When you prepare a naturalization application, you entrust us with sensitive personal information. This article gives an overview of the technical and organizational measures we use to protect this data. The binding details are set out in our privacy policy.
Encryption
Your personal data is stored in encrypted form (AES). This means that even if someone were to gain unauthorized access to the data storage, the contents would not be readable without the corresponding key.
Hosting in Germany
We run civitas. with Hetzner in Germany. Your data is therefore held on servers within the European Union and is subject to the data protection law that applies here.
Retention period
We do not store your data longer than necessary. After the delivery of your application, your data is deleted after 90 days. Only information we are legally required to retain remains thereafter.
Processors
For individual tasks, we use carefully selected service providers. We have data processing agreements under Art. 28 GDPR in place with them, which oblige them to handle your data confidentially and in accordance with the rules:
- Stripe — payment processing
- Hetzner — hosting the application in Germany
- Postmark — sending our emails
Passwordless sign-in
At civitas., you sign in without a password. Instead of a password, you receive a one-time sign-in link (Magic-Link) by email. This means there is no password that could be guessed, reused, or stolen from another service. For security reasons, the link is valid only for a limited time.
Your rights: For the rights you have over your data and how to request access or erasure, see the article "Your GDPR rights: access and erasure" as well as the privacy policy.