ROCKVALID
Demo mode
Data protection

Store less.
Prove what matters.

This notice explains how personal data is processed when you visit ROCKVALID, use the current browser certification demo or verify a ROCKVALID PDF.

Controller

Who is responsible?

Controller
ROCKVALID UG (haftungsbeschränkt) in Gründung
Address
Greifswalder Straße 13B, 10405 Berlin, Germany
Email
info@rockvalid.com
Privacy contact
datenschutz@rockvalid.com

Current workflow

Which data can be processed?

The precise data depends on the function you use. ROCKVALID does not require a permanent account or personal blockchain wallet.

01

Website access

IP address, time, requested URL, response status, browser or user-agent information, referrer, error data and security events can be processed in server logs.

02

PDF and temporary session

The uploaded PDF, filename, temporary session identifiers, process status and the generated ROCKVALID PDF are processed so the workflow can be completed.

03

Name and selected action

ROCKVALID processes the entered first and last name and whether you sign, issue or object to the document.

04

finAPI / bank result

For the current GiroIdent flow, ROCKVALID can receive process identifiers, account-holder or payer information, a name-check result, payment status, amount, currency and references required for the process.

05

ROCKVALID record

The completed PDF can contain the recorded name, action, time, ROCKVALID identifiers and — when a document has been continued — the readable confirmation history.

06

Verification

A PDF submitted for verification is read to calculate its cryptographic fingerprints and inspect the ROCKVALID record. The result is compared with the public proof.

Open banking

finAPI and your bank

The current public demo uses finAPI GiroIdent for the configured name check. The external provider and the selected bank process the data required for their part of the flow.

01

No banking password in a ROCKVALID form

ROCKVALID itself does not ask you to type online-banking credentials into the ROCKVALID page. If bank authentication is required, it takes place in the provider or bank interface.

02

Name check

The name entered in ROCKVALID can be compared with account-holder information returned through the configured provider flow.

03

Payment

If the combined flow includes a payment, ROCKVALID processes the payment status and references needed to complete the certification.

04

Provider information also applies

The privacy and legal information of finAPI and the selected bank applies in addition when you use their interfaces.

PDF and public proof

What becomes visible?

The completed PDF and the public network serve different purposes.

In the completed PDF

  • the recorded person and action can be visible
  • ROCKVALID identifiers and timestamps can be included
  • for continued documents, earlier confirmations can be included as readable history
  • anyone you give the PDF to may be able to read this information

In the public proof

  • the PDF itself is not published
  • compact cryptographic fingerprints and identifiers are used
  • transaction data and timestamps on a public blockchain are public and generally permanent
  • public proof data is designed to be smaller than the document itself

Purposes and legal bases

Why data is processed

The applicable legal basis depends on the purpose.

PurposeTypical dataLegal basis
Provide certification and verificationPDF, name, action, session and proof data, provider resultArt. 6(1)(b) GDPR
Initiate and confirm a paymentAmount, status, reference and provider identifiersArt. 6(1)(b) GDPR
Security and abuse preventionAccess, error and security logs; technical identifiersArt. 6(1)(f) GDPR
Accounting and legal obligationsRequired transaction, invoice and correspondence dataArt. 6(1)(c) GDPR
Optional functions or communicationData requested for that optional functionArt. 6(1)(a) GDPR where consent is required

Recipients

Who may receive data?

Data is shared only when needed for the selected function or required by law.

01

Technical service providers

Hosting, infrastructure and security providers may process data on behalf of ROCKVALID.

02

finAPI and selected bank

Data needed for GiroIdent and any connected payment is processed by the provider and bank involved in the selected flow.

03

Public blockchain infrastructure

Only the compact public proof is submitted or looked up; the PDF itself is not sent as blockchain content.

04

Professional or public recipients

Advisers, auditors, courts or authorities may receive data where this is legally required or necessary to establish, exercise or defend legal claims.

Storage and deletion

How long is data retained?

ROCKVALID is not intended to be a permanent customer document archive.

01

Temporary document processing

Session files are retained only as needed to complete provider return, certification, public proof and download, subject to technical and legal requirements.

02

Access logs

Technical access logs are normally retained for up to seven days unless a security event requires longer evidence preservation.

03

Business records

Payment, invoice and business correspondence data can be retained for statutory commercial and tax periods.

04

Provider-side data

finAPI and the selected bank apply their own retention rules and legal obligations.

05

Public proof

Public blockchain records are designed to be permanent and normally cannot be erased by ROCKVALID.

EUDI Wallet Sandbox

Identity verification in the EUDI Wallet Lab

At /eudi-lab/, ROCKVALID can use the German EUDI Wallet Sandbox instead of finAPI for test name verification.

01

Requested data

ROCKVALID requests only given_name and family_name from the PID credential. Date of birth, address, nationality and other PID attributes are not requested in this lab.

02

Disclosure and verification

The EUDI Wallet shows the requested disclosure. ROCKVALID uses the name only after successful cryptographic verification of the wallet presentation and binds it to the document action initiated by the user.

03

Temporary protocol data

OpenID4VP temporarily processes random nonces, state values, short-lived keys and technical transaction identifiers. They provide replay protection and secure transaction binding and expire with the lab flow.

04

Test environment without finAPI payment

The EUDI Lab uses the EUDI Sandbox for identification. finAPI is not used in this flow and no financial payment is made. As in the normal certification flow, the verified name may become visible in the generated ROCKVALID PDF and its signature chain.

Language & tracking

Six language versions, no behavioural advertising.

ROCKVALID provides German, English, French, Spanish, Italian and Polish pages. The selected language is represented by the page URL and may be suggested from browser settings.

01

No advertising profiles

The current service is not used to build behavioural advertising profiles.

02

Necessary browser or provider storage

Technically necessary storage can be used for security, language routing or provider hand-off. Provider and bank interfaces may use their own necessary storage.

International processing

Cross-border data

Public network and provider infrastructure can involve processing outside Germany or the European Economic Area.

01

Public network

Public proof data is distributed across the relevant network and cannot be treated like data held in one German database.

02

Providers

Where the GDPR requires a transfer safeguard, an adequacy decision, contractual safeguards or another lawful mechanism must apply.

Automated checks

Name match and process status

The workflow uses automated technical checks but does not decide whether the contents of your PDF are true or legally valid.

01

Name and process checks

A failed or incomplete configured check can stop the demo certification.

02

No intended Article 22 decision

These checks are not intended to produce a legal or similarly significant decision about you within the meaning of Article 22 GDPR.

Your rights

Data-subject rights

Subject to the statutory requirements, you may contact ROCKVALID about your personal data.

You may have rights to

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction (Art. 18 GDPR)
  • data portability where applicable (Art. 20 GDPR)
  • object to processing based on legitimate interests (Art. 21 GDPR)
  • withdraw consent for the future where processing is based on consent

Complaints

  • You may lodge a complaint with a data-protection supervisory authority.
  • For the Berlin establishment, the competent authority is generally the Berlin Commissioner for Data Protection and Freedom of Information.

Security measures include transport encryption, access controls, temporary identifiers, data minimisation and security logging. No internet service can guarantee absolute security.

Last updated: 21 August 2026