Vaultivo

Legal

Privacy policy

This is a convenience translation. The German version is the binding one.

This policy describes what personal data Vaultivo processes, why, on what legal basis, and for how long. It covers this website and the application.

Controller

The controller for the purposes of the GDPR is:

Name
Aurel-Mihai Botinanț
Legal form
Sole trader
Address
1030 Wien, Arsenal Objekt 3/59
VAT ID
ATU75149545
Companies register
Not registered — as a sole trader the business is below the registration threshold.
Email
contact@vaultivo.at

Contact for data protection enquiries

No data protection officer has been appointed; on our current assessment the conditions in Art. 37 GDPR are not met. For questions, or to exercise your rights, use the address above.

When you visit this site

This site is static and served by Cloudflare Pages. On each request Cloudflare processes technically necessary connection data — your IP address, the time, and the address requested — in order to serve the page and keep the service secure.

No analytics, tracking or advertising services are used, now or planned. Only strictly necessary cookies are set, which is why there is no consent banner.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and reliable operation.

When you write to us

The contact form sends us your email address, your message and, if you give it, your name. These are forwarded to us by email so that we can reply. They are not stored on this website.

Cloudflare Turnstile is used to keep automated submissions out. In the configuration used here, Turnstile sets no cookies.

Messages from the form and to the published contact address are deleted after three months.

Messages to the published contact address are forwarded to a mailbox hosted by Google (Gmail), and we reply from there. Correspondence with us therefore does not stay within the EU. This concerns correspondence only, never documents archived in Vaultivo.

Legal basis: Art. 6(1)(b) and (f) GDPR — answering your enquiry, and legitimate interest in preventing abuse.

When you use Vaultivo

For an account we process account and contract data: company name, address, country, a VAT ID where given, and the name and email address of each user.

For security-relevant actions the IP address is also recorded in the audit trail.

The contents of archived documents sit on a different footing: invoices and receipts contain other people’s personal data — contacts, customer names, addresses. For that data the business archiving it is the controller and Vaultivo is a processor acting only on its instructions, under the data processing agreement.

Legal basis: Art. 6(1)(b) GDPR for performance of the contract, Art. 6(1)(c) for statutory retention duties, and Art. 6(1)(f) for logging.

Processors

We use the following service providers. Businesses are given 30 days’ notice of changes to this list; if they object, they may terminate.

Service Role Region
DigitalOcean Server, database and object storage — where the documents live fra1 — Frankfurt, DE
Backblaze, Inc. Backup copy of the archived originals and their PDF versions, at a second provider EU Central — Amsterdam, NL
OpenAI Ireland Ltd. Reading text and document data IE / US
Mailgun Inbound document email and outbound system email EU
Stripe Payments Europe, Limited Payments and invoicing IE
Cloudflare DNS, delivery of this website, email forwarding for the contact address EU / global
Sentry Application error and operational logs — no document content EU
GitHub, Inc. Scheduled cleanup of the backup copy — processes storage paths, no document content US / global

Virus scanning, text extraction and document conversion are not carried out by third parties. They run in self-hosted components inside the same EU-hosted environment.

Transfers outside the EU

Text extraction by OpenAI involves a transfer outside the EU; in addition, some of the sub-processors listed above process outside the EU, as shown in the list. The contracting party for text extraction is OpenAI Ireland Ltd., established in Ireland; processing also takes place in the United States.

That transfer is made on the European Commission’s Standard Contractual Clauses of 4 June 2021. A data processing agreement with OpenAI Ireland Ltd. was concluded on 8 August 2026.

According to OpenAI, content submitted through the API is not used to train models.Confirmed on: 08.08.2026

OpenAI retains content submitted through the API for up to 30 days for abuse monitoring.

How long data is kept

  • Documents and related data: for the term of the contract. After cancellation the archive first becomes read-only.
  • Contact enquiries: three months.
  • Audit entries: for as long as the account exists.
  • Backups: deleted data remains for up to 7 days — in the database backups, as a prior version in the file storage, and in the backup copy at the second provider. After that it is removed from all three.

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object to processing (Art. 21 GDPR).

Complaints may be made to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna. You may also contact the supervisory authority where you live.

Changes

We update this policy when the processing changes. The version published on this page is the one that applies.