Back to Home
Privacy

Privacy Policy

Transparency, accountability and a clearly structured overview of how personal data is processed at vollsign.

Focus

Data minimization, clear responsibilities and documented processing

Security

SSL or TLS encryption and protected transmission of confidential content

Contents

Hosting, responsible party, data subject rights, cookies and signature data

Abschnitt 01

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.

Abschnitt 02

2. Hosting

We host the content of our website at Hetzner Cloud in Frankfurt am Main, Germany. The content we host is stored exclusively on servers in Germany and never leaves the EU.

For individual processing steps we use additional service providers outside the EU (e.g. SMS delivery via Twilio, USA, under EU Standard Contractual Clauses). The full, current list is available at /subprocessors.

Abschnitt 03

3. General Notes and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

Abschnitt 04

4. Responsible Party

vollsign GmbH 123 Main Street 60311 Frankfurt am Main Germany Phone: +49 (0) 30 1234567 Email: [email protected]

Provisional details: the address and phone number of the responsible party are placeholders and will be replaced with the actual company data before public launch (see also Legal Notice).

Abschnitt 05

5. Data Collection on this Website

Cookies & Traffic Measurement

Our website uses technically necessary cookies. These are required for our website to function properly. We do not use tracking cookies or analysis cookies. For public law-firm profiles (/p/firm-name), we count page views to give the firm basic usage statistics: the IP address and browser identifier are combined with the current date and hashed server-side into a one-way value (not a cookie, not traceable back to an individual, rotates daily so there is no tracking across days). The legal basis is our and the firm's legitimate interest in visible profile traffic (Art. 6(1)(f) GDPR). Retention: 12 months.

Abschnitt 06

6. Language Detection

On your first visit, we determine an approximate language preference (German/English) from the country code provided by our hosting/CDN provider (derived from the IP address, not separately transmitted to any third party). The result is stored in a cookie ("locale", up to 12 months). You can change the language at any time using the language switcher; your choice then takes precedence over the automatic detection.

Abschnitt 07

7. Your Rights

You have the right to request information about your stored personal data, its origin and recipients and the purpose of data processing at any time and free of charge, as well as a right to correction, blocking or deletion of this data.

  • Right to information (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to deletion (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

Abschnitt 08

8. Data Security

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator.

Abschnitt 09

9. Account and Session Data

Each time you sign in to your account we store technical details about the session. They protect your account and let you review and end your active sessions in your account settings. We process:

  • The IP address the sign-in came from
  • Device and browser details (device type, browser, operating system)
  • Approximate location derived from the IP address (country, region, city). The lookup runs locally on our servers; no data is sent to third parties for it.
  • Time of sign-in and of last activity

The legal basis is our legitimate interest in the security of your account (Art. 6(1)(f) GDPR). Session data is deleted automatically after 30 days. You can review and end active sessions at any time in your account settings.

Abschnitt 10

10. Retention Periods

We delete or anonymize personal data automatically once the purpose it was collected for has ended. The following periods apply:

  • Login sessions for your account: 30 days after expiry
  • Login sessions for our administrative access: 90 days after expiry, so that security incidents can be investigated
  • Incomplete registrations: no later than 24 hours after the confirmation code expires
  • Profile and website analytics (pseudonymous visitor hash, referrer, browser details, country): 12 months
  • Signature evidence: kept indefinitely by default, unless the firm has configured a retention period. If the firm sets a period (minimum 6 years under § 50 BRAO), the document's personal data (name, contact details, signature image, document content) is automatically anonymized once it expires. The cryptographic evidence (hashes, TSA timestamp, audit log) is kept permanently for evidentiary purposes in either case and is not deleted. Deletion before the period expires can be requested and will be reviewed, provided no statutory retention obligation applies

Statutory retention obligations remain unaffected. On request we will tell you what data we hold about your account (Art. 15 GDPR).

Abschnitt 11

11. Electronic Signatures

When using our signature function, the following data is processed. This data is required for the legally valid documentation of the electronic signature and is stored in accordance with statutory retention periods.

  • Name and contact details of the signer
  • IP address and timestamp
  • Signature image data
  • For AES: phone number for SMS verification
  • Device and browser characteristics (browser type and version, operating system, screen resolution, time zone and language setting) as technical evidence of the signature
  • Approximate location derived from the IP address (country and city, no precise positioning)

Abschnitt 12

12. External Services & Subprocessors

For address lookup we use the map service OpenStreetMap Nominatim (OpenStreetMap Foundation). When you search for an address in the application, the search term you enter is transmitted to that service in order to determine the corresponding coordinates. No account data is transmitted. Please do not enter anything into the address search beyond the address you are looking for.

In addition, we use service providers for hosting, payment processing (Stripe), SMS delivery (Twilio) and cryptographic timestamping (freetsa.org). The full, continuously updated list with each provider's purpose, location and contract status is available at /subprocessors.

Abschnitt 13

13. Changes to This Privacy Policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to reflect changes to our services in this privacy policy.

Status: August 13, 2026