
passify App / passify Web Applications – Version 1.0.7 dated 21 August 2026
passify GmbH, St. Annenufer 2, 20457 Hamburg (“passify”, “we”, “us”), ensures compliance with statutory requirements and internal company policies in connection with the passify app. Accordingly, pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR), we would like to inform you about the collection, processing and use of personal data in connection with the use of our applications (the passify app and the passify web applications). We process personal data only in accordance with applicable statutory and data protection requirements, in particular those arising from the GDPR and the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG).
Passify has set itself the goal – combined in a single solution – of simplifying your everyday working life while increasing the safety and security of our contractual partners (operators of logistics sites). In doing so, we focus on an efficient user experience as well as the protection of your data, which is extremely important to us.
Passify has taken extensive data security measures to protect your data. Compliance with applicable data protection mechanisms is a matter of course for us.
We process, store and share only the information and data with our partners that is required for the provision of our services.
These notices apply to the processing of personal data in the passify app and the passify web applications.
The controller responsible for the processing of your personal data in connection with the registration, provision and use of the passify app, the passify Trucking Company Portal, and general user and account management is, in principle,
passify GmbH, St. Annenufer 2, 20457 Hamburg
Our Data Protection Officer can be reached for all questions relating to data protection at the following email address: datenschutz@passifyapp.de.
passify processes personal data under its own data protection responsibility to the extent this is necessary for establishing, performing and managing the user relationship with you or your company. This concerns, in particular, the setting up and administration of user accounts, authentication, the management of roles and permissions within the web portal, the technical provision of the platform, our own communication with users, the handling of support requests, IT security, and the fulfilment of passify’s own legal and contractual obligations.
Insofar as you apply for access to a specific logistics site via passify, use site-specific permissions, go through site-specific check-in, access-token or slot processes, or where corresponding site-specific information is transmitted to the relevant logistics site operator, the respective logistics site operator is instead the controller responsible under data protection law. In these cases, passify processes the relevant personal data as a processor for the respective competent logistics site operator, exclusively on that operator’s instructions and for the purposes determined by the logistics site operator.
Which logistics site operator is responsible in a given case depends on the logistics site to which you are applying for access or whose services you use via passify. The identity and contact details of the respective competent logistics site operator are generally apparent from the specific booking, check-in or access process within the app or the relevant portal. If you have any questions in this regard, you may contact passify at any time.
A special rule applies to the messaging function (Section 3.8). The respective logistics site operator is responsible under data protection law for the occasion, content and further use of messages sent via this function. Passify processes the message content as a processor on the instructions of the respective logistics site. By contrast, passify processes, under its own data protection responsibility, the data required for the technical provision and security of the communication channel as well as for the storage described in Section 3.8 for the purposes of preventing misuse and preserving evidence. For questions regarding the occasion, content and further use of messages, please contact the respective logistics site operator.
The following categories of personal data may be processed by us in connection with our services:
Purposes of Processing
In order to download and install our app from an app store (e.g. Google Play Store or Apple App Store), you must first register for a user account with the app store provider and enter into a corresponding user agreement with that provider. We have no influence over this and, in particular, are not a party to any such user agreement. When downloading and installing the app, the information required for this purpose is transmitted to the relevant app store, in particular your username, your email address and the customer number of your account, the time of the download, and the individual device identifier. We have no influence over this data collection and are not responsible for it. We process the data provided to us only insofar as this is necessary for downloading and installing the app on your mobile device (e.g. smartphone, tablet).
As a registered and verified user, provided you hold the relevant permission (e.g. a transport order), you may gain access to logistics sites (e.g. terminals) via digital mechanisms, enter the premises, and, where applicable, carry out further actions before or after entry (e.g. slot booking).
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
Processing of the data is necessary for the performance of the contract (provision and use of the app).
Purposes of Processing
In order to obtain the status of a registered and verified user and thereby have the option of using passify’s services, including (and possibly) the services of operators of logistics sites (e.g. terminals), you must create a passify account within the app (“registration”).
An email address and phone number are mandatory for registration. This data is stored in the user account. In addition, you will be asked to specify the trucking company for which you work, whereby you may select “not specified”.
Registration with the above-mentioned data already provides limited access to functionalities of the passify app and allows you to get an impression of the app’s “look and feel”.
Upon registration, we check whether registrations already exist using the registration information provided (email address and phone number).
