Privacy Policy
1. Introduction and acceptance
Gennex IT Solutions LLC ("Gennex," "ServeLynx," "Company," "we," "our," or "us") respects privacy and is committed to handling personal information responsibly. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with ServeLynx and related services.
By visiting our websites, submitting information directly to us, or using the Service, you acknowledge the practices described in this Policy. Where consent is legally required, we will request consent separately. A Customer may also provide additional privacy notices that govern the Customer's use of information within its ServeLynx account.
This Policy does not replace the privacy notice of a Customer that uses ServeLynx. If a business entered your information into ServeLynx or used ServeLynx to communicate with you, that business may be the party primarily responsible for your information and your request should generally be directed to that business.
2. Scope
This Policy applies to personal information processed through or in connection with:
- our websites, landing pages, forms, demo requests, marketing pages, and online communications;
- ServeLynx cloud-hosted web applications and application programming interfaces;
- the ServeLynx mobile application, available to customers on Android, with iOS available on request;
- customer and end-customer portals, payment links, digital-signature pages, and shared documents;
- account setup, authentication, billing, training, implementation, support, and professional services;
- communications sent through ServeLynx, including appointment messages, reminders, quotes, invoices, payment links, service reports, and account notices; and
- integrations and third-party services connected to ServeLynx by us, a Customer, or an Authorized User.
This Policy does not govern a third party's independent products, websites, employment practices, service work, or privacy practices.
3. Definitions
Authorized User: an employee, technician, contractor, dispatcher, manager, administrator, office worker, or other individual whom a Customer authorizes to access or use the Service.
Customer: the business, organization, or person that subscribes to or contracts for the Service.
Customer Data: information, records, files, content, and personal information submitted to, generated in, or managed through a Customer account, including information about a Customer's workforce, customers, vendors, jobs, assets, communications, and transactions.
End Customer: an individual or business that receives services, communications, invoices, portal access, or other interactions from a Customer using ServeLynx.
Personal Information: information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household. It does not include information excluded from applicable law, such as properly de-identified information.
Service: the ServeLynx websites, applications, APIs, mobile app, portal, integrations, support, billing, and related services.
Service Provider or Processor: a party that processes personal information on behalf of another business or controller under contractual instructions.
Subprocessor: a vendor engaged by Gennex to process Customer Data in support of the Service.
4. Our privacy roles
4.1 Information controlled by Gennex
Gennex generally acts as a business or controller when it determines the purposes and means of processing information for its own activities, including website operation, demo requests, sales, billing contacts, customer account administration, security, support, legal compliance, and Gennex marketing.
4.2 Customer-controlled information
For Customer Data, Gennex generally acts as a service provider or processor on behalf of the Customer. The Customer determines what information is entered, which features and integrations are enabled, which users receive access, how long data should be retained within the account, and how the information is used in the Customer's business.
4.3 Limited independent processing
We may process Customer Data independently only where necessary to secure and operate the Service, comply with law, enforce agreements, prevent fraud or abuse, respond to emergencies, create de-identified information, or as otherwise permitted by the Customer agreement and applicable law. We do not use Customer Data to market unrelated third-party products to individuals.
5. Information we collect
The information collected depends on the features used, the Customer's configuration, device permissions, connected integrations, and the information Customers and users choose to provide.
