Version 1.2 · 2026-07-27
Privacy Policy — SecurApp
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:
[Provider — full company name or name of individual]
[Address — street, building number]
[Postcode] [City], Germany
E-Mail: [e-mail]
Phone: [phone]
2. Data Protection Officer
[If legally required or voluntarily appointed — Art. 37 GDPR:]
[Name of Data Protection Officer]
[Address — if different from the controller's address]
E-Mail: [DPO e-mail]
If no Data Protection Officer has been appointed, please direct any data protection enquiries to the controller's contact address above.
[Legal review required: appointment obligation under Art. 37 GDPR and § 38 BDSG; § 38(1) includes organisations that regularly employ at least 20 persons continuously engaged in automated processing.]
3. Principles of Processing
The controller processes personal data exclusively on the legal bases exhaustively listed in Art. 6 GDPR (and Art. 9 GDPR where applicable). A legal basis is explicitly assigned to each processing activity (full matrix: internal document docs/legal/lawful-basis.md).
Processing principles under Art. 5(1) GDPR are observed:
- Lawfulness, fairness and transparency (lit. a)
- Purpose limitation (lit. b)
- Data minimisation (lit. c)
- Accuracy (lit. d)
- Storage limitation (lit. e): Data are deleted once the purpose no longer applies (see Section 8).
- Integrity and confidentiality (lit. f): Technical and organisational measures pursuant to Art. 32 GDPR.
Accountability under Art. 5(2) GDPR is fulfilled through an append-only audit log (audit_event).
4. Data Processed, Purposes and Legal Bases
4.1 User Account and Authentication (mvp-01)
Legal basis: Art. 6(1)(b) GDPR (performance of contract); Art. 6(1)(f) GDPR (legitimate interests) for security logging.
E-mail address
Purpose: Account identification, login, transactional notifications (deadline reminders, verification e-mail, password reset).
Recipients: E-mail service provider Resend (processor; sending routed through Ireland, account/log data stored in the US according to the provider; DPA and international-transfer review — see Section 6).
Retention: Until the erasure request. Access is blocked immediately; primary data are erased by the scheduled deletion date, no later than 30 days after the request.
Password hash (Argon2id)
Purpose: Secure account access.
Retention: Until account deletion; not disclosed to any third party.
TOTP secret (encrypted, optional)
Purpose: Two-factor authentication.
Retention: Until deactivation of 2FA or account deletion.
Session token (HttpOnly cookie)
Purpose: Authenticated session management.
Retention: Maximum 30-day inactivity timeout; immediate invalidation on logout.
Verification and reset tokens
Purpose: E-mail confirmation, password recovery (single-use).
Retention: Maximum 48 hours (verification) / 30 minutes (password reset); automatic deletion thereafter.
Time zone (user preference)
Purpose: Correct calculation and display of GDPR deadlines.
Retention: Until account deletion.
IP address and user agent
Purpose: IT security, abuse prevention, brute-force protection.
Legal basis: Art. 6(1)(f) GDPR — legitimate interests of the controller and users in service security.
Storage: The application does not persist IP addresses in plain text. It stores an HMAC-SHA-256 value using a secret kept separately. Rotation is a controlled operational procedure and is not currently automated monthly.
Retention: IP hash: 90 days from event timestamp, then nullified (ipHash = NULL). A user-agent string may be personal data and is retained in the working design for up to 3 years as part of the audit log; necessity and duration require approval under LEGAL-03.
4.2 Digital Twin — Management of Personal Data (mvp-02)
Legal basis: Art. 6(1)(b) GDPR (performance of contract — the Digital Twin is the central data object of the core service).
For particularly sensitive optional fields (IBAN, ID document number): Art. 6(1)(a) GDPR (consent) where not strictly necessary for contract performance [legal review required: delimitation lit. a / lit. b for IBAN].
Master data (first name, last name, date of birth, address)
Purpose: Auto-populating GDPR request letters.
Recipients: Indirectly — the data appears in the letter sent to the company chosen by the user. The receiving company processes these data as an independent controller (SecurApp is not responsible for that processing).
Retention: Until account deletion; in archive context 90 days after request closure.
Contact data (e-mail, phone)
Purpose: Letter address; optional contact information in requests.
Retention: As master data.
Online accounts (service name, username, linked company)
Purpose: Assigning requests to affected accounts; overview of digital footprint.
Retention: Until account deletion or manual removal by the user.
