OpenDisclosure

Privacy notice

Website, accounts and payments · Updated 5 October 2026

Noah Haibach, trading as Datalevia, operates OpenDisclosure and is responsible for personal data used to run this website, manage customer accounts and handle enquiries and billing. Our address and email are in the Impressum. You can also contact us online.

For documents, requests and personal data processed in a customer’s disclosure workspace, that organisation determines the purposes of processing. We process that information on its instructions under the applicable data-processing agreement. Contact the relevant organisation about its disclosure decisions and published documents.

  • Website delivery and security: IP address, requested URL, time, browser information and technical request data are processed to deliver pages, diagnose failures and prevent abuse. The basis is our legitimate interest in operating a reliable and secure service (GDPR Article 6(1)(f)).
  • Contact and support: your email, message and any name or organisation you provide are used to answer your enquiry. Contract-related enquiries are processed under Article 6(1)(b); other enquiries under our legitimate interest in responding (Article 6(1)(f)). The contact form delivers your message by email. Please do not include sensitive documents in a general enquiry.
  • Accounts and workspaces: email, identity-provider identifier, organisation, memberships, roles and account activity are used to provide access and attribute actions. The basis is Article 6(1)(b) for contractual account administration, and Article 6(1)(f) for authorised staff access and service security.
  • Billing: customer and invoice details, billing address, tax identifiers, payment references, subscription status and billable usage are used to fulfil the contract (Article 6(1)(b)) and comply with accounting and tax obligations (Article 6(1)(c)).
  • Spam protection: our self-hosted proof-of-work check processes challenge responses and limited request identifiers to prevent automated abuse. It is used for our legitimate interest in protecting contact and signup forms (Article 6(1)(f)).

Account and billing details needed to provide a paid service must be supplied for us to fulfil the order. Optional contact fields can be left blank. We do not use this information to make solely automated decisions with legal or similarly significant effects about you.

Signed-in access uses a secure HTTP-only session cookie and identity-provider cookies needed for authentication. The browser stores a theme preference locally and temporarily remembers a signup email in session storage. Form spam protection uses technical challenge state. These support service functions; the application does not include advertising trackers or third-party analytics.

You can clear cookies and browser storage in your browser. Doing so may sign you out or reset preferences. Mollie’s hosted payment page has its own privacy and cookie information.

  • Hetzner: application hosting and document storage in the EU.
  • Scaleway: transactional email delivery and infrastructure services.
  • Bunny.net: website delivery and edge security; technical request data is processed when you access the website. See Bunny.net’s privacy information.
  • Mollie: payment processing and invoice delivery. Payment information is supplied to Mollie through its payment flow. See Mollie’s privacy notice.
  • Mistral: optional AI processing, enabled only when the workspace organisation opts in. Document excerpts needed for that task are sent to the configured Mistral connection. AI is disabled by default and is not used to process general website visits or contact enquiries.

Authorised operators may access information as needed for support, security and billing. We may disclose records where a legal obligation requires it. We do not sell personal data.

Application and document storage is hosted in the EU. Public website delivery and external payment services may involve providers’ international networks and subprocessors. Their linked privacy notices explain their locations and transfer safeguards; contact us for information about the processing arrangements applicable to your organisation.

Enquiries are kept for the time needed to answer and follow up, and longer where they form part of a contract or legal claim. Account information is retained while needed to operate the workspace and meet security or legal obligations. Billing records are retained for the applicable statutory accounting and tax periods. Technical records are retained only as needed for delivery, security and investigation.

Workspace document retention follows the organisation’s settings and legal holds. The standard lifecycle removes working copies three months after a request closes; after the configured retention period, published copies and audit records may remain. Closing an account or request does not override a legal hold or statutory retention obligation.

Subject to the GDPR’s conditions, you can request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests for reasons relating to your situation. Where processing relies on consent, you can withdraw it for future processing.

Send requests through our contact form or the email in the Impressum. We may need to verify your identity. For personal data controlled by a workspace organisation, contact that organisation; we assist it under our processing agreement.

You can complain to a data protection supervisory authority, including the authority where you live or work. The authority for our location is the Hessian Commissioner for Data Protection and Freedom of Information.