Application privacy
Application privacy
Information about personal-data processing in the signed-in Doconio application.
Version 1.0 — Last updated: 24 July 2026
This privacy information applies to the signed-in Doconio application at app.doconio.com.
Separate website privacy information applies to the marketing website
doconio.com.
1. Controller and contact
Gallien Ventures GmbH
Schwarzmeerstraße 42
10319 Berlin
Germany
Phone: +49 (0)30 2578 5767
Email: info@doconio.com
2. Roles of Doconio and its customers
Gallien Ventures determines the purposes and essential means of processing for the provision and administration of user accounts, application security and technical operations, and the performance measurement described below.
Where a Doconio customer processes personal data relating to employees, suppliers, contacts, or other data subjects in the application, that customer is generally the controller. Gallien Ventures processes such data as a processor under the data processing agreement concluded with the customer. The customer remains responsible for informing data subjects and for the lawfulness of its business processing.
3. User account, sign-in, and communication
For registration, invitations, sign-in, and account management, we process in particular:
- name, business email address, and preferred language,
- organization, memberships, roles, and permissions,
- sign-in, security, and two-factor status,
- session, device, and technical connection information,
- communication and delivery information for invitations, security messages, notifications, and support.
Processing is necessary to provide the application and perform the user relationship under Article 6(1)(b) GDPR. Where the contract is concluded with the user's organization, processing is also based on our legitimate interest in securely providing and administering the contracted application under Article 6(1)(f) GDPR. Processing required by law is based on Article 6(1)(c) GDPR.
4. Browser storage
The application uses technically necessary local and session storage in particular for sign-in and session handling, language and display preferences, the selected organization, invitation handoffs, and integration flows explicitly initiated by the user. This information is necessary for the application or integration flow requested by the user. The application does not use analytics, advertising, or profiling cookies.
The Web Vitals described in section 6 use neither cookies nor local or session storage.
5. Technical operations, security, and audit data
When operating the application, the IP address, timestamp, requested technical API operation, response status, duration, device and browser information, and security and error events may be processed. Business audit data provides a traceable record of material actions in the application.
This processing supports secure, stable, and traceable provision, troubleshooting, prevention of misuse, and contractual evidence requirements. It is based on Article 6(1)(b) and (f) GDPR. Our legitimate interest is the secure and reliable operation of the application and the protection of customer, user, and company data.
6. Data-minimised performance measurement
In the production application, we measure the following in 25 percent of browser sessions:
- Largest Contentful Paint (LCP),
- Interaction to Next Paint (INP),
- Cumulative Layout Shift (CLS).
The measurements are sent to Azure Application Insights together with the rating, navigation
type, fixed route family, narrow or wide device category, production marker, and build
version. Unknown routes are grouped as other.
Tenant, user, resource, or session IDs, email addresses, search terms, full URLs, dynamic route
segments, and business content are not sent. Automatic page-view, route, Fetch/XHR, dependency,
and exception telemetry is disabled. Automatically generated user, session, device, web, and
operation contexts are removed before transmission, and the IP context is set to 0.0.0.0.
The sender IP is technically visible temporarily during encrypted transport and at the Azure ingestion endpoint. Azure-side IP masking remains enabled; the raw IP is not stored in the performance measurements. Individual measurements are retained for 30 days in the production Log Analytics workspace. Groups are evaluated only after 100 measurements have actually been stored.
Processing is used to identify real-world rendering and interaction problems that cannot be identified through laboratory and load testing alone. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the performant and reliable provision of the application. The measurements are not used for advertising, user profiling, employee performance monitoring, or behavioural monitoring.
7. Service providers, regions, and international access
We use Microsoft Ireland Operations Ltd. and affiliated Microsoft companies for Azure Static Web Apps, Azure App Service, Azure SQL, Blob Storage, Key Vault, Application Insights, Log Analytics, and other agreed Azure services.
The production API, database, storage, and monitoring platform is located in Azure Germany West Central. The customer application's static files are served from Azure West Europe. Support and operational access permitted by law may have an international dimension under Microsoft's contractual framework. The Microsoft Products and Services Data Protection Addendum and the transfer mechanisms provided therein form the contractual basis.
Further information is available in our public subprocessor list and international data access information.
8. Retention
We retain personal data only for as long as necessary for the respective purpose, the user or contractual relationship, security and evidence obligations, or statutory retention requirements. Individual browser performance measurements are retained for 30 days. Customer business data is processed in accordance with the customer agreement, data processing agreement, and the applicable export and deletion procedures.
9. Data subject rights
Subject to the statutory requirements, data subjects have rights including access, rectification, erasure, restriction of processing, and data portability. They also have the right to object, on grounds relating to their particular situation, to processing based on Article 6(1)(f) GDPR.
To exercise your rights or object to processing, send an informal message to info@doconio.com. Where a request concerns business data processed by a Doconio customer under its own responsibility, we may refer the request to the responsible customer or assist that customer under the data processing agreement.
You also have the right to lodge a complaint with a data protection supervisory authority.
10. Changes
We update this privacy information when purposes, data categories, service providers, or material technical procedures change. The current date and version number are published at the beginning of this document.