Twin field version history
Purpose: Traceability of changes; support for Art. 16 rectification requests (Phase 2).
Retention: Until account deletion (cascade delete).
Sensitive fields (date of birth, ID document number, IBAN)
Protection: Per-field AES-256-GCM envelope encryption; key management via Vault Transit Secrets Engine on Hetzner Cloud (EU/Falkenstein) — see Section 6.
Frontend display: Masked (e.g. ••••1990).
Retention: Until manual deletion by the user or account deletion.
Note on Art. 9 GDPR: Within the MVP scope, no special categories of personal data (health data, biometric data, etc.) are structurally captured. If a user enters such data in free-text fields, this is done at their own risk. For future features processing Art. 9 data structurally, explicit consent (Art. 9(2)(a) GDPR) will be obtained.
4.3 GDPR Request Generator and Communication System (mvp-03, mvp-05)
Legal basis: Art. 6(1)(b) GDPR (performance of contract — core service); Art. 6(1)(f) GDPR (legitimate interests of the user in evidence preservation) for archiving.
Request content (generated letter text)
Purpose: Sending the GDPR request to the company selected by the user; proof of content.
Recipients: The company addressed by the user (independent controller).
Retention: In the technical working design, 90 days after request closure; extension at the User's request is not implemented.
Request metadata (type, company, status, timestamp)
Purpose: Deadline management, status overview, auditing.
Retention: 90 days after request closure.
Request drafts (status DRAFT)
Purpose: Temporary storage of unsent requests.
Retention: 90 days of inactivity, then automatic deletion. During the final 14 days, a deletion notice is shown in the request list and detail view. No separate email is sent, and merely opening the draft does not extend the period.
Reply alias e-mail address (reply-<ulid>@inbox.securapp.de)
Purpose: Routing incoming company replies to the respective request — without disclosing the user's personal e-mail address to the company.
Privacy-by-Design feature: The personal account e-mail address is not disclosed to the addressed company as the reply address. Resend does process it for account e-mails and notifications, so this statement does not apply to the e-mail processor.
Recipients: Resend (inbound routing, processor). The receiving company sees only the alias address.
Retention: The alias mapping is part of the request and, in the technical working design, is deleted with it 90 days after closure.
Incoming replies and attachments
Purpose: assignment to the request, display in the conversation, notification and archiving. Resend accepts mail for the inbound domain; SecurApp retrieves content and attachments through the provider API. Attachments are checked by a self-hosted malware scanner before release. Quarantine, rejection and deletion periods must be finalised in Section 8 and under LEGAL-03. Scanning cannot guarantee that a file is harmless.
Identity verification
SecurApp does not verify the User's identity or authority and does not tell the recipient that identity verification has been completed. The User selects the information sent for matching. Where doubts are justified, the recipient company may request additional proportionate information. Copies of identity documents should not be sent without a concrete need.
4.4 Company Directory (mvp-04)
Legal basis: Art. 6(1)(f) GDPR (legitimate interests — providing the curated directory as a service feature).
The company directory contains only information about legal entities and their data protection functional mailboxes (e.g. datenschutz@, dpo@) — no personalised contact details of natural persons. Sources are exclusively publicly accessible privacy policies and legal notices.
Companies or their representatives may request correction or removal of a directory entry via the form at /transparenz/eintrag-korrigieren (processing within 7 business days).
4.5 Deadline Management and Escalation (mvp-06)
Legal basis: Art. 6(1)(b) GDPR (performance of contract); Art. 6(1)(f) GDPR (legitimate interests of the user in compliance with deadlines).
SecurApp technically adds one buffer day after dispatch and then displays an indicative deadline. Art. 12(3) GDPR generally requires a response without undue delay and within one month; depending on complexity and number of requests, it may be extended by up to two further months subject to the information requirements stated there. The display is not a binding calculation for an individual case. Reminder e-mails are sent through Resend. An escalation draft is generated only after a User action and transmitted only after a further explicit send action.
4.6 Document Archive (mvp-07)
Legal basis: Art. 6(1)(b) GDPR (performance of contract — the archive is a contractually committed part of the service); Art. 6(1)(f) GDPR (legitimate interests of the user in integrity-protected evidence preservation).
Sent requests as PDF
Content: Date, recipient address, reply alias, request text, SHA-256 integrity hash.
Signature: Self-signed certificate (SecurApp-own CA); hash stored append-only in audit_event (DEC-13).
Retention: 90 days after request closure; 30-day transition period after account deletion.
