Skip to main content

Privacy Policy

This is a courtesy translation. The German original is the legally binding version: Datenschutzerklärung.

Here you'll find information on how DolmiDesk™ handles your data in accordance with the GDPR.

Last updated: July 23, 2026

Preamble

With this privacy policy, we want to inform you which types of your personal data we process, for which purposes, and to what extent. This policy applies to all processing of personal data carried out by us – in particular in connection with the provision of our software-as-a-service application DolmiDesk (accessible at app.dolmidesk.com), our websites, and our communication with you.

DolmiDesk is an application for interpreters and translation service providers for managing jobs, customers, cost bearers, and for creating and sending invoices, reminders, and e-invoices.

Controller

Dmitry Dugarev

Address: Mombacher Weg 26, 65936 Frankfurt am Main, Germany

Email address: support@dolmidesk.com

Imprint: dolmidesk.com/legal/imprint

Overview of processing activities

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects affected.

Types of data processed

  • Basic data (e.g., name, company name, address)
  • Contact data (e.g., email addresses, phone numbers)
  • Payment data (e.g., bank details, invoice data)
  • Contract data (e.g., selected plan, contract term)
  • Content data (e.g., the jobs, customer, and invoice data you record in DolmiDesk)
  • Usage data (e.g., features accessed, usage times – only with your consent)
  • Meta, communication, and process data (e.g., IP addresses, timestamps, device information)
  • Log data (e.g., log files, audit logs)

Categories of data subjects

  • Customers (users of the application)
  • Prospects
  • Communication partners
  • Business and contractual partners
  • Individuals whose data our customers record in the application (see the section "Processing on behalf of our customers")

Purposes of processing

  • Provision of contractual services and fulfillment of contractual obligations
  • Provision of our online offering and ensuring user-friendliness
  • Operating the information technology infrastructure
  • Security measures
  • Communication
  • Office and organizational procedures
  • Product improvement and reach measurement (only with your consent)

Below you will find an overview of the GDPR legal bases on which we process personal data. Please note that, in addition to the GDPR provisions, national data protection requirements may also apply in your or our country of residence or establishment. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.

  • Consent (Art. 6 Abs. 1 S. 1 lit. a DSGVO): You have given your consent to the processing of your personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual inquiries (Art. 6 Abs. 1 S. 1 lit. b DSGVO): Processing is necessary to perform a contract or to carry out pre-contractual measures at your request.
  • Legal obligation (Art. 6 Abs. 1 S. 1 lit. c DSGVO): Processing is necessary to comply with a legal obligation (e.g., commercial and tax law retention obligations).
  • Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO): Processing serves to protect our legitimate interests or those of third parties, provided your rights do not override these interests.

National data protection provisions in Germany: In addition, special provisions apply in Germany, namely the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) – in particular regarding the right to information, erasure, objection, the processing of special categories of personal data, as well as transfer and automated decision-making. § 25 of the Act on Data Protection and Privacy in Telecommunications and Digital Services (TDDDG) also applies to access to information on your end devices (e.g., cookies).

Security measures

In accordance with legal requirements – taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing – we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

Important measures include, in particular:

  • Encrypted transmission of all data between your browser and our servers (TLS/HTTPS).
  • Encrypted storage of generated documents (e.g., invoice PDFs) with file-specific keys in private, non-publicly accessible storage systems.
  • Tenant-separated data storage: your data is logically strictly separated from the data of other customers.
  • Access protection through server-side sessions, two-factor authentication, and passkeys.
  • Hosting exclusively in data centers within the European Union.
  • Consideration of data protection already during development through privacy-friendly default settings (Art. 25 DSGVO).

You can find a detailed description in the document "Technical and organizational measures (TOM)", which you can download in the application under Settings → Privacy.

Disclosure of personal data

In the course of our processing of personal data, it may happen that this data is transferred to, or disclosed to, other bodies, companies, legally independent organizational units, or persons – for example, to IT service providers who operate our infrastructure. In doing so, we always observe the legal requirements and enter into appropriate agreements with the recipients of the data (in particular data processing agreements pursuant to Art. 28 DSGVO). You can find a current list of the subprocessors we use in the document "List of subprocessors" in the application under Settings → Privacy.

