Privacy Policy — MVO Doc Check & Hosting
1. Controller
GiBSeS OÜ, Juhkentali 8, 10132 Tallinn, Estonia, Estonian register no. [REG. NR. — to be inserted]. Email: info@gibses.com. Service support: doccheck@gibses.com. We have not appointed a data protection officer; contact the addresses above for any privacy matter.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account and contact data | business email address; name and role if you provide them; company name and VAT number | you |
| Uploaded documents | instructions, declarations, technical documents; they may contain names of authors, signatories or contacts | you |
| Findings and reports | the output of the check, linked to your account | generated by us |
| Access and technical logs | IP address, timestamp, browser type, pages requested, error events | your browser |
| Payment data | transaction ID, amount, invoice details; card data is held by Stripe and never reaches us | you, via Stripe |
| Support correspondence | emails you send to doccheck@gibses.com | you |
We do not intentionally collect special categories of data. Do not upload documents containing them.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6(1)) |
|---|---|
| Provide the Service: run checks, host documents, deliver reports, manage your account | (b) performance of a contract |
| Invoicing, accounting, tax | (c) legal obligation |
| Security, abuse prevention, error diagnosis | (f) legitimate interest in a secure service |
| B2B communications about the Service and related products to relevant business contacts | (f) legitimate interest in direct marketing to existing business customers; you can opt out immediately at any time, with one click in every email or by writing to doccheck@gibses.com |
| Newsletter | (a) consent, revocable at any time |
| Enforce our terms, handle disputes | (f) legitimate interest |
We do not use uploaded documents to train any model, and we do not sell personal data.
4. Recipients and processors
We share data only with the providers needed to run the Service, under data-processing agreements (art. 28 GDPR):
| Provider | Role | Location |
|---|---|---|
| Contabo GmbH | hosting of the application, database and files (VPS) | Germany (EU) |
| Stripe Payments Europe Ltd | payment processing | Ireland (EU); Stripe group companies may process data in the USA |
| Resend | transactional email (order confirmations, reports, reminders) | USA |
| Anthropic PBC | language-model analysis | USA |
| Google (Google Cloud / Gemini) | language-model analysis | USA / EU |
| DeepSeek | language-model analysis, public content only (see below) | China |
How documents reach the language-model providers. To produce findings, extracts of your documents are sent in fragments to a language-model provider through its API. We apply the following rule:
- Documents uploaded by customers (manuals, declarations, technical documents) are processed only by providers established in the EU or USA that commit contractually not to use API data for training (currently Anthropic and Google, under their business/API terms).
- The Chinese provider (DeepSeek) is used only for content that is already public, such as the text of the Regulation, harmonised standards summaries, or public guidance. Customer documents are never sent to DeepSeek.
Authorities, courts or professional advisers may receive data where the law requires or permits it.
5. Transfers outside the EU/EEA
Where a provider processes data in the USA, the transfer is based on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, where the provider is certified, on the EU-US Data Privacy Framework. No customer document is transferred to a country without an adequacy decision or SCCs. Copies of the safeguards are available on request.
6. Retention
| Data | Retention |
|---|---|
| Documents uploaded for a check, and the report | 90 days after delivery of the report, then deleted — unless the document set is part of an active Hosting subscription |
| Hosted documents | for the duration of the subscription, plus 90 days for download after termination, then deleted |
| Access and technical logs | 12 months |
| Account data | for the duration of the relationship, then 12 months, unless a longer period applies below |
| Invoices and accounting records | 7 years after the end of the financial year, as required by the Estonian Accounting Act |
| Support correspondence | 24 months after the last exchange |
| Newsletter consent record | until revoked, plus 3 years as proof |
7. Your rights
You have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting past processing.
To exercise a right, email doccheck@gibses.com from the address linked to your account, or write to the postal address above. We answer within one month; we may ask for information to confirm your identity.
You may lodge a complaint with the Estonian supervisory authority: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, https://www.aki.ee — or with the authority of your own member state.
8. Cookies and analytics
The site uses only technically necessary cookies (session, security, language choice). We set no advertising or third-party tracking cookies. If we measure traffic, we use self-hosted, cookie-free analytics that stores no personal identifiers and does not follow you across sites. No consent banner is needed for this.
9. Security
Data is stored on servers in Germany, encrypted in transit (TLS) and at rest. Access is restricted to staff who need it, under confidentiality obligations. Uploaded files are isolated per customer.
10. Changes
We may update this policy. The current version is always published at https://doccheck.gibses.com. Material changes affecting active customers are notified by email.
Last update: 2026-09-14.