App Privacy Policy

  • The Docomondo DMS App (document management), available on iOS, Android, Web, and macOS;
  • The Docomondo Budget App (personal finance tracking), available on iOS, Android, and Web;
  • The Docomondo Expense App (expense reporting and organisational finance), available on iOS, Android, and Web

These services are collectively referred to in this Privacy Policy as “docomondo” or the “Service.”

This Privacy Policy outlines how we collect, use, store, disclose, and protect your personal data when you use our Service, and the rights you have in relation to your data. By using the Service, you acknowledge that your Personal Data will be processed as described in this Privacy Policy and on the applicable legal bases set out herein.

Unless otherwise defined herein, terms used in this Policy have the same meaning as those set out in our Terms and Conditions.

We attach great importance to protection and security of your personal data. We regard the protection of your private sphere and the compliance with the data protection requirements as the key matter when collecting, processing and using your personal data. Therefore, your personal data are collected, processed and used exclusively in compliance with the provisions of data protection laws.

It is important for us as a company that while using our Service you can trust that we observe data protection at all times. You should know which personal data are collected by us during your use of the Service and how we process and use them. Moreover, we would like to inform you about measures we take to protect your personal data against manipulation, loss, destruction and abuse. We do not own, sell or disclose your data to unauthorised third parties.

1. Definitions

Personal Data (or Data)Personal Data means any information relating to an identified or identifiable natural person (“Data Subject”), including information such as a name, identification number, location data, an online identifier, financial data, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
docomondo User, User or Data SubjectA User refers to any individual who registers for or interacts with the docomondo Service in any capacity, including individual account holders, participants under organisational or team accounts, and trial users.
Data ControllerPanera Tec AG acts as the Data Controller of your Personal Data when you use any of the docomondo applications (DMS, Budget, or Expense), whether accessed via iOS, Android, Web, or macOS. In some cases—particularly where integrations with third-party services such as SaltEdge are involved—Panera may act as a joint controller or independent controller in accordance with applicable data protection laws.
Data Processor (or   Service Provider)A Data Processor is any third party that processes Personal Data on behalf of Panera in accordance with Article 28 of the GDPR. This includes cloud storage providers, email service providers, analytics partners, and other technical infrastructure providers used to deliver the docomondo Service.

2. Collecting Personal Data

2.1 Personal Data We Do Collect

We collect and process different types of Personal Data depending on how you interact with the Docomondo Service. The nature and scope of the data collected will vary based on the specific application you use—Docomondo DMS, Docomondo Budget, or Docomondo Expense—and the platform through which you access the Service (e.g. iOS, Android, Web App, or macOS).

The following categories of Personal Data may be collected, depending on your use of the Service:

Contact and Registration Data
Collected when you create or manage an account on any of the apps:

– Name

– Email address

– Password or login token (where applicable)

– Device language and country settings.
Content
Content uploaded or otherwise submitted by you through the Service may or may not contain Personal Data. Content is protected using the technical and organisational security measures described in Section 8. Depending on the Service, the storage option selected by you and the functionality used, Content may be transmitted, synchronised, indexed, displayed or automatically processed as necessary to provide the relevant Service functionality. Such automated processing may include document recognition, optical character recognition (OCR), data extraction and, in the Budget and Expense Services, AI-assisted processing. The applicable storage locations, access restrictions and security measures for Content are described in more detail in Section 8.

Uploading Content into our Service does not change that Content's ownership or copyright status. If the Content was yours to begin with, it remains yours after you put it in the Service. Of course, if the Content wasn’t yours to begin with, putting it in the Service doesn’t make it yours.
Device and Usage Data
Collected automatically when you interact with the Service:

– Device type and model

– Operating system and version

– IP address

– Browser or app version

– Crash logs, diagnostics, and performance data

– Usage patterns, session lengths, and interaction events

This data is processed via analytics providers such as Post Hog, Google Analytics, Firebase, Sentry, and Meta (Facebook) Pixel.
Demographic and Statistical Data
Collected with your explicit consent for feature development and analytics:

– Country

– Date of birth

– Gender

Statistical data is processed in anonymised or pseudonymised form whenever possible
Location Data
With your explicit consent, we may collect your geolocation:

– In the DMS app: to assist in tagging scanned documents.

