Privacy Policy
Clanker GmbH
Privacy Policy
Privacy information for ShareKYC, a brand of Clanker GmbH in Austria.
Last updated: 2026-06-24
1. Controller and Contact
Clanker GmbH, Gumpendorfer Straße 36/46, 1060 Vienna, Austria. ShareKYC is a brand of Clanker GmbH.
For privacy requests: [email protected]
2. Data Categories We Process
2.1 Account Data
Name, email address, password (hashed), profile photo (optional), language preference, and two-factor authentication settings.
2.2 KYC Profile and Identity Data
The personal identity data you enter into a KYC profile, such as name, gender, date and place of birth, nationality, address, national or personal ID numbers, and identity-document data (document type, number, issuing authority, dates of issue and expiry). This may include data revealing sensitive characteristics; we treat it with heightened protection. Sensitive profile data is stored encrypted in the Secure Vault (see Section 12) and cannot be read by us without you unlocking it.
2.3 Identity Documents
Identity documents and related files you upload (such as passports, ID cards, or proof of address). These documents are stored encrypted in the Secure Vault.
2.4 Identity Verification Data
Where you use electronic identity verification, data required to perform document and biometric checks is processed via our verification provider SmartIdent, including a verification session identifier, the verification result and status, extracted document data, and check scores. Verification results we store are kept encrypted in the Secure Vault.
2.5 Share and Access Data
Share links you create, including the selected fields and documents, recipient name and email (where provided), expiry date, download permission, and access limits, together with access logs such as view and download counts and timestamps. For KYC requests, the request details, recipient, matter reference, purpose, and the profile a person submits in response.
2.6 Billing Data
Billing name, company name, billing address, VAT ID, and payment method details. Payment data is processed and stored by our payment provider Stripe — we do not store full credit card numbers.
2.7 Usage and Security Logs
IP addresses, browser type, access times, pages visited, error logs, and security events (login attempts, session data).
2.8 Communication Data
Support requests and correspondence sent to us.
3. Purposes of Processing
We process your data for the following purposes:
- Service delivery: Operating the ShareKYC platform, storing your KYC profiles and documents in the Secure Vault, enabling secure sharing, and processing KYC requests and responses.
- Identity verification: Performing electronic identity verification through SmartIdent when you choose to verify a profile.
- Authentication: Verifying your identity, managing sessions, and enabling two-factor authentication.
- Billing: Processing payments, issuing invoices, and managing subscriptions through Stripe.
- Support: Responding to your inquiries and resolving issues.
- Security: Detecting and preventing fraud, abuse, and unauthorized access; maintaining audit trails.
- Compliance: Fulfilling legal obligations (tax records, regulatory requirements).
- Improvement: Analyzing usage patterns to improve the Service (in aggregated, non-identifying form).
4. Legal Bases (GDPR Art. 6)
| Purpose | Legal Basis |
|---|---|
| Service delivery, identity verification, billing | Art. 6(1)(b) — Performance of contract |
| Tax records, legal compliance | Art. 6(1)(c) — Legal obligation |
| Security, fraud prevention, service improvement | Art. 6(1)(f) — Legitimate interest |
| Optional cookies, marketing (if applicable) | Art. 6(1)(a) — Consent |
Where you share special-category identity data, processing additionally relies on your explicit consent (Art. 9(2)(a)) or another applicable exception under Art. 9 GDPR.
5. Recipients and Sub-Processors
We share data with the following categories of service providers, all acting as processors under GDPR:
| Provider | Purpose | Location |
|---|---|---|
| SmartIdent | Electronic identity verification (document and biometric checks) | EU / SCCs |
| Stripe | Payment processing and invoicing | USA (SCCs) |
| Hosting provider | Server hosting and infrastructure | EU |
| Email provider | Transactional email delivery | EU / SCCs |
We do not sell personal data. We do not transmit the encrypted contents of your Secure Vault to these providers in readable form. An up-to-date list of sub-processors is available upon request at [email protected].
6. International Data Transfers
Where data is transferred outside the European Economic Area (EEA), we rely on:
- EU Standard Contractual Clauses (SCCs) as adopted by the European Commission.
- Additional technical and organizational safeguards, including encryption in transit and at rest.
- Where available, adequacy decisions by the European Commission.
7. Cookies and Tracking
7.1 Essential Cookies
We use strictly necessary cookies for authentication (session cookies) and CSRF protection. These cannot be disabled as they are required for the Service to function.
7.2 No Third-Party Tracking
We do not use third-party analytics, advertising trackers, or social media tracking pixels. We do not participate in cross-site tracking.
8. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data | Duration of the account, deleted within 30 days after account deletion |
| KYC profile data and documents | Until you delete the profile or document, or within 30 days after account deletion |
| Identity verification results | Stored with the profile until deleted; underlying check data is held by the provider per its retention policy |
| Share links and access logs | Until the share is revoked or expires; access logs kept up to 90 days thereafter |
| Billing data and invoices | 7 years after the end of the billing relationship (Austrian tax law, BAO §132) |
| Security and access logs | 90 days |
| Support correspondence | 3 years after resolution |
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access (Art. 15): Request a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
- Restriction (Art. 18): Restrict processing in certain circumstances.
- Data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdrawal of consent (Art. 7): Withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise your rights, contact us at: [email protected]
We will respond within 30 days. Requests are free of charge unless manifestly unfounded or excessive.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority:
Austrian Data Protection Authority (Datenschutzbehörde) Barichgasse 40-42, 1030 Vienna, Austria Website: https://www.dsb.gv.at Email: [email protected]
11. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects concerning you. Electronic identity verification provides results and check scores to support your decisions, but does not make a binding decision about you on its own.
12. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- End-to-end-style Secure Vault encryption: Sensitive KYC profile data, uploaded documents, and verification results are encrypted in a Secure Vault whose key is derived from your password and personal Security Key. We cannot access the contents of your vault without you unlocking it with your key.
- Encryption of data in transit (TLS) and at rest.
- Password hashing using industry-standard algorithms.
- Regular security updates and vulnerability monitoring.
- Access controls and principle of least privilege.
- Secure, secret share links with expiry, optional download permission, and access limits.
13. Children's Privacy
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "last updated" date at the top indicates the most recent revision.
15. Contact
For all privacy-related inquiries: [email protected]
Clanker GmbH, Gumpendorfer Straße 36/46, 1060 Vienna, Austria.