Last updated: 7 August 2026 · Controller, data categories, purposes, your rights
The controller within the meaning of Art. 4(7) GDPR is:
Jonathan Sternberg, trading as Sternberg Consulting
Hohe Str. 3
08491 Netzschkau, Germany
Email: privacy@agnocheck.com
Data Protection Officer: no data protection officer has been appointed
AGNO is a platform that documents cleaning work: cleaning plans, who executed them, photo evidence, approvals, customer reviews and complaints. This means personal data of three groups is processed:
3.1 For account and billing data of our direct customers, we are the controller.
3.2 For content data — cleaning plans, evidence records, photos, employee names and PINs, customer reviewer inputs — the respective customer (typically the cleaning company) is the controller and we act as processor under Art. 28 GDPR. We conclude a Data Processing Agreement (DPA/AVV) with business customers on request.
3.3 If you are an employee or customer of a company using AGNO, please contact that company first to exercise your data subject rights; we support them in fulfilling your request.
Payments are processed by Paddle.com Market Ltd. (merchant of record). Paddle processes payment data (card details, billing address, transaction data) under its own privacy policy; we receive only transaction confirmations and invoice-relevant data. Legal basis: Art. 6(1)(b) GDPR. See Paddle’s privacy policy.
If you contact us (email, support), we process your message and contact details to handle the request. Legal basis: Art. 6(1)(b) or (f) GDPR. We retain support communications only as long as necessary to resolve the request, document the business relationship, or meet legal obligations.
We use the following recipients and service providers to operate AGNO:
Where a subprocessor is located outside the EU/EEA, we ensure an adequate level of protection via adequacy decisions or standard contractual clauses (Art. 44 et seq. GDPR).
We apply technical and organizational measures under Art. 32 GDPR, including: encrypted transport (TLS), encryption at rest, hashed credentials and PINs, tenant isolation, role-based access, audit logging of workspace actions, and regular backups. Temporary customer-authorized support access is itself recorded in the audit trail.
Under the GDPR you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent where processing is based on consent (Art. 7(3)). To exercise your rights, contact privacy@agnocheck.com.
You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence or place of work. The authority responsible for us is the Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden, Germany.
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Alerts (e.g. overdue tasks) are rule-based notifications, not decisions about persons.
We may update this policy to reflect legal or functional changes. The current version is always available on this page; material changes are communicated to registered customers by email.