QuovalisSign in

Privacy Policy

Version 2026-08-14-privacy-0.9 — information pursuant to Articles 13/14 GDPR on the processing of personal data in the Quovalis service. Last revised: 14 August 2026.

1. Controller

Lennard de Rijk, trading as Quovalis (Einzelunternehmen), Muster-Hauptstrasse 1, 80331 München, Germany — contact@quovalis.eu.

2. Our role: controller and processor

For the account, billing, security and website data described below we act as controller. For the contents of certificates submitted for validation and the resulting validation records we act as processor on behalf of the customer (Art. 28 GDPR): the customer determines the purposes of that processing and supplies its legal basis, and a data processing agreement governs it. The retention windows shown for validation records are service parameters of the customer’s plan. The customer is responsible for being entitled to submit certificate data and for any information duties toward the persons identifiable from submitted certificates.

3. What we process, why, and for how long

DataPurpose (legal basis)Retention
Account: email address, password (stored as argon2id hash); with the optional email second factor, short-lived sign-in codes (stored hashed)Authentication, service emails (Art. 6(1)(b) — contract, for the person contracting with us; Art. 6(1)(f) for further members acting for a corporate customer — legitimate interest: providing and securing the service for the customer)Life of the account; erased on closure
Record of accepted agreement versions: the account name as it stood at the time of acceptance, which document was accepted (Terms of Service, Data Processing Agreement), its version identifier and the time of first acceptance. While the accepting member’s account exists, the record also references that member.Evidence that the contract was concluded and on which text (Art. 6(1)(b) — contract; Art. 6(1)(f) and Art. 17(3)(e) — establishment, exercise and defence of legal claims)Kept after account closure. The reference to the member who accepted is removed together with that person’s user record; the account name, document, version and time of acceptance remain for the duration of the applicable limitation periods (regularly to the end of the third year after the account is closed; longer where a statutory retention duty or a pending legal claim requires), and are then deleted or irreversibly anonymised
Sessions: token hash, IP address, browser user agentSign-in, abuse forensics (Art. 6(1)(b); Art. 6(1)(f) — legitimate interest: keeping accounts and the platform secure)7 days or until sign-out; expired rows swept hourly
Abuse counters: IP addresses and email domains of signup/login attemptsThrottling and abuse prevention (Art. 6(1)(f) — legitimate interest: preventing automated abuse and account takeover)7 days
Team invites and join requests: invitee/requester email address (join requests also a password hash), requested role and a hashed token. For team invitations we receive the invitee’s email address and requested role from the account owner or administrator who sends the invitation.Adding members to an account (Art. 6(1)(b), (f) — legitimate interest: letting customers manage their own teams; invitation mail links to this policy)Expired invites and expired or decided join requests are purged hourly; accepted invites persist as membership data for the life of the account
Billing data: customer/business name, billing address, VAT ID where provided, invoice and payment recordsInvoicing, accounting and tax compliance (Art. 6(1)(b), (c) — statutory accounting duties). Invoicing is manual (SEPA bank transfer); no payment service provider is used.Statutory retention periods for accounting and tax records (8 years for invoices and accounting records, up to 10 years for accounting books — § 147 AO / § 257 HGB, as amended 2025) — also after account closure
Billing settlement records: monthly frozen billing figures (plan base and overage amounts) together with a snapshot of the customer/business name as at the end of the settled month. Settlement records are created only for months in which an amount is owed; accounts that never owe an amount have no settlement records and no name snapshot.Invoicing, accounting and tax compliance, and maintaining a verifiable billing ledger (Art. 6(1)(b), (c) — statutory accounting and tax duties, § 147 AO / § 257 HGB)Until the end of the statutory accounting retention period (end of the calendar year of the settlement plus 8 years; accounting books up to 10 years) — also after account closure. At the end of the applicable retention period the settlement record is deleted, or all customer-identifying fields and references in it are irreversibly anonymised; billing figures may thereafter be retained only in a form that can no longer be linked to a customer or natural person.
Validation records: submitted certificates’ subject/issuer names, serials and attributes plus the verdict — certificate contents can identify persons; the requester’s IP is not storedValidation and results retrieval, performed on the customer’s behalf as processor (Art. 28 — the customer supplies the legal basis; see section 2)Per plan: Free accounts using a public email provider 30 days, other Free accounts 90 days, paid plans 365 days (whole records deleted)
Usage aggregates (per-tenant hourly counters)Quota enforcement, usage display, billing and investigation of disputed charges (Art. 6(1)(b); Art. 6(1)(f) — legitimate interest: maintaining verifiable usage records)Identifiable counters are retained for the current billing period and thereafter for at most three years from the end of the calendar year in which the usage occurred, then deleted or irreversibly aggregated without the tenant reference. Counters no longer required for billing, quota enforcement or a pending dispute may be deleted earlier.
Audit trail (account/admin actions with actor references)Accountability, security (Art. 6(1)(f) — legitimate interest: tamper-evident records of administrative actions)3 years from the event, then deleted or irreversibly anonymised; records relating to a documented security incident, investigation or legal claim may be retained for the duration of that matter and the applicable limitation period. Actor references are unresolvable after account erasure.
Contact messages: reply email, optional name, subject and message; for signed-in senders, account and tenant referencesAnswering enquiries (Art. 6(1)(b), (f) — legitimate interest: responding to messages sent to us)180 days, including unread messages; deleted in hourly bounded batches. Deleted copies age out of backups within at most 31 additional days.
Operational, security and delivery logs: request logs with timestamps, route, method, status and duration (no IP address); tenant or account references where needed for troubleshooting; the client IP address in sampled API-key allowlist-denial events (at most one log line per key and IP per minute); and recipient email addresses where an email we send fails or is suppressed. Failure diagnostics can also contain a certificate authority’s OCSP/CRL responder URL or an unrecognised PSD2 role value; logs never contain certificate subject or issuer names, serial numbers or subject alternative names.Operating, securing and troubleshooting the service, investigating failed email delivery and preventing abuse (Art. 6(1)(f) — legitimate interest: service security, reliability and error diagnosis; where a log line relates to validation processing performed on a customer’s behalf, it is part of that processing under Art. 28 and the data processing agreement)Central logs are retained for 14 days and are not included in backups; a local fallback copy is size-limited and overwritten. Log records preserved for a documented security incident, investigation or legal claim may be retained for the duration of that matter and the applicable limitation period.