International data transfers

Processing of your data generally takes place in data centers within the European Union (France and the Netherlands). Should we have data processed in a third country (outside the EU/EEA), or should this occur in connection with the use of third-party services, this will only take place in accordance with legal requirements. Where the level of data protection in a third country is recognized by means of an adequacy decision (Art. 45 DSGVO), this serves as the basis – for providers from the USA, in particular certification under the EU-US Data Privacy Framework (DPF). Otherwise, data transfer only takes place if the level of data protection is secured in another way, such as through standard contractual clauses (Art. 46 Abs. 2 lit. c DSGVO).

For more information, see commission.europa.eu/law/law-topic/data-protection_de and www.dataprivacyframework.gov/.

General information on data storage and deletion

We delete your personal data in accordance with legal provisions as soon as any underlying consent is withdrawn or no further legal grounds for processing exist – this applies when the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where legal obligations or particular interests require longer retention.

Data that must be retained for commercial or tax law reasons, or for the pursuit of legal claims, is archived accordingly. The relevant retention and deletion periods are, in particular:

  • 10 years: Retention period for books, records, annual financial statements, inventories, and related work instructions (§ 147 Abs. 1 Nr. 1 i. V. m. Abs. 3 AO, § 14b Abs. 1 UStG, § 257 Abs. 1 Nr. 1 i. V. m. Abs. 4 HGB).
  • 8 years: Retention period for accounting vouchers, e.g., invoices and expense receipts (§ 147 Abs. 1 Nr. 4 und 4a i. V. m. Abs. 3 AO, § 257 Abs. 1 Nr. 4 i. V. m. Abs. 4 HGB).
  • 6 years: Retention period for other business documents, insofar as they are significant for taxation (§ 147 Abs. 1 Nr. 2, 3, 5 i. V. m. Abs. 3 AO, § 257 Abs. 1 Nr. 2 u. 3 i. V. m. Abs. 4 HGB).
  • 3 years: Storage of data to account for potential warranty and damages claims (§§ 195, 199 BGB).

After termination of your contract, we delete your user account and the content data you recorded, insofar as no statutory retention obligations conflict with this. Details are governed by the data processing agreement.

Rights of data subjects

Under the GDPR, you as a data subject have, in particular, the following rights:

  • Right to object: You may object at any time to the processing of your personal data carried out on the basis of Art. 6 Abs. 1 lit. e or f DSGVO; this also applies to profiling based on these provisions. In particular, you have the right to object to processing for direct marketing purposes.
  • Right to withdraw consent: You may withdraw any consent given at any time with effect for the future – for example, consent to product telemetry directly in the application via "Your privacy settings" in the account menu or under Settings → Privacy.
  • Right to information: You have the right to learn whether and which of your data is being processed, as well as to receive a copy of this data and further information in accordance with legal requirements. You can download a copy of the personal data stored for your user account at any time yourself, in the application under Settings → Privacy.
  • Right to rectification: You may request the completion or correction of inaccurate data.
  • Right to erasure and restriction of processing: In accordance with legal requirements, you may request the erasure of your data or a restriction on its processing.
  • Right to data portability: You have the right to receive your data in a structured, commonly used, and machine-readable format, or to request its transfer to another controller. An export function is available for this purpose in the application under Settings → Data export.
  • Right to lodge a complaint with a supervisory authority: You may lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden.

Business services

We process the data of our contractual partners – i.e., customers and prospects – in connection with contractual and similar legal relationships, as well as in communication (including pre-contractual), for example to respond to inquiries. This data serves to fulfill our contractual obligations – in particular the provision of DolmiDesk – as well as to safeguard our rights, for administrative tasks, and for organizing our company.