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
Processing of the data is necessary for the performance of the contract (provision and use of the app) and enables users to gain a limited overview of the app at an early stage. It also enables us to ensure that multiple registrations by users are avoided.
Purposes of Processing
In order to be able to use the essential functionalities of the passify app (e.g. entering logistics sites), we verify your identity within the passify app using an app-based identification procedure provided by the external service provider IDnow. For this purpose, (parts of) your core data and contract data (identity document and photo/selfie) are processed, as well as, within the app-based identification procedure, special categories of data (biometric data) on account of the comparison of photos/selfies with the person concerned. We use a multi-stage procedure consisting of a check of the person and a check of the identity documents.
The verification and processing of the biometric information takes place at the external service provider IDnow. The service is merely integrated into the passify app. Passify has no direct access to your biometric data at any time. This data is, in principle, processed by the service provider IDnow.
Verification process:
In order to be able to use the essential functionalities of passify, you will be asked in the app to verify your identity.
Verification is started via a button in the app labelled “Verify ID”. You are then taken to the verification environment of the service provider IDnow; by clicking the “Verify ID” button, you give your voluntary consent to the processing of your personal data for the purpose of validating your identity. (Note: you may withdraw the consent given at any time with effect for the future. In the event of withdrawal, the app can no longer be used to its full extent.)
Before starting the verification, you have the opportunity to review IDnow’s terms of service (https://go.idnow.de/terms/de) and privacy policy (https://go.idnow.de/privacy/de).
To continue with the verification, you confirm, by ticking a checkbox, that you agree to IDnow’s terms of service and have read IDnow’s privacy policy.
If this has not already been done, you will then be asked via a pop-up for permission to access the camera; this permission is mandatory for the verification.
The verification process then begins.
As part of the check of the person, a photo/selfie must be taken within the app. During the so-called “liveness” check – which may be applied, where relevant – a short video is recorded in which you, for example, move your head slightly from side to side to show that you are actually present in front of the device. In both cases, the check of the identity document includes a check of security features (e.g. holograms) in order to rule out the use of forged documents. Successful verification is only possible with a valid, non-expired identity document.
To ensure that you use only one validated passify account, following successful verification as part of the registration we check our user database to determine whether a user account already exists in relation to the registration information (consisting of parts of the core, communication and contract data). We further compare the surname and first name provided at initial registration with the information on the identity document to check whether the information matches (a high degree of correspondence is required).
Following successful verification, relevant data (name, first name, date of birth, issuing authority, nationality, nation of the document) is stored in your passify user account. Where applicable, your surname and first name will be automatically adjusted to match the information stated on the identity document.
The data processed for verification purposes (name, first name, date of birth, document number, type of identity document, issuing authority, validity period of the identity document), as well as the copy of your identity document and your selfie, are, in principle, deleted by the external service provider after verification has been completed, and at the latest after 30 days. Passify itself never stores a copy of your identity document, your selfie, or any biometric data.
Note: verification is valid for one year. At the latest upon expiry of this validity period – but possibly also earlier, on a random and spot-check basis – passify carries out re-verifications using the external service provider’s app-based identification procedure in order to safeguard and further enhance the security of the system as well as the currency, accuracy and protection of the data.
Legal basis for the above processing: Art. 9(2) lit. a) in conjunction with Art. 6(1) sentence 1 lit. a), Art. 7 GDPR. The processing of your biometric data as part of the identification procedure is based on your explicit and voluntary consent. You may withdraw this consent at any time with effect for the future. Following withdrawal, the functions based on the identification procedure will no longer be available. The lawfulness of any processing carried out prior to withdrawal remains unaffected.
Art. 6(1) sentence 1 lit. f) GDPR. Comparing your registration information against existing user accounts, as well as comparing the name provided at registration with the information on the identity document, is based on our legitimate interest in preventing fraudulent multiple registrations and ensuring the accuracy of the data held in the user account. No biometric data is processed for these comparisons.
Art. 6(1) sentence 1 lit. f) GDPR – re-verification. Periodic re-verification following expiry of the validity period, as well as unprompted, spot-check re-verifications, are based on our legitimate interest and the legitimate interest of the logistics site operators in the currency and accuracy of identity data and in preventing the transfer of user accounts to third parties. The processing of your biometric data as part of re-verification continues to take place exclusively on the basis of your consent.
