Privacy Policy: Signature Portal
1. Scope
Netcetera Software Services (“NCS”), acting as a qualified trust service provider (“TSP”) under Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (“eIDAS Regulation”), offers a service for registering qualified certificates and for using qualified remote electronic signatures under the eIDAS Regulation.
This privacy policy informs users of this trust service about the nature, scope, and purpose of NCS's collection and use of personal data.
This privacy policy will be updated where necessary to reflect current circumstances, such as changes to the applicable data protection provisions.
2. Purpose and legal basis of data processing
Before it can issue a qualified certificate, the TSP must verify the identity of the user for whom the certificate is to be issued. As part of this verification, the user's personal data is collected, entered into the certificate, and retained on a permanent basis for verification purposes.
The TSP provides certification and trust services to the user on the basis of:
the eIDAS Regulation, and
the Trust Services Act (“VDG”) of 18 July 2017,
the Trust Services Ordinance (“VDV”) of 15 February 2019.
This data is therefore processed based on Article 6(1)(b), (c), and (f) of the General Data Protection Regulation (GDPR).
Personal information is also processed to meet accounting obligations, process payments, and issue invoices.
To further improve and tailor our products, online offerings, and services, we collect statistical data on user behavior. This data is collected without personal data, or only in anonymized or pseudonymized form, in accordance with data protection law. For this purpose we use our own statistics server based on Piwik, operated in accordance with the recommendations issued by the Independent State Centre for Data Protection Schleswig-Holstein on 15 March 2011. We use cookies on the website for statistical data collection, which can be deactivated.
You can also configure your browser to be notified when cookies are set and to allow cookies only on a case-by-case basis, to exclude the acceptance of cookies for certain cases or in general and to enable automatic deletion of cookies when the browser is closed. Disabling cookies may partially or fully limit the functionality of the website. Please note that deleting cookies in your browser will also require you to opt in again (cookie consent banner) or opt out again (see Piwik statistics above).
3. Scope of data processing
3.1 What data is processed?
The following personal data of the user is collected:
Surname, first name
Date of birth
Email, phone number
User's IP address
Depending on the identification method used, the following personal data of the user is collected, or collected optionally:
Address
Nationality
Birth name
User-specific identifier
The following data must be stored in the certificate and may be publicly accessible:
Surname, first name
Certificate serial number
The following personal data is collected for invoicing, to meet accounting obligations, and for payment processing, if an online payment is made:
Surname, first name
Address
If identity verification is carried out using a classic or automated video identification procedure, a recording of the identification process is additionally stored alongside the data listed above.
During the signing process, documents are provided and processed by the user.
Further data stored when using the services is set out in the TSP's general privacy policy.
3.2 Where is data processed?
All data is stored and processed exclusively in the TSP's data centers. For payment processing, the information required for this purpose is processed by the payment service provider Mollie B.V.
3.3 Who receives the data?
Data is transferred to contractual partners as part of the disclosure of certificates (generally limited to the user's name). This may also involve recipients outside the EU.
The information required to process payments is processed by the payment service provider Mollie B.V. in accordance with the privacy policy published by Mollie B.V.
3.4 How long is the data stored?
For qualified signature certificates, the requirements of Section 16(4) of the Trust Services Act on permanent retention apply to the certificates and the certificate verification data, including the user's contact details. To ensure the identification process remains permanently traceable, the certificates and certificate verification data are stored for the entire duration of the TSP's operations. If the TSP ceases operations, it must hand over the data to the Federal Network Agency (Bundesnetzagentur) or to another qualified trust service provider. For the reasons stated above, deletion of the data is not provided for.
Invoices issued are retained for the statutory minimum retention period of 10 years and deleted thereafter.
3.5 How is the data secured?
All data stored by the TSP is protected against unauthorized access, loss, and alteration using current security standards. Extensive technical and organizational security measures are applied, meeting a standard that at minimum complies with statutory requirements.
3.6 Details of control measures under data processing agreements
The data protection officer of NCS conducts regular reviews. In addition, the qualified trust services provided by the processor are regularly audited by an accredited conformity assessment body to verify their compliance with eIDAS.
4. Rights and complaints
The user has the following rights vis-à-vis the TSP regarding personal data concerning them:
Right of access under Article 15 GDPR
Right to rectification under Article 16 GDPR
Right to erasure under Article 17 GDPR
Right to restriction of processing under Article 18 GDPR
Right to object to processing under Article 21 GDPR
Right to data portability under Article 20 GDPR
Except for the right of access, exercising any of the other rights will result in revocation of the certificate.
Furthermore, the user has the right, on grounds relating to their particular situation, to object at any time to the processing of their personal data carried out under Article 6(1)(e) GDPR (processing in the public interest) or Article 6(1)(f) GDPR (processing based on a balancing of interests); this also applies to profiling based on these provisions.
If the user objects, the TSP will no longer process the user's personal data unless it can demonstrate compelling legitimate grounds for the processing that override the user's interests, rights, and freedoms, or unless the processing serves to assert, exercise, or defend legal claims.
In connection with the use of information society services, and notwithstanding Directive 2002/58/EC, the user may exercise their right to object using automated means involving technical specifications.
The user has the right to withdraw consent to the processing of personal data at any time, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal.
The user may exercise these rights by contacting the TSP's data protection officer.
The user also has the right to lodge a complaint with a data protection supervisory authority regarding the TSP's processing of their personal data.
The supervisory authority responsible for the TSP can be reached at:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
(State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestrasse 2-4
P.O. Box 20 04 44
40102 Düsseldorf, Germany
Phone: +49 211 38424-0
Fax: +49 211 38424-10
Email: poststelle@ldi.nrw.de
5. Contact details
5.1 Controller
Netcetera Software Services GmbH
Vitalisstrasse 67
50827 Cologne, Germany
Email: bvsign@netcetera-de.com
5.2 Data protection officer
You can reach out to our Data Protection Officer via E-Mail: datenschutz@netcetera-de.com