4. Recipients / processors

  • Hosting: Hetzner Online GmbH (Germany) (Art. 28 processor).
  • Transactional email: Scaleway SAS (France) (Art. 28 processor) — receives email addresses for verification, password-reset, sign-in code (second factor) and team-invitation mail; invitation mail includes addresses of invitees who do not yet have an account. Scaleway also delivers our internal operational alert emails to our own operator address; these can contain pseudonymous account identifiers (tenant references) but no customer names, email addresses or certificate data.
  • Inbound email: Google Ireland Limited (Ireland) (Art. 28 processor) — hosts the mailboxes behind contact@quovalis.eu and our other addresses, and so processes any message you send us — including one exercising the rights in section 5 — as well as the operational alert emails described above once they arrive. On the plan we use, this mail is not restricted to servers in the EU/EEA and may be processed in other countries, including the United States. That transfer is governed by Google’s Cloud Data Processing Addendum, which we have accepted and which provides the safeguards required by Chapter V GDPR (standard contractual clauses, or an equivalent transfer solution adopted by Google in its place). We do not send certificate contents or validation records by email.
  • Accounting and invoicing: EU-hosted accounting software used to prepare and store invoices processes the billing data listed above. The specific vendor will be named here before any billing data is transferred to it.

No data is sold or used for advertising. No profiling. We do not make decisions about individuals that produce legal or similarly significant effects within the meaning of Art. 22 GDPR; validation verdicts are technical outputs provided to our customers, who determine how they are used.

The contact form’s arithmetic challenge is generated and checked locally. Its ten-minute signed token is bound to your IP address; the IP is used only for the challenge and short-lived Redis rate limits and is not stored with your message. No third-party CAPTCHA provider receives your data.

5. Erasure and your rights

The account owner can close the account (console → Settings, password re-entry required); closure immediately revokes all API keys and deletes the user records and sessions of every member. The account itself is closed rather than deleted: its name and its record of accepted agreement versions are kept as evidence that the contract was concluded (see section 3), while the reference to the individual who accepted is removed along with that person’s user record. Stored validation records are purged after a 7-day grace window. Billing and settlement records subject to statutory retention duties (invoicing, accounting and tax records) are excluded from this erasure and kept for the statutory periods (see section 3), including a snapshot of the customer name in the monthly settlement records of months for which an amount was owed. Erased data leaves every backup layer within at most 31 days of deletion under normal operation (backup copies rotate out on fixed, monitored schedules).

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21). Contact: contact@quovalis.eu. You may lodge a complaint with a supervisory authority; the authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht — BayLDA), Ansbach.

6. Cookies and local storage

Two first-party, strictly necessary cookies — one for the session and one for CSRF protection — and one locally stored display preference (your chosen colour theme) are detailed in the cookie notice. No tracking or third-party cookies are used, hence no consent banner.

7. Data location and security

The service is operated within the EU/EEA — application, databases, backups and outbound service email alike. The one exception is email you send to our published addresses, which is handled by the inbound email provider named in section 4 and may be processed outside the EU/EEA on the basis stated there. Transport is TLS-encrypted; passwords are stored only as salted argon2id hashes and API key secrets only as one-way hashes of high-entropy random values; access is logged in an append-only audit trail.

Archived versions

Every version any customer could accept stays available here, unchanged — including the one in force — so the text you agreed to can always be retrieved. The signup consent covers this policy by reference alongside the Terms of Service.

  • 2026-08-14-privacy-0.9 (in force)
ContactImprintTermsPrivacyCookiesDPA