Privacy Policy
Transparency, accountability and a clearly structured overview of how personal data is processed at vollsign.
Data minimization, clear responsibilities and documented processing
SSL or TLS encryption and protected transmission of confidential content
Hosting, responsible party, data subject rights, cookies and signature data
Abschnitt 01
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.
Abschnitt 02
2. Hosting
We host the content of our website at Hetzner Cloud in Frankfurt am Main, Germany. The content we host is stored exclusively on servers in Germany and never leaves the EU.
For individual processing steps we use additional service providers outside the EU (e.g. SMS delivery via Twilio, USA, under EU Standard Contractual Clauses). The full, current list is available at /subprocessors.
Abschnitt 03
3. General Notes and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
Abschnitt 04
4. Responsible Party
vollsign GmbH 123 Main Street 60311 Frankfurt am Main Germany Phone: +49 (0) 30 1234567 Email: [email protected]
Provisional details: the address and phone number of the responsible party are placeholders and will be replaced with the actual company data before public launch (see also Legal Notice).
Abschnitt 05
5. Data Collection on this Website
Cookies & Traffic Measurement
Our website uses technically necessary cookies. These are required for our website to function properly. We do not use tracking cookies or analysis cookies. For public law-firm profiles (/p/firm-name), we count page views to give the firm basic usage statistics: the IP address and browser identifier are combined with the current date and hashed server-side into a one-way value (not a cookie, not traceable back to an individual, rotates daily so there is no tracking across days). The legal basis is our and the firm's legitimate interest in visible profile traffic (Art. 6(1)(f) GDPR). Retention: 12 months.
Abschnitt 06
6. Language Detection
On your first visit, we determine an approximate language preference (German/English) from the country code provided by our hosting/CDN provider (derived from the IP address, not separately transmitted to any third party). The result is stored in a cookie ("locale", up to 12 months). You can change the language at any time using the language switcher; your choice then takes precedence over the automatic detection.
Abschnitt 07
7. Your Rights
You have the right to request information about your stored personal data, its origin and recipients and the purpose of data processing at any time and free of charge, as well as a right to correction, blocking or deletion of this data.
- Right to information (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to deletion (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
Abschnitt 08
8. Data Security
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator.
Abschnitt 09
9. Account and Session Data
Each time you sign in to your account we store technical details about the session. They protect your account and let you review and end your active sessions in your account settings. We process:
- The IP address the sign-in came from
- Device and browser details (device type, browser, operating system)
- Approximate location derived from the IP address (country, region, city). The lookup runs locally on our servers; no data is sent to third parties for it.
- Time of sign-in and of last activity
The legal basis is our legitimate interest in the security of your account (Art. 6(1)(f) GDPR). Session data is deleted automatically after 30 days. You can review and end active sessions at any time in your account settings.
Abschnitt 10
10. Retention Periods
We delete or anonymize personal data automatically once the purpose it was collected for has ended. The following periods apply:
- Login sessions for your account: 30 days after expiry
- Login sessions for our administrative access: 90 days after expiry, so that security incidents can be investigated
- Incomplete registrations: no later than 24 hours after the confirmation code expires
- Profile and website analytics (pseudonymous visitor hash, referrer, browser details, country): 12 months
- Signature evidence: kept indefinitely by default, unless the firm has configured a retention period. If the firm sets a period (minimum 6 years under § 50 BRAO), the document's personal data (name, contact details, signature image, document content) is automatically anonymized once it expires. The cryptographic evidence (hashes, TSA timestamp, audit log) is kept permanently for evidentiary purposes in either case and is not deleted. Deletion before the period expires can be requested and will be reviewed, provided no statutory retention obligation applies
Statutory retention obligations remain unaffected. On request we will tell you what data we hold about your account (Art. 15 GDPR).
Abschnitt 11
11. Electronic Signatures
When using our signature function, the following data is processed. This data is required for the legally valid documentation of the electronic signature and is stored in accordance with statutory retention periods.
- Name and contact details of the signer
- IP address and timestamp
- Signature image data
- For AES: phone number for SMS verification
- Device and browser characteristics (browser type and version, operating system, screen resolution, time zone and language setting) as technical evidence of the signature
- Approximate location derived from the IP address (country and city, no precise positioning)
Abschnitt 12
12. External Services & Subprocessors
For address lookup we use the map service OpenStreetMap Nominatim (OpenStreetMap Foundation). When you search for an address in the application, the search term you enter is transmitted to that service in order to determine the corresponding coordinates. No account data is transmitted. Please do not enter anything into the address search beyond the address you are looking for.
In addition, we use service providers for hosting, payment processing (Stripe), SMS delivery (Twilio) and cryptographic timestamping (freetsa.org). The full, continuously updated list with each provider's purpose, location and contract status is available at /subprocessors.
Abschnitt 13
13. Changes to This Privacy Policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to reflect changes to our services in this privacy policy.
Status: August 13, 2026