| Category | Examples | Primary purposes |
|---|---|---|
| Account and identity | Name, business name, title, role, username, email, phone number, profile details, account status, authentication events, password-reset and one-time-code records. | Account creation, authentication, permissions, support, security, billing, and administration. |
| Customer and service records | Customer contacts, service locations, assets, equipment, serial numbers, notes, appointments, service history, quotes, invoices, warranties, contracts, inspections, purchase records, inventory, and vendor records. | Provide field-service, scheduling, customer, financial, inventory, reporting, and document workflows. |
| Workforce and timekeeping | Assignments, job status, clock-in/out, work sessions, breaks, travel, time-off requests, time records, service activity, productivity information, GPS timestamps, live and historical location, photos, and signatures. | Dispatch, job verification, timekeeping, payroll support, safety, route visibility, workforce management, and reporting. |
| Location | Approximate location derived from IP address and precise GPS coordinates when a user grants permission and activates a location-enabled work feature. | Clock events, live maps, dispatch, routing, work-session tracking, security, fraud prevention, and service records. |
| Communications | Emails, SMS messages, reminders, delivery records, opt-out records, support messages, call notes, message content, metadata, and customer updates. | Operational messages, customer communications, support, security notices, billing, and permitted marketing. |
| Payments and billing | Billing contact, subscription, transaction IDs, payment status, last four digits, billing address, processor response, refunds, chargebacks, and tax/accounting records. | Subscription billing, portal payments, receipts, accounting, fraud prevention, disputes, refunds, and legal records. |
| Files and user content | Documents, PDFs, images, service reports, inspection forms, contracts, warranties, signatures, work notes, attachments, AI prompts, and AI-generated outputs. | Storage, document generation, service reporting, signatures, inspections, AI assistance, portal access, and support. |
| Device, usage, and logs | IP address, browser, device type, operating system, mobile identifiers, app version, session information, feature usage, access time, crash/error information, audit logs, and security events. | Authentication, troubleshooting, analytics, performance, security, fraud prevention, and legal compliance. |
| Integration data | Information exchanged with payment, accounting, mapping, communication, marketing, storage, AI, or other services selected by the Customer. | Enable the selected integration and synchronize or process authorized records. |
| Website and marketing | Demo requests, contact forms, referral source, preferences, analytics events, campaign information, and sales communications. | Respond to inquiries, schedule demos, measure website use, improve marketing, and manage business relationships. |
6. Sources of information
- Directly from you when you create or use an account, request a demo, complete a form, communicate with us, upload files, use the mobile app, make a payment, or otherwise provide information.
- From Customers and Authorized Users that enter or upload information about their workforce, customers, vendors, jobs, assets, transactions, documents, and business processes.
- Automatically from browsers, devices, mobile permissions, servers, cookies, session technologies, logs, analytics, and security systems.
- From connected services and integrations authorized by a Customer or Authorized User.
- From payment processors, banks, app stores, referral partners, public business sources, and professional contacts where lawful and relevant to our business relationship.
7. How we use information
- provide, host, operate, maintain, support, secure, and improve the Service;
- create and administer accounts, roles, permissions, authentication, sessions, and access controls;
- enable scheduling, dispatch, service calls, work orders, inspections, assets, contracts, warranties, quotes, invoices, payments, inventory, purchasing, reporting, and related workflows;
- enable mobile features such as work sessions, clock events, job updates, parts usage, photos, signatures, GPS timestamps, live location, and historical location where configured;
- provide customer portals and controlled access to invoices, quotes, payments, signatures, documents, warranties, service history, and communications;
- send operational, security, billing, support, and permitted marketing communications;
- process subscriptions, online payments, refunds, chargebacks, taxes, accounting, receipts, and financial records;
- operate integrations selected by Customers, including payment, accounting, mapping, messaging, marketing, storage, and AI services;
- generate or assist with drafts through AI features when a user intentionally invokes those features;
- detect, investigate, prevent, and respond to fraud, abuse, spam, phishing, security threats, unauthorized access, and violations of our agreements;
- debug, test, analyze, develop, and improve product functionality and user experience;
- provide onboarding, training, implementation, customer success, and professional services;
- comply with legal, regulatory, tax, accounting, court, law-enforcement, and contractual obligations; and
- protect the rights, property, safety, and security of Gennex, Customers, Authorized Users, End Customers, and others.
8. Customer Data and Customer responsibilities
Customers control their Customer Data and are responsible for the lawfulness, accuracy, quality, integrity, and appropriateness of the information they collect and place in ServeLynx. Customers are also responsible for their use of the Service and the actions of their Authorized Users.
Before collecting, uploading, monitoring, using, or disclosing personal information through ServeLynx, each Customer must:
- have a lawful basis and all necessary rights, notices, authorizations, and consents;
- provide legally required privacy, employee-monitoring, location-tracking, timekeeping, call/text, marketing, and consumer notices;
- obtain legally required consent from employees, contractors, technicians, customers, prospects, and contacts;
- honor unsubscribe, STOP, do-not-call, privacy-rights, deletion, access, correction, and similar requests;
- configure roles, permissions, integrations, retention, and portal access appropriately;
- avoid collecting unnecessary sensitive or regulated information;
- ensure Customer Data and Customer instructions do not violate law, third-party rights, or the Customer agreement; and
- contact Gennex before using ServeLynx for data subject to special contractual, international, sector-specific, or localization requirements.
