Privacy Policy
Applies to DocAccord / LC Clear at docaccord.com, docaccord.de, lcclear.com and lcclear.de. Last updated: August 2026.
This page is also available in German (language switcher, top right). Other languages fall back to this English version; German remains the legally authoritative text.
1. Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Truvest Capital Market GmbH, Mottmannstr. 1-3, 53842 Troisdorf, Germany
Managing Director: Albert Rempel
Phone: +49 (2241) 3283999, Email: info@truvest.de
Commercial Register: HRB 15784, District Court Siegburg
VAT ID: DE328403733, LEI: 98450088887BF68H7C56
2. General Information
This Privacy Policy complies with the requirements of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telemedia Act (TMG).
Important note: DocAccord / LC Clear serves business customers exclusively (B2B). Registration requires a business email address; we do not offer our services to consumers.
3. Data Collection When Using the Application
3.1 Server Log Files
On every visit, our hosting provider automatically collects technical data (IP address, date/time of the request, page accessed, browser type, referrer URL). Purpose: secure and stable operation, abuse and fraud prevention (including rate limiting on login attempts). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security).
3.2 Registration and User Account
A user account is required to use the service. We collect: business email address, company name, password (stored only as a bcrypt hash), and the time you accepted our Terms of Service. When signing in via Google or Apple (OAuth), we additionally receive the email address transmitted by those services. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
3.3 Document Checking (Core Function)
The content of documents you upload or enter is transmitted to Anthropic PBC (San Francisco, USA; provider of the "Claude" AI models) for automated analysis, solely for the purpose of the check you requested against UCP 600 / ISBP 745. We do not permanently store the document content ourselves in our database. Only metadata about the check is stored permanently: timestamp, L/C reference number (if provided), overall result, and the number of errors and warnings found - for billing and the usage overview in your account. Legal basis: Art. 6(1)(b) GDPR.
The check result is an automated decision-support tool within the meaning of Art. 22 GDPR, but it does not make any legally binding decision for you and does not replace the independent examination by the bank.
4. Cookies and Tracking
This application does not use cookies or third-party tracking technologies. We do not employ analytics tools such as Google Analytics, Facebook Pixel, or similar. For sign-in, we store a session token and your language preference in your browser's local storage; this data is sent by your browser with every request to our servers to keep you signed in and remember your language choice. Should cookies be introduced in the future, you will be informed in advance and asked for your consent (Art. 6(1)(a) GDPR).
5. Disclosure of Data to Third Parties
Personal data is disclosed to third parties only where necessary for the performance of a contract (Art. 6(1)(b) GDPR), where there is a legal obligation (Art. 6(1)(c) GDPR), or where you have given your consent (Art. 6(1)(a) GDPR).
5.1 Hosting
This application is operated on servers of Hetzner Online GmbH (Germany). A data processing agreement (DPA) is in place with our hosting provider. Data transmission between your browser and our servers is encrypted (TLS/SSL).
5.2 Service Providers
- Anthropic PBC (USA) - AI-powered analysis of document content
- Paddle - payment processing for subscriptions and single checks, acting as its own controller (Merchant of Record)
- Resend - sending transactional emails (registration, password reset)
- Google LLC / Apple Inc. - only when you use the respective sign-in option (OAuth)
Data processing agreements or appropriate safeguards are in place with all processors.
6. International Data Transfers
Anthropic, Resend, Google, and Apple (also) process data in the USA. We ensure an adequate level of data protection through EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the respective provider's participation in the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR).
7. Your Rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection to processing (Art. 21 GDPR), and the right to withdraw any consent given at any time (Art. 7(3) GDPR). The right to erasure does not apply where statutory retention obligations (e.g. HGB, AO) apply.
To exercise these rights, an informal message to info@truvest.de is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR):
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Phone: +49 211 38424-0, Email: poststelle@ldi.nrw.de, Website: www.ldi.nrw.de
8. Data Security
We store passwords exclusively as bcrypt hashes. Sessions are secured via time-limited JWT tokens, which are immediately invalidated on a password change. Login and registration attempts are protected against automated attacks by rate limiting. Data transmission is encrypted (TLS/SSL).
9. Retention Period
We store account and usage data for as long as your account exists, plus statutory retention periods for billing-relevant documents (in particular § 257 HGB, § 147 AO: generally 6 or 10 years). Server log files are automatically deleted after 7 days. After your account is deleted, data that is no longer required is deleted or anonymized, unless a statutory retention obligation applies.
10. Minors
Our services are directed exclusively at business customers and not at persons under 18 years of age. We are not aware that we process personal data of minors; should we become aware of this, we will delete the relevant data immediately.
11. Changes to This Policy
We will update this Privacy Policy whenever changes to our data processing make this necessary (e.g. new service providers or features). The version published on this page at the time of your visit applies.
12. Privacy Contact
Truvest Capital Market GmbH, Attn: Management / Data Protection
Mottmannstr. 1-3, 53842 Troisdorf, Germany
Email: privacy@truvest.de, Phone: +49 (2241) 3283999
No internal Data Protection Officer has been appointed, as the statutory requirements for doing so (Art. 37 GDPR, § 38 BDSG) are not met. We will respond to your request as quickly as possible, and no later than within one month.