Privacy Policy
Draft, version 0.4 — information pursuant to Articles 13/14 GDPR on the processing of personal data in the Quovalis service. Last revised: 4 August 2026.
1. Controller
Thomas Braun, trading as Quovalis (Einzelunternehmen), Oskar-von-Miller-Ring 20, 80333 München, Germany — contact@quovalis.eu.
2. Our role: controller and processor
For the account, billing, security and website data described below we act as controller. For the contents of certificates submitted for validation and the resulting validation records we act as processor on behalf of the customer (Art. 28 GDPR): the customer determines the purposes of that processing and supplies its legal basis, and a data processing agreementgoverns it. The retention windows shown for validation records are service parameters of the customer’s plan. The customer is responsible for being entitled to submit certificate data and for any information duties toward the persons identifiable from submitted certificates.
3. What we process, why, and for how long
| Data | Purpose (legal basis) | Retention |
|---|---|---|
| Account: email address, password (stored as argon2id hash); with the optional email second factor, short-lived sign-in codes (stored hashed) | Authentication, service emails (Art. 6(1)(b) — contract, for the person contracting with us; Art. 6(1)(f) for further members acting for a corporate customer — legitimate interest: providing and securing the service for the customer) | Life of the account; erased on closure |
| Sessions: token hash, IP address, browser user agent | Sign-in, abuse forensics (Art. 6(1)(b); Art. 6(1)(f) — legitimate interest: keeping accounts and the platform secure) | 7 days or until sign-out; expired rows swept hourly |
| Abuse counters: IP addresses and email domains of signup/login attempts | Throttling and abuse prevention (Art. 6(1)(f) — legitimate interest: preventing automated abuse and account takeover) | 7 days |
| Team invites and join requests: invitee/requester email address (join requests also a password hash), requested role and a hashed token. For team invitations we receive the invitee’s email address and requested role from the account owner or administrator who sends the invitation. | Adding members to an account (Art. 6(1)(b), (f) — legitimate interest: letting customers manage their own teams; invitation mail links to this policy) | Expired invites and expired or decided join requests are purged hourly; accepted invites persist as membership data for the life of the account |
| Billing data: customer/business name, billing address, VAT ID where provided, invoice and payment records | Invoicing, accounting and tax compliance (Art. 6(1)(b), (c) — statutory accounting duties). Invoicing is manual (SEPA bank transfer); no payment service provider is used. | Statutory retention periods for accounting and tax records (8 years for invoices and accounting records, up to 10 years for accounting books — § 147 AO / § 257 HGB, as amended 2025) — also after account closure |
| Billing settlement records: monthly frozen billing figures (plan base and overage amounts) together with a snapshot of the customer/business name as at the end of the settled month. Settlement records are created only for months in which an amount is owed; accounts that never owe an amount have no settlement records and no name snapshot. | Invoicing, accounting and tax compliance, and maintaining a verifiable billing ledger (Art. 6(1)(b), (c) — statutory accounting and tax duties, § 147 AO / § 257 HGB) | Until the end of the statutory accounting retention period (end of the calendar year of the settlement plus 8 years; accounting books up to 10 years) — also after account closure. At the end of the applicable retention period the settlement record is deleted, or all customer-identifying fields and references in it are irreversibly anonymised; billing figures may thereafter be retained only in a form that can no longer be linked to a customer or natural person. |
| Validation records: submitted certificates’ subject/issuer names, serials and attributes plus the verdict — certificate contents can identify persons; the requester’s IP is not stored | Validation and results retrieval, performed on the customer’s behalf as processor (Art. 28 — the customer supplies the legal basis; see section 2) | Per plan: Free accounts using a public email provider 30 days, other Free accounts 90 days, paid plans 365 days (whole records deleted) |
| Usage aggregates (per-tenant hourly counters) | Quota enforcement, usage display, billing and investigation of disputed charges (Art. 6(1)(b); Art. 6(1)(f) — legitimate interest: maintaining verifiable usage records) | Identifiable counters are retained for the current billing period and thereafter for at most three years from the end of the calendar year in which the usage occurred, then deleted or irreversibly aggregated without the tenant reference. Counters no longer required for billing, quota enforcement or a pending dispute may be deleted earlier. |