ServeLynx provides software tools. Gennex does not control a Customer's employment decisions, payroll determinations, workforce policies, service work, invoices, communications, legal compliance, or relationship with its own customers and personnel.
9. Mobile app permissions and device information
Depending on the features used, the ServeLynx mobile app may request access to device capabilities such as precise or approximate location, background location, camera, photo library, files or storage, and notifications. The operating system may display its own permission prompts. We access a permission only when enabled by the user or device administrator and used for a supported feature.
Disabling a permission may limit or prevent the related feature. For example, disabling location may prevent live tracking or GPS verification, and disabling camera or photo access may prevent photo or signature workflows. Users can manage permissions through device settings, subject to Customer policies and applicable law.
The app and supporting infrastructure may process device type, operating system, app version, IP address, device or installation identifiers, session information, notification tokens, crash information, and security events to authenticate users, maintain sessions, troubleshoot, protect accounts, and deliver app functionality.
10. Precise location and workforce tracking
Precise location is sensitive information. ServeLynx may process precise GPS location only when a Customer enables a location feature, the user grants the required device permission, and the user starts or uses a location-enabled work function. Customers must provide workplace notices and obtain any required consent before using these features.
10.1 When location collection may occur
Location collection may begin when an Authorized User starts an active work session, clocks in or out, begins job travel, starts or ends a job, requests navigation, or otherwise activates a location-enabled feature. Depending on the device permission and Customer configuration, precise location may continue to be collected while the app is in the background during an active work session. Continuous background collection is not intended to continue after the user ends the applicable work session or location-enabled activity.
10.2 Information and purposes
Location information may include coordinates, accuracy, timestamps, speed or movement information supplied by the device, device and user identifiers, and the work event associated with the location. It may be used for dispatch, route visibility, clock and job verification, job progress, safety, fraud prevention, service reporting, productivity analysis, and related field-service operations.
10.3 Visibility
Precise location may be visible to the Customer's administrators, dispatchers, managers, or other personnel authorized by the Customer. Gennex personnel may access location information only as reasonably necessary for support, security, legal compliance, or operation of the Service and subject to access restrictions.
10.4 Retention
Continuous or historical location points are ordinarily retained for up to seven days after collection and then deleted through scheduled cleanup, unless a Customer configuration, written agreement, investigation, legal hold, security need, or legal obligation requires a different period. GPS timestamps or coordinates associated with clock-in/out events, work sessions, service records, or audit events may remain as part of Customer Data for the account retention period.
10.5 Customer and user responsibilities
Customers are responsible for all legally required employee and contractor notices, policies, consent, collective-bargaining obligations, wage-and-hour requirements, and restrictions on off-duty tracking. Questions about an employer's or Customer's use of location information should be directed to that Customer. Users can manage mobile permissions, but doing so may limit their ability to perform assigned workflows.
11. Communications, SMS, and email
ServeLynx may be used to send appointment confirmations, reminders, invoices, quotes, payment links, service reports, customer updates, security notices, support responses, product notices, and other messages. Messages may be sent by email, SMS/text, portal notification, or other configured methods.
We may process recipient details, message content, templates, sender information, timestamps, delivery status, errors, opt-out records, and related metadata. Communication providers may also process this information under their own terms and privacy practices.
Customers are responsible for obtaining all required consent and authority to send messages, accurately identifying the sender, complying with marketing and telecommunications laws, maintaining consent evidence, and honoring opt-out, unsubscribe, STOP, do-not-call, quiet-hour, and similar requests. Gennex may block or suspend messaging that presents a legal, security, abuse, deliverability, or reputational risk.
You may opt out of Gennex marketing emails through the unsubscribe link or by contacting us. You may opt out of supported SMS programs by replying STOP. Opting out of marketing does not prevent transactional, account, security, billing, legal, or service-related messages that are permitted or required by law.