Disclosure to third parties only takes place where necessary to fulfill the purposes mentioned or to comply with legal obligations. We delete this data after the expiry of the statutory retention periods; data not subject to retention obligations is deleted as soon as it is no longer needed for contract performance.

Types of data processed: basic data, payment data, contact data, contract data, usage data, as well as meta, communication, and process data. Data subjects: customers, prospects, business and contractual partners. Legal bases: performance of a contract and pre-contractual inquiries (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legal obligation (Art. 6 Abs. 1 S. 1 lit. c DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO).

Registration and user account

Using DolmiDesk requires a user account. During registration, we process your email address, your name, and a password of your choice (which is stored exclusively in cryptographically secured form). You can optionally enable two-factor authentication or set up passkeys; the data required for this (e.g., public keys) is stored to secure your account. Logins are managed server-side as sessions; you can view and end active sessions in the settings.

Legal bases: performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO); for security measures, also legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO).

Payment processing

To bill for our services, we process the necessary invoice and payment data (e.g., billing address, VAT identification number, payment status). Payment processing is carried out via the payment service provider Stripe. When you initiate a payment, you are redirected to a payment page operated by Stripe; the payment details entered there (e.g., card number, IBAN) are processed exclusively by Stripe and are not transmitted to us in plain text. We only receive from Stripe the information necessary for the performance of the contract (including payment status, payment method, and transaction identifier). Stripe also processes the data as an independent controller in its own right, to the extent necessary to fulfill its own regulatory and anti-money-laundering obligations.

  • Service provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (for users in the EEA); parent company: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA
  • Legal bases: Performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legal obligation (Art. 6 Abs. 1 S. 1 lit. c DSGVO)
  • Website: stripe.com
  • Privacy policy: stripe.com/de/privacy
  • Data processing agreement: concluded with the provider (Stripe Data Processing Agreement)
  • Basis for third-country transfers: EU-US Data Privacy Framework (DPF) and standard contractual clauses (Art. 46 Abs. 2 lit. c DSGVO)

Legal bases: performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legal obligation (Art. 6 Abs. 1 S. 1 lit. c DSGVO).

Processing on behalf of our customers

DolmiDesk is a tool with which our customers process personal data of third parties – for example, the names and contact details of their clients, job locations, and billing data. Our customers are the controllers under data protection law for this content data; we process it exclusively as a processor pursuant to Art. 28 DSGVO on the basis of a data processing agreement, strictly bound by instructions, and only for the purpose of providing the application.

We do not evaluate this content data for our own purposes, do not pass it on to third parties (other than the subprocessors named in the document "List of subprocessors"), and delete it in accordance with the data processing agreement. Data subjects whose data was recorded by our customers in DolmiDesk should contact the respective controller to exercise their rights; we support our customers in responding to such requests.

Legal basis in relation to our customers: performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO) in conjunction with the data processing agreement (Art. 28 DSGVO).

Provision of the online offering and web hosting

We process user data in order to be able to provide our online services. This includes, in particular, the IP address, which is necessary to deliver content and functions to your browser or end device.

Types of data processed: usage data, meta, communication, and process data, log data. Data subjects: users. Purposes: provision of the online offering, operation of the IT infrastructure, security measures. Legal bases: performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO).

Collection of access data and log files

Access to our services is logged in server log files, which may contain, among other things, the IP address, time of access, and browser information. The log files serve operational security, error analysis, and protection against overload and misuse. Log files are deleted or anonymized after 30 days at the latest, unless they are still needed to investigate a specific incident.

Legal bases: legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO).

Hosting with Scaleway

Our application, the database, the document store, and the sending of system emails are operated at Scaleway. Processing takes place exclusively in data centers within the European Union (France and the Netherlands).

