Version: 0.2 | 20 April 2026
The controller within the meaning of the GDPR is: Lyubomira Petkova, Von-der-Tann-Straße 17, 67433 Neustadt an der Weinstraße.
General e-mail: info@blocaro.com
Privacy e-mail: privacy@blocaro.com
Legal/DSA e-mail: legal@blocaro.com
In the publicly accessible area, we do not use any analytics tools, marketing cookies, or comparable technologies. A cookie consent banner is currently not required.
When accessing the website, the following technically necessary connection data is processed: IP address, date/time, page accessed, data volume transferred, HTTP status code, referrer URL, browser type/version, operating system. Legal basis: Art. 6(1)(f) GDPR. Log files are deleted after at most 14 days.
a) Registration and user account: To create a user account, we process your e-mail address and password (stored in cryptographically encrypted form). Legal basis: Art. 6(1)(b) GDPR.
b) Document upload and granular sharing: When uploading documents, we process the contained content and metadata. When inviting third parties, we process their e-mail address. Data protection information pursuant to Art. 14 GDPR is transmitted in the invitation e-mail. Legal basis: Art. 6(1)(b) GDPR.
c) Authentication: In the logged-in area, access tokens and refresh tokens are stored in the browser's localStorage. Legal basis: Art. 6(1)(b) GDPR, § 25(2) No. 2 TDDDG. On the checkout page, Stripe.js is integrated (legal basis: Art. 6(1)(b) GDPR).
d) B2B use (allocation of roles): To the extent that business customers process personal data of third parties in documents, Blocaro acts as a data processor (Art. 28 GDPR). Blocaro processes the following in its own capacity: account, contract, billing, communication, log, and security data. A DPA is provided.
Third-country transfers take place exclusively on the basis of the EU Commission's standard contractual clauses.
Data is stored for as long as your account is active. After termination of contract, a multi-stage deletion process begins: days 0–14 full access; days 15–29 read-only access with export capability (ZIP archive); from day 30 automatic permanent deletion. Immediate deletion is possible upon explicit request. Server log files are deleted after 14 days.
Please direct requests to: privacy@blocaro.com
Exclusively automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.