12. Payment processing and financial information
ServeLynx supports subscription billing, online payments, payment links, partial payments, refunds, chargebacks, and portal payments through third-party processors such as Stripe and Square. Payment processors may collect card details, bank information, billing addresses, authentication information, fraud signals, and transaction information under their own terms and privacy policies.
Gennex and ServeLynx do not intentionally store complete payment-card numbers or card security codes. We may receive and store limited payment metadata such as transaction identifiers, status, last four digits, billing contact information, processor responses, refunds, disputes, and chargeback records for billing, receipts, reporting, accounting, support, fraud prevention, and legal compliance.
Customers must not place full card numbers, card security codes, bank-login credentials, or other sensitive payment authentication information in notes, attachments, forms, AI prompts, or other general-purpose fields.
13. Customer portal and End-Customer information
Customers may provide their End Customers with portal or shared-link access to invoices, quotes, payment options, service reports, warranties, contracts, signatures, documents, and service history. The Customer determines which information is published, who receives access, and when access is revoked.
If you are an End Customer of a business using ServeLynx, that business is generally responsible for its relationship with you, including the information it enters, services it performs, communications it sends, documents it shares, invoices it issues, and its response to privacy requests concerning Customer-controlled information. Gennex may assist the Customer as required by law or contract.
14. AI-assisted features
ServeLynx may offer optional AI-assisted features to draft or improve service descriptions, work notes, quotes, reports, customer communications, summaries, or other content. AI processing occurs only when a user intentionally invokes an AI feature or a Customer has configured an automated AI workflow.
When used, prompts, instructions, source text, and related content may be transmitted to OpenAI or another disclosed AI provider to generate an output. The provider may process and temporarily retain inputs, outputs, and metadata according to its applicable business terms and data controls. As of the effective date of this Policy, OpenAI states that business/API data is not used to train its models by default and that API inputs and outputs may ordinarily be retained for abuse monitoring for up to 30 days unless different approved controls or legal requirements apply.
Gennex does not use Customer Data to train a general-purpose AI model. We may use de-identified operational information to evaluate feature performance, security, and reliability. We will not authorize a provider to use Customer Data for general model training unless the Customer has expressly opted in or a separate written agreement clearly permits that use.
AI outputs may be inaccurate, incomplete, biased, or unsuitable. Customers and Authorized Users are responsible for reviewing, editing, approving, and deciding whether to use any AI-generated content. Users must not submit protected health information, Social Security numbers, full payment-card data, bank credentials, government IDs, trade secrets, or other unnecessary sensitive information to AI features.
15. Cookies, analytics, and similar technologies
We use first-party session cookies, local or session storage, log files, authentication tokens, and similar technologies that are necessary to sign users in, maintain sessions, secure accounts, remember preferences, prevent fraud, and operate the Service. Disabling necessary technologies may prevent login or other functionality.
We may use Plausible or a similar privacy-focused analytics service to understand aggregate website or product usage. We do not currently use personal information for cross-context behavioral advertising or deploy advertising pixels for targeted advertising through ServeLynx. Before adding advertising cookies, retargeting, or cross-context behavioral advertising, we will update this Policy and deploy any required notice, consent, and opt-out mechanisms.
16. How we disclose information
We may disclose personal information only as reasonably necessary for the purposes described in this Policy, including:
- To Customers and Customer administrators for information managed within the Customer account.
- To Authorized Users according to Customer-defined roles, permissions, locations, assignments, and workflows.
- To service providers, subprocessors, contractors, and vendors that help us host, store, secure, support, monitor, communicate, bill, process payments, map locations, provide analytics, generate AI outputs, or operate the Service.
- To third-party services and integrations selected, connected, or authorized by a Customer or Authorized User.
- To payment processors, banks, card networks, accounting providers, and fraud-prevention providers for financial workflows.
- To professional advisers, insurers, auditors, accountants, and attorneys under appropriate confidentiality duties.
- To regulators, courts, law enforcement, government authorities, or other parties when required by law, valid legal process, or reasonably necessary to protect rights, safety, property, or security.
- In connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to appropriate safeguards and applicable law.
- With your consent, at your direction, or as clearly disclosed when information is collected.
- In aggregated, anonymized, or de-identified form that does not reasonably identify an individual.