  • Service provider: Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, France
  • Legal bases: Performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO)
  • Website: www.scaleway.com
  • Privacy policy: www.scaleway.com/en/privacy-policy/
  • Data processing agreement: concluded with the provider (part of the Scaleway terms of service)
  • Third-country transfer: none – processing exclusively within the EU

Delivery via Cloudflare

The web application is delivered via the Cloudflare network, which also serves as a content delivery network (CDN) and for protection against attacks (e.g., DDoS). Our website dolmidesk.com is furthermore hosted entirely on Cloudflare (Cloudflare Pages). In this context, Cloudflare processes technically necessary connection data (in particular the IP address). The application form for the beta program (see "Applications for the beta program and prospect mailing list") is also processed via a Cloudflare function (Cloudflare Pages Function), which forwards your input to our self-hosted Notifuse service; in doing so, Cloudflare also processes, for the brief duration of the transmission, the data you provided in the form.

  • Service provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO) – secure and performant delivery of the online offering
  • Website: www.cloudflare.com
  • Privacy policy: www.cloudflare.com/privacypolicy/
  • Data processing agreement: concluded with the provider (Cloudflare Data Processing Addendum)
  • Basis for third-country transfers: EU-US Data Privacy Framework (DPF) and standard contractual clauses (Art. 46 Abs. 2 lit. c DSGVO)

Use of cookies

We use cookies and comparable technologies (e.g., your browser's local storage) firstly to the extent necessary for the operation of the application:

  • Session cookie: After logging in, a cookie stores your session identifier so that you remain logged in. It is strictly necessary for the provision of the service and becomes invalid when you log out or when the session expires.
  • Language setting: Your selected language is stored in your browser's local storage so that the application starts in your language.
  • Consent status: The selection you make in the consent dialog (see below) is stored in your browser's local storage so that you don't have to be asked again on future visits.

The storage of, and access to, information on your end device is, in these cases, strictly necessary to provide the service you explicitly requested (§ 25 Abs. 2 Nr. 2 TDDDG); no consent is required for this.

We only use cookies and comparable storage technologies beyond this with your consent (§ 25 Abs. 1 TDDDG; Art. 6 Abs. 1 S. 1 lit. a DSGVO). On your first visit to the application, a consent dialog (cookie banner) asks for your selection for the categories "Functional", "Statistics", and "Marketing". We currently only use technologies requiring consent in the "Statistics" category (the analytics service PostHog, see the section "Web analytics"); we do not use cookies or comparable identifiers for advertising purposes. You can change or withdraw your selection at any time with effect for the future – via "Your privacy settings" in the account menu of the application.

Legal bases: performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO), consent (Art. 6 Abs. 1 S. 1 lit. a DSGVO); § 25 Abs. 1 and Abs. 2 Nr. 2 TDDDG.

Email dispatch and contact management

Sending system and receipt emails

Emails are sent from the application – for example, confirmation links, security notices, as well as receipt emails initiated by you (e.g., sending invoices to your customers). Sending is carried out via Scaleway's transactional email infrastructure (see above); the recipient address, subject, content, and delivery information are processed.

Legal bases: performance of a contract (Art. 6 Abs. 1 S. 1 lit. b DSGVO).

Applications for the beta program and prospect mailing list

Using the form at dolmidesk.com/join-beta, you can apply for a place in the beta program. In doing so, we process the data you provide (name, email address, calendar used, desired billing period, optionally invoice volume and a message) as well as the time of application, in order to review your application and, if accepted, provide you with access.

Enrollment in the mailing list follows a double opt-in procedure: after submitting the form, you receive an email with a confirmation link. Only after your confirmation is your application reviewed; without confirmation, we delete your details.

We use the Notifuse software to manage this mailing list and to send the associated emails. We operate Notifuse ourselves, on our own hardware, at our business address in Germany (address, see section "Controller"). Notifuse itself is therefore not a third-party cloud service; the contact and mailing-list data is stored exclusively on our own hardware. However, since our website and application form are hosted at, and processed via, a Cloudflare function respectively (see "Delivery via Cloudflare"), your form input passes through Cloudflare's infrastructure in transit before reaching our Notifuse service; no further processing of the mailing-list data by an external provider takes place. Access to the administration interface is protected by upstream access control and two-factor authentication; transmission takes place exclusively in encrypted form (TLS). For the delivery of emails, we use the same sending infrastructure as for our other system emails (see "Hosting with Scaleway").

