ROCKVALID OTF public demo
Privacy notice

Store less.
Prove what matters.

This notice explains how personal data is processed when you visit ROCKVALID, use the current OTF certification demo or verify a ROCKVALID PDF.

Public demo: use only the sandbox credentials shown on the Certify page. Do not enter real online-banking credentials into the ROCKVALID website and do not upload confidential PDFs, special-category personal data or documents with significant legal or financial consequences.

Controller and contact

Who is responsible?

ROCKVALID UG (haftungsbeschränkt) in Gründung
Greifswalder Straße 13B
10405 Berlin
Germany

Privacy contact: datenschutz@rockvalid.com

Current workflow

Data processed in the OTF demo

The precise data depends on the function and provider you select. ROCKVALID does not require a permanent user account or a personal blockchain wallet for the current OTF workflow.

1. Website access

The server may process IP address, time, requested URL, response status, browser or user-agent information, referrer, error data and security events.

2. PDF upload and session

The uploaded PDF, original filename, a random session identifier, a download token, process status and the generated certified PDF are processed in a server-side OTF session.

3. Name and provider selection

ROCKVALID processes the first and last name entered on the Certify page, the selected provider and the technical identifiers required to continue the chosen demo process.

4. Identity and payment result

Depending on the provider flow, ROCKVALID may receive an account-holder or payer name, a name-match result, payment status, amount, currency, reference, and provider, payment or check IDs.

5. Certification record

ROCKVALID processes a temporary RVID, the recorded name, provider/payment references, document fingerprints, identity-binding fingerprints, proof status and blockchain transaction identifiers.

6. Verification

A PDF submitted to the Verifier is read to calculate its fingerprints and inspect embedded ROCKVALID data. These values are compared with public blockchain proof data.

Provider credentials: test-bank login data is entered in the interface supplied by the selected provider or test bank. ROCKVALID is not intended to receive your real banking password, PIN or TAN.

Open banking

finAPI and TrueLayer

The current Certify page offers demo workflows through finAPI and TrueLayer. When you start one of these workflows, required data is sent to the selected provider and, where applicable, to the selected test bank. The provider returns technical process, identity or payment results to ROCKVALID.

  • finAPI GiroIdent + Payment: the entered name is used for the configured name check. If the result does not match, the combined process stops before certification.
  • finAPI Payment: processes payment initiation and payment status. A payment-only result is not automatically equivalent to a separate identity verification.
  • TrueLayer Sandbox: processes the sandbox payment and may return account-holder information supplied by the test-payment source.

The provider's own privacy and legal information applies in addition to this notice when you use its interface.

PDF and public proof

What becomes part of the result?

The generated ROCKVALID PDF contains visible or embedded certification data. In the current demo this can include the recorded name, temporary RVID, provider or payment reference and certification status. Anyone who receives the completed PDF may be able to read this information. You control whom you give the downloaded PDF to.

The public blockchain record does not contain the uploaded PDF. The current OTF proof is designed to contain compact technical values such as a protocol marker, a document fingerprint and an identity-binding fingerprint. Blockchain transaction data and timestamps are public, globally replicated and generally cannot be deleted later.

A document fingerprint is a one-way cryptographic value, not a copy of the PDF. It can nevertheless be personal data where it can be linked to a person or document through additional information.

Purposes and legal bases

Why data is processed

Purpose Typical data Legal basis
Provide OTF certification and verification PDF, name, session and proof data, provider result Art. 6(1)(b) GDPR
Initiate and confirm payment Payment amount, status, reference and provider IDs Art. 6(1)(b) GDPR
Security and abuse prevention Access, error and security logs; technical identifiers Art. 6(1)(f) GDPR
Accounting and legal compliance Required transaction, invoice and correspondence data Art. 6(1)(c) GDPR
Optional functions or communications Data specifically requested for that function Art. 6(1)(a) GDPR where consent is required

The legitimate interests are secure and reliable system operation, fraud prevention, troubleshooting and the establishment, exercise or defence of legal claims.