17. Service providers, subprocessors, and integrations
The following providers and categories may receive personal information depending on the features used and the Customer's configuration. Optional integrations process data only when connected or used. Provider names and functions may change as the Service evolves; material changes will be reflected in this Policy or communicated as required by contract or law.
| Category | Provider | Purpose |
|---|---|---|
| Hosting, infrastructure, and object storage | Akamai Technologies, Inc. (Linode) | Host, store, back up, secure, and operate the Service and uploaded files. |
| Transactional email | SendGrid or another configured email-delivery provider | Send account, support, appointment, invoice, quote, reminder, and service messages; process delivery and error records. |
| Marketing email | Mailchimp, when enabled or selected | Manage Customer-authorized marketing lists, campaigns, preferences, and delivery records. |
| SMS/text messaging | Twilio, when enabled | Send appointment confirmations, reminders, updates, and related delivery or opt-out records. |
| Payments | Stripe and Square, when enabled | Process subscriptions, customer payments, payment links, refunds, disputes, chargebacks, and related metadata. |
| Mapping and geolocation | Google Maps Platform or another configured mapping provider | Address validation, geocoding, maps, routes, and technician-location visualization. |
| Accounting | Intuit QuickBooks, when connected | Synchronize authorized customers, vendors, invoices, payments, refunds, bills, and accounting records. |
| Analytics | Plausible or similar privacy-focused analytics | Measure website or product usage and improve performance. |
| AI assistance | OpenAI, when an AI feature is used | Generate or improve authorized text and other content based on user prompts and source information. |
| App distribution and device services | Apple and Google, as applicable | Distribute mobile applications, process store interactions, device permissions, platform diagnostics, and app-related services. |
| Support, monitoring, and operations | Configured ticketing, logging, security, and communication providers | Provide support, troubleshooting, account management, monitoring, security, and incident response. |
Third-party providers have their own terms and privacy practices. Customers are responsible for reviewing optional integrations before connecting them and for ensuring that the transfer is lawful and appropriate for their data.
18. Legal bases for EEA/UK processing
Where the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction require a legal basis, Gennex relies on one or more of the following, as applicable:
- Contract: processing necessary to provide accounts, billing, support, and requested Service functionality.
- Legitimate interests: securing, operating, supporting, improving, and protecting the Service and our business, preventing fraud, enforcing agreements, and managing customer relationships, where those interests are not overridden by individual rights.
- Consent: where required for marketing, optional cookies, device permissions, sensitive processing, or another optional feature.
- Legal obligation: compliance with tax, accounting, regulatory, court, law-enforcement, and other legal duties.
- Vital interests or public interest: only where applicable and permitted by law.
For Customer Data processed on behalf of a Customer, the Customer is generally responsible for selecting the legal basis, providing notices, responding to individuals, and issuing lawful instructions to Gennex.
19. International transfers
Gennex is based in the United States, and information may be processed in the United States and other countries where Gennex or its providers operate. Those countries may have privacy laws that differ from the laws of your jurisdiction.
Where a legally required cross-border transfer mechanism applies, the parties may address it in a written Data Processing Addendum, Standard Contractual Clauses, United Kingdom addendum, or another approved mechanism. Gennex does not represent that merely using ServeLynx, without an applicable written agreement and proper Customer compliance, satisfies every international transfer, localization, or sector-specific requirement.
Customers located outside the United States or transferring regulated international data should contact Gennex before using the Service for that data so the parties can determine whether additional contractual and technical measures are required.
20. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, the Customer's instructions, the Customer agreement, security and operational needs, and applicable legal obligations. We consider the type and sensitivity of information, the purpose of processing, risk of harm, contractual requirements, legal limitation periods, and whether the purpose can be achieved with less or de-identified information.
