Legal

Privacy Policy

for the website and free dossierwerk demo

Last updated: 29 June 2026

1. Controller

Dossierwerk - Gesellschaft in Gründung

Ein Projekt von Daniel Kohlstaedt und Debashish Bhattacharya

Bäckerstraße 7, 38162 Cremlingen, Deutschland

General enquiries: compliance@dossierwerk.com

Privacy requests: compliance@dossierwerk.com

2. Scope

This policy applies to the public website, the free dossierwerk demo, one-time-code login, meeting bookings, sales and support communication, and newsletters.

The public demo is a product demonstration and is not intended for real, confidential or personal product documentation.

3. Roles

Dossierwerk - Gesellschaft in Gründung acts as controller for website, account, communication, analytics and booking data. If customer personal data is processed on behalf of a customer in the future, the parties will first enter into a Data Processing Agreement under Article 28 GDPR.

4. Website and hosting

The website is hosted through AWS Amplify. Technical logs may include IP address, time, requested resource, browser, operating system, referrer, status code and security information.

The legal basis is Article 6(1)(f) GDPR. Logs are normally retained for 30 days.

5. Demo access and authentication

We process business email address, login time, authentication data, session information and security logs.

Supabase provides the production application and database infrastructure in North EU (Stockholm), eu-north-1. Resend sends one-time codes and transactional system emails from Ireland, eu-west-1.

The legal basis is Article 6(1)(b) GDPR and, for security logging, Article 6(1)(f) GDPR.

6. No customer-document storage in the demo

The live public demo does not store or host customer documents. Upload, drag-and-drop and analysis flows are demonstrative only.

Users must not submit real test reports, declarations, product files, trade secrets, personal data or other confidential material.

7. Meeting booking

Meetings may be booked through Cal.com. An embedded popup is used by default, with https://cal.eu/dossierwerk/30min available as an external fallback.

We may process name, business email, selected time, time zone, optional form data and technical access data under Article 6(1)(b) GDPR.

8. Analytics

We use Plausible Analytics for privacy-oriented audience measurement. We do not use advertising trackers or session-recording tools.

Depending on the deployed configuration, the legal basis is Article 6(1)(f) GDPR or consent. Where consent is required, analytics will not load before consent.

9. Email communication

Resend is used only for login and transactional system emails.

Instantly is used for targeted B2B cold outreach to business contacts. Mailchimp is used only for newsletters sent to subscribers or other contacts with a valid opt-in.

Newsletter processing is based on Article 6(1)(a) GDPR. B2B outreach is assessed under the applicable legal rules on a case-by-case basis.

10. Service providers

Purpose
Provider
Region
Website hosting
AWS Amplify
according to AWS configuration
Application and database
Supabase
North EU (Stockholm), eu-north-1
OTP and transactional email
Resend
Ireland, eu-west-1
Scheduling
Cal.com
according to provider configuration
Analytics
Plausible
according to provider configuration
B2B outreach
Instantly
according to provider configuration
Newsletter
Mailchimp
according to provider configuration

11. International transfers

Transfers outside the EEA take place only in accordance with Articles 44 et seq. GDPR, including adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses with supplementary safeguards.

12. Retention

Data
Normal retention
Website logs
30 days
Demo data
30 days after demo end or reset
Security and authentication logs
90 days
Cookie preference
12 months
Language preference
12 months
Backups
overwritten within 90 days
Accounting and tax records
statutory periods

13. No public AI training

Customer or user data is not used to train public or generally available AI models without explicit consent. Fully anonymised and aggregated data may be used only for internal product improvement and not for external benchmarking.

14. Your rights

–

Access, rectification, erasure and restriction.

–

Data portability where applicable.

–

Objection to legitimate-interest processing.

–

Withdrawal of consent with future effect.

–

Complaint to a supervisory authority, including the State Commissioner for Data Protection of Lower Saxony.

15. Security and changes

We apply appropriate technical and organisational safeguards, including encrypted transmission, access controls, session controls and security logging.

We may update this policy when services, providers or legal requirements change.