– In the Expense app: to calculate mileage reports.

Location data is never collected without your prior authorisation and may be disabled at any time in your device settings.
Content and Document Data
If you upload, scan or otherwise process documents or receipts using one of the docomondo Services, we may process:

- scanned files, uploaded documents, receipt images and associated metadata or tags;
- text recognised from scanned images or documents (OCR);
- information extracted or interpreted from such Content, including merchant, date, amount, currency, tax information and other relevant fields; and
- categories, budgets or other account settings where required to provide automated allocation or categorisation suggestions.

Depending on the Service, platform and functionality used, document and receipt recognition may be performed locally on the User's device using technologies such as Apple VisionKit or Google ML Kit and/or through Amazon Web Services technologies such as Amazon Textract. The DMS Service uses OCR and document recognition functionality but does not use AI-assisted interpretation of document content. The Budget and Expense Services additionally use Amazon Bedrock with Amazon Nova models for AI-assisted receipt processing. In the Budget Service, receipt content may be analysed to suggest which of the User's configured budgets the receipt could be assigned to. In the Expense Service, receipt content may be analysed to suggest an appropriate expense category based on the categories configured within the User's account. Amazon Bedrock may also assist in extracting, interpreting and structuring relevant receipt information. Automated recognition, extraction, interpretation and suggestions are intended to assist the User and may contain errors or inaccuracies. Users can review and correct extracted, interpreted or suggested information. For the DMS Service, where documents are stored exclusively on the User's device or within the User's personal Apple iCloud or Google Drive account, Panera has no technical access to the document contents unless the User explicitly provides or shares such Content with Panera. Certain metadata required to provide the Service, such as tags, dates or filters, may nevertheless be processed within infrastructure operated or controlled by Panera. The applicable storage locations, access restrictions and security measures for Content, including DMS Content stored within the Docomondo Cloud, are described in more detail in Section 8.
Financial and Transactional Data (Budget and Expense Apps)
Collected only when you choose to connect bank accounts or manage budgets:

– Bank account metadata

– Transaction history

– Budget categories and limits

– Shared budget participants

Only the bank account metadata and transaction history are retrieved via SaltEdge, which is authorised under PSD2 regulations. As part of this process, we transmit your verified email address to SaltEdge to enable secure session creation and access to your authorised financial data. You will be informed of this processing during onboarding. SaltEdge acts as an independent data controller for this processing and handles your data in accordance with   its   own   Privacy   Policy,   available   at https://www.saltedge.com/pages/privacy_policy.

Budget categories and limits as well as hared budget participants are collected directly by Panera within the app environment. Panera does not store your banklogin credentials and only receives financial data that you explicitly authorise to be hared. All data transfers are encrypted. Payment data for subscription processing is
handled by Stripe (for web-based payments) or by Apple App Store and Google Play Store (for in-app purchases on iOS and Android, respectively), while RevenueCat manages subscription status but does not process or handle any payments
Organisational and Team Data (Expense App Only)
When using the Expense app in an organisational context:

– Submitted expenses, receipts, and categories

– Mileage records

– Approval status and comments from managers

– Company email domains or team group identifiers

This data is processed strictly to facilitate the employer-authorised use of the Expense functionality and may be visible to authorised team managers or finance admins within your organisation.
Tracking Technologies
We use tracking technologies such as cookies, SDKs, and usage beacons to monitor Service performance, user engagement, and crash behaviour. These include services provided by Google Analytics, PostHog, Firebase, Sentry, and Facebook Pixel. Please also refer to our Cookie Policy for further details about tracking on the website.
Meta (Facebook) SDK & App Events —Mobile Apps
Appliesto: Docomondo Budget, DMS, Expenses (iOS/Android)

‍We use the Meta (Facebook) SDK solelyto measure the effectiveness of our external advertising campaigns(attribution). We do not show advertising inside our apps.