| Data type | Retention approach |
|---|---|
| Active Customer Data | For the subscription term unless deleted earlier by the Customer or according to account configuration. |
| Post-termination production Customer Data | Customers should export data before termination. Production data may remain accessible for export for up to 30 days after termination unless a written agreement states otherwise. After that period, access may be disabled and production data may be deleted. |
| Backups | Encrypted or protected backup copies may remain until overwritten or deleted through ordinary backup rotation. Backups are not ordinarily restored solely to respond to an individual deletion request unless required by law. Deleted data may reappear only if a backup is restored for disaster recovery and will be subject to the next deletion cycle. |
| Continuous historical GPS points | Ordinarily up to 7 days, unless a different Customer configuration, written agreement, investigation, legal hold, security need, or legal obligation applies. |
| Clock, work-session, and job-event GPS timestamps | Retained with the associated Customer business record for the Customer Data retention period. |
| Account, subscription, payment, tax, and accounting records | For the account term and afterward as reasonably necessary for tax, accounting, fraud prevention, disputes, chargebacks, contract enforcement, and legal obligations. |
| Security, access, and audit logs | For a period reasonably necessary for security, troubleshooting, abuse prevention, audit, and legal compliance, taking into account the nature and risk of the event. |
| Communications and opt-out records | For as long as needed to deliver communications, support Customers, resolve disputes, demonstrate consent or opt-out compliance, prevent unwanted messages, and comply with law. |
| AI prompts and outputs | Outputs saved into a Customer account remain as Customer Data. Gennex may retain limited operational records as needed for security and troubleshooting. The AI provider may retain inputs and outputs according to its business terms and configured data controls. |
| Marketing information | Until you opt out, the business relationship ends, or the information is no longer reasonably needed, subject to suppression-list retention necessary to honor opt-outs. |
| Support records | For as long as reasonably necessary to resolve the issue, document the customer relationship, improve support, protect security, and meet legal or contractual obligations. |
| De-identified information | May be retained for legitimate business purposes where it cannot reasonably identify an individual and we maintain it in de-identified form. |
We may preserve information beyond an ordinary retention period when required by law, court order, legal hold, investigation, security need, fraud prevention, dispute, tax or accounting obligation, or Customer instruction. When the reason ends, the information will be returned to the ordinary deletion process.
21. Security
We use commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, acquisition, destruction, loss, misuse, alteration, or disclosure. Depending on the Service component and current implementation, safeguards may include encrypted transmission, password hashing, authentication controls, one-time codes, role-based permissions, least-privilege access, environment and tenant separation, access and audit logging, monitoring, backups, software updates, vulnerability remediation, and confidentiality obligations.
No system, storage method, or transmission is completely secure. We cannot guarantee absolute security or that unauthorized parties will never defeat our safeguards. Security also depends on Customers and users maintaining strong and unique credentials, protecting devices, configuring permissions correctly, promptly removing former personnel, securing connected integrations, and reporting suspected incidents.
Customers must notify us promptly of suspected unauthorized access, credential compromise, data exposure, malicious activity, or security incidents involving the Service. We may reset credentials, suspend access, require corrective action, or take other protective measures when reasonably necessary.
22. Security incidents and breach notification
If we become aware of a security incident involving personal information, we will investigate, contain, mitigate, preserve relevant evidence, and take other steps we determine appropriate under the circumstances. Where required by applicable law or a written agreement, we will notify affected Customers, individuals, regulators, or other parties within the required time.
For Customer Data, Gennex may notify the applicable Customer and provide reasonably available information needed for the Customer to evaluate and satisfy its own notification obligations. The Customer remains responsible for notices to its employees, contractors, customers, regulators, or other affected persons unless law or a written agreement assigns a different responsibility.
Customers must maintain current administrative and security contact information. A delay caused by inaccurate or outdated Customer contact information is outside Gennex's reasonable control.
23. Privacy choices and rights
Depending on your location, relationship with us, and applicable law, you may have rights to request access, confirmation, correction, deletion, portability, restriction, objection, withdrawal of consent, limitation of certain sensitive information uses, opt-out of certain sales, sharing, targeted advertising, or profiling, appeal a denied request, or complain to a regulator.
To submit a request concerning information Gennex controls, email [email protected] or use the contact form at www.servelynx.com/contact. Describe the request and your relationship to ServeLynx. We may request additional information to verify identity, authority, account relationship, or state of residence. Authorized agents may submit requests where permitted by law, subject to verification of authority and the individual's identity.
If a request concerns Customer-controlled information, we may direct the requester to the Customer, forward the request to the Customer, or assist the Customer according to law and contract. We may deny or limit requests where an exception applies, including where information must be retained for security, fraud prevention, tax, accounting, legal claims, contract performance, or other permitted reasons. We will explain appeal options where required.