Purposes of Processing
Access to the passify app following successful registration includes password protection or the use of authentication methods provided by your device (“Face ID” or other individual features based on information stored on the device). In order to use certain functionality within the passify app (e.g. terminal access, hereinafter “Gate Access”), successful authentication of this kind is mandatory. For this purpose, passify uses the service provided by your device. At no point are any features or data relating to these authentication methods themselves processed by passify, stored by passify, or transmitted to passify. Passify merely receives the information as to whether authentication was successful or not.
To enable authentication, the relevant permission must be granted. This permission can be managed in the app’s permission settings. Further information on this can be found under “Permissions Requested”.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR. Processing is necessary for the performance of the user agreement, as securing access to your user account forms part of the contractually owed service.
Art. 6(1) sentence 1 lit. f) GDPR. In addition, processing is based on our legitimate interest in the security of our systems and in preventing unauthorised access to user accounts.
For the purpose of secure identity management and to ensure efficient access control at logistics sites, we process biometric data as part of the use of the app.
This takes place in two steps:
Initial identity determination: comparison of an official identity document with a live image of the user (video-ident or auto-ident procedure).
Authentication (check-in): a further comparison of the user, either on site or at app login, to verify their access authorisation.
Technical functioning: the system operates on the principle of data minimisation and “privacy by design”. When capturing the user’s face, the image material is not permanently stored as raw data (a photo) for comparison purposes. Instead, an algorithm extracts specific features of the facial geometry and immediately converts them into a mathematical string (hash value / biometric template). This hash value is encrypted and designed such that it is technically impossible to reconstruct the original facial image from it. The comparison is carried out exclusively by comparing these mathematical representations. The processing and storage of this reference data takes place on secure servers of our processor IDnow within the European Union.
Legal Bases for the Processing
The processing of this data is based on several legal bases, depending on the specific context of use and the controller(s) involved:
Art. 9(2) lit. a) in conjunction with Art. 6(1) sentence 1 lit. a), Art. 7 GDPR. The processing of your biometric data as part of the identification procedure is based on your explicit and voluntary consent. You may withdraw this consent at any time with effect for the future. Following withdrawal, the functions based on the identification procedure will no longer be available. The lawfulness of any processing carried out prior to withdrawal remains unaffected.
Art. 6(1) sentence 1 lit. f) GDPR. Comparing your registration information against existing user accounts, as well as comparing the name provided at registration with the information on the identity document, is based on our legitimate interest in preventing fraudulent multiple registrations and ensuring the accuracy of the data held in the user account. No biometric data is processed for these comparisons.
Art. 6(1) sentence 1 lit. f) GDPR – re-verification. Periodic re-verification following expiry of the one-year validity period, as well as unprompted, spot-check re-verifications, are based on our legitimate interest and the legitimate interest of the logistics site operators in the currency and accuracy of identity data and in preventing the transfer of user accounts to third parties. The processing of your biometric data as part of re-verification continues to take place exclusively on the basis of your consent.
Fulfilment of the site operators’ legal obligations (Art. 6(1) sentence 1 lit. c) GDPR). Insofar as biometric validation is mandatory for access to certain security areas (e.g. ISPS-certified port terminals, customs areas or hazardous goods warehouses), the processing serves to support the relevant terminal and site operators in fulfilling their statutory protection and control obligations. In this context, the app functions as a technical tool for ensuring the personal identification required by law.
Purposes of Processing
Where the relevant permission exists (e.g. a collection order for a particular terminal) and provided that a validated identity is involved, the Gate Access function may be used. It is important for Gate Access that your current vehicle registration number is stored. This is necessary for the performance of the contract, as it allows a check as to whether the driver is in the correct lane and whether the vehicle registration number matches the order data transmitted to passify by the terminal operator, thereby enabling the vehicle and the order to be matched.
In addition, when the Gate Access function is triggered, the current location of the device is checked in order to display the nearest logistics site and to ensure that the device – and thus the authorised driver – is in the immediate vicinity of the logistics site for which Gate Access is being requested. This ensures faster and more efficient processing and increases security, as it prevents the gate/barrier from being opened remotely.
To compare the information in the operating system of the logistics site operator (e.g. terminal), the pseudonymised Trucker ID and the previously provided vehicle registration number are transmitted to the logistics site operator (e.g. terminal). In doing so, entry and exit times are stored by passify for the purpose of logging entries and exits. The association between Trucker ID and vehicle registration number is deleted after 12 hours.
During your stay at the logistics site (checked-in status), your location is collected and stored after every on-site interaction in order to increase security on the premises and to prevent entry into prohibited areas.