Data processed (only with your consent): automatically logged app events (AutoLogAppEvents, e.g., install/app launch), the Purchase event upon completion of an in-app subscription (amount, currency, timestamp), technical data (app/OS version, IP), as well as advertising identifiers (IDFA on iOS, GAID on Android).

Legal basis: Consent (Art. 6(1)(a) GDPR; where applicable ePrivacy/TTDSG). Without consent, AutoLogAppEvents and advertiser ID collection remain disabled; no app events are sent to Meta. iOS: tracking only after approval via AppTrackingTransparency (ATT).

Recipient/controller: Meta Platforms Ireland Ltd. (acting as an independent controller).

Purpose: Attribution and optimisation of our off-app advertising (e.g., to understand which ad led to an install or purchase).

Withdrawal: you can withdraw consent at any time in App or system-wide via iOS/Android settings; withdrawal takes effect immediately.

International transfers: where applicable, transfers to Meta group companies outside the EEA rely on Standard Contractual Clauses (SCCs) and, where available, adequacy decisions (e.g., EU-US Data Privacy Framework).

Retention: attribution/usage data is generally retained for up to 24 months; Meta applies its own retention periods.

WebApp Tracking (Meta Pixel) — Consent via in-app popup
In our Web App, we only activate the Meta Pixel after you have expressly consented via the in-app consent popup, to measure the effectiveness of our external advertising campaigns (attribution/optimisation). We process standard events (e.g., PageView) and, upon completion of a web-app subscription, the “Purchase” event (including value/currency parameters). No Meta events are triggered on the public website. Note: we do not serve advertising inside the app; the pixel is used exclusively for campaign attribution/optimisation.

Legal basis: Consent (Art. 6(1)(a) GDPR; ePrivacy/TTDSG).

Recipient/controller: Meta Platforms Ireland Ltd. (independent controller).

Categories of data: cookie/device identifier (e.g., _fbp), IP address, user-agent, referrer/URL, technical event data, and event parameters (e.g., amount/currency for Purchase).

Opt-out/withdrawal: you can change your choice or withdraw consent at any time in the Web App privacy/tracking settings; changes take effect immediately.

International transfers: may occur to Meta group companies outside the EEA, relying on SCCs and, where applicable, adequacy decisions (e.g., EU-US Data Privacy Framework).

Retention: we retain attribution/tracking data for up to 24 months; Meta applies its own retention periods.

2.2 Personal Data We Do Not Collect

We want to be fully transparent with you, and for this reason we want to disclose which Personal Data we do not collect when you use our Service.

We do not collect or process any of the following data types through the docomondo Service:

  • Emails or email content
  • Contact lists or address book data
  • Chat messages or text messages
  • Images or media stored elsewhere on your device
  • SMS or call history
  • Audio recordings

We do not routinely access or manually review the content of documents or receipts submitted through the Service. However, document or receipt content may be processed automatically where necessary to provide functionality requested by the User.In the DMS Service, OCR and document recognition may be performed locally on the User's device using technologies such as Apple VisionKit (iOS) or Google ML Kit (Android), or through other processing methods described in this Privacy Policy depending on the platform and functionality used. The DMS Service does not use AI-assisted interpretation of document content.In the Budget and Expense Services, receipt content may be processed automatically using Amazon Web Services technologies, including Amazon Textract and Amazon Bedrock with Amazon Nova models, as described in Section 2.1 and Section 10. Such processing is used to recognise, extract, structure and interpret receipt information and to provide budget allocation or expense category suggestions.The applicable storage locations, access restrictions and security measures are described in Section 8.

2.3 Sensitive Personal Data

The following Personal Data is considered sensitive (the "Sensitive Personal Data") and is subject to specific processing conditions:

  • Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs;
  • Trade-union membership;
  • Genetic data, biometric data processed solely to identify a human being;
  • Health-related data;
  • Data concerning a person’s sex life or sexual orientation.

