Officer contact and complaint process will be published before commercial launch.
11. Cookies and local storage
The current marketing site does not use custom advertising cookies or analytics pixels. The application uses essential browser storage for authentication, preferences, and offline field workflows. If non-essential analytics or advertising tools are added, this notice and the consent choices will be updated first.
12. Incidents, children, and changes
Privacy incidents are assessed, recorded, and reported to regulators and affected people when required by law. The service is designed for businesses and is not directed to children.
This notice may change as the service, providers, and legal requirements evolve. The date will be updated and material changes will be communicated conspicuously where required.