Privacy Policy

You would like to know if we, as a data protection company, also stick to the rules and, for example, adhere to the data subject’s right to be informed? But of course!

We collect personal data when you use DS-Doku.

1. Data processing when working with DS-Doku

If you work with DS-Doku as a user, personal data is processed for the following purposes:

  • Provision of the system
  • Granting user rights
  • Logging of DS-Doku usage for audit and system security reasons

The following data categories are being processed about users:

  • Name
  • Business email address
  • Employer
  • Rights and user settings
  • Which data you have entered, changed or deleted when in DS-Doku
  • Your Mr.FOX-points In addition, personal data about other people may be processed if users enter them in input fields in DS-Doku.

If these data were not collected by the user himself, it was provided by the employer or colleagues or calculated within DS-Doku.

The data can be viewed by your employer and, if applicable, employees within your own group. Service providers who provide or maintain the IT infrastructure and who are separately bound to confidentiality can also view the data.
The storage period depends on the above-mentioned purposes and, if applicable, on the statutory retention periods.

The legal basis for data processing is the fulfilment of your contractual obligations to your employer (Art. 6 Para. 1 letter b GDPR) as well as the legitimate interests of your employer (and, if applicable, the external data protection officer) in the audit-proof documentation of the current status within the organisation (Art. 6 Para. 1 letter f GDPR).

2. Data processing for the technical provision of DS-Doku

For the technical provision of the service it is necessary to process personal data:

  • Server log files
    The provider and the system collect and store information that your browser automatically transmits to us. These are mainly browser type and version, operating system used, referrer URL (originating address), host name of the accessing computer, the requested files with date and time and the IP address.
    These data are not merged with other data sources.
    The basis for data processing is Art. 6 Para. 1 letter f GDPR, which permits the processing of data on the basis of legitimate interest. In this case, there is a legitimate interest in a secure and functioning operation of the web server. In order to ensure this, the administration must be able to detect and trace attacks and malfunctions of the system via server log files. In order to be able to recognize attack patterns, accesses to the server must be stored. As soon as these data are no longer needed, they are deleted. For technical reasons, the data is disclosed to the IT service providers, who are bound by instructions and contract to us.

  • Cookies
    DS-Doku sometimes uses cookies. They serve to make the offer more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser. The cookies used here are so-called “session cookies” to enable access to the site. They are automatically deleted at the end of your visit.
    You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for specific cases or in general and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be limited. The cookies are required for the electronic communication process and are stored on the basis of Art. 6 Para. 1 letter f GDPR. We have a legitimate interest in the storage of cookies for the technically error-free and optimised provision of our services. Insofar as other cookies are stored for other purposes, these are explained separately in this privacy policy.

  • Service „AppSignal“
    To detect technical errors DS-Doku uses AppSignal’s services (AppSignal B.V., Rietwaard 4, 5236 WC ’s-Hertogenbosch, The Netherlands). Although it is not this service’s the main purpose to analyse personal data, in individual cases the transmission of a log-in name or IP address cannot be ruled out. The legal basis for data processing is EU Standard Contractual Clauses and Art. 6 Para. 1 letter f GDPR. The legitimate interest lies in the correction of errors and optimisation of the functionality of the website.

  • Newsletter
    DS-Doku users can subscribe to the newsletter. To do so, they can register with their e-mail address. The legal basis is consent (Art. 6 Para. 1 letter a GDPR).
    You can unsubscribe at any time, for example by clicking on the unsubscribe link in the footer of the e-mail or by sending an e-mail to We use technical service providers to send the newsletter. We do not evaluate the usage or click behaviour on a personal basis.

3. Responsibility

Your employer is responsible for data processing by DS-Doku.
If your employer has appointed an external data protection officer, the employer and the company of the external data protection officer are joint controllers.
The contact details, including those of the data protection officer, can be found on the “Help & Contact” page.

4. Your rights

As a data subject, you are entitled to the following rights, provided that the legal requirements are met:

  • Right to be informed, Art. 15 GDPR
  • Right to rectification, Art. 16 GDPR
  • Right to erasure, Art. 17 GDPR
  • Right to restriction of processing, Art. 18 GDPR
  • Right to data portability, Art. 20 GDPR
  • Right to object, Art. 21 GDPR If the data processing is based on your consent, you may revoke this consent at any time with effect for the future. If the data processing is based on legitimate interests, you can assert your right to object. You must give reasons for your objection. You also have the right to complain about the data processing to the data protection supervisory authority. If you have any further questions about how and for what purposes we process your data, please contact us.