Privacy Policy
Privacy Policy
Default template – please complete master data and publish your own version if needed.
Controller under the GDPR:
{{companyName}} ({{legalForm}})
{{addressBlock}}
Email: {{email}}
Phone: {{phone}}
Data Protection Officer: {{dpoName}} · {{dpoEmail}}
Supervisory authority: {{supervisoryAuthority}}
This notice informs you pursuant to Art. 13/14 GDPR about processing of personal data when using RD-Office (“Application”).
1. Legal bases
We process personal data only where a legal basis under Art. 6(1) GDPR applies, in particular contract (b), legal obligation (c), legitimate interests (f) balancing your rights, and consent (a) which you may withdraw (Art. 7(3)). Special categories (Art. 9) are processed only where permitted (e.g. employment law, consent).
2. Hosting & infrastructure
The Application is operated by the controller with processors under Art. 28 (see section 8). Technically necessary data (IP in security logs, timestamp, user agent) may be processed for delivery and security (Art. 6(1)(f)). Log retention is kept as short as reasonably possible.
Infrastructure stack (DPA on file):
| Service | Provider | Purpose | Typical data |
|---|---|---|---|
| App hosting | Vercel Inc. | Deliver the web application | IP, request metadata, logs |
| Database | Neon or similar (EU) | Store application data | Application content |
| Domain registrar | STRATO GmbH (DE) | Domain registration with the registry (e.g. DENIC) | Registrant contact data |
| DNS | Cloudflare, Inc. | Domain name resolution (typically DNS-only, no proxy) | DNS queries / zone data; if proxied, also HTTP(S) metadata |
STRATO and Cloudflare do not set analytics/marketing cookies in the Application. Browser cookies: see Cookie Policy.
3. Accounts & authentication
Name, email, hashed password, roles/memberships, optional avatar, 2FA/passkey data, email OTP (short-lived one-time login code), trust-device binding; last login time (lastLoginAt); keyed SHA-256 hash of the IP (server-side secret, no raw IP on the account); city from the hosting geo header (Vercel); optional linked Apple/Google account IDs (link-only, no social sign-up); optional Microsoft Entra ID for company SSO (admin-enabled only, no sign-up) — for authentication and security (Art. 6(1)(b)/(f)).
Draft — session and account security: The session lasts 24 hours from login. Idle-timeout logout (sign-out solely due to inactivity) is not the default. A city change (geo header) or IP change (compared via the keyed hash, not the raw IP) may trigger re-authentication. IP hash and city are processed for account security and abuse prevention (Art. 6(1)(f) GDPR). We do not store a persistent raw IP on the account for this purpose; a raw IP may appear briefly in server/security logs (section 2).
Draft — email OTP and passkey as first factor: In addition to a password you may sign in with an email one-time code (OTP) or a passkey. Email OTP is used only for authentication: a short-lived one-time code is sent to the account email (no new account via this path, no marketing). The code can be used once and expires shortly. Delivery and verification go through the authentication processor (Art. 28 GDPR). Passkey and email OTP count as a strong first factor; after a successful passkey or email-OTP sign-in we do not require an additional TOTP (authenticator app). After a password login, TOTP/2FA setup or verification remains required where configured. Legal basis: Art. 6(1)(b)/(f) GDPR.
Draft — login-method cookie (mto_login_method): After a successful sign-in we set an httpOnly cookie (24 hours, server-signed, SameSite=Lax). Content: the login method used (password, passkey or email OTP), bound to the user id and an expiry. Purpose: decide whether an extra TOTP step is needed. No tracking or analytics. Deleted on logout, expiry (24 hours) or cookie deletion. Details: Cookie Policy.
The native app stores the session token in SecureStore and may keep local demo inbox data on-device. Email OTP codes expire after a short validity or one-time use; the mto_login_method cookie is deleted on logout, expiry (24 hours) or cookie deletion. Session/login metadata (lastLoginAt, IP hash, city) are deleted on logout, session expiry (24 hours) or account deletion; other data is deleted with the account, unlink, logout, or app uninstall as applicable.
