Compliance← xbanq.com

XBANQ GmbH · Trust Center

Compliance, stated plainly

What data the XBANQ app ecosystem holds, where it lives, who processes it, and what we have not achieved yet. This page is retrieved from the compliance database. Recorded statements and evidence references require review against the actual deployment.

Records retrieved from all four sources · generated 23 September 2026 · Datenschutz · Impressum

01 — DSGVO / GDPR

The recorded data map

XBANQ GmbH, Neuhofer Weg 2, 91257 Pegnitz, is the controller for the services described here. There is no tracking, no analytics, no advertising, and no third-party scripts on our websites. The console uses one strictly necessary cookie: your sign-in session.

This register is the Art. 30 GDPR record of processing activities, served live from the database table that IS the register — not a copy of it.

What data is stored where, and why — live from the Art. 30 register
SystemPurpose · lawful basisData heldRecipientsRetention
Accounts (console)Operating your license account: sign-in, company membership, role.Contract — Art. 6(1)(b)E-mail address · Full name · Company membership · RoleSupabase (EU region)Until the account is deleted (self-serve in the console)
AI transparency logEU AI Act Art. 50 provenance for AI-generated content.Legal obligation — Art. 6(1)(c)Content type · Model · Provider · Disclosure shown · TimestampSupabase (EU region)For the AI Act documentation period
Audit logInformation security, abuse prevention, privileged-action accounting.Legitimate interest — Art. 6(1)(f)Action · Entity · Actor id · TimestampSupabase (EU region)Rolling security retention
City licence requests (funnel)Answering an offer request for an xbanq.city municipal licence: preparing and sending the written offer.Contract — Art. 6(1)(b)Full name · Organisation · Role · Work e-mail address · Phone number (optional) · Free-text message · The licence configuration the visitor made · Salted hash of the IP address · User agentSupabase (EU region), Resend (e-mail delivery, EU processing; AV / DPA in place)Three years after the last contact, then deleted; earlier on request (Art. 17)
Consent recordsDemonstrating consent under Art. 7 GDPR.Legal obligation — Art. 6(1)(c)E-mail address · Purpose · Granted/withdrawn timestamps · Salted IP hash · EvidenceSupabase (EU region)For the statutory proof period (German law, typically 3 years)
E-mail deliverySending license keys, invoices and the newsletter you opted into.Contract — Art. 6(1)(b)Recipient address · Message id · Delivery statusResendDelivery logs retained by the provider per their schedule
Incident logArt. 33/34 GDPR and NIS2/CRA incident documentation.Legal obligation — Art. 6(1)(c)Severity · Title · Detection/containment/resolution times · Affected-data flag · Notification stateSupabase (EU region)For the statutory documentation period
LicensesLicense verification for the desktop apps.Contract — Art. 6(1)(b)SHA-256 hash of the license key · Key hint (last 4 characters) · Plan · Tier · ExpirySupabase (EU region)While the license exists; revoked hashes pruned with cleanup
MachinesEnforcing the per-license machine limit.Legitimate interest — Art. 6(1)(f)Machine id (per-install identifier) · First/last seen · IP address at verification · App user-agentSupabase (EU region)While the parent license exists
NewsletterProduct news, double opt-in.Consent — Art. 6(1)(a)E-mail address · Double-opt-in state · Confirm token · LocaleSupabase (EU region), ResendUntil unsubscribe; erased on DSR request
PaymentsBilling: purchases, invoices, subscriptions.Legal obligation — Art. 6(1)(c)Stripe customer id · Invoice amounts · Invoice PDFs (hosted by Stripe)Stripe (EU processing), Supabase (EU region)Invoices for the statutory retention period (German commercial law)
  • No external-EU transfers recorded. These are recorded transfer declarations, not independent verification of provider location or processing. Review safeguards against your deployment.
  • No profiling, no automated decisions about natural persons — license checks act on keys and machine ids.
  • The desktop apps (XBANQ Pulse) process machine data locally; telemetry does not exist. The only network calls are license verification and signed update checks.
  • Consent records. Newsletter state and consent records are maintained. A complete transactional lifecycle history and evidence review remain in progress.

01 b — Your rights, self-serve

The data subject rights portal

Access, rectification, erasure, restriction, portability, objection, and complaint to Bayerisches Landesamt für Datenschutzaufsicht — one e-mail to hello@xbanq.com has always been enough. The forms below record the request in the audit ledger. Confirmation-mail status is reported separately. Identity verification and review precede disclosure or erasure; responses are required without undue delay under Article 12(3).

Request access to or export of your personal data under Articles 15 and 20 GDPR. Identity verification and review come before disclosure.

One request is enough. Article 12(3) requires a response without undue delay, generally within one calendar month, subject to permitted extensions. A confirmation e-mail is attempted for the address above; nothing is executed without verification.

Account deletion removes sign-in and profile after applicable ownership, billing and stored-asset issues are resolved. It does not erase every record. Financial retention, asset cleanup and other data-rights requests require separate review.

