Privacy Policy — DRAFT
⚠️ TEMPLATE / DRAFT — NOT LEGAL ADVICE. Must be reviewed and adapted by qualified legal counsel (GDPR/UK GDPR/CCPA as applicable) before use. Complete every
[BRACKET].
Controller for this policy: [Zentrum24 — full legal entity + registered address]. Product: ProveWise (the "Service"). Effective: [date]. Version: 0.1 (draft).
This policy explains how we handle personal data. Roles: for the documents and records a customer uploads, the customer is the data controller and we act as a processor on their behalf (see the DPA). For account, authentication, and billing data we act as an independent controller, and this policy covers that processing.
1. Personal data we process (as controller)
| Category | Examples | Source |
|---|---|---|
| Account / identity | name, username, work email, tenant, role | you, at signup / admin invite |
| Authentication | password hash, session tokens, login events, IP address, user-agent | you, automatically |
| Billing | plan, seats, subscription status, invoices (card data is handled by Stripe, not stored by us) | you / Stripe |
| Support | messages you send us | you |
We do not run third-party analytics or advertising trackers. The Service sets only a session cookie (authentication) and a locale-preference cookie, plus a CSRF token cookie — all strictly necessary for the Service to function.
2. Why we process it (purposes & legal bases)
- Provide and secure the Service — performance of contract / legitimate interests.
- Authenticate users and prevent abuse (rate-limiting, audit logging) — legitimate interests / legal obligation.
- Billing and tax — performance of contract / legal obligation.
- Support and service communications — performance of contract / legitimate interests.
- [Marketing, if any — consent. COMPLETE.]
3. Sub-processors / recipients
We share personal data only with providers that help us run the Service, under contract: - Amazon Web Services (AWS) — hosting, database, document storage, and transactional email (SES). Region: [confirm]. - Stripe — subscription billing and payment processing. We do not sell personal data. [List any others; keep current — see the DPA sub-processor terms.]
4. International transfers
If personal data is transferred outside your region (e.g. to the US), we rely on [appropriate safeguards — Standard Contractual Clauses / adequacy — COMPLETE].
5. Retention
- Account data: for the life of the account and [X] after closure.
- Audit-trail and signature records: retained per the customer's configured retention and regulatory requirements; the audit trail is append-only and tamper-evident and is not deleted on request where retention/regulation requires it.
- Billing records: as required by law [e.g. 7–10 years].
6. Your rights
Subject to law, individuals may request access, correction, deletion, restriction, portability, and objection. Note: for documents/records processed on a customer's behalf, direct such requests to that customer (the controller); we will assist them per the DPA. Contact us at [privacy@ email]. You may also complain to your supervisory authority.
7. Security
We use technical and organizational measures including encryption in transit, hashed passwords, tenant isolation, an append-only audit trail, electronic-signature re-authentication, login rate-limiting, CSRF protection, and access controls. See the DPA security annex.
8. Children
The Service is a business tool not directed to children and not intended for personal data of children.
9. Changes
We may update this policy; we will post the new version and update the date. Material changes will be notified.
Contact / Data Protection: [privacy@ email]. [EU/UK representative + DPO, if required — COMPLETE.]