Note: in order to enter a logistics site at all, you must accept the site-specific safety instructions for the relevant logistics site (provided individually by the operator for each site) by pressing a button within the passify app. Acceptance of the safety instructions must be repeated at regular intervals, as determined individually by the operator (validity period of the acceptance), or following any amendment thereto, and this is documented within the system. Once the safety instructions have been accepted, and for as long as this remains valid, your Trucker ID as well as your surname and first name will be listed in the “driver list” of the relevant terminal.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
Processing of the data is necessary for the performance of the contract (provision and use of the app), in order to increase security for operators of logistics sites (e.g. terminals) and to protect potentially critical infrastructure from criminal acts.
Art. 6(1) sentence 1 lit. f) GDPR. The recurring collection of location data during your stay at the logistics site is based on the legitimate interest of the relevant site operator in the safety and security of the premises and the persons present there, as well as in the protection of critical infrastructure.
Standard Slot Booking / Transport Pre-Notification
In order to book a slot for the processing of orders at logistics sites, the trucker registers at the relevant point in the processing procedure via passify with the slot booking tool, or uses the slot booking function within the passify app, provided this has been set up and enabled at the relevant logistics site. As part of the slot booking, the Trucker ID as well as the surname and first name of the trucker are transmitted by passify to the logistics site operator.
Special Case: “Fuel Station Slot Booking”
Via passify, authorised and verified truckers from enabled trucking companies are able to book slots for certain refuelling processes (e.g. at hydrogen fuel stations) via the passify app. Depending on the relevant contractual partner or fuel station operator, entering a fuel card number may be required as part of the booking process. As part of the booking, billing-relevant information (time slot, fuel card number where applicable, trucking company together with its address) may be transmitted to the fuel station operator.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
Processing of the data is necessary for the performance of the contract (provision and use of the app). The aim is to provide the slot booking and transport pre-notification function in order to manage delivery and collection processes at the terminal.
Controllership
The respective logistics site operator is responsible under data protection law for the occasion, content and further use of messages sent via the messaging function (see Section 1). Passify provides the communication channel on a technical level and processes the data referred to above under its own responsibility, insofar as this is necessary for the operation, security and misuse prevention of this channel.
Purposes of Processing
The messaging function enables direct communication between terminals and the relevant trucker. The messaging function serves to ensure the safety and security of the logistics site and of the persons present there. In addition, important notices and information regarding processing procedures (slot booking, processing at the logistics site) are communicated in order to make the process at the terminal more transparent, to speed it up, and to draw attention to compliance with regulations.
The messaging function is available to truckers who have accepted the terms and conditions of the relevant logistics site. Once these terms and conditions cease to apply, the operator’s ability to contact you via the messaging function also ends. The rules governing the duration of validity are determined by the site operator itself, and corresponding information should be obtained directly from the site operator.
Communication can only be initiated by the operator of the logistics site. This gives the operator the ability to contact a trucker directly and personally via the passify app. The trucker is free to respond to a received message. There is never any obligation to respond. In addition to a text message, a voice note is also available as a means of reply. This serves to clarify the relevant matter as quickly as possible and is intended to enable efficient and straightforward communication in order to best ensure safety and security.
As part of the messaging function, the Trucker ID is transmitted to the operator of the logistics site. The operator can identify you on the basis of this identifier together with the information already available to it from the slot booking, transport pre-notification and check-in processes.
Use of the messaging function by the client (Auftraggeber) is permitted exclusively for communications that are directly connected with a current, upcoming or past stay by a trucker at their logistics site, provided that this still gives rise to queries or to the need to clarify the relevant processing procedure. The client’s ability to contact a trucker in relation to a past stay ends, at the latest, upon expiry of the storage period described below for the communications relating to that stay. Use for any other purpose, in particular for advertising purposes or for general communication outside the aforementioned context, is not permitted for the client.