EML files (sent and received e-mails)
Retention: 90 days after request closure.
Encryption: The SecurApp application server encrypts archive files at application level using AES-256-GCM (per-user DEK, KEK-wrapped via Vault Transit) before transfer to object storage. Direct access only to the storage layer is therefore insufficient to read content. The regular admin interface exposes no content; highly privileged, audited recovery access to the application and Vault remains a technical trust boundary.
ZIP export: Download link generated on request (valid 15 minutes); file automatically deleted thereafter.
4.7 Audit Events (all areas)
Legal basis: Art. 6(1)(c) GDPR (legal obligation — accountability pursuant to Art. 5(2) GDPR); Art. 6(1)(f) GDPR (legitimate interests — integrity assurance).
All security- and privacy-relevant actions are logged in an append-only table (audit_event): action, actor ID, timestamp, SHA-256 hash of the affected object, pseudonymised IP (hash), user agent.
Retention: In the technical design awaiting approval, 3 years from the event timestamp. Actor ID, IP hash and user agent are then removed and the concrete target ID is generalised; only a minimised factual record remains. Whether and to what extent Art. 17(3)(e) GDPR or accountability duties justify that remainder must be decided for the actual purposes and claims; no blanket exemption is asserted.
5. No Automated Decision-Making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place that produces legal effects concerning data subjects or similarly significantly affects them.
6. Recipients and Processors
The following service providers process personal data exclusively on instructions from the controller (Art. 28 GDPR). A Data Processing Agreement (DPA) has been or will be concluded with all service providers before go-live. Safeguards for international transfers must be legally reviewed and documented as set out in Section 7 before go-live.
6.1 Plus Five Five, Inc. (`Resend`) — E-mail Sending and Inbound Routing
Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA
[Legal review required: Resend documents that selecting Ireland controls only routing/sending and that account data, including e-mail metadata, logs and API records, is stored in the US. Review the DPA, subprocessors, transfer mechanism, transfer impact assessment and retention periods.]
Purpose: Sending transactional e-mails (verification, deadline reminders, notifications) and inbound routing of company replies via reply aliases.
Sending route: Ireland (eu-west-1); account/log data: US according to current provider documentation (DEC-09).
DPA/transfer status: Mandatory legal approval under LEGAL-01 before go-live.
6.2 Hetzner Online GmbH — Hosting, Object Storage, Key Management
Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany
Purpose:
(a) Hosting of the application and database (PostgreSQL) on Hetzner Cloud servers (Falkenstein, FSN1, Germany).
(b) Object storage for the document archive (EML files, signed PDFs, ZIP exports) — Hetzner Object Storage, Falkenstein, Germany (DEC-16).
(c) Key management (HashiCorp Vault Transit Secrets Engine, self-hosted on Hetzner Cloud) for envelope encryption (DEC-17).
Server location: Germany, Falkenstein (EU).
DPA status: Standard data processing agreement available via Hetzner Cloud Console; to be accepted before go-live (DEC-16, DEC-17).
Note on the company directory: When dispatching a request, the company addressed by the user receives the generated letter content (including personal data of the user). The receiving company processes these data as an independent controller (Art. 4(7) GDPR). SecurApp has no influence over the processing by the respective company.
7. Third-Country Transfers
The self-operated application, database, storage and Vault stack is planned for Germany (Hetzner, Falkenstein). Resend, however, documents that account data, including e-mail metadata, logs and API records, is stored in the US; choosing Ireland as the sending region does not change that storage. [Legal review required: lawfulness and safeguards under Art. 44 et seq. GDPR, including the DPA, subprocessors, suitable transfer mechanism and transfer impact assessment.] Production use is blocked until LEGAL-01 records approval.
8. Retention Periods and Erasure
The following are maximum retention periods; earlier erasure upon request (Art. 17 GDPR) is possible unless overriding interests or legal obligations apply.
User account data (e-mail, preferences): until the erasure request; access is blocked immediately and primary data are erased no later than 30 days afterwards.
Password hash: until the scheduled deletion date, no later than 30 days after the erasure request; login is disabled from the time of the request.
TOTP secret: until 2FA deactivation or account deletion.
Session tokens: max. 30-day idle timeout; on logout immediately.
Verification/reset tokens: max. 48 hours (verification) / 30 minutes (reset).
Digital Twin field data (all fields): until account deletion (cascade delete).