We will not unlawfully discriminate against an individual for exercising an applicable privacy right. Certain functionality may be unavailable if the requested deletion or restriction prevents us or the Customer from providing the Service.
24. U.S. state privacy notice
This section applies only to the extent Gennex is subject to an applicable comprehensive U.S. state privacy law or voluntarily extends the described right. Statutory thresholds, exemptions, and definitions differ by state, and many Customer Data activities are performed by Gennex solely as a service provider or processor.
During the preceding 12 months, we may have collected the categories described in Section 5, including identifiers; customer and commercial information; internet or electronic-network activity; precise and approximate geolocation; professional or employment-related information; audio, visual, electronic, or similar information such as photos, documents, and signatures; limited inferences concerning usage or workflows; and sensitive personal information such as precise location and account credentials.
We collect and use those categories for the business and commercial purposes described in Sections 7 through 15 and disclose them to the categories of recipients described in Sections 16 and 17. Retention is described in Section 20. Sources are described in Section 6.
Subject to applicable law, a resident may request to know or access categories and specific pieces of information, obtain a portable copy, correct inaccurate information, delete information, opt out of certain sale, sharing, targeted advertising, or profiling, limit certain uses of sensitive information, and appeal a denied request. Submit requests through the methods in Section 23.
We use precise geolocation and account credentials only as reasonably necessary for Service functionality, security, authentication, Customer-requested workforce/location features, fraud prevention, and legal compliance. We do not use sensitive personal information to infer personal characteristics for unrelated purposes.
25. Sale, sharing, targeted advertising, and profiling
We do not sell personal information for money. We do not knowingly sell or share personal information for cross-context behavioral advertising and do not knowingly sell or share personal information of individuals under 16. We do not use Customer Data for targeted advertising to individuals across unrelated businesses or services.
We disclose information to service providers and integrations to provide the Service, which is not treated as a sale or sharing when the provider is contractually restricted and the disclosure qualifies for an applicable statutory exception. If our practices change, we will update this Policy and provide any legally required opt-out mechanism before the new practice begins.
ServeLynx may generate operational reports, assignment recommendations, or workflow insights from Customer instructions and Service usage. We do not currently use solely automated processing to make decisions that produce legal or similarly significant effects about individuals on Gennex's behalf. Customers are responsible for any independent employment, credit, insurance, housing, eligibility, or similarly significant decisions they make using information from ServeLynx.
26. Do Not Track and Global Privacy Control
Some browsers send Do Not Track signals, and there is no uniform technical standard governing all such signals. Because we do not currently use personal information for cross-context behavioral advertising, a Do Not Track signal may not change the operation of the Service.
Where required by applicable law and technically applicable to a processing activity, we will honor recognized opt-out preference signals such as Global Privacy Control. Necessary security, authentication, account, and operational processing will continue.
27. Account and data deletion
ServeLynx is generally deployed in a separate environment for each Customer. User accounts within that environment are created, administered, and controlled by the Customer's authorized administrators. For Customer Data in that environment, Gennex generally acts as a service provider or processor on the Customer's behalf.
A Customer administrator may delete, anonymize, suspend, or deactivate an Authorized User account according to the Customer's instructions, the available system functionality, the Customer agreement, and applicable retention requirements. Deactivation or suspension prevents access but is not the same as deletion.
An Authorized User should first submit an account or data deletion request to the Customer administrator. If the Authorized User cannot identify or contact the Customer administrator, the user may email [email protected]. Gennex may verify the requester's identity and relationship to the Customer and may refer or forward the request to the Customer. Except where required by applicable law, Gennex will not independently delete Customer Data from a Customer-controlled environment without authorization from the Customer or another person legally authorized to provide the instruction.
Deleting a user account does not necessarily delete business records created, entered, approved, signed, assigned, or processed by that user. The Customer or Gennex may retain service records, invoices, payments, time records, work-session and job-event location records, inspection forms, signatures, photos, communications, audit logs, security records, tax and accounting records, and other information that may lawfully be retained. Where reasonably supported and directed by the Customer, identifying profile information may be removed, anonymized, or replaced with a designation such as "Deleted User" while the underlying business record is preserved.
