Legal

Privacy policy

Last updated: 6 October 2026

This privacy policy explains which personal data is processed when you use the FastDoc QES app for iOS and Android (Part A) and when you visit this website (Part B).

In short: the app works without an account, without our own servers and without tracking. Your documents, your PIN and your CAN never leave your phone. The only connection the app makes when signing is the certificate check (OCSP) with the issuer of your eHBA. Purchases are handled by Apple or Google. The website sets no cookies and uses no analytics.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

BrainWave Software GmbH
Heilig-Kreuz-Straße 24
86152 Augsburg
Germany

Represented by its Managing Director Eldo Devole
Commercial register: Local Court (Amtsgericht) Augsburg, HRB 39856
Email: [email protected]

For any question about data protection, or to exercise your rights, contact us at [email protected].

2. Part A: The FastDoc QES app

FastDoc QES uses your electronic health professional card (eHBA) to create qualified electronic signatures (QES) on PDF documents. The app is built so that we cannot see what you sign. All the data listed below stays on your device; nothing is sent to us.

Overview: data the app processes
DataWhere it is processedSent to us
PDF documentsOn your device; signed PDFs in the folder you chooseNo
PIN.QESOnly in memory during signing; passed directly to your card and never storedNo
CAN, handwritten drawing, and the name, title, profession and certificate from your eHBAEncrypted in the device's protected storage (iOS Keychain or Android Keystore)No
Signing log (time, document checksum, certificate serial number, result)File in the app's storage on your deviceNo
Trial signature counter, subscription status, time you accepted the terms, chosen output folderApp settings on your deviceNo
Certificate details for the validity checkSent to your card's issuer (section 2.4)No
Purchase and subscription dataWith Apple or GoogleNo (transaction reports only, without payment data)

2.1 No account, no servers of our own

Signing PDFs requires no registration, email address or password. Opening, signing and saving happen entirely on your device; the signing time also comes from your device's clock. There is no FastDoc server to which documents, logs or usage data are sent.

2.2 Documents

You open documents through your device's file picker or via "Open in …" from other apps. The app only gets access to the file you select; the operating system may place a copy in the app's temporary storage for this. The signed PDF is saved to the folder you set, or shared with the app you choose; sharing also creates a temporary copy. Temporary files stay inside the app's protected sandbox and are cleaned up by the operating system. If you choose a cloud storage service (e.g. iCloud Drive or Google Drive), that provider's terms apply; we get no access.

Documents may contain health data of patients (Art. 9 GDPR). Because they are processed exclusively on your device and under your control, we do not process this data. You, or your organisation, remain responsible for the documents, including where they are stored and with whom signed documents are shared.

2.3 eHBA, PIN, CAN and drawing

The app talks to your eHBA via NFC. You enter your PIN.QES in the app. It is held in memory only for the duration of the signing process, passed to the card only in encrypted form and then discarded; it is never stored and never logged.

The CAN (six digits printed on the card) secures the wireless link between card and phone. After the first successful connection the app stores it so you do not have to enter it for every signature. The app likewise stores your optional handwritten drawing for the stamp and the name, title, profession and certificate from your eHBA, to create the visible stamp. This data is kept encrypted in the operating system's protected storage (iOS Keychain or Android Keystore) and is not synced with iCloud.

A signature necessarily contains details from your qualified certificate (in particular your name and profession) and the time of signing. These are embedded in the PDF and shown as a visible stamp, with your drawing if you wish. That is the purpose of the signature and only happens when you sign.

The legal basis for this on-device processing is the performance of the app's terms of use (Art. 6(1)(b) GDPR).

2.4 Certificate check (OCSP)

Before every signature the app checks whether your certificate is still valid. Using the addresses stored in the certificate itself, it first downloads the issuer's public certificate from the trust service provider that issued your eHBA (e.g. D-Trust, medisign, SHC+Care or T-Systems) and then queries that provider's validation service (OCSP). Only data identifying your certificate (serial number and issuer hash values) is sent, together with, for technical reasons, your IP address and the time of the request. The document is never sent.

The response is embedded in the signature so it remains verifiable later. If the certificate is revoked or the service is unreachable, nothing is signed. The requests go directly from your device to the trust service provider, which processes them as an independent controller under its own privacy policy; we receive no information about them. The legal basis is Art. 6(1)(b) GDPR, as the check is required for a valid qualified signature.

2.5 Signing log and other app data

So that you can trace when you signed what, the app keeps a local signing log. For every signing attempt it records the time, the checksum (SHA-256) of the document, the serial number of the certificate used and the result, plus a technical error message if signing failed. The log contains neither document contents nor file names. It is kept, together with a copy of your signing certificate, in the app's documents folder; on iOS these files are visible in the Files app and when the device is connected to a computer.