Recipients

Who may receive data?

Data is shared only as required for the relevant function or by law. Recipients may include:

  • hosting, infrastructure and security service providers;
  • finAPI GmbH for the selected finAPI identity or payment workflow;
  • the relevant TrueLayer entity for the selected TrueLayer workflow;
  • the bank or test bank selected in the provider interface;
  • the Cardano network and blockchain infrastructure used for proof submission and lookup;
  • professional advisers, auditors, courts or authorities where legally required.

ROCKVALID does not sell uploaded document contents and does not provide PDFs to advertising partners.

Storage and deletion

How long data is retained

OTF session files and data are held on the ROCKVALID server so the provider return, certification, blockchain submission and document download can be completed. They are not intended to form a permanent customer document archive.

Current demo limitation: a fixed, user-visible automatic deletion deadline for every OTF session has not yet been fully implemented and verified. Until that control is active and the concrete period is published here, do not upload confidential or production documents.
  • Technical access logs are normally retained for up to seven days, unless a security event requires longer evidence preservation.
  • Payment, invoice and business correspondence data may be retained for statutory commercial and tax periods.
  • Provider-side retention is governed by the selected provider's privacy notice and regulatory duties.
  • Public blockchain records are designed to be permanent and cannot normally be erased by ROCKVALID.

Browser storage and tracking

No behavioural advertising

The OTF page may store the selected interface language in your browser's local storage. ROCKVALID does not currently use this OTF service for behavioural advertising or the creation of advertising profiles.

Technically necessary storage or cookies may be used if required for security or a provider hand-off. The selected provider and bank may use their own necessary storage in their interfaces.

International processing

Cross-border data

Public blockchain data is distributed globally. Provider or infrastructure processing may also involve countries outside Germany or the European Economic Area. Where the GDPR requires safeguards for a transfer, the relevant adequacy decision, contractual safeguards or another lawful transfer mechanism must apply. Details of provider-side processing are available in the linked provider notices.

Automated checks

Name matching and payment status

The workflow applies automated technical checks, including a provider name-match result and payment status. A failed or incomplete check can stop the demo certification. This does not determine the truth or legal validity of the PDF and is not intended to produce a legal or similarly significant effect within the meaning of Article 22 GDPR.

Necessary information

Is providing data mandatory?

You are not legally required to use ROCKVALID. The PDF, process name and provider/payment data requested by the selected flow are necessary to perform that OTF certification. If you do not provide them, the certification cannot be completed. Verification similarly requires the PDF to be checked.

Data-subject rights

Your rights

Subject to the applicable legal requirements, you may have the right to:

  • access your personal data (Article 15 GDPR);
  • rectify inaccurate data (Article 16 GDPR);
  • request erasure (Article 17 GDPR);
  • restrict processing (Article 18 GDPR);
  • receive portable data where applicable (Article 20 GDPR);
  • object to processing based on legitimate interests (Article 21 GDPR); and
  • withdraw consent at any time for the future.

You may also lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or the alleged infringement. For ROCKVALID's Berlin establishment, the competent authority is generally the Berlin Commissioner for Data Protection and Freedom of Information.

ROCKVALID cannot erase public blockchain data. This is why the public proof is deliberately limited to compact technical values rather than the uploaded PDF or a plaintext name.

Security

Protecting the workflow

ROCKVALID uses technical and organisational measures appropriate to the current service, including transport encryption, access controls, random session and download identifiers, data minimisation and security logging. No internet service can guarantee absolute security.

Keep the completed ROCKVALID PDF secure, check it before sharing and verify the actual file rather than relying on a screenshot of a verification result.

Version

Changes to this notice

This notice may be updated when the OTF workflow, providers, retention controls, proof format or legal requirements change. The version published on this page applies.

Last updated: 29 July 2026