Deletion of an individual user account is separate from termination of a Customer's entire ServeLynx subscription. Subscription-level export, production deletion, and backup retention are governed by Section 20 and the applicable Customer agreement.
Where an applicable app-store rule requires an in-app or web-based deletion path, Gennex will provide an appropriate request path through the application, website, Customer administrator, or a combination of those methods. For the full public account and data deletion notice, including how to submit a request and what happens to your information, visit our Account & Data Deletion page.
28. Children's privacy
ServeLynx is a business platform and is not directed to children under 13 or a higher minimum age where required by local law. We do not knowingly collect personal information directly from children for Gennex's own purposes. If you believe a child provided information directly to us without appropriate authorization, contact [email protected] so we can investigate and take appropriate action.
Customers are responsible for determining whether they may lawfully enter information concerning minors, such as a household contact or service recipient, and for obtaining any required consent. Customers must not use ServeLynx to profile, market to, or make prohibited decisions about children.
29. Sensitive and regulated data restrictions
Unless Gennex expressly authorizes the specific processing in a signed written agreement, ServeLynx is not designed, approved, or intended for protected health information subject to HIPAA, Social Security numbers, complete government-identification numbers, full payment-card data or card security codes, bank-login credentials, biometric identifiers used for identification, highly sensitive financial credentials, criminal-justice information, classified information, export-controlled technical data, or other data requiring a specialized compliance program.
Customers and users must not upload or enter such information into notes, attachments, forms, messages, AI prompts, or other fields. A general DPA, confidentiality provision, or use of encryption does not by itself authorize regulated data. Any authorization must specifically identify the data, legal framework, security requirements, allocation of responsibility, and required addendum, such as a business associate agreement where applicable.
Gennex may remove, quarantine, restrict, or suspend processing of prohibited data and may require the Customer to assist with deletion, remediation, investigation, or notification. The Customer remains responsible for consequences arising from unauthorized submission of prohibited data, subject to applicable law and the Customer agreement.
30. De-identified and aggregated information
We may create and use aggregated, anonymized, or de-identified information for security, analytics, service performance, product improvement, benchmarking, reporting, capacity planning, and business operations. We maintain de-identified information in de-identified form and will not attempt to re-identify it except as permitted by law, such as to test de-identification, investigate security, or protect against fraud.
Where practical, benchmarking and product analytics are designed to avoid identifying a Customer or individual. We do not publicly disclose a Customer's confidential operational information without authorization.
31. Third-party websites and services
The Service may contain links to or integrations with third-party websites, applications, payment pages, mapping tools, accounting systems, app stores, or other services. Their privacy practices are governed by their own policies and agreements. Gennex does not control and is not responsible for a third party's independent collection, use, security, availability, or legal compliance, except to the extent applicable law expressly provides otherwise.
32. Changes to this Policy
We may update this Policy to reflect changes in law, technology, providers, features, security, or business operations. The Last Updated date identifies the current version. We will provide additional notice of material changes when required by law or contract, which may include website, email, in-app, or Customer-administrator notice.
Changes apply prospectively from the effective date unless law requires otherwise. If a change requires consent, we will request consent before applying the change to processing that requires it.
33. Relationship to Customer agreements
This Policy describes privacy practices and does not expand contractual warranties, service levels, indemnities, or liability beyond those expressly stated in an applicable Customer agreement or required by law. If a signed Data Processing Addendum conflicts with this Policy regarding Customer Data, the Data Processing Addendum controls to the extent of the conflict. If a Customer agreement provides greater protection, that agreement controls for that Customer.
Nothing in this Policy limits non-waivable rights or obligations under applicable law. Gennex's members, managers, officers, employees, and contractors act on behalf of Gennex within the scope of their duties; Customer claims and contractual remedies are governed by the applicable agreement and law.
34. Contact us
For privacy questions, requests, complaints, or concerns, contact:
Attn: Privacy Officer
Email: [email protected]
Phone: +1 941-274-9813
Online: www.servelynx.com/contact
If your request concerns information held by a ServeLynx Customer, please also contact that Customer directly because the Customer may be responsible for responding to the request.