The app's settings also store the trial signature counter, whether a subscription has been unlocked, when you accepted the terms of use and this privacy policy, and which output folder you chose.

Technical diagnostic messages (without PIN, CAN or document content) are written only to your device's system log; they are not transmitted.

2.6 Trial, purchases and subscriptions

Paid subscriptions are bought in Apple's App Store (Apple Distribution International Ltd., Ireland) or on Google Play (Google Ireland Ltd., Ireland). Payment, billing, renewal, cancellation and refunds are handled by these providers as independent controllers under their own privacy policies. The app checks on the device, via Apple's and Google's purchase interfaces, whether a subscription is active; "Restore purchases" restores it after reinstalling. There is no server of our own for purchase validation.

We receive no payment data and no names from Apple or Google. The stores only provide us with transaction and revenue reports, which we use to meet tax and commercial obligations and keep for the statutory periods (up to ten years) (Art. 6(1)(c) GDPR).

2.7 Permissions

2.8 No tracking, no advertising

The app contains no analytics, tracking or crash-reporting tools and no advertising, does not use an advertising ID and creates no usage statistics. We do not know what you sign or when.

If you have agreed in your device's system settings to share crash and diagnostic data with app developers, Apple or Google may provide us with aggregated crash reports that cannot be traced back to you. You can change this setting on your device at any time.

If you use your operating system's device backup (iCloud Backup or Google backup), app data such as settings and the signing log may be part of that backup. You set this backup up yourself; Apple or Google process it as independent controllers.

2.9 Practice connection (coming soon)

The announced connection to practice management systems (PVS) will require an Attrian account. This feature is not available in the current version. Before it launches we will add the related processing to this policy. Nothing changes for signing PDFs on your phone.

2.10 Retention and deletion

Data on your device stays there until you delete it. You can remove your stored CAN and drawing in the app under "Mein Profil" (My profile). The Delete data page explains what is removed when you uninstall and what remains in the iOS Keychain. Signed PDFs remain in the storage location you chose and are not deleted by the app.

3. Part B: This website

3.1 Hosting

This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner. The legal basis is our legitimate interest in providing the website securely and reliably (Art. 6(1)(f) GDPR).

3.2 No server log files

When you visit the website, the server necessarily processes your IP address and the details your browser sends (e.g. the page requested, browser type) in order to deliver the page. This data is processed only for the duration of the connection. The server stores no access logs and creates no access statistics. The legal basis is our legitimate interest in providing the website (Art. 6(1)(f) GDPR).

3.3 No cookies, no analytics

This website sets no cookies, stores no information in your browser (e.g. in local storage) and uses no analytics, tracking or marketing services. That is why there is no cookie banner. Fonts, icons and the product film are served from our own server, not from Google Fonts, YouTube or similar services.

3.4 Libraries loaded from unpkg

To render its pages, the website loads the open-source JavaScript libraries React, ReactDOM and Babel from the content delivery network unpkg.com. In the process your IP address is transmitted to the operator of unpkg and its infrastructure provider Cloudflare, Inc. (USA). The files are loaded with checksums (Subresource Integrity), so modified files are not executed. The legal basis is our legitimate interest in fast and reliable delivery (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework.

3.5 Contact by email

If you email us, we process your details to answer your request (Art. 6(1)(b) GDPR for contract or support requests, otherwise Art. 6(1)(f) GDPR). We delete the data once your request has been dealt with, unless statutory retention obligations apply. Please do not send us patient documents, and never send your PIN.

4. Recipients and transfers outside the EU

We do not sell data and do not share data for advertising. The only recipients of personal data are:

Apple, Google and Cloudflare may also process data in the USA. The European Commission has adopted an adequacy decision for the USA (EU-US Data Privacy Framework), under which these companies are certified.

5. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). To exercise them, contact [email protected].

Right to object: where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.

Because the app does not send data to us, we usually hold no data that we could attribute to you (Art. 11 GDPR). You can view and delete the data on your device yourself at any time.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

No automated decision-making, including profiling (Art. 22 GDPR), takes place. You are under no obligation to provide us with personal data.

6. Security, minors, changes

The website is served exclusively over an encrypted connection (TLS). The app stores the CAN and drawing encrypted in the device's protected storage; the connection for the certificate check is also secured.

FastDoc QES is intended for health professionals with an eHBA and is not directed at children.

We update this policy when the app, the website or the law changes. The version published here applies. In case of doubt, the German version prevails.