Privacy Policy
We process personal data exclusively on the basis of the GDPR. The controller is Advocato GmbH (i. Gr.), Musterstraße 1, 10115 Berlin.
1. Data we process
- Account: name, email, role (client/lawyer), country, language.
- Payment data: via Stripe (PCI-DSS); we do not store card data.
- Consultation: ticket history, chat messages, video call metadata (duration, start/end).
- Emergency: voluntary location data (only with explicit release in the browser).
2. Video calls
Video consultations are carried out via Daily.co (EU servers selectable). There is NO server-side recording. Lawyer and client are subject to attorney–client privilege.
3. Legal bases
Art. 6(1)(b) GDPR (contract), (c) (legal obligation), (f) (legitimate interest in operation and security). For location data in an emergency: (a) (consent).
4. Disclosure
Recipients are exclusively the selected lawyer, our payment service provider (Stripe) and – on request – a legal-expenses insurance partner (affiliate lead). Processors are contractually bound pursuant to Art. 28 GDPR.
5. Data subject rights
Access, rectification, erasure, restriction, data portability, objection, and complaint to a supervisory authority. Contact: datenschutz@advocato.app.
6. Retention period
Ticket and invoice data: 10 years (HGB/AO – German Commercial and Fiscal Code). Account: until deletion. Chat content: 2 years after ticket closure, thereafter anonymised statistics.
7. Data processing agreement (DPA)
Lawyers handling mandates via Advocato receive a data processing agreement pursuant to Art. 28 GDPR upon request. Requests to datenschutz@advocato.app.
8. Location data in an emergency
When triggering an emergency, the browser may ask for location permission. Sharing is voluntary; it helps the lawyer assess the context (e.g. traffic stops). The location is shared only with the assigned lawyer and stored with the ticket.
9. Subprocessors
- Stripe Payments Europe Ltd. (IE) — Payment processing, identity verification (Stripe Identity), tax calculation.
- Daily.co / Pluot Communications, Inc. (US, EU-Server wählbar) — Video consultation. No recording.
- Supabase / Lovable Cloud (EU) — Database, authentication, file storage, push notifications.
- Cloudflare, Inc. (US/EU) — Hosting/CDN, DDoS protection.
- Google Firebase Cloud Messaging — Push delivery (only if push is enabled).
- Resend / Email-Versand-Dienstleister — Transactional and authentication emails.
10. Your rights in the app
In the privacy center you can export your data as JSON (Art. 20) and delete your account (Art. 17) at any time.
11. Cookies & consent
We only use strictly necessary cookies (session, CSRF). Optional cookies are only set after consent via the banner. Consents are logged server-side and can be withdrawn at any time in the browser (by deleting cookies).