Protecting your Personal Data is of the utmost importance to us. The Service does not require Users to provide Sensitive Personal Data and is not specifically designed for the processing of such data. We therefore ask you not to upload or submit Sensitive Personal Data through the Service unless this is necessary for your intended use and you are legally entitled to do so. If Sensitive Personal Data is nevertheless contained in Content submitted by a User, it may be processed only to the extent technically necessary to provide the Service functionality requested by the User and subject to applicable data protection law.

3. How We Collect Personal Data

We collect information about you when you use our Service, including registering and taking certain actions within it.

Means of collectionExplanationPersonal Data collected
Directly
Your use of the AppWe keep track of certain information about you when you visit and interact  with our App.This information includes the Content and Usage Data (as defined above in Section 2  collect)
Your registration on the AppWe collect information about you when you register on docomondo as a User.This information includes the Contact Data and the Registration Data (as defined above in Section 2 Collect).
Device   and connection informationWe   collect   information   about   your phone, tablet, or other devices you use to access the App.This information includes the Location Data and Usage Data (as defined above in Section 2 Collect). How much of this information we collect depends on the type and settings of the device you use to access our Service.
Tracking technologiesWe and our third-party partners, such as our advertising and analytics partners, use   tracking   technologies  (e.g.,   web beacons, device identifiers and pixels) to provide functionality and to recognise you   across   different   services   and devices.This information includes the Tracking Data (as defined above in Section 2 Collect). For more information, please refer to our Cookie Policy.
Indirectly
Other partnersWe receive information about you and your activities on and off the App from third-party partners, such as advertising and   market   research   partners   who provide us with information about your interest in and engagement with, our Services and online advertisements.This information includes the Usage Data and Tracking Data (as defined above in Section 2 Collect).

4. Legal Basis and Purposes

We process your Personal Data in accordance with the lawful bases set out under Article 6(1) of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), as applicable, depending on the specific context and purpose of the processing. The legal bases we rely on include:

Legal BasisExplanationPurpose
ContractTo   perform   our contractual   obligations or take steps linked to a contract with you or your organisation.  
  • To register you as a Docomondo User as instructed by you
  • To provide and administer services as instructed by you.
  • To provide you with customer support.
Consent (Article 6(1) (a))We process data based on your explicit consent, given when you enable optional   features   (e.g. marketing   preferences, geolocation).   You   can withdraw consent at any time.
Collecting demographic or statistical data (e.g., gender, date of birth).

Geolocation   data   for   specific   features   (e.g.,   mileage tracking in Expense App).

Cookies and tracking for analytics and marketing.

Meta SDK/App Events (mobile) and Meta Pixel (WebApp) for campaign attribution and optimisation (no in-app advertising).
Contractual Necessity (Article 6(1) (b))We process data when necessary to fulfil our agreement with you.To provide access to core Service functions such as account creation, document management, budgeting and expense tracking, including automated receipt recognition, extraction and interpretation of receipt information and AI-assisted budget allocation or expense category suggestions in the Budget and Expense Services.
Legal Obligation (Article 6(1) (c))We process data when required to comply with legal obligations.To   meet   regulatory   requirements   such   as   financial reporting, audit obligations, and anti-fraud checks.
Legitimate Interests (Article 6(1) (f)We process data when it's   in   our   legitimate interests   and   does   not override your rights.To improve the Service, conduct user analytics, enhance security, and prevent misuse or fraud.
Special Categories (Article 9)We   don’t   intentionally process   sensitive   data (e.g., health, biometrics) unless required by law or consent.Not generally applicable. The Service does not require or intentionally collect Special Category Data. However, such data may incidentally be contained in Content submitted by a User. In such cases, it will only be processed to the extent technically necessary to provide the requested Service functionality and where permitted by applicable data protection law.
Public interestTo meet regulatory and public interest obligations.To maintain records and conduct compliance checks, e.g. anti-money laundering, fraud and crime prevention.

5. Data Retention

We will retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including for legal, accounting, or reporting obligations.