4. Application modules (overview)
Depending on enabled modules we may process accounting/invoice data, CRM contacts, banking reconciliation, HR/payroll/personnel files, shift/ops/hub data, audit logs, API keys and backups — typically under Art. 6(1)(b)/(c)/(f) and statutory retention (often 6–10 years in DE; document-specific HR retention up to 30 years). Details available on access request (Art. 15).
5. Cookies
See our Cookie Policy. Strictly necessary cookies without consent; optional categories only with consent.
Draft — language and approximate region: The UI follows your saved language (account and NEXT_LOCALE cookie). Without a saved choice we use the browser language, otherwise English. If the hosting platform sends a country code (request header; we do not store the IP for this) that maps to another supported language, we may ask once whether you want to switch. We never auto-switch language based on location. Legal basis: Art. 6(1)(f) GDPR (intelligible presentation) and Art. 6(1)(b) for the account language.
6. Communication
Contact form: name, email, message — solely to handle your request. Optional email delivery (e.g. reminders, 2FA codes, email OTP for sign-in, invitations) via configured processors or the authentication provider, only when activated for that purpose.
7. Payments & portals
Optional payment providers process payment data at the provider; we usually store references only. Token-based portals: anyone with the link can view the shared content; tokens are renewable.
8. Recipients
Processors (hosting, email, optional OCR, banking, storage) under Art. 28; domain registrar STRATO GmbH (DE) and DNS Cloudflare, Inc. (DPA on file); identity/store platforms only when used (Apple / Google / Microsoft Entra); authorities where legally required; tax advisors with granted access. Stack: Vercel (app), Neon (EU DB), STRATO (registrar), Cloudflare (DNS, typically DNS-only). Optional when configured: Apple/Google identity, Microsoft Entra company SSO, Expo/EAS, OpenAI/xAI OCR, GoCardless/PayPal, SendGrid, Stripe. Passkey private keys remain on the user device / platform authenticator. Draft: email OTP codes are delivered via the authentication processor and held there briefly for verification; we do not store the code permanently.
9. International transfers
Where data is processed outside the EU/EEA we use appropriate safeguards (adequacy, SCCs Art. 46, supplementary TOMs). This includes US providers such as Vercel and Cloudflare (Customer DPA including SCCs). STRATO processes domain registration data in Germany. Details on request.
10. Retention
We store data only as long as necessary for the purposes or statutory retention, then erase or anonymise unless an Art. 17(3) exception applies.
11. Your rights
Access, rectification, erasure, restriction, portability, objection (Art. 15–21), withdraw consent, lodge a complaint with a supervisory authority (Art. 77), including {{supervisoryAuthority}}. Contact: {{dpoEmail}} / {{email}}.
12. Obligation to provide data
Without certain data (e.g. account email, invoice master data) we cannot perform the contract or legal duties.
13. Automated decisions
No automated decision-making under Art. 22 GDPR with legal effects.
14. Security
Appropriate TOMs (Art. 32): RBAC, TLS, hashed passwords, 2FA, passkey or email OTP as a strong first factor (no extra TOTP), audit logs, limited session lifetime (24 hours from login), re-authentication on city/IP change, backups. Idle-timeout logout is not the default.
15. Changes
We update this notice when needed. The published version is available at /legal/privacy.
16. Artificial intelligence (EU AI Act Art. 50)
Substantial parts of this website (copy, UI, documentation) were created with AI assistance. The mandatory notices under Art. 50 of Regulation (EU) 2024/1689 appear as a separate first-visit banner (published site only) and a persistent short notice – separate from the cookie banner and not dependent on cookie consent. Details and OCR processing: Artificial intelligence notice.
No automated decision-making under Art. 22 GDPR with legal effects. The Hub assistant is rule-based (not generative AI).
Placeholders such as {{companyName}} are filled from Settings → Organization. Have your DPO/legal counsel adapt this template to your entity.