You can withdraw your consent to receive these emails at any time with effect for the future – via the unsubscribe link in each email, or informally by message to us. After withdrawal, or after the beta program ends, we delete your data from the mailing list, insofar as no statutory retention obligations conflict with this.

Types of data processed: basic data, contact data, content data, meta and process data (e.g., confirmation timestamp). Data subjects: prospects. Legal bases: consent (Art. 6 Abs. 1 S. 1 lit. a DSGVO), pre-contractual measures (Art. 6 Abs. 1 S. 1 lit. b DSGVO).

Contact and inquiry management

If you contact us – by email, contact form, or another means – we process your details insofar as this is necessary to handle your inquiry.

Types of data processed: basic data, contact data, content data. Data subjects: communication partners. Legal bases: performance of a contract and pre-contractual inquiries (Art. 6 Abs. 1 S. 1 lit. b DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f DSGVO).

Web analytics, monitoring, and optimization

To improve the product, we use the analytics service PostHog – exclusively with your consent. You give this consent via the "Statistics" category of the consent dialog (cookie banner, see the section "Use of cookies"). In addition, you can independently disable collection via the "Anonymous usage statistics" toggle in the application under Settings → Privacy; analysis only takes place if both are enabled. Without your consent, no analysis takes place.

We collect usage events (e.g., features accessed, click paths) as well as technical details (e.g., browser, operating system). Collection takes place anonymously: no user profiles are created, events are not linked to your user account, and session recordings are disabled. We use PostHog's EU cloud: data is stored exclusively on servers within the European Union (Frankfurt am Main, Germany). Content data you record in DolmiDesk (e.g., the names of your customers) is not subject to analysis.

  • Service provider: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA (data storage: EU cloud, Frankfurt am Main)
  • Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a DSGVO; § 25 Abs. 1 TDDDG)
  • Website: posthog.com
  • Privacy policy: posthog.com/privacy
  • Data processing agreement: concluded with the provider (PostHog Data Processing Agreement)
  • Basis for third-country transfers: data storage within the EU; for any support access by the provider: EU-US Data Privacy Framework (DPF) and standard contractual clauses (Art. 46 Abs. 2 lit. c DSGVO)
  • Withdrawal (opt-out): at any time via "Your privacy settings" in the account menu (cookie banner) or the toggle under Settings → Privacy

Changes and updates

We ask that you regularly review the content of this privacy policy. We will adapt this policy as soon as changes to the data processing we carry out make this necessary. As soon as a change requires an action on your part (e.g., renewed consent) or other individual notification, we will inform you.

Insofar as this privacy policy states addresses and contact information of companies and organizations, these may change over time; we ask that you verify this information before making contact.

Definitions

Below you will find an overview of the terms used in this privacy policy. Where statutory definitions exist, these apply; the following explanations serve to improve comprehensibility:

  • Basic data: Essential information required for identifying and managing contractual partners and user accounts (e.g., name, contact information, customer number).
  • Content data: Information generated when creating and editing content – in DolmiDesk, in particular, the job, customer, and invoice data recorded by customers.
  • Contact data: Details that enable communication (e.g., phone numbers, email addresses, postal addresses).
  • Meta, communication, and process data: Data about the handling of information (e.g., timestamps, IP addresses, communication histories, audit logs).
  • Usage data: Information on how and when digital offerings are used (e.g., features accessed, usage times, device information).
  • Personal data: Any information relating to an identified or identifiable natural person (e.g., name, identification number, location data, online identifier).
  • Log data: Records of events or activities in a system (e.g., timestamps, IP addresses, error messages).
  • Controller: The person or organization that decides on the purposes and means of processing personal data.
  • Processing: Any operation involving personal data – collecting, evaluating, storing, transmitting, or deleting.
  • Contract data: All details of an agreement between parties (e.g., services, term, payment terms).
  • Payment data: Details needed to carry out transactions (e.g., bank details, invoice information).