Legal
Privacy policy
Last updated: 6 October 2026
This privacy policy explains which personal data is processed when you use the FastDoc QES app for iOS and Android (Part A) and when you visit this website (Part B).
In short: the app works without an account, without our own servers and without tracking. Your documents, your PIN and your CAN never leave your phone. The only connection the app makes when signing is the certificate check (OCSP) with the issuer of your eHBA. Purchases are handled by Apple or Google. The website sets no cookies and uses no analytics.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
BrainWave Software GmbH
Heilig-Kreuz-Straße 24
86152 Augsburg
Germany
Represented by its Managing Director Eldo Devole
Commercial register: Local Court (Amtsgericht) Augsburg, HRB 39856
Email: [email protected]
For any question about data protection, or to exercise your rights, contact us at [email protected].
2. Part A: The FastDoc QES app
FastDoc QES uses your electronic health professional card (eHBA) to create qualified electronic signatures (QES) on PDF documents. The app is built so that we cannot see what you sign. All the data listed below stays on your device; nothing is sent to us.
| Data | Where it is processed | Sent to us |
|---|---|---|
| PDF documents | On your device; signed PDFs in the folder you choose | No |
| PIN.QES | Only in memory during signing; passed directly to your card and never stored | No |
| CAN, handwritten drawing, and the name, title, profession and certificate from your eHBA | Encrypted in the device's protected storage (iOS Keychain or Android Keystore) | No |
| Signing log (time, document checksum, certificate serial number, result) | File in the app's storage on your device | No |
| Trial signature counter, subscription status, time you accepted the terms, chosen output folder | App settings on your device | No |
| Certificate details for the validity check | Sent to your card's issuer (section 2.4) | No |
| Purchase and subscription data | With Apple or Google | No (transaction reports only, without payment data) |
2.1 No account, no servers of our own
Signing PDFs requires no registration, email address or password. Opening, signing and saving happen entirely on your device; the signing time also comes from your device's clock. There is no FastDoc server to which documents, logs or usage data are sent.
2.2 Documents
You open documents through your device's file picker or via "Open in …" from other apps. The app only gets access to the file you select; the operating system may place a copy in the app's temporary storage for this. The signed PDF is saved to the folder you set, or shared with the app you choose; sharing also creates a temporary copy. Temporary files stay inside the app's protected sandbox and are cleaned up by the operating system. If you choose a cloud storage service (e.g. iCloud Drive or Google Drive), that provider's terms apply; we get no access.
Documents may contain health data of patients (Art. 9 GDPR). Because they are processed exclusively on your device and under your control, we do not process this data. You, or your organisation, remain responsible for the documents, including where they are stored and with whom signed documents are shared.
2.3 eHBA, PIN, CAN and drawing
The app talks to your eHBA via NFC. You enter your PIN.QES in the app. It is held in memory only for the duration of the signing process, passed to the card only in encrypted form and then discarded; it is never stored and never logged.
The CAN (six digits printed on the card) secures the wireless link between card and phone. After the first successful connection the app stores it so you do not have to enter it for every signature. The app likewise stores your optional handwritten drawing for the stamp and the name, title, profession and certificate from your eHBA, to create the visible stamp. This data is kept encrypted in the operating system's protected storage (iOS Keychain or Android Keystore) and is not synced with iCloud.
A signature necessarily contains details from your qualified certificate (in particular your name and profession) and the time of signing. These are embedded in the PDF and shown as a visible stamp, with your drawing if you wish. That is the purpose of the signature and only happens when you sign.
The legal basis for this on-device processing is the performance of the app's terms of use (Art. 6(1)(b) GDPR).
2.4 Certificate check (OCSP)
Before every signature the app checks whether your certificate is still valid. Using the addresses stored in the certificate itself, it first downloads the issuer's public certificate from the trust service provider that issued your eHBA (e.g. D-Trust, medisign, SHC+Care or T-Systems) and then queries that provider's validation service (OCSP). Only data identifying your certificate (serial number and issuer hash values) is sent, together with, for technical reasons, your IP address and the time of the request. The document is never sent.
The response is embedded in the signature so it remains verifiable later. If the certificate is revoked or the service is unreachable, nothing is signed. The requests go directly from your device to the trust service provider, which processes them as an independent controller under its own privacy policy; we receive no information about them. The legal basis is Art. 6(1)(b) GDPR, as the check is required for a valid qualified signature.
2.5 Signing log and other app data
So that you can trace when you signed what, the app keeps a local signing log. For every signing attempt it records the time, the checksum (SHA-256) of the document, the serial number of the certificate used and the result, plus a technical error message if signing failed. The log contains neither document contents nor file names. It is kept, together with a copy of your signing certificate, in the app's documents folder; on iOS these files are visible in the Files app and when the device is connected to a computer.
The app's settings also store the trial signature counter, whether a subscription has been unlocked, when you accepted the terms of use and this privacy policy, and which output folder you chose.
