Website access
IP address, time, requested URL, response status, browser or user-agent information, referrer, error data and security events can be processed in server logs.
This notice explains how personal data is processed when you visit ROCKVALID, use the current browser certification demo or verify a ROCKVALID PDF.
Controller
Current workflow
The precise data depends on the function you use. ROCKVALID does not require a permanent account or personal blockchain wallet.
IP address, time, requested URL, response status, browser or user-agent information, referrer, error data and security events can be processed in server logs.
The uploaded PDF, filename, temporary session identifiers, process status and the generated ROCKVALID PDF are processed so the workflow can be completed.
ROCKVALID processes the entered first and last name and whether you sign, issue or object to the document.
For the current GiroIdent flow, ROCKVALID can receive process identifiers, account-holder or payer information, a name-check result, payment status, amount, currency and references required for the process.
The completed PDF can contain the recorded name, action, time, ROCKVALID identifiers and — when a document has been continued — the readable confirmation history.
A PDF submitted for verification is read to calculate its cryptographic fingerprints and inspect the ROCKVALID record. The result is compared with the public proof.
Open banking
The current public demo uses finAPI GiroIdent for the configured name check. The external provider and the selected bank process the data required for their part of the flow.
ROCKVALID itself does not ask you to type online-banking credentials into the ROCKVALID page. If bank authentication is required, it takes place in the provider or bank interface.
The name entered in ROCKVALID can be compared with account-holder information returned through the configured provider flow.
If the combined flow includes a payment, ROCKVALID processes the payment status and references needed to complete the certification.
The privacy and legal information of finAPI and the selected bank applies in addition when you use their interfaces.
PDF and public proof
The completed PDF and the public network serve different purposes.
Purposes and legal bases
The applicable legal basis depends on the purpose.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide certification and verification | PDF, name, action, session and proof data, provider result | Art. 6(1)(b) GDPR |
| Initiate and confirm a payment | Amount, status, reference and provider identifiers | Art. 6(1)(b) GDPR |
| Security and abuse prevention | Access, error and security logs; technical identifiers | Art. 6(1)(f) GDPR |
| Accounting and legal obligations | Required transaction, invoice and correspondence data | Art. 6(1)(c) GDPR |
| Optional functions or communication | Data requested for that optional function | Art. 6(1)(a) GDPR where consent is required |
Recipients
Data is shared only when needed for the selected function or required by law.
Hosting, infrastructure and security providers may process data on behalf of ROCKVALID.
Data needed for GiroIdent and any connected payment is processed by the provider and bank involved in the selected flow.
Only the compact public proof is submitted or looked up; the PDF itself is not sent as blockchain content.
Advisers, auditors, courts or authorities may receive data where this is legally required or necessary to establish, exercise or defend legal claims.
Storage and deletion
ROCKVALID is not intended to be a permanent customer document archive.
Session files are retained only as needed to complete provider return, certification, public proof and download, subject to technical and legal requirements.
Technical access logs are normally retained for up to seven days unless a security event requires longer evidence preservation.
Payment, invoice and business correspondence data can be retained for statutory commercial and tax periods.
finAPI and the selected bank apply their own retention rules and legal obligations.
Public blockchain records are designed to be permanent and normally cannot be erased by ROCKVALID.
EUDI Wallet Sandbox
At /eudi-lab/, ROCKVALID can use the German EUDI Wallet Sandbox instead of finAPI for test name verification.
ROCKVALID requests only given_name and family_name from the PID credential. Date of birth, address, nationality and other PID attributes are not requested in this lab.
The EUDI Wallet shows the requested disclosure. ROCKVALID uses the name only after successful cryptographic verification of the wallet presentation and binds it to the document action initiated by the user.
OpenID4VP temporarily processes random nonces, state values, short-lived keys and technical transaction identifiers. They provide replay protection and secure transaction binding and expire with the lab flow.
The EUDI Lab uses the EUDI Sandbox for identification. finAPI is not used in this flow and no financial payment is made. As in the normal certification flow, the verified name may become visible in the generated ROCKVALID PDF and its signature chain.
Session protection
The browser-based certification process uses a first-party session cookie solely as the access key for the process started by the user.
When a document review starts, ROCKVALID creates a cryptographically random access key. The browser automatically sends it with subsequent requests. The review or session ID alone is therefore not sufficient to retrieve the preview, status or result.
The cookie contains only the random access key. It contains no document content, names, identity data, selected action, RV-LOC or blockchain data. The server does not store the key itself, but only a cryptographic verification value bound to the specific process ID.
The cookie is protected by Secure, HttpOnly and SameSite=Strict and is bound to the requested host by the __Host- prefix. It is not used for advertising, audience measurement, analytics, profiling or cross-site tracking.
The cookie is a session cookie. A review that is not continued expires on the server after 30 minutes. An incomplete certification session is generally retained for no more than 24 hours, and a completed download result for no more than 48 hours. The server-side deadline is decisive; after expiry or deletion, a remaining cookie no longer grants access.
Storage or access on the end device is based on section 25(2)(2) TDDDG because the cookie is necessary for the browser-based service explicitly started by the user. To the extent that the related processing is necessary to carry out the certification service requested by the user, it is based on Article 6(1)(b) GDPR. Protection of the process against unauthorised access is additionally based on the legitimate interest under Article 6(1)(f) GDPR. Native clients such as Gretchen may transmit the same access key through a protected HTTP header instead of a cookie.
Language & tracking
ROCKVALID provides German, English, French, Spanish, Italian and Polish pages. The selected language is represented by the page URL and may be suggested from browser settings.
The current service is not used to build behavioural advertising profiles.
Technically necessary storage can be used for security, language routing or provider hand-off. Provider and bank interfaces may use their own necessary storage.
International processing
Public network and provider infrastructure can involve processing outside Germany or the European Economic Area.
Public proof data is distributed across the relevant network and cannot be treated like data held in one German database.
Where the GDPR requires a transfer safeguard, an adequacy decision, contractual safeguards or another lawful mechanism must apply.
Automated checks
The workflow uses automated technical checks but does not decide whether the contents of your PDF are true or legally valid.
A failed or incomplete configured check can stop the demo certification.
These checks are not intended to produce a legal or similarly significant decision about you within the meaning of Article 22 GDPR.
Your rights
Subject to the statutory requirements, you may contact ROCKVALID about your personal data.
Security measures include transport encryption, access controls, temporary identifiers, data minimisation and security logging. No internet service can guarantee absolute security.
Last updated: 21 August 2026