Privacy Policy
The protection of your personal data is important to us. This policy informs you about which data we process in connection with the DiscloseKit service (disclosekit.eu), for what purpose and on what legal basis.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Kristian Hoffmann
Karl-Kraut-Straße 15
30177 Hannover, Germany
Email: moin@kristianhoffmann.de
2. Basis of processing
We process personal data only where this is legally permitted. The legal bases are in particular Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures), Art. 6(1)(a) GDPR (consent), Art. 6(1)(c) GDPR (legal obligation, e.g. tax retention duties) and Art. 6(1)(f) GDPR (legitimate interests, such as operational security and the prevention of abuse).
3. Data region and hosting
Our application data (accounts, products, AI system inventory, transparency statements and evidence logs) is stored in the EU. We operate the database ourselves, self-hosted on a server in the EU.
- Application and database infrastructure: Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. On a server in Germany (Frankfurt), we operate the application frontend and API as well as our self-hosted database and authentication. For technical reasons, delivery generates server log data (including IP address, timestamp, requested resource and user agent) which serves operational security (Art. 6(1)(f) GDPR).
Insofar as personal data is transferred to service providers in third countries (e.g. the USA), this takes place on the basis of appropriate safeguards, in particular the EU standard contractual clauses.
4. SSL/TLS encryption
This site uses TLS encryption for security reasons. You can recognise an encrypted connection by the “https://” in the address bar of your browser.
5. Cookies
We use technically necessary cookies to operate the logged-in area (session/authentication cookies). These are strictly required for the provision of the service (Art. 6(1)(f) GDPR and § 25(2) TDDDG respectively) and cannot be deselected.
No analytics currently take place: no analytics service is configured, no corresponding script is loaded and no analytics cookies are set. We do not use marketing or advertising cookies either. Should we introduce analytics, this will happen only after your explicit consent.
7. Registration and user account
An account is required to use the dashboard. Authentication is passwordless via a sign-in link sent by email (magic link) or, optionally, via a sign-in service of your choice (Google, GitHub, Apple), where enabled. For this purpose we process your email address and the associated sign-in identifier. The legal basis is Art. 6(1)(b) GDPR.
8. Free Article 50 checker
The public checker can be used without registration. Your answers and the result are stored anonymised. An email address is stored only if you explicitly request the report, and only after you have confirmed your address via a double opt-in confirmation link (Art. 6(1)(a) GDPR).
9. Newsletter
Subscribing to a newsletter is optional and technically separate from the transactional report. Inclusion in the mailing list takes place exclusively after explicit consent in a double opt-in procedure (Art. 6(1)(a) GDPR). You can withdraw your consent at any time with effect for the future, for example via the unsubscribe link in every newsletter email.
10. Email delivery
For sending transactional emails (confirmation of the checker report, team invitations, system-related messages) as well as the newsletter we use the service Brevo. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin. In this process your email address and the content of the respective message are processed. The basis is a data processing agreement.
11. Payment processing
For paid plans we use the payment service provider Stripe. The provider for users in the European Economic Area is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You enter your payment data (e.g. card details) exclusively with Stripe; it is not stored on our servers. We store only the Stripe customer and subscription identifiers as well as the plan status. The legal basis is Art. 6(1)(b) GDPR.
12. Disclosure widget
The embeddable disclosure widget is cookie-free. It sends an anonymous impression counter so that a daily aggregate of the displays can be maintained for your evidence log. No IP addresses are stored, no cookies are set and no individual records per page view are kept. The basis is our legitimate interest in keeping evidence (Art. 6(1)(f) GDPR).
13. Recipients and processors
We use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR exist or are concluded:
- Hostinger International Ltd. (application, database and authentication infrastructure in Germany)
- Stripe Payments Europe, Ltd. (payment processing)
- Sendinblue GmbH / Brevo (email delivery)
14. Retention period
We store personal data only for as long as is necessary for the respective purposes or as long as statutory retention obligations (in particular under commercial and tax law) exist. Afterwards the data is deleted or anonymised.
15. Your rights
Under the GDPR you have in particular the following rights:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
A message to moin@kristianhoffmann.de is sufficient to exercise your rights. You can delete a user account and the associated products yourself at any time.
16. Right to lodge a complaint with a supervisory authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The competent authority for the controller is the Landesbeauftragte für den Datenschutz Niedersachsen.
17. Changes to this policy
We adapt this privacy policy as soon as changes to the data processing we carry out make this necessary. The current version published on this page applies in each case.
18. Language
This English text is a convenience translation. The German version of this privacy policy is the authoritative one; in the event of any discrepancy, the German version prevails.