| Audit trail (account/admin actions with actor references) | Accountability, security (Art. 6(1)(f) — legitimate interest: tamper-evident records of administrative actions) | 3 years from the event, then deleted or irreversibly anonymised; records relating to a documented security incident, investigation or legal claim may be retained for the duration of that matter and the applicable limitation period. Actor references are unresolvable after account erasure. |
| Contact messages: reply email, optional name, subject and message; for signed-in senders, account and tenant references | Answering enquiries (Art. 6(1)(b), (f) — legitimate interest: responding to messages sent to us) | 180 days, including unread messages; deleted in hourly bounded batches. Deleted copies age out of backups within at most 31 additional days. |
| Operational, security and delivery logs: request logs with timestamps, route, method, status and duration (no IP address); tenant or account references where needed for troubleshooting; the client IP address in sampled API-key allowlist-denial events (at most one log line per key and IP per minute); and recipient email addresses where an email we send fails or is suppressed. Failure diagnostics can also contain a certificate authority’s OCSP/CRL responder URL or an unrecognised PSD2 role value; logs never contain certificate subject or issuer names, serial numbers or subject alternative names. | Operating, securing and troubleshooting the service, investigating failed email delivery and preventing abuse (Art. 6(1)(f) — legitimate interest: service security, reliability and error diagnosis; where a log line relates to validation processing performed on a customer’s behalf, it is part of that processing under Art. 28 and the data processing agreement) | Central logs are retained for 14 days and are not included in backups; a local fallback copy is size-limited and overwritten. Log records preserved for a documented security incident, investigation or legal claim may be retained for the duration of that matter and the applicable limitation period. |
4. Recipients / processors
- Hosting: Hetzner Online GmbH (Germany) (Art. 28 processor).
- Transactional email: Scaleway SAS (France) (Art. 28 processor) — receives email addresses for verification, password-reset, sign-in code (second factor) and team-invitation mail; invitation mail includes addresses of invitees who do not yet have an account. Scaleway also delivers our internal operational alert emails to our own operator address; these can contain pseudonymous account identifiers (tenant references) but no customer names, email addresses or certificate data.
- Accounting and invoicing: EU-hosted accounting software used to prepare and store invoices processes the billing data listed above. The specific vendor will be named here before any billing data is transferred to it.
No data is sold or used for advertising. No profiling. We do not make decisions about individuals that produce legal or similarly significant effects within the meaning of Art. 22 GDPR; validation verdicts are technical outputs provided to our customers, who determine how they are used.
The contact form’s arithmetic challenge is generated and checked locally. Its ten-minute signed token is bound to your IP address; the IP is used only for the challenge and short-lived Redis rate limits and is not stored with your message. No third-party CAPTCHA provider receives your data.
5. Erasure and your rights
The account owner can close the account (console → Settings, password re-entry required); closure immediately revokes all API keys, deletes the user records and sessions of every member, and anonymises the tenant. Stored validation records are purged after a 7-day grace window. Billing and settlement records subject to statutory retention duties (invoicing, accounting and tax records) are excluded from this erasure and kept for the statutory periods (see section 3), including a snapshot of the customer name in the monthly settlement records of months for which an amount was owed. Erased data leaves every backup layer within at most 31 days of deletion under normal operation (backup copies rotate out on fixed, monitored schedules).
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21). Contact: contact@quovalis.eu. You may lodge a complaint with a supervisory authority; the authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht — BayLDA), Ansbach.
6. Cookies and local storage
Two first-party, strictly necessary cookies — one for the session and one for CSRF protection — and one locally stored display preference (your chosen colour theme) are detailed in the cookie notice. No tracking or third-party cookies are used, hence no consent banner.
7. Data location and security
Data is processed within the EU/EEA. Transport is TLS-encrypted; passwords are stored only as salted argon2id hashes and API key secrets only as one-way hashes of high-entropy random values; access is logged in an append-only audit trail.