GDPR requests and communication: working design of 90 days after closure (CLOSED/ESCALATED); drafts after 90 days of inactivity. During the final 14 days, drafts show a notice in the list and detail view; no separate notice is currently sent before deletion of closed requests.
EML and PDF archive: 90 days after request closure; on account deletion at most 30 days after the deletion request.
Reply alias mapping: deleted as part of the request in the working design 90 days after closure.
Audit events: working design of 3 years; actor ID, IP hash and user agent are then removed and the target ID generalised. The period and remaining factual record require legal approval (see Section 4.7).
IP hash in audit events: 90 days, then nullified.
Directory feedback: at most 24 months.
Company suggestions: after review, or no later than 183 days after submission.
Directory audit: IP hash for 90 days; admin and free-text references for a working-design maximum of 3 years, then minimised.
Orphan provider events without user, message or content reference: 90 days.
ZIP export files: 15 minutes after generation (automatic S3 lifecycle deletion).
Encrypted backups: rolling 35 daily generations; disaster recovery only, with erasure cascades re-applied after restore.
Provider copies/backups: Resend documents production backups persisted for 30 days and replicated globally, and deletion of user/customer data within 90 days after account termination; individual erasure and the applicable contract version remain to be resolved under LEGAL-01.
The complete technical retention matrix is maintained internally and approved by the named owners before publication.
9. Rights of Data Subjects
Data subjects have the following rights against the controller, which may be exercised at any time using the contact details in Section 1:
Right of access (Art. 15 GDPR): Right to obtain confirmation of whether personal data concerning them are processed, and if so, to access those data and receive information on purposes, categories, recipients, retention periods, origin and existence of automated decision-making.
Right to rectification (Art. 16 GDPR): Right to rectification of inaccurate or completion of incomplete personal data. Master data in the Digital Twin can be modified directly by the user in the settings.
Right to erasure (Art. 17 GDPR): Right to erasure of personal data when the purpose no longer applies, consent has been withdrawn, no overriding legitimate interest exists, or processing was unlawful. No blanket exemption is assumed for audit records: necessity, period and any Art. 17(3) restriction are assessed for the specific purpose or case; the technical working design minimises the record after three years.
Right to restriction of processing (Art. 18 GDPR): Right to restriction while accuracy is contested, processing is unlawful and erasure is refused, the data are needed for legal claims, or an objection under Art. 21 GDPR has been lodged.
Right to data portability (Art. 20 GDPR): Right to receive data provided on the basis of Art. 6(1)(b) or Art. 6(1)(a) in a structured, commonly used, machine-readable format and to transmit those data to another controller. In SecurApp: the ZIP export function (Section 4.6, AC-08 mvp-07) technically covers this right.
Right to object (Art. 21 GDPR): Right to object to processing based on Art. 6(1)(f) GDPR. For direct marketing, no justification is required (Art. 21(2) GDPR). SecurApp does not engage in direct marketing towards users.
Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent (e.g. optionally entered sensitive fields), consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint (Art. 77 GDPR): Data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.
Before publication, the state supervisory authority competent for the non-public controller at its actual establishment must be inserted with name, address and website. Irrespective of this, a complaint may in particular be lodged with an authority at the data subject's habitual residence, place of work or place of the alleged infringement. [Legal review required and operator identity to be inserted.]
10. Data Security
The controller implements technical and organisational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk, including in particular:
- Transport encryption (TLS 1.2 or higher) for all connections.
- Per-field AES-256-GCM envelope encryption for sensitive data categories.
- Password hashing with Argon2id.
- IP address pseudonymisation using HMAC-SHA-256 with a secret key.
- Append-only recording with minimisation executable only by the restricted retention worker.
- Tenant separation via owner columns and Row-Level Security in the database.
- HttpOnly/Secure cookies for session tokens.
- Rate-limiting and temporary account lock on login failures.
- Key management via Vault Transit Secrets Engine (EU/Falkenstein) with least-privilege policy.
11. No Legal Advice
SecurApp is a technical tool to assist in exercising GDPR rights. The letters and information generated by the app do not constitute legal advice and do not replace advice from a qualified lawyer. For complex legal matters, consulting a qualified legal professional is recommended.
12. Changes to This Privacy Policy
This working draft is current as of 2026-07-27. The approved current version is available at /legal/datenschutz. Registered users will be informed of material changes; where renewed contractual acceptance is required, it will be obtained separately from the privacy information.
*Version 1.2 | 2026-07-27 | Product/privacy-counsel approval pending*