DSGVO / GDPR
11/11
controls recorded as implemented
recorded statuses — evidence review required · 100% of recorded applicable controls
Recorded mapping to GDPR articles
XBANQ GmbH · Trust Center
What data the XBANQ app ecosystem holds, where it lives, who processes it, and what we have not achieved yet. This page is retrieved from the compliance database. Recorded statements and evidence references require review against the actual deployment.
Records retrieved from all four sources · generated 23 September 2026 · Datenschutz · Impressum
01 — DSGVO / GDPR
XBANQ GmbH, Neuhofer Weg 2, 91257 Pegnitz, is the controller for the services described here. There is no tracking, no analytics, no advertising, and no third-party scripts on our websites. The console uses one strictly necessary cookie: your sign-in session.
This register is the Art. 30 GDPR record of processing activities, served live from the database table that IS the register — not a copy of it.
| System | Purpose · lawful basis | Data held | Recipients | Retention |
|---|---|---|---|---|
| Accounts (console) | Operating your license account: sign-in, company membership, role.Contract — Art. 6(1)(b) | E-mail address · Full name · Company membership · Role | Supabase (EU region) | Until the account is deleted (self-serve in the console) |
| AI transparency log | EU AI Act Art. 50 provenance for AI-generated content.Legal obligation — Art. 6(1)(c) | Content type · Model · Provider · Disclosure shown · Timestamp | Supabase (EU region) | For the AI Act documentation period |
| Audit log | Information security, abuse prevention, privileged-action accounting.Legitimate interest — Art. 6(1)(f) | Action · Entity · Actor id · Timestamp | Supabase (EU region) | Rolling security retention |
| City licence requests (funnel) | Answering an offer request for an xbanq.city municipal licence: preparing and sending the written offer.Contract — Art. 6(1)(b) | Full name · Organisation · Role · Work e-mail address · Phone number (optional) · Free-text message · The licence configuration the visitor made · Salted hash of the IP address · User agent | Supabase (EU region), Resend (e-mail delivery, EU processing; AV / DPA in place) | Three years after the last contact, then deleted; earlier on request (Art. 17) |
| Consent records | Demonstrating consent under Art. 7 GDPR.Legal obligation — Art. 6(1)(c) | E-mail address · Purpose · Granted/withdrawn timestamps · Salted IP hash · Evidence | Supabase (EU region) | For the statutory proof period (German law, typically 3 years) |
| E-mail delivery | Sending license keys, invoices and the newsletter you opted into.Contract — Art. 6(1)(b) | Recipient address · Message id · Delivery status | Resend | Delivery logs retained by the provider per their schedule |
| Incident log | Art. 33/34 GDPR and NIS2/CRA incident documentation.Legal obligation — Art. 6(1)(c) | Severity · Title · Detection/containment/resolution times · Affected-data flag · Notification state | Supabase (EU region) | For the statutory documentation period |
| Licenses | License verification for the desktop apps.Contract — Art. 6(1)(b) | SHA-256 hash of the license key · Key hint (last 4 characters) · Plan · Tier · Expiry | Supabase (EU region) | While the license exists; revoked hashes pruned with cleanup |
| Machines | Enforcing the per-license machine limit.Legitimate interest — Art. 6(1)(f) | Machine id (per-install identifier) · First/last seen · IP address at verification · App user-agent | Supabase (EU region) | While the parent license exists |
| Newsletter | Product news, double opt-in.Consent — Art. 6(1)(a) | E-mail address · Double-opt-in state · Confirm token · Locale | Supabase (EU region), Resend | Until unsubscribe; erased on DSR request |
| Payments | Billing: purchases, invoices, subscriptions.Legal obligation — Art. 6(1)(c) | Stripe customer id · Invoice amounts · Invoice PDFs (hosted by Stripe) | Stripe (EU processing), Supabase (EU region) | Invoices for the statutory retention period (German commercial law) |
01 b — Your rights, self-serve
Access, rectification, erasure, restriction, portability, objection, and complaint to Bayerisches Landesamt für Datenschutzaufsicht — one e-mail to hello@xbanq.com has always been enough. The forms below record the request in the audit ledger. Confirmation-mail status is reported separately. Identity verification and review precede disclosure or erasure; responses are required without undue delay under Article 12(3).
Account deletion removes sign-in and profile after applicable ownership, billing and stored-asset issues are resolved. It does not erase every record. Financial retention, asset cleanup and other data-rights requests require separate review.
02 — AVV / Data Processing Agreement
Companies using XBANQ apps with a company account can conclude an AVV under Art. 28 DSGVO. The offer: print this page (or the PDF your browser produces from it) or request the countersignable document by e-mail — we countersign within five working days.
Request the AVV document via e-mail — hello@xbanq.com, countersigned within 5 working days.
03 — EU AI Act
XBANQ Pulse contains no AI system of its own. It monitors the AI workloads you run on your Mac — the models, agents and quotas are yours and stay local. Nothing Pulse observes leaves the machine.
XBANQ Work OS (in development) orchestrates AI agents that act on your instructions. Our commitments for it: human oversight of consequential actions (confirmation before execution), a logged audit trail of agent activity, data minimization (only the data a workflow needs), and no practices prohibited under Art. 5.
Instrumented generation paths attempt to record content type, model, provider and a disclosure flag. Logging is best-effort; these counts do not prove coverage of all generated content or that a person saw a disclosure. The provenance register stores metadata rather than content.
0AI-generated pieces logged with provenance.
Where users interact with AI, that is disclosed in the interface (Art. 50). We do not build or operate systems that classify natural persons by biometrics, score social behaviour, or infer emotions at work — the categories Art. 5 prohibits.
04 — Security architecture
05 — ISO 27001 · SOC 2 · DSGVO · AI Act · CRA · NIS2
We hold neither an ISO 27001 certificate nor a SOC 2 report today, and you will not find a badge claiming otherwise on any XBANQ surface. What we do have is a control matrix — each record is a declared status with an evidence reference. These include seed records and do not establish independent verification, complete framework coverage or audit readiness.
DSGVO / GDPR
11/11
controls recorded as implemented
recorded statuses — evidence review required · 100% of recorded applicable controls
Recorded mapping to GDPR articles
EU AI Act
5/6
controls recorded as implemented · 1 partial · 0 planned
recorded statuses — evidence review required · 83% of recorded applicable controls
Recorded mapping to AI transparency duties
ISO 27001
36/45
controls recorded as implemented · 9 partial · 0 planned
recorded statuses — evidence review required · 80% of recorded applicable controls
Recorded mapping to selected Annex A controls
SOC 2
18/24
controls recorded as implemented · 5 partial · 1 planned
recorded statuses — evidence review required · 75% of recorded applicable controls
Trust Services Criteria mapped
CRA
3/5
controls recorded as implemented · 1 partial · 1 planned
recorded statuses — evidence review required · 60% of recorded applicable controls
Cyber Resilience Act product-security duties
NIS2
1/4
controls recorded as implemented · 3 partial · 0 planned
recorded statuses — evidence review required · 25% of recorded applicable controls
Recorded risk-management and reporting controls
Status counts describe this selected mapping only. Evidence references and review dates need validation; a date recorded by a seed migration is not an independent review. Missing, old or incomplete evidence must be resolved before making readiness claims.
Need the mapping for a vendor review? Download our control matrix — generated live from the same rows that score this page — or ask: hello@xbanq.com
06 — Incident history
This section shows entries returned by the public incident register. An empty result does not establish that no incidents have occurred. Regulatory applicability, awareness and notification timing require separate assessment; this display does not prove that a notification was sent.
No public incident entries returned. The database returned an empty public list for this request.