Privacy Policy

The protection of your personal data is important to us. This policy informs you about which data we process in connection with the DiscloseKit service (disclosekit.eu), for what purpose and on what legal basis.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Kristian Hoffmann
Karl-Kraut-Straße 15
30177 Hannover, Germany
Email: moin@kristianhoffmann.de

2. Basis of processing

We process personal data only where this is legally permitted. The legal bases are in particular Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures), Art. 6(1)(a) GDPR (consent), Art. 6(1)(c) GDPR (legal obligation, e.g. tax retention duties) and Art. 6(1)(f) GDPR (legitimate interests, such as operational security and the prevention of abuse).

3. Data region and hosting

Our application data (accounts, products, AI system inventory, transparency statements and evidence logs) is stored in the EU. We operate the database ourselves, self-hosted on a server in the EU.

  • Application and database infrastructure: Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. On a server in Germany (Frankfurt), we operate the application frontend and API as well as our self-hosted database and authentication. For technical reasons, delivery generates server log data (including IP address, timestamp, requested resource and user agent) which serves operational security (Art. 6(1)(f) GDPR).

Insofar as personal data is transferred to service providers in third countries (e.g. the USA), this takes place on the basis of appropriate safeguards, in particular the EU standard contractual clauses.

4. SSL/TLS encryption

This site uses TLS encryption for security reasons. You can recognise an encrypted connection by the “https://” in the address bar of your browser.

5. Cookies

We use technically necessary cookies to operate the logged-in area (session/authentication cookies). These are strictly required for the provision of the service (Art. 6(1)(f) GDPR and § 25(2) TDDDG respectively) and cannot be deselected.

No analytics currently take place: no analytics service is configured, no corresponding script is loaded and no analytics cookies are set. We do not use marketing or advertising cookies either. Should we introduce analytics, this will happen only after your explicit consent.

7. Registration and user account

An account is required to use the dashboard. Authentication is passwordless via a sign-in link sent by email (magic link) or, optionally, via a sign-in service of your choice (Google, GitHub, Apple), where enabled. For this purpose we process your email address and the associated sign-in identifier. The legal basis is Art. 6(1)(b) GDPR.

8. Free Article 50 checker

The public checker can be used without registration. Your answers and the result are stored anonymised. An email address is stored only if you explicitly request the report, and only after you have confirmed your address via a double opt-in confirmation link (Art. 6(1)(a) GDPR).

9. Newsletter

Subscribing to a newsletter is optional and technically separate from the transactional report. Inclusion in the mailing list takes place exclusively after explicit consent in a double opt-in procedure (Art. 6(1)(a) GDPR). You can withdraw your consent at any time with effect for the future, for example via the unsubscribe link in every newsletter email.

10. Email delivery

For sending transactional emails (confirmation of the checker report, team invitations, system-related messages) as well as the newsletter we use the service Brevo. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin. In this process your email address and the content of the respective message are processed. The basis is a data processing agreement.

11. Payment processing

For paid plans we use the payment service provider Stripe. The provider for users in the European Economic Area is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You enter your payment data (e.g. card details) exclusively with Stripe; it is not stored on our servers. We store only the Stripe customer and subscription identifiers as well as the plan status. The legal basis is Art. 6(1)(b) GDPR.

12. Disclosure widget

The embeddable disclosure widget is cookie-free. It sends an anonymous impression counter so that a daily aggregate of the displays can be maintained for your evidence log. No IP addresses are stored, no cookies are set and no individual records per page view are kept. The basis is our legitimate interest in keeping evidence (Art. 6(1)(f) GDPR).

13. Recipients and processors

We use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR exist or are concluded:

  • Hostinger International Ltd. (application, database and authentication infrastructure in Germany)
  • Stripe Payments Europe, Ltd. (payment processing)
  • Sendinblue GmbH / Brevo (email delivery)

14. Retention period

We store personal data only for as long as is necessary for the respective purposes or as long as statutory retention obligations (in particular under commercial and tax law) exist. Afterwards the data is deleted or anonymised.

15. Your rights

Under the GDPR you have in particular the following rights:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)

A message to moin@kristianhoffmann.de is sufficient to exercise your rights. You can delete a user account and the associated products yourself at any time.

16. Right to lodge a complaint with a supervisory authority

Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The competent authority for the controller is the Landesbeauftragte für den Datenschutz Niedersachsen.

17. Changes to this policy

We adapt this privacy policy as soon as changes to the data processing we carry out make this necessary. The current version published on this page applies in each case.

18. Language

This English text is a convenience translation. The German version of this privacy policy is the authoritative one; in the event of any discrepancy, the German version prevails.