All messages exchanged via the messaging function are stored for a period of 90 days from the date of sending. This storage serves to preserve evidence in the event that the messaging function is used contrary to the purpose limitation described above – for example, in the case of impermissible, harassing or criminally relevant communications. It enables both parties to subsequently prove such an occurrence. Both the trucker and the logistics site operator may extend this period once by a further 90 days, so that storage lasts for a maximum of 180 days from the date of sending. The extension may be initiated unilaterally, without the other party’s consent, up until expiry of the original period. The relevant communication partner is notified of this within the messaging function. To enable communication to take place in your preferred language, we engage a service provider as a processor for the translation of message content (see Section 5). Only the message text itself is transmitted to this service provider – not your name, your Trucker ID, or any other core data. However, the transmitted text itself may contain personal data, insofar as such information is included in the message text. The service provider uses the content exclusively to carry out the translation on our behalf, and in particular not for its own purposes and not to train models; no storage takes place beyond the duration of the processing. Please do not include in messages any information that is not necessary for the relevant occasion. Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
The provision of the messaging function serves to perform the user agreement concluded between you (the user) and us (the app operator). The aim is to provide you with a simplified communication channel in order to ensure the safety and security of the logistics site and of the persons present there, and to make processing procedures more transparent and efficient.
Art. 6(1) sentence 1 lit. f) GDPR
The transmission and processing of the message content itself is based on legitimate interests. The legitimate interest of the relevant logistics site operator lies in ensuring the safety and security of the site, the facilities located there and the persons present there, as well as in managing processing procedures efficiently and in compliance with applicable rules. Our own legitimate interest lies in providing a functional communication channel that is secure against misuse. The storage of messages for 90 or 180 days is based on our legitimate interest as well as the legitimate interest of the logistics site operators in preventing, and preserving evidence of, legal violations and criminal offences in connection with the use of the messaging function.
Purposes of Processing
In the event of a breach of applicable law, of a logistics site operator’s terms and conditions, or of that operator’s safety instructions, the relevant operator may record a note to that effect. Such a note may be associated with a temporary or permanent restriction of your access to that site, or with a restriction on the use of the passify app.
The note is recorded in a free-text field by the operator of the logistics site. The relevant operator is responsible for the content and accuracy of the note. passify has no access to the content of such notes; the information is stored in encrypted form. Separate information regarding suspensions can be found within the app.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. f) GDPR
The legitimate interest in storing violations that lead to a (temporary) suspension of user accounts is justifiably held by the operators of logistics sites in taking measures for building and facility security, measures for business management, and measures to prevent criminal offences.
Purposes of Processing
In order to make full use of the passify app or connected services, and to enable an efficient processing procedure for you, certain actions or functions within the passify app or connected services are subject to a fee. Payments are processed via the external payment service provider Stripe.
Acquiring a “passify PassKey” Licence
For certain actions or functions (e.g. Gate Access, slot booking), the acquisition of a passify PassKey (a usage licence for ISPS facilities) is required. This can be acquired via the passify app by truckers themselves, or via the “passify Trucking Company Portal” by trucking companies on behalf of the truckers assigned to that trucking company.
Once a passify PassKey has been acquired, it is assigned to the relevant trucker, and all functions requiring the passify PassKey are automatically activated as a result.
Note regarding data received from the payment service provider:
Following successful payment processing, passify receives the following information from the payment service provider for further processing and invoicing: invoice recipient, invoice address, tax ID where applicable (if provided during the payment process), and the scope of services purchased/booked, which is processed in part on a fully automated basis and allocated to the relevant users (trucker or trucking company).
Further information on Stripe can be found under “Categories of Recipients”.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
Purposes of Processing
A dedicated “passify Trucking Company Portal” (hereinafter the “web portal”) is available for trucking companies. This is initially set up by passify at the initiative of a trucking company. The trucking company provides passify with the desired email address as well as the first and last name of the administrator. Following setup, a confirmation email is sent to that email address. Before first using the web portal, each user must review the privacy notices and accept the terms and conditions. The user may then set a self-created password. Further users can be created and modified within the web portal by the administrator.
All users of a trucking company’s web portal can view the other users of that trucking company, including their role (admin or user).
Companies have the option of synchronising their company with Secure Release Order providers offered within passify (e.g. German Ports Release Order). If this is done, passify uses the VAT ID stored for the company to make a request to the Secure Release Order provider and receives the corresponding company IDs held by that provider. These are stored against the company within passify. The connection can be revoked in the portal at any time.
Once a trucking company has registered in the web portal, truckers are able to associate themselves with that trucking company. A connection between an app user’s (trucker’s) profile and a trucking company is never established automatically, but always requires active interaction (a “handshake procedure”). This takes place in two ways:
Initiated by the driver: the trucker selects a company in the app and sends a request. The company must confirm this within the web portal.
Initiated by the company: the company sends a request using the Trucker ID. The trucker must actively accept this request in their app.
