Privacy Policy

We process personal data exclusively on the basis of the GDPR. The controller is Advocato GmbH (i. Gr.), Musterstraße 1, 10115 Berlin.

1. Data we process

  • Account: name, email, role (client/lawyer), country, language.
  • Payment data: via Stripe (PCI-DSS); we do not store card data.
  • Consultation: ticket history, chat messages, video call metadata (duration, start/end).
  • Emergency: voluntary location data (only with explicit release in the browser).

2. Video calls

Video consultations are carried out via Daily.co (EU servers selectable). There is NO server-side recording. Lawyer and client are subject to attorney–client privilege.

3. Legal bases

Art. 6(1)(b) GDPR (contract), (c) (legal obligation), (f) (legitimate interest in operation and security). For location data in an emergency: (a) (consent).

4. Disclosure

Recipients are exclusively the selected lawyer, our payment service provider (Stripe) and – on request – a legal-expenses insurance partner (affiliate lead). Processors are contractually bound pursuant to Art. 28 GDPR.

5. Data subject rights

Access, rectification, erasure, restriction, data portability, objection, and complaint to a supervisory authority. Contact: datenschutz@advocato.app.

6. Retention period

Ticket and invoice data: 10 years (HGB/AO – German Commercial and Fiscal Code). Account: until deletion. Chat content: 2 years after ticket closure, thereafter anonymised statistics.

7. Data processing agreement (DPA)

Lawyers handling mandates via Advocato receive a data processing agreement pursuant to Art. 28 GDPR upon request. Requests to datenschutz@advocato.app.

8. Location data in an emergency

When triggering an emergency, the browser may ask for location permission. Sharing is voluntary; it helps the lawyer assess the context (e.g. traffic stops). The location is shared only with the assigned lawyer and stored with the ticket.

9. Subprocessors

  • Stripe Payments Europe Ltd. (IE) — Payment processing, identity verification (Stripe Identity), tax calculation.
  • Daily.co / Pluot Communications, Inc. (US, EU-Server wählbar) — Video consultation. No recording.
  • Supabase / Lovable Cloud (EU) — Database, authentication, file storage, push notifications.
  • Cloudflare, Inc. (US/EU) — Hosting/CDN, DDoS protection.
  • Google Firebase Cloud MessagingPush delivery (only if push is enabled).
  • Resend / Email-Versand-DienstleisterTransactional and authentication emails.

10. Your rights in the app

In the privacy center you can export your data as JSON (Art. 20) and delete your account (Art. 17) at any time.

11. Cookies & consent

We only use strictly necessary cookies (session, CSRF). Optional cookies are only set after consent via the banner. Consents are logged server-side and can be withdrawn at any time in the browser (by deleting cookies).