Legal
Privacy.
Last updated · September 15, 2026
This is a convenience translation of the German original. The German version is the legally binding one; where the two differ, the German text prevails.
This notice describes how REVERCE GmbH processes personal data when you use verstag (workspace accounts, image and video uploads, C2PA provenance verification, the derivative editor, signed exports and transactional e-mail).
Controller
REVERCE GmbH
Hofaue 35, 42103 Wuppertal, Germany
E-mail: hello@verstag.io
Processing on behalf of our customers
For the content and administrative data of a workspace — uploaded image and video files, the persons depicted in them, their metadata, the derivatives created from them, the membership, role and invitation data of the workspace and the associated verification and audit record — we are not the controller but the processor. The controller is the company operating the workspace. The basis is the Data Processing Agreement, which forms Appendix 1 to our terms.
If you are a data subject of such a workspace and wish to exercise your rights, please contact its operator. If your request reaches us directly, we forward it there.
We are ourselves the controller for the other processing described on this page, in particular for account, access and billing data, for error reports, and for the connection metadata of our technical operations.
What we process and why
We process personal data only where we have a legal basis under the GDPR, and in line with our legitimate interests in operating verstag and supporting our customers.
- Account and profile — sign-in and account data processed by our authentication system (e-mail address, the password secret in the form stored by the authentication provider, session and token records) as well as profile fields you enter, such as a display name. Purpose: performance of the contract with you as a registered user and securing access (Art. 6(1)(b); abuse prevention, Art. 6(1)(f) GDPR).
- Contract and billing — name, billing address, VAT identification number, and plan and payment data, processed through our payment provider. Purpose: performance of the contract and invoicing (Art. 6(1)(b) GDPR) and compliance with commercial- and tax-law retention duties (Art. 6(1)(c) GDPR in conjunction with § 257 HGB, § 147 AO).
- Workspaces, memberships and invitations — which workspaces you belong to, your role, and invitations you send or redeem (invitee’s e-mail address, invitation status, expiry). We process this data on behalf of the operator of the respective workspace (Art. 28 GDPR); the legal basis is determined by the operator as controller.
- Image and video uploads and provenance verification — the image and video files you upload, their metadata (file name, type, size, dimensions, and duration for video), the EXIF and XMP information embedded in the file — which, depending on the capture device, may contain location and device data as well as creator and editor information — and the provenance information extracted from embedded C2PA manifests during verification, which may include signature and certificate details and stated source types of the material. This processing takes place on behalf of the operator of your workspace (Art. 28 GDPR).
- Derivatives and signing — the derivative specifications you create (crop, format, labelling options), the rendered output files and the C2PA signature metadata attached to them (the workspace’s signing identity, time stamps, certificate serial numbers). This processing, too, takes place on behalf of the operator of your workspace (Art. 28 GDPR).
- Audit trail — we log signing, verification and download events (who triggered what, when, under which policy state) in order to provide the workspace with a verifiable provenance and compliance record, which is a core promise of the product. We keep the audit history on behalf of the operator of your workspace (Art. 28 GDPR).
- Transactional e-mail — invitations into a workspace are delivered on behalf of its operator (Art. 28 GDPR); messages concerning account security, such as password resets, are sent by us as controller (Art. 6(1)(b) GDPR).
- Technical operation — our hosting providers process connection metadata (IP addresses, time stamps, HTTPS artefacts) necessary to route requests, contain abuse and secure the service (legitimate interests, Art. 6(1)(f) GDPR). If an error occurs, we additionally capture an error report (the address called, technical information about the device, the identifier of the signed-in account) in order to detect and fix it (Art. 6(1)(f) GDPR).
verstag uses no analytics or marketing trackers. We do not sell personal data.
Processors and recipients
We use carefully selected service providers. Depending on how you use the product, data may be processed by:
- Supabase — authentication and the application database (accounts, workspaces, provenance records).
- Hetzner — server hosting and S3-compatible object storage for uploaded image and video files and rendered derivatives (EU data centres).
- Resend — delivery of transactional e-mail. No open or click tracking takes place: our e-mails contain no tracking pixel and links are not rewritten.
- Stripe — payment processing and invoicing for paid plans (name, billing address, VAT identification number and payment details). You enter payment details directly with Stripe; we store no card data.
- Bugsink — error reporting and operational monitoring. An error report may contain the address called, technical information about the device and the identifier of the signed-in account; your image and video files are not transmitted.
- Google Cloud KMS (region europe-west3, Frankfurt) — custody of the signing key. The service receives only the hash value to be signed, never your file.
- SSL.com — qualified time-stamping service under RFC 3161. It receives only a hash value of the signature in order to confirm the time of signing, never your file.
Verification and labelling of your files run fully automatically. No member of staff reviews them in normal operation, and there is no automated decision-making producing legal effects within the meaning of Art. 22 GDPR.
Transfers to third countries take place to the following extent: SSL.com processes in the United States and receives hash values only; for payments, Stripe Payments Europe transfers data to Stripe, Inc. in the United States; for Supabase, Resend and Google Cloud, the respective US parent company may access data processed in the EU in the course of operations and support. We base these transfers on the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914). You can obtain a copy of the clauses at hello@verstag.io; they are also published on EUR-Lex.
Storage and cookies
We use strictly necessary storage only (browser storage and cookies), to keep you signed in and to remember interface state such as the sidebar layout. No third-party or marketing cookies are used. Should this ever change, we will update this notice and obtain consent where required.
Retention
We retain personal data only for as long as necessary for the purposes set out above, for the duration of your account and workspace membership, and for statutory retention periods. Uploaded image and video files and rendered derivatives are subject to the workspace’s configurable retention policy: once the retention period expires, the binaries are permanently deleted, while the provenance and audit records are kept as evidence for as long as the workspace exists; after the end of the contract, their erasure follows clause 10 of the Data Processing Agreement. We store connection metadata and error reports only for as long as necessary for operations, security and troubleshooting.
Files you upload solely for verification, without adding them to your library, are stored temporarily for the duration of the check and deleted automatically no later than 12 hours after upload.
Your rights
Subject to applicable law, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. You may also lodge a complaint with a supervisory authority. You can reach us at hello@verstag.io.
Right to object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR — here: abuse prevention, technical operation and error reports. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Address your objection to hello@verstag.io.
Data protection officer
Jan Metz
HCP Consultants
E-mail: info@hcp-consultants.de
Telephone: +49 202 7484621