The association only takes effect once this mutual confirmation process has been completed. A trucker can dissolve the association via the app at any time; the company can end the association via the portal. Once the association has been dissolved, the company no longer has access to the driver’s current data.
Truckers may change their trucking company or delete the association at any time. From the point at which an association is changed or deleted, the trucker will no longer be listed on the (former) trucking company’s list.
Trucking companies are able, via the web portal, to book or acquire the passify PassKey (a licence to enter ISPS facilities) or further services for individual truckers or jointly for several truckers assigned to that trucking company.
Both the use of the web portal by trucking companies and the association of a trucker with a trucking company take place exclusively on a voluntary basis and are neither required nor a precondition for use of the passify app.
Trucking companies are furthermore able to view slot bookings made by their associated drivers, as well as to assign slot bookings to their associated drivers themselves.
The following trucker information may be viewed by trucking companies within the web portal: Trucker ID, surname, first name, email address, company status (confirmed / pending), passify status (unblocked / not unblocked), restriction list (e.g. access restrictions for certain areas), PassKey (held / not held), booked slots (including slot booking information).
In return, upon successful connection, the corresponding IDs held for the company by Secure Release Order providers are added to the driver’s user account. Once the association between driver and company is ended, these IDs are immediately removed from the driver’s user profile again.
Legal basis for the above processing
Performance of the contract with the trucking company and its users (Art. 6(1) sentence 1 lit. b) GDPR)
The processing of data relating to administrators and dispatchers, as well as the provision of the platform infrastructure, takes place in order to perform the user agreement (terms and conditions for trucking companies) in respect of the web portal.
Performance of the contract with the app user/trucker (Art. 6(1) sentence 1 lit. b) GDPR)
The transmission of the above-mentioned data to the trucking company, and the receipt of bookings (PassKeys, slots) by the company, take place on the basis of the app’s user agreement. By selecting the “link company” function and confirming the request, the user (trucker) instructs us, within the scope of the app’s functionality, to make the data relevant for dispatching purposes available to the selected employer/client, in order to take advantage of benefits such as centralised payment of fees or slot planning by the dispatcher.
When accessing our app, we process data sent by your device in order to enable use of the app. This is a technically necessary process in the course of which data is transmitted. In the event of malfunctions, the data is used for error analysis and rectification, in order to optimise the app. For this purpose, the data (database ID and operating system version) is stored for a limited time in so-called protocols or log files, until the data has been fully anonymised. Anonymisation means that the data is altered in such a way that information relating to an identified or identifiable individual can no longer be attributed to that individual, or can only be attributed with a disproportionate amount of time, cost and effort.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. b) GDPR
Processing of the data is necessary for the performance of the contract (provision and use of the app), in order to keep our app available (i.e. stable and secure), to optimise and further develop it, and thereby to offer our customers the best possible service and increase customer satisfaction.
To improve our customer service and enable direct communication with users, we offer a support chat within our app. Use of our chat service is entirely voluntary.
By using the chat, you consent to the data transmitted through use of the chat service being used by passify GmbH to answer questions, to improve the response behaviour of the pre-connected chatbot, to optimise product functions, and for error rectification. When accessing the support chat, we process technical data, such as, for example, the device name of your device. This data is used, in the event of malfunctions or disruptions to the app or web applications, for troubleshooting, identification and the subsequent rectification of errors. For downstream troubleshooting and to establish a connection between device-specific technical information and error patterns, it is necessary to store the data for 12 months. Support messages and user data are automatically deleted after 12 months of inactivity. Personal data provided within the chat (e.g. where you enter your name) is processed with your consent to the data processing. If you enter personal data into the chat (e.g. your name, your date of birth, etc.), and if conclusions can be drawn from this information regarding your state of health, your gender, your sexual orientation and/or your ethnic origin, your consent also extends to this information.
Legal basis for the above processing
Art. 6(1) sentence 1 lit. a) GDPR
The processing of your personal data is based on your voluntary consent. By using the support chat, you consent to the data you provide (e.g. name, email address, device information, communication content) being processed and stored for the purpose of handling your enquiry and improving our support and the quality control of the product.
For some functions, the app must be able to access certain services and data on your mobile device. Below, we explain which permissions the app may request and for which types of functions these permissions are required on the various operating systems.
