Privacy policy

Which data DocLif processes, for what purpose, on what legal basis and for how long.

As of: 09/05/2026

Controller

The German version of this policy is the legally binding one.

Responsible for the processing of personal data on this website and in the DocLif service is:

Felix Obenaus
Ofenstraße 9a
44147 Dortmund
Deutschland
Email: contact@felix-go.de

A data protection officer does not have to be appointed by law. Please send questions about data protection to the address above.

Hosting and server logs

DocLif runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, located in Germany. Hetzner processes the data exclusively on my behalf; a data processing agreement pursuant to Art. 28 GDPR is in place.

Technical log data is created with every request: IP address, time, requested address, amount of data transferred, status code, browser identifier. It is needed to deliver the service and to detect attacks. The legal basis is Art. 6 (1) (f) GDPR – my legitimate interest in stable and secure operation. The logs are deleted after 14 days at the latest.

Visiting the start page

The start page loads the current prices and the operating status from its own server. External fonts, maps, video services or reach measurement tools are not embedded – your browser talks only to this service.

Account and registration

For an account, the email address, display name and a password are processed. The password is stored only as a hash value and is not known to me. In addition there is data created while the account is used: time of the last sign-in, chosen plan, storage used.

The legal basis is Art. 6 (1) (b) GDPR – the processing is necessary to perform the user agreement. Without this data no account can be maintained.

Uploaded documents

The actual purpose of the service: you upload documents, DocLif stores them, recognises their text and files them. In doing so the following is created and processed:

  • the file itself, stored encrypted in the object store
  • the recognised text and the details derived from it such as sender, date, amount, due dates and category
  • history data: when a document was uploaded, changed or deleted

Which personal data arises is determined solely by you, through the content you upload. The legal basis is Art. 6 (1) (b) GDPR.

Text recognition and automatic analysis

Text recognition (Tesseract) and content analysis by a language model (Ollama) run on the same server as the service. No documents are transmitted to an AI provider or any other third party for this. There is no automated decision within the meaning of Art. 22 GDPR: the analysis makes suggestions that you can check and change.

To improve the suggestions, DocLif may draw on already checked examples from your own collection as context. These examples do not leave your account and are not used to train a model.

Fetching from email mailboxes

Optionally you can store an email mailbox from which DocLif fetches attachments. For this the server address, user name and password are stored; the credentials are held encrypted in the database. What is fetched are the attachments of the messages in the configured folder, along with sender, subject and time so that the import can be traced.

This processing only takes place if you set up a mailbox (Art. 6 (1) (b) GDPR). You can remove it at any time; the credentials are deleted with it.

Share links

You can share documents via a link. The link contains a random token, can be given a password and an expiry date, and can be revoked at any time. Shares are excluded from search engines and do not pass on the referrer. Whoever receives a share link sees the shared documents – so choose the recipients deliberately.

Payment processing

Paid plans are handled by external payment providers. Your payment data – card number, bank details, PayPal account – is entered there and does not reach DocLif. Only the transaction identifier, the booked plan and the payment status are reported back to me so that the subscription can be activated.

  • Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
  • PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

The legal basis is Art. 6 (1) (b) GDPR. Both providers may transfer data to group companies in the USA; the transfer is safeguarded by the EU-US Data Privacy Framework or by standard contractual clauses pursuant to Art. 46 GDPR. Invoice data is subject to commercial and tax retention periods of up to ten years (Art. 6 (1) (c) GDPR).

Sending email

DocLif sends messages that belong to its operation: confirmation of registration, link to reset the password, notice of a failed analysis, share invitations. Sending runs through the mail server of the hosting provider (Hetzner Online GmbH). DocLif does not send advertising mails.

Getting in touch

If you write to me by email or through the contact form, I process your details to answer the enquiry. The legal basis is Art. 6 (1) (b) GDPR for contract-related enquiries, otherwise Art. 6 (1) (f) GDPR. The message is deleted as soon as the matter is settled and no retention period stands in the way.

Cookies and reach measurement

DocLif sets no cookies for analysis or advertising purposes and embeds no tracking services. Only technically necessary items are stored in your browser: the sign-in token of your session and your choice between a light and a dark appearance. Both stay on your device and are not evaluated.

Retention and deletion

Your data stays stored as long as your account exists. Deleted documents remain in the trash for up to 90 days and are then removed for good. If you delete your account, your documents and the associated data are deleted; excluded is data that I have to keep for legal reasons – essentially invoice records.

Your rights

You have the following rights towards the controller:

  • access to the data stored about you (Art. 15 GDPR)
  • rectification of incorrect data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
  • data portability in a common format (Art. 20 GDPR)
  • objection to processing based on a legitimate interest (Art. 21 GDPR)
  • withdrawal of a given consent with effect for the future (Art. 7 (3) GDPR)

A message to contact@felix-go.de is enough. Many rights you can also exercise yourself: documents can be downloaded and deleted, and the account can be closed in the profile.

Right to complain to the supervisory authority

You can complain to a data protection supervisory authority, for instance to the one responsible for me:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4
40213 Düsseldorf

Changes to this policy

If the service changes, this policy changes with it. The version available here is the one that applies; the date above states its status.