1. Website access
The server may process IP address, time, requested URL, response status, browser or user-agent information, referrer, error data and security events.
This notice explains how personal data is processed when you visit ROCKVALID, use the current OTF certification demo or verify a ROCKVALID PDF.
Controller and contact
Privacy contact: datenschutz@rockvalid.com
Current workflow
The precise data depends on the function and provider you select. ROCKVALID does not require a permanent user account or a personal blockchain wallet for the current OTF workflow.
The server may process IP address, time, requested URL, response status, browser or user-agent information, referrer, error data and security events.
The uploaded PDF, original filename, a random session identifier, a download token, process status and the generated certified PDF are processed in a server-side OTF session.
ROCKVALID processes the first and last name entered on the Certify page, the selected provider and the technical identifiers required to continue the chosen demo process.
Depending on the provider flow, ROCKVALID may receive an account-holder or payer name, a name-match result, payment status, amount, currency, reference, and provider, payment or check IDs.
ROCKVALID processes a temporary RVID, the recorded name, provider/payment references, document fingerprints, identity-binding fingerprints, proof status and blockchain transaction identifiers.
A PDF submitted to the Verifier is read to calculate its fingerprints and inspect embedded ROCKVALID data. These values are compared with public blockchain proof data.
Open banking
The current Certify page offers demo workflows through finAPI and TrueLayer. When you start one of these workflows, required data is sent to the selected provider and, where applicable, to the selected test bank. The provider returns technical process, identity or payment results to ROCKVALID.
The provider's own privacy and legal information applies in addition to this notice when you use its interface.
PDF and public proof
The generated ROCKVALID PDF contains visible or embedded certification data. In the current demo this can include the recorded name, temporary RVID, provider or payment reference and certification status. Anyone who receives the completed PDF may be able to read this information. You control whom you give the downloaded PDF to.
The public blockchain record does not contain the uploaded PDF. The current OTF proof is designed to contain compact technical values such as a protocol marker, a document fingerprint and an identity-binding fingerprint. Blockchain transaction data and timestamps are public, globally replicated and generally cannot be deleted later.
Purposes and legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide OTF certification and verification | PDF, name, session and proof data, provider result | Art. 6(1)(b) GDPR |
| Initiate and confirm payment | Payment amount, status, reference and provider IDs | Art. 6(1)(b) GDPR |
| Security and abuse prevention | Access, error and security logs; technical identifiers | Art. 6(1)(f) GDPR |
| Accounting and legal compliance | Required transaction, invoice and correspondence data | Art. 6(1)(c) GDPR |
| Optional functions or communications | Data specifically requested for that function | Art. 6(1)(a) GDPR where consent is required |
The legitimate interests are secure and reliable system operation, fraud prevention, troubleshooting and the establishment, exercise or defence of legal claims.
Recipients
Data is shared only as required for the relevant function or by law. Recipients may include:
ROCKVALID does not sell uploaded document contents and does not provide PDFs to advertising partners.
Storage and deletion
OTF session files and data are held on the ROCKVALID server so the provider return, certification, blockchain submission and document download can be completed. They are not intended to form a permanent customer document archive.
Browser storage and tracking
The OTF page may store the selected interface language in your browser's local storage. ROCKVALID does not currently use this OTF service for behavioural advertising or the creation of advertising profiles.
Technically necessary storage or cookies may be used if required for security or a provider hand-off. The selected provider and bank may use their own necessary storage in their interfaces.
International processing
Public blockchain data is distributed globally. Provider or infrastructure processing may also involve countries outside Germany or the European Economic Area. Where the GDPR requires safeguards for a transfer, the relevant adequacy decision, contractual safeguards or another lawful transfer mechanism must apply. Details of provider-side processing are available in the linked provider notices.
Automated checks
The workflow applies automated technical checks, including a provider name-match result and payment status. A failed or incomplete check can stop the demo certification. This does not determine the truth or legal validity of the PDF and is not intended to produce a legal or similarly significant effect within the meaning of Article 22 GDPR.
Necessary information
You are not legally required to use ROCKVALID. The PDF, process name and provider/payment data requested by the selected flow are necessary to perform that OTF certification. If you do not provide them, the certification cannot be completed. Verification similarly requires the PDF to be checked.
Data-subject rights
Subject to the applicable legal requirements, you may have the right to:
You may also lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or the alleged infringement. For ROCKVALID's Berlin establishment, the competent authority is generally the Berlin Commissioner for Data Protection and Freedom of Information.
Security
ROCKVALID uses technical and organisational measures appropriate to the current service, including transport encryption, access controls, random session and download identifiers, data minimisation and security logging. No internet service can guarantee absolute security.
Keep the completed ROCKVALID PDF secure, check it before sharing and verify the actual file rather than relying on a screenshot of a verification result.
Version
This notice may be updated when the OTF workflow, providers, retention controls, proof format or legal requirements change. The version published on this page applies.
Last updated: 29 July 2026