Technical diagnostic messages (without PIN, CAN or document content) are written only to your device's system log; they are not transmitted.
2.6 Trial, purchases and subscriptions
Paid subscriptions are bought in Apple's App Store (Apple Distribution International Ltd., Ireland) or on Google Play (Google Ireland Ltd., Ireland). Payment, billing, renewal, cancellation and refunds are handled by these providers as independent controllers under their own privacy policies. The app checks on the device, via Apple's and Google's purchase interfaces, whether a subscription is active; "Restore purchases" restores it after reinstalling. There is no server of our own for purchase validation.
We receive no payment data and no names from Apple or Google. The stores only provide us with transaction and revenue reports, which we use to meet tax and commercial obligations and keep for the statutory periods (up to ten years) (Art. 6(1)(c) GDPR).
2.7 Permissions
- NFC: to communicate with your eHBA.
- Internet: only for the certificate check (section 2.4) and the stores' purchase functions (section 2.6).
- Files: access only to the documents you select or share with the app, and to the folder you set for signed PDFs.
- Camera, notifications and Face ID / biometric unlock: belong to the announced practice connection (section 2.9). The current version does not request or use these permissions.
2.8 No tracking, no advertising
The app contains no analytics, tracking or crash-reporting tools and no advertising, does not use an advertising ID and creates no usage statistics. We do not know what you sign or when.
If you have agreed in your device's system settings to share crash and diagnostic data with app developers, Apple or Google may provide us with aggregated crash reports that cannot be traced back to you. You can change this setting on your device at any time.
If you use your operating system's device backup (iCloud Backup or Google backup), app data such as settings and the signing log may be part of that backup. You set this backup up yourself; Apple or Google process it as independent controllers.
2.9 Practice connection (coming soon)
The announced connection to practice management systems (PVS) will require an Attrian account. This feature is not available in the current version. Before it launches we will add the related processing to this policy. Nothing changes for signing PDFs on your phone.
2.10 Retention and deletion
Data on your device stays there until you delete it. You can remove your stored CAN and drawing in the app under "Mein Profil" (My profile). The Delete data page explains what is removed when you uninstall and what remains in the iOS Keychain. Signed PDFs remain in the storage location you chose and are not deleted by the app.
3. Part B: This website
3.1 Hosting
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner. The legal basis is our legitimate interest in providing the website securely and reliably (Art. 6(1)(f) GDPR).
3.2 No server log files
When you visit the website, the server necessarily processes your IP address and the details your browser sends (e.g. the page requested, browser type) in order to deliver the page. This data is processed only for the duration of the connection. The server stores no access logs and creates no access statistics. The legal basis is our legitimate interest in providing the website (Art. 6(1)(f) GDPR).
3.3 No cookies, no analytics
This website sets no cookies, stores no information in your browser (e.g. in local storage) and uses no analytics, tracking or marketing services. That is why there is no cookie banner. Fonts, icons and the product film are served from our own server, not from Google Fonts, YouTube or similar services.
3.4 Libraries loaded from unpkg
To render its pages, the website loads the open-source JavaScript libraries React, ReactDOM and Babel from the content delivery network unpkg.com. In the process your IP address is transmitted to the operator of unpkg and its infrastructure provider Cloudflare, Inc. (USA). The files are loaded with checksums (Subresource Integrity), so modified files are not executed. The legal basis is our legitimate interest in fast and reliable delivery (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework.
3.5 Contact by email
If you email us, we process your details to answer your request (Art. 6(1)(b) GDPR for contract or support requests, otherwise Art. 6(1)(f) GDPR). We delete the data once your request has been dealt with, unless statutory retention obligations apply. Please do not send us patient documents, and never send your PIN.
4. Recipients and transfers outside the EU
We do not sell data and do not share data for advertising. The only recipients of personal data are:
- Hetzner Online GmbH, as processor for hosting the website;
- Apple or Google, as independent providers of the app stores and purchase handling;
- the trust service provider that issued your eHBA, for the certificate check;
- unpkg and Cloudflare, for delivering the website's libraries.
Apple, Google and Cloudflare may also process data in the USA. The European Commission has adopted an adequacy decision for the USA (EU-US Data Privacy Framework), under which these companies are certified.
5. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). To exercise them, contact [email protected].
Right to object: where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
Because the app does not send data to us, we usually hold no data that we could attribute to you (Art. 11 GDPR). You can view and delete the data on your device yourself at any time.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
No automated decision-making, including profiling (Art. 22 GDPR), takes place. You are under no obligation to provide us with personal data.
6. Security, minors, changes
The website is served exclusively over an encrypted connection (TLS). The app stores the CAN and drawing encrypted in the device's protected storage; the connection for the certificate check is also secured.
FastDoc QES is intended for health professionals with an eHBA and is not directed at children.
We update this policy when the app, the website or the law changes. The version published here applies. In case of doubt, the German version prevails.