Retention periods will vary based on the type of data and the purpose for which it was collected. Generally, we retain Personal Data for the following periods:

  • User Account Data: For as long as you maintain an active account or as required to provide the Service and comply with our contractual obligations. If you delete your account, we will delete or anonymise Personal Data associated with your account without undue delay, unless and to the extent that continued retention is required or permitted by applicable law, including for legal, accounting, security, fraud prevention or the establishment, exercise or defence of legal claims. Residual copies may remain in backup systems for a limited period until deleted in accordance with our standard backup and retention procedures.
  • Financial and Transaction Data (e.g., SaltEdge transactions): Retained for as long as necessary to provide the relevant Service functionality and in accordance with the retention settings or instructions applicable to the relevant account. Certain records may be retained for longer where required or permitted by applicable legal, accounting, tax, regulatory, security or dispute-resolution obligations.
  • Usage Data and Analytics: Retained for up to 24 months for performance analysis and to improve the Service.
  • Marketing and Demographic Data: Retained for up to 3 years unless you opt-out or withdraw consent
  • Attribution/Tracking data (Meta App Events & Meta Pixel): up to 24 months.
  • Amazon Bedrock / Amazon Nova processing: When Amazon Nova models are used through Amazon Bedrock, customer inputs and model outputs are not stored or reviewed by Amazon Bedrock and are not used by AWS to train Amazon Nova or other Amazon Bedrock models. Panera has not enabled Amazon Bedrock Model Invocation Logging. Information returned to docomondo as a result of the processing, such as extracted receipt information or budget allocation and expense category suggestions, may be stored as part of the relevant Budget or Expense data and is subject to the retention periods applicable to such data.

We will retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including for legal, accounting, or reporting obligations.

If you have any questions about the retention of your Personal Data or wish to exercise your rights, please contact us at privacy@docomondo.com  

6. Storage And Data Transfers

Your Personal Data is stored either locally on your personal device, within the docomondo cloud infrastructure (the "docomondo Cloud"), or—for users of the DMS App—on your personal iCloud or Google Drive account, depending on your selected configuration. We may also use carefully selected, data privacy-compliant Service Providers (as defined in Section 10) located in Liechtenstein, Switzerland, European Union and the United States.

For AI-assisted receipt processing in the Budget and Expense Services, requests are submitted to Amazon Bedrock from our AWS infrastructure in Frankfurt, Germany (eu-central-1). We use Amazon Bedrock EU Geographic Cross-Region Inference. This means that individual inference requests may be routed to and processed in another supported AWS Region within the EU geographic inference profile. AWS Geographic Cross-Region Inference is designed to keep such processing within the applicable EU geographic boundary. Data transmitted between AWS Regions is encrypted and remains on the AWS network. Further information about our use of Amazon Bedrock and Amazon Nova is provided in Section 10.

In particular, authentication and account management data may be processed by Clerk, a U.S.-based service provider that stores all data exclusively in the United States. Clerk is certified under the EU-U.S.Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework (collectively,10
the “DPF”), which the European Commission and UK Government have recognised as providing an adequate level of protection for personal data pursuant to Article 45 of the EU and UK GDPR. Clerk’s certification may be reviewed at: https://clerk.com/legal/dpf. For more information on Clerk’s data processing obligations, see its Data Processing Agreement: https://clerk.com/legal/dpa.

In addition to DPF-certified providers, where Personal Data is transferred outside the EEA or UK to a country that is not subject to an applicable adequacy decision, we implement appropriate safeguards as required by applicable data protection law. These may include the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, as amended or replaced from time to time, and, where applicable, the UK International Data Transfer Agreement or UK International Data Transfer Addendum.

This also applies to processing by Meta Platforms in the context of app events/pixel; in such cases, SCCs and - where applicable - adequacy decisions (e.g., EU-US Data Privacy Framework) are used.

We take all steps reasonably necessary to ensure that your Personal Data is treated securely and in accordance with applicable data protection laws, and that no transfer of your Personal Data takes place to any organisation or country unless adequate safeguards are in place.