02 — AVV / Data Processing Agreement

Auftragsverarbeitungsvertrag

Companies using XBANQ apps with a company account can conclude an AVV under Art. 28 DSGVO. The offer: print this page (or the PDF your browser produces from it) or request the countersignable document by e-mail — we countersign within five working days.

AVV offer — key terms

Controller (Auftraggeber)
The customer company named in the contract
Processor (Auftragsverarbeiter)
XBANQ GmbH, Neuhofer Weg 2, 91257 Pegnitz, Germany
Subject matter
Operation of the XBANQ console: account, license, machine and billing records as described in § 01
Sub-processors
Supabase (database, EU region), Stripe (payments), Resend (e-mail delivery) — current list on request, changes announced with objection right
Technical measures
As described in § 04 of this page (encryption in transit, hashing, RLS, least privilege, EU hosting)
Deletion
Account closure and erasure are reviewed separately; billing records may require retention, and company assets may require transfer
Audit
Information on request; on-site audits as agreed in the full document

Request the AVV document via e-mail — hello@xbanq.com, countersigned within 5 working days.

03 — EU AI Act

AI transparency

XBANQ Pulse contains no AI system of its own. It monitors the AI workloads you run on your Mac — the models, agents and quotas are yours and stay local. Nothing Pulse observes leaves the machine.

XBANQ Work OS (in development) orchestrates AI agents that act on your instructions. Our commitments for it: human oversight of consequential actions (confirmation before execution), a logged audit trail of agent activity, data minimization (only the data a workflow needs), and no practices prohibited under Art. 5.

Art. 50 provenance — the live record

Instrumented generation paths attempt to record content type, model, provider and a disclosure flag. Logging is best-effort; these counts do not prove coverage of all generated content or that a person saw a disclosure. The provenance register stores metadata rather than content.

0AI-generated pieces logged with provenance.

Where users interact with AI, that is disclosed in the interface (Art. 50). We do not build or operate systems that classify natural persons by biometrics, score social behaviour, or infer emotions at work — the categories Art. 5 prohibits.

04 — Security architecture

What the platform actually does

  • License keys are hashed. Only the SHA-256 hash of a key is stored — a database leak yields no working keys. Even our staff see only a 4-character hint; re-issuing rotates the key.
  • Row-level security on every table. Console reads run under your own signed-in session and the database itself enforces what you may see — verified table by table in the 2026-09-07 security audit.
  • Service-role isolation. Privileged operations run only in audited server-side actions that re-check ownership or staff status before anything is touched. The service key never reaches a browser.
  • The technical log. Privileged actions land in an append-only audit ledger (the input for the ISO 27001 logging control); AI provenance and incidents carry their own registers. No message contents are ever logged.
  • No card data on our servers. Payments run entirely on Stripe's hosted checkout and billing portal; we store only Stripe identifiers and invoice metadata.
  • EU hosting, strict headers. Hetzner (Germany) for the site; CSP, HSTS, X-Frame-Options DENY and Referrer-Policy on every response; no third-party scripts.
  • Signed updates only. Desktop app updates ship as minisign-signed artifacts; the updater refuses anything unsigned.

05 — ISO 27001 · SOC 2 · DSGVO · AI Act · CRA · NIS2

Where we honestly stand

We hold neither an ISO 27001 certificate nor a SOC 2 report today, and you will not find a badge claiming otherwise on any XBANQ surface. What we do have is a control matrix — each record is a declared status with an evidence reference. These include seed records and do not establish independent verification, complete framework coverage or audit readiness.

DSGVO / GDPR

11/11

controls recorded as implemented

recorded statuses — evidence review required · 100% of recorded applicable controls

Recorded mapping to GDPR articles

EU AI Act

5/6

controls recorded as implemented · 1 partial · 0 planned

recorded statuses — evidence review required · 83% of recorded applicable controls

Recorded mapping to AI transparency duties

ISO 27001

36/45

controls recorded as implemented · 9 partial · 0 planned

recorded statuses — evidence review required · 80% of recorded applicable controls

Recorded mapping to selected Annex A controls

SOC 2

18/24

controls recorded as implemented · 5 partial · 1 planned

recorded statuses — evidence review required · 75% of recorded applicable controls

Trust Services Criteria mapped

CRA

3/5

controls recorded as implemented · 1 partial · 1 planned

recorded statuses — evidence review required · 60% of recorded applicable controls

Cyber Resilience Act product-security duties

NIS2

1/4

controls recorded as implemented · 3 partial · 0 planned

recorded statuses — evidence review required · 25% of recorded applicable controls

Recorded risk-management and reporting controls

Status counts describe this selected mapping only. Evidence references and review dates need validation; a date recorded by a seed migration is not an independent review. Missing, old or incomplete evidence must be resolved before making readiness claims.

Need the mapping for a vendor review? Download our control matrix — generated live from the same rows that score this page — or ask: hello@xbanq.com

06 — Incident history

The incident register, in the open

This section shows entries returned by the public incident register. An empty result does not establish that no incidents have occurred. Regulatory applicability, awareness and notification timing require separate assessment; this display does not prove that a notification was sent.

No public incident entries returned. The database returned an empty public list for this request.