Legal
This is a convenience translation. The German version is the binding one.
This policy describes what personal data Vaultivo processes, why, on what legal basis, and for how long. It covers this website and the application.
The controller for the purposes of the GDPR is:
No data protection officer has been appointed; on our current assessment the conditions in Art. 37 GDPR are not met. For questions, or to exercise your rights, use the address above.
This site is static and served by Cloudflare Pages. On each request Cloudflare processes technically necessary connection data — your IP address, the time, and the address requested — in order to serve the page and keep the service secure.
No analytics, tracking or advertising services are used, now or planned. Only strictly necessary cookies are set, which is why there is no consent banner.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and reliable operation.
The contact form sends us your email address, your message and, if you give it, your name. These are forwarded to us by email so that we can reply. They are not stored on this website.
Cloudflare Turnstile is used to keep automated submissions out. In the configuration used here, Turnstile sets no cookies.
Messages from the form and to the published contact address are deleted after three months.
Messages to the published contact address are forwarded to a mailbox hosted by Google (Gmail), and we reply from there. Correspondence with us therefore does not stay within the EU. This concerns correspondence only, never documents archived in Vaultivo.
Legal basis: Art. 6(1)(b) and (f) GDPR — answering your enquiry, and legitimate interest in preventing abuse.
For an account we process account and contract data: company name, address, country, a VAT ID where given, and the name and email address of each user.
For security-relevant actions the IP address is also recorded in the audit trail.
The contents of archived documents sit on a different footing: invoices and receipts contain other people’s personal data — contacts, customer names, addresses. For that data the business archiving it is the controller and Vaultivo is a processor acting only on its instructions, under the data processing agreement.
Legal basis: Art. 6(1)(b) GDPR for performance of the contract, Art. 6(1)(c) for statutory retention duties, and Art. 6(1)(f) for logging.
We use the following service providers. Businesses are given 30 days’ notice of changes to this list; if they object, they may terminate.
| Service | Role | Region |
|---|---|---|
| DigitalOcean | Server, database and object storage — where the documents live | fra1 — Frankfurt, DE |
| Backblaze, Inc. | Backup copy of the archived originals and their PDF versions, at a second provider | EU Central — Amsterdam, NL |
| OpenAI Ireland Ltd. | Reading text and document data | IE / US |
| Mailgun | Inbound document email and outbound system email | EU |
| Stripe Payments Europe, Limited | Payments and invoicing | IE |
| Cloudflare | DNS, delivery of this website, email forwarding for the contact address | EU / global |
| Sentry | Application error and operational logs — no document content | EU |
| GitHub, Inc. | Scheduled cleanup of the backup copy — processes storage paths, no document content | US / global |
Virus scanning, text extraction and document conversion are not carried out by third parties. They run in self-hosted components inside the same EU-hosted environment.
Text extraction by OpenAI involves a transfer outside the EU; in addition, some of the sub-processors listed above process outside the EU, as shown in the list. The contracting party for text extraction is OpenAI Ireland Ltd., established in Ireland; processing also takes place in the United States.
That transfer is made on the European Commission’s Standard Contractual Clauses of 4 June 2021. A data processing agreement with OpenAI Ireland Ltd. was concluded on 8 August 2026.
According to OpenAI, content submitted through the API is not used to train models.Confirmed on: 08.08.2026
OpenAI retains content submitted through the API for up to 30 days for abuse monitoring.
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object to processing (Art. 21 GDPR).
Complaints may be made to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna. You may also contact the supervisory authority where you live.
We update this policy when the processing changes. The version published on this page is the one that applies.