Privacy Policy
Stand: 22 June 2026 · Diese Fassung ist noch in juristischer Prüfung · die finale Version ersetzt sie ohne Änderung an Funktion oder Rechten.
We take the protection of your data seriously. Your personal data is processed confidentially and in accordance with EU GDPR and this privacy policy. doWallet is hosted in Germany (Frankfurt am Main); your data never leaves the EEA in our hot path.
1. Controller
Controller under GDPR is Applox GmbH. Full address, contact and management are in the Impressum.
2. Data Protection Officer
Reach our DPO at dsb@dowallet.de.
3. Data Collected
3.1 Account & usage
- Email, name, bcrypt-hashed password · account + auth.
- Organization / workspace membership, role.
- Session metadata (IP, user-agent, timestamp) · abuse detection.
- Audit log: who changed what, before/after diff. Retention: 365 days.
3.2 Pass data
- Template + campaign definitions (entered by customer).
- Issued passes with serial, AES-256-GCM-encrypted authToken, attributes, UTM attribution.
- Device registrations (anonymous push tokens from Apple/Google).
- Lifecycle events (activated, deactivated, reactivated).
3.3 Pass holders (your customers' customers)
When an end-user claims a pass, we store the device registration and any optionally provided email · solely on behalf of the pass issuer (data processing under Art. 28 GDPR, see DPA in our Terms).
4. Legal bases
- Art. 6(1)(b) · contract performance · platform provision.
- Art. 6(1)(c) · legal obligation · tax retention.
- Art. 6(1)(f) · legitimate interest · security, fraud prevention, audit log.
- Art. 6(1)(a) · consent · marketing cookies (if active).
5. Recipients / processors
- Hetzner Online GmbH (Frankfurt, DE) · hosting + backups; DPA in place.
- Apple Inc. · APNs push for iOS passes (Standard Contractual Clauses).
- Google LLC · Google Wallet API for Android passes (SCCs).
- Email sending: [EU provider, TBD].
6. Cookies
Only strictly-necessary cookies (session, CSRF) by default. Analytics or marketing cookies require explicit opt-in via the cookie banner. Withdraw consent any time via the footer link „Cookie-Einstellungen".
7. Your rights
- Art. 15 · Access · full export of your data.
- Art. 16 · Rectification.
- Art. 17 · Erasure · 30-day grace period, reversible.
- Art. 18 · Restriction.
- Art. 20 · Portability · JSON archive.
- Art. 21 · Objection.
- Right to lodge a complaint with a supervisory authority.
Access + export are self-serve in Settings → Profile → Data Rights. Other rights via dsgvo@dowallet.de.
8. Retention
- Active accounts: duration of the contract.
- Deleted accounts: 30-day grace, then irreversible erasure.
- Audit log: 365 days rolling.
- Invoice data: 10 years (tax law, pseudonymized).
9. Technical & organizational measures
- TLS 1.3 only.
- Wallet credentials + pass auth tokens AES-256-GCM with rotatable keys.
- Passwords bcrypt-hashed.
- Rate limit, CSRF, helmet CSP, CORS allowlist.
- Hetzner Cloud firewalls, encrypted backups.
- Annual pen-tests, full audit log with IP/UA.
10. International data transfers
Primary processing inside the EU. Apple (APNs) and Google (Wallet API) are US providers; transfers under Standard Contractual Clauses, only as required for push/wallet functionality.
11. Changes to this policy
We reserve the right to update this policy; material changes notified by email.