You can manage permissions at any time via your operating system, i.e. view, activate and deactivate them. To do so, on iOS you can open the “Settings” app. In the following menu, you will find an overview of all apps installed on your device. Select the passify app there and manage your permissions. On Android, you can likewise open the “Settings” app and select the “Apps” menu item. In the following menu, you will find an overview of all apps installed on your device. Select the passify app there and manage your permissions. The exact labels may differ slightly depending on the iOS or Android version used.
Please note that deactivating/refusing certain permissions may result in functional limitations within the passify app.
Logistics Site Operators
A contractual relationship exists with the respective logistics site operators to which you apply (or may apply) for access, under which we act as a processor for the logistics site operator. As processor for the logistics site operators, we are subject to confidentiality obligations and are contractually required to transmit your personal data only for the purposes intended and to uphold data protection vis-à-vis the relevant operators.
Service Providers / Processors
To process your data, we in part engage specialised service providers who in turn act on our behalf (e.g. IT service providers, hosting providers, data centres, payroll service providers, etc.). Our service providers are carefully selected by us and regularly monitored. They process personal data only on our instructions and strictly in accordance with our directions, on the basis of corresponding data processing agreements. Data passed on may only be processed by the relevant processor on the basis of agreements pursuant to Art. 28(3) sentence 1 GDPR. Processors are subject to confidentiality obligations and are contractually required to uphold data protection through the data processing agreement.
IDnow (Identification Service Provider)
To fulfil statutory requirements and, in particular, to support our contractual partners, the operators of logistics sites, in meeting requirements under the ISPS Code, we use a digital and certified procedure for identifying and authenticating our users. We use the service provider IDnow (IDnow GmbH, Auenstr. 100, 80469 Munich, Germany). A data processing relationship exists between passify and IDnow. As processor, IDnow is subject to confidentiality obligations and is contractually required to uphold data protection through the data processing agreement. IDnow’s procedures are certified by independent bodies and thereby offer a particularly high level of security and reliability. For the purpose of identifying our users, passify only stores the personal data transmitted by IDnow that is absolutely necessary for unambiguous identification (name, first name, date of birth, issuing authority). Passify has no direct access to this data. IDnow deletes all personal data after a maximum of 30 days. For the authentication process, our service provider stores an encrypted and non-reversible mathematical representation which, although based on a biometric analysis, does not itself contain any biometric data. This representation is deleted without delay as soon as the user account is closed or the function is deactivated (e.g. through withdrawal of consent).
Trucking Companies
On a voluntary basis, a trucker may associate themselves with a registered trucking company. The association can be deleted at any time, either by the trucking company or by the trucker. For as long as the association exists, the relevant trucker is listed on the driver list within the web portal. Only the information required to enable the trucking company to uniquely identify/verify the trucker, and which is necessary for functions within the trucking company’s web portal, is stored and processed.
The following information may be viewed by trucking companies within the web portal: Trucker ID, surname, first name, email address, company status (confirmed / pending), passify status (unblocked / not unblocked), restriction list (e.g. access restrictions for certain areas), GoKey (held / not held), booked slots (including slot booking information).
Payment Service Provider
We use an external payment service provider, via whose platform users (truckers and/or trucking companies) and we can carry out payment transactions, including the purchase and payment processing of the passify GoKey. The provider of these payment services is Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). Stripe processes your payment data as an independent controller, not as our processor. We have no influence over the design of this processing. When paying via Stripe, the payment data you enter is transmitted to Stripe. You have the option of choosing from among the payment methods provided by Stripe. Personal data exchanged between Stripe and the controller may be transmitted by Stripe to credit reporting agencies. The purpose of this transmission is identity and creditworthiness verification. Stripe may pass on personal data to affiliated companies and service providers or sub-processors where this is necessary to fulfil contractual obligations, or where the data is to be or must be processed on Stripe’s behalf. You may object to this processing of your data at any time by sending a message to Stripe or to the credit reporting agencies engaged by it. However, Stripe may nevertheless remain entitled to process your personal data where this is necessary for contractual payment processing. Stripe is responsible for the processing of the data. Further information on data processing and the applicable data protection provisions of Stripe can be found at https://stripe.com/de/privacy.
WhatsApp (Community Channel)
Within our mobile app, we offer you the opportunity to join an external WhatsApp channel (broadcast channel). Through this channel, we provide you with voluntary surveys in order to continuously improve the quality of our app and to gauge the satisfaction of our users.
Participation is entirely voluntary. By actively joining the WhatsApp channel, your action is treated as consent pursuant to Art. 6(1) lit. a GDPR. You may withdraw this consent at any time with effect for the future by leaving the channel again. Participation in the WhatsApp channel is not a prerequisite for using our app.
