Legal text template
Privacy notice
Structural template for privacy information covering the public website and the GHSDoku application. It must be adapted to the actual production operation.
Controller and privacy contact
[Add complete contact details of the data controller] [Add data protection officer or contact point where required]
Purposes, data categories and legal bases
[For website access, registration, contract performance, support and the application, document each purpose, data category, data subject and specific legal basis. Do not combine consent, contract, legal obligation and legitimate interests indiscriminately.]
Cookies and local browser storage
GHSDoku does not load analytics, advertising or social-media scripts and does not set tracking cookies on public pages. No consent for optional cookies is therefore requested at present. After sign-in, the “ghsdoku_refresh” cookie (HttpOnly, path /auth) maintains the session and the “ghsdoku_csrf” cookie (path /) protects against cross-site form requests. Both use SameSite=Lax, Secure in HTTPS environments and expire with the configured session, by default after 30 days. A manually selected language, billing country and the prepared currency as well as requested UI settings such as tabs, filters and columns are stored locally in the browser until changed or removed through browser controls. The default billing country is not stored without a selection. Legacy session tokens found in browser storage are removed once and are not created again.
Hosting, access data and logs
[Add the production hosting provider, region, processing agreement, technical access data, security logs, purposes and retention for the cloud service.]
User accounts and organisations
[Describe processing of names, email addresses, roles, company assignments, login and audit data, including purpose and retention.]
Hazardous substance and document data
[Explain which technical data and PDFs customers provide, who receives access within a tenant and the customer responsibility for personal data contained in uploads.]
Email delivery
[Add SMTP or email provider, processing region, message types, delivery logs and retention periods.]
Contracts, invoices and Stripe
[Only where billing is enabled: describe customer, contract, tax and payment data transferred, Stripe roles, possible international transfers, legal basis and retention according to the actual live configuration.]
Recipients and processors
[List all actual recipient categories and processors. Verify processing agreements and subprocessors.]
Retention and deletion
[Add concrete periods or transparent criteria for accounts, technical and contract data, documents, backups, logs, email and statutory retention.]
Data subject rights and complaints
[Explain access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint rights as applicable. Add the competent authority based on the operator location.]
Technical and organisational measures
[Describe only measures actually implemented, such as transport encryption, access control, tenant separation, backups, logging and restore testing. Do not claim unverified guarantees or certifications.]
Version and changes
[Add the final notice date or version and define how material changes are communicated.]