Application privacy
Application privacy
Information about personal-data processing in the signed-in Doconio application.
Version 1.1 — Last updated: 7 September 2026
This privacy information applies to the signed-in Doconio application at app.doconio.com.
Separate website privacy information applies to the marketing website
doconio.com.
1. Controller and contact
Seleos GmbH
Schwarzmeerstraße 42
10319 Berlin
Germany
Phone: +49 (0)30 2578 5767
Email: info@doconio.com
2. Roles of Doconio and its customers
Seleos determines the purposes and essential means of processing for the provision and administration of user accounts, application security and technical operations, and the performance measurement described below.
Where a Doconio customer processes personal data relating to employees, suppliers, contacts, or other data subjects in the application, that customer is generally the controller. Seleos processes such data as a processor under the data processing agreement concluded with the customer. The customer remains responsible for informing data subjects and for the lawfulness of its business processing.
3. User account, sign-in, and communication
For registration, invitations, sign-in, and account management, we process in particular:
- name, business email address, and preferred language,
- organization, memberships, roles, and permissions,
- sign-in, security, and two-factor status,
- session, device, and technical connection information,
- communication and delivery information for invitations, security messages, notifications, and support. If a callback is explicitly requested, we additionally process the submitted phone number and preferred time window. These callback details are deleted after the request is answered or after 30 days at the latest; the contact case and recorded response remain as support and operational evidence.
Processing is necessary to provide the application and perform the user relationship under Article 6(1)(b) GDPR. Where the contract is concluded with the user's organization, processing is also based on our legitimate interest in securely providing and administering the contracted application under Article 6(1)(f) GDPR. Processing required by law is based on Article 6(1)(c) GDPR.
4. Browser storage
The application uses technically necessary local and session storage in particular for sign-in and session handling, language and display preferences, the selected organization, invitation handoffs, and integration flows explicitly initiated by the user. This information is necessary for the application or integration flow requested by the user. The application does not use analytics, advertising, or profiling cookies.
The Web Vitals described in section 6 use neither cookies nor local or session storage.
5. Technical operations, security, and audit data
When operating the application, the IP address, timestamp, requested technical API operation, response status, duration, device and browser information, and security and error events may be processed. Business audit data provides a traceable record of material actions in the application.
This processing supports secure, stable, and traceable provision, troubleshooting, prevention of misuse, and contractual evidence requirements. It is based on Article 6(1)(b) and (f) GDPR. Our legitimate interest is the secure and reliable operation of the application and the protection of customer, user, and company data.
6. Data-minimised performance measurement
In the production application, we measure the following on a sample of browser sessions:
- Largest Contentful Paint (LCP),
- Interaction to Next Paint (INP),
- Cumulative Layout Shift (CLS).
The measurements are sent to Azure Application Insights together with a coarse, non-personal classification (rating, navigation type, general page area, device type, production marker, and build version).
Tenant, user, resource, or session IDs, email addresses, search terms, full URLs, dynamic route segments, and business content are not sent. Automatic page-view, route, Fetch/XHR, dependency, and exception telemetry is disabled.
The sender IP is technically visible temporarily during encrypted transport and at the Azure ingestion endpoint. Azure-side IP masking remains enabled; the raw IP is not stored in the performance measurements. Individual measurements are retained for 30 days in the production Log Analytics workspace. Evaluation only happens in groups, so no individual person can be identified.
Processing is used to identify real-world rendering and interaction problems that cannot be identified through laboratory and load testing alone. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the performant and reliable provision of the application. The measurements are not used for advertising, user profiling, employee performance monitoring, or behavioural monitoring.
Product and adoption measurement
To improve the product, we record a closed server-side list of successful business event facts, such as the first application of a catalog package, completion of an evidence request, or successful use of Audit Pack, Teams, MCP, and Document AI. Stored fields are limited to event type, timestamp, tenant assignment, coarse product area, and a coarse actor category. Active users are counted only through a one-way pseudonym that changes monthly; user IDs, names, email addresses, document titles, file names, search or comment content, and other business free text are not copied into this dataset.
Only aggregated results are available to Doconio platform administrators. Values are fully suppressed when fewer than five eligible tenants exist. There is no tenant or user drill-down and no employee performance or behavioural monitoring. Demo and test tenants are excluded. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is evidence-based, data-minimised improvement of the service. Event facts are retained for the tenant lifetime and deleted during tenant hard purge so that first use is not distorted by a rolling retention period.
7. Service providers, regions, and international access
We use Microsoft Ireland Operations Ltd. and affiliated Microsoft companies for Azure Static Web Apps, Azure App Service, Azure SQL, Blob Storage, Key Vault, Application Insights, Log Analytics, and other agreed Azure services.
The production API, database, storage, and monitoring platform is located in Azure Germany West Central. The customer application's static files are served from Azure West Europe. Support and operational access permitted by law may have an international dimension under Microsoft's contractual framework. The Microsoft Products and Services Data Protection Addendum and the transfer mechanisms provided therein form the contractual basis.
Further information is available in our public subprocessor list and international data access information.
8. Retention
We retain personal data only for as long as necessary for the respective purpose, the user or contractual relationship, security and evidence obligations, or statutory retention requirements. Individual browser performance measurements are retained for 30 days. Customer business data is processed in accordance with the customer agreement, data processing agreement, and the applicable export and deletion procedures. Retention of data-minimised product and adoption events is described in section 6.
9. Data subject rights
Subject to the statutory requirements, data subjects have rights including access, rectification, erasure, restriction of processing, and data portability. They also have the right to object, on grounds relating to their particular situation, to processing based on Article 6(1)(f) GDPR.
To exercise your rights or object to processing, send an informal message to info@doconio.com. Where a request concerns business data processed by a Doconio customer under its own responsibility, we may refer the request to the responsible customer or assist that customer under the data processing agreement.
You also have the right to lodge a complaint with a data protection supervisory authority.
10. Changes
We update this privacy information when purposes, data categories, service providers, or material technical procedures change. The current date and version number are published at the beginning of this document.