When you join our WhatsApp channel, WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, processes certain personal data as an independent provider, including:
We have configured the WhatsApp channel such that no comments or replies to channel posts are possible, no personal survey responses are collected via WhatsApp itself, and communication only takes place in one direction (a purely informational channel). Data storage period: all personal data is deleted after 30 days at the latest.
WhatsApp stores the above-mentioned data in accordance with its own policies, generally for the duration of your account or channel membership, but according to its privacy policy may also process it beyond that period for its own purposes (e.g. to improve its services, for security purposes, or to comply with legal obligations). A transfer of data to third countries (e.g. the USA) cannot be ruled out.
Further information on data processing by WhatsApp can be found in WhatsApp’s privacy policy (https://www.whatsapp.com/legal/privacy-policy-ee)
We do not process any personal data of yours in connection with the WhatsApp channel. Any surveys are designed to be data-minimising and structured such that no conclusions can be drawn about individual persons. Your responses are collected anonymously, or – where technically necessary – pseudonymously, and used exclusively for internal evaluation and improvement purposes.
Secure Release Order Providers (including German Ports Release Order)
As a result of the introduction of secure release procedures at logistics sites, passify takes on the role of identity provider for some terminals in the context of secure release processes. This requires companies to synchronise their passify profile with Secure Release Order providers. This takes place at the initiative of a user of the company portal. As part of the synchronisation, the company’s VAT ID is used to check, via the interfaces of the Secure Release Order providers, whether an account is held there for the company. The account IDs are then stored against the company within passify. The connection can be revoked at any time.
Translation Service Provider (Google Translate)
To provide the translation function within the messaging function, we engage Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (or Google LLC) as a processor. The content of messages exchanged via the messaging function is transmitted to Google for the purpose of automatic translation (Google Cloud Translation API). A data processing agreement pursuant to Art. 28 GDPR is in place with Google. Voice messages are excluded from translation.
Notification Services
For the delivery of push notifications on mobile devices, as well as for the delivery of browser notifications when using the web portal, we use the notification services of Firebase Cloud Messaging, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (or Google LLC). Processing in the USA cannot be ruled out in this context.
Other
In addition, further statutory obligations to transmit data may arise in individual cases; however, these do not arise generally, but only in specific individual cases. This also includes cooperation with investigating authorities and the disclosure of data in this context, in compliance with data protection law. Data processing generally takes place within the EU/EEA. Processing of data outside the EU/EEA is permitted subject to the requirements of Art. 44 et seq. GDPR. In the course of the further development of our business, we may change the structure of our company through a change of legal form, or the establishment, purchase or sale of subsidiaries, departments or components. In connection with such transactions, customer data may be transferred together with the relevant part of the company being transferred. Where we disclose personal data to third parties to the extent described above, we ensure that this takes place in accordance with this privacy notice and applicable data protection law.
In principle, we process your data only until the purposes for which the data was collected have been fulfilled. Thereafter, your data is deleted or anonymised, unless processing or storage of your data is necessary for the assertion, exercise or defence of legal claims. In the case of statutory retention obligations, deletion or anonymisation is only considered once the relevant retention obligation has expired. Until deletion or anonymisation, the data is retained in a restricted (blocked) form.
Access Logging (Log Files, Technical Data)
IDnow (External Service Provider)
Other Activity Data
User Account (Inactive)
Restriction Notes and Access Restrictions
Request for Deletion of the User Account
Billing-Relevant Data
Technical Data
Message and Communication Data from the Messaging Function:
Data from Notification Functions (Push Notifications and Browser Notifications)
We receive part of your data not from you directly, but from the following sources:
The following rights are available to you under applicable data protection law:
You also have the right to lodge a complaint with a data protection supervisory authority, in particular with a supervisory authority in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. For Hamburg, the competent supervisory authority is the Hamburg Commissioner for Data Protection and Freedom of Information of the Free and Hanseatic City of Hamburg, Ludwig-Erhard-Straße 22, 20459 Hamburg, email: mail-box@datenschutz.hamburg.de
If you wish to exercise your rights, please direct your request to:
passify GmbH, St. Annenufer 2, 20457 Hamburg, or to the email address: datenschutz@passifyapp.de
Automated Decision-Making
No decision based exclusively on automated processing, including profiling within the meaning of Art. 22 GDPR, takes place.