7. Data Disclosure

We may disclose your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation (e.g., in response to valid requests by public authorities, such as a court, government agency, or regulatory body, under UK GDPR Article 6(1)(c));
  • Protect and defend our rights or property, including in relation to legal claims and compliance with contractual obligations;
  • Prevent or investigate possible wrongdoing in connection with docomondo, such as fraud, abuse, or unlawful activities, under legitimate interests (UK GDPR Article 6(1)(f));
  • Protect the safety of App visitors or the public, such as in emergency situations where public health or safety is at risk;
  • Protect ourselves against legal liability, including disclosures required in defending against claims or legal actions.

Where third-party recipients process Personal Data on our behalf as data processors, the processing is subject to appropriate contractual arrangements in accordance with Article 28 of the UK GDPR and EU GDPR. Where a recipient acts as an independent or joint controller, its processing is subject to the applicable data protection law and the relevant legal basis and safeguards.

8. Data Security

We take reasonable technical and organizational security measures that we deem appropriate in order to protect your stored data against manipulation, loss, or unauthorised third-party access. Our security measures are continually adapted to technological developments.

Where third-party Service Providers process Personal Data on our behalf as data processors, we require them to implement appropriate technical and organisational security measures in accordance with applicable data protection law. We also take internal data privacy seriously. Our employees and Service Providers are subject to appropriate confidentiality and data protection obligations and are granted access to Personal Data only insofar as this is necessary for them to carry out their respective tasks or mandate. Content stored within infrastructure operated or controlled by Panera is protected by appropriate security measures, including encryption in transit and, where applicable, at rest. Content stored on a User's personal device or within a personal third-party cloud storage account is additionally subject to the security measures and settings of the respective device or storage provider. For the Docomondo DMS App, users may choose to store documents on their personal iCloud, Google Drive, local device storage, or the Docomondo Cloud. By contrast, data from the Budget and Expense apps is always stored securely on the Docomondo Cloud. When DMS documents are stored exclusively on iCloud, Google Drive, or locally on the User's device, Panera has no technical access to the document contents. Certain metadata required to provide the Service, such as tags, dates or filters, may nevertheless be processed within infrastructure operated or controlled by Panera, as described in Section 2.1.

When Content is stored within the Docomondo Cloud, Panera's systems and selected Service Providers may automatically process such Content where necessary to provide the functionality described in this Privacy Policy, including the automated processing described in Sections 2.1 and 2.2. Human access by Panera personnel to document or receipt contents is restricted to a very limited number of authorised employees and occurs only where necessary and with the User's explicit consent, for example for support or technical troubleshooting. Such access is restricted to our authorised office network through IP whitelist restrictions. Employees with such access are bound by strict confidentiality obligations and have signed Non-Disclosure Agreements (NDAs).

For the DMS Web App, OCR data from uploaded documents may be processed and stored where necessary to provide functionality such as full-text search. This processing is performed automatically by the system. Human access to such data is subject to the access restrictions described above.

For DMS Users who exclusively use the mobile application and store their documents outside the Docomondo Cloud, document content and OCR data are not stored within Panera's infrastructure and are not technically accessible to Panera. OCR may be performed locally on the User's device as described in Section 2.1. Certain metadata required to provide the Service may nevertheless be processed by Panera as described in Section 2.1. Content stored on the User's device or within a personal third-party cloud storage account remains subject to the security and access controls of the respective device or storage provider.

The following table of technical and organizational measures describes the steps we have taken to protect your Personal Data:

MeasureDetailsConcrete actions
Confidential
Physical   access controlNo unauthorised access to our facilities.Keys/magnetic chip cards
Electronic access controlNo   unauthorised   use   of   the   Data processing and Data storage systems.
  • Secure passwords
  • Two-factor authentication
  • Encryption of data carriers/storage media
Internal   access controNo   unauthorised  reading,  copying, changes or deletions of Personal Data within the system.
  • Rights authorisation concept
  • Need-based rights of access
Integrity
Data   transfer controlNo   unauthorised   Reading,   Copying, Changes   or   Deletions   of   Data   with electronic transfer or transport.
  • Encryption
  • Virtual Private Networks (VPN) Electronicsignature
Data   entry controlVerification  whether   and   by   whom personal   data   is   entered   into   a   Data Processing   System,   is   changed   or deleted.Timestamp-based   logging   is implemented.   As   only   one   authorised staff member currently has access, user- specific tracking is not required but will be implemented   as   user   base   expands. Confidentiality   and   accountability   are contractually ensured.
Availability and resilience
Availability controlPrevention   of   accidental   or   wilful destruction or loss.
  • Backup and recovery measures for Personal Data and Content stored within infrastructure operated or controlled by Panera. These measures do not apply to Content stored exclusively on a User's device or within a personal Apple iCloud, Google Drive or other third-party storage account to which Panera has no technical access.
  • virus protection,
  • Firewall
  • Reporting procedures
Contract controlNo third-party processing of Personal Data on our behalf without appropriate contractual arrangements and safeguards as required by Article 28 of the EU GDPR and UK GDPR, where applicable.
  • Clear   and   unambiguous   contractualarrangements
  • Formalised order management
  • Strict controls on the selection of the Service Provider
  • Duty of pre-evaluation
  • Supervisory follow-up checks
Data Protection policiesThe   processing   of   Personal   Data   is guided   by   binding   confidentiality obligations   and   will   be   formalised through internal policiesCurrently,   employees   with   access   to Personal   Data   are   bound   by   Non- Disclosure Agreements (NDAs).

The security of your Personal Data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. We hereby notify you of the danger emanating from viruses or other harmful software (malware) or from hacking, phishing or other comparable attacks. We recommend that you use antivirus software, a spam filter, and other software to protect your system (e.g., a firewall) and to keep them up to date. Subject to Section 5 of our Terms and Conditions and to the extent permitted by applicable law, Panera shall not be liable for manipulation of, interference with or unauthorised access to a User's IT systems by third parties in connection with the User's access to or use of the Service.

9. Data Protection Right

Under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), you have several rights regarding your Personal Data, which we summarise below. We will respond to your request without undue delay and, in any event, within one month of receipt, subject to any extension permitted by applicable data protection law. Please note that we may ask you to verify your identity before responding to such requests. These rights are intended to give you greater control over your Personal Data, and we are fully committed to upholding them in all applicable jurisdictions.

Right to access  (Article 15  UK/EU GDPR)
You have the right to request a copy of your Personal Data held by us and confirm how we are processing it.
Right to  Rectification  (Article 16  UK/EU GDPR)
You have the right to ask us to correct our records if you believe they contain incorrect or incomplete information about you.
Right to  Withdraw  Consent (Article  7 UK/EU GDPR)
If you have provided your consent to the collection, processing and transfer of your Personal Data, you have the right to fully or partly withdraw your consent. This includes cases where you wish to opt out from marketing messages.

Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there is another Legal Basis for the processing. To stop receiving emails from us, please click on the "unsubscribe" link in the email you received from us.
Right to Erasure (Article 17  UK/EU GDPR)
Also known as the "right to be forgotten," you have the right to request that we delete your Personal Data when it is no longer necessary for the purposes it was collected or if you withdraw your consent.
Right to  Restriction of  Processing  (Article 18  UK/EU GDPR)
You have the right to request the restriction of our processing of your Personal Data where you believe it to be inaccurate, our processing is unlawful, or where we no longer need to process it for the initial Purpose, but where we are not able to delete it due to a legal obligation or because you do not want us to delete it.
Right to Data  Portability  (Article 20  UK/EU GDPR)
You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format (e.g., CSV, Excel) and to transmit this data to another data controller without hindrance, where the processing is based on your consent or contractual necessity.

This right applies only to data you have provided to us directly (e.g., through account creation or service usage) and when the processing is carried out by automated means).
Right to Object  (Article 21)
You have the right to object to the processing of your Personal Data, including for direct marketing purposes, or where we are processing your data based on legitimate interests or public tasks.
Right to lodge a  complaint with a supervisory  authority
You have the right of appeal to a data protection supervisory authority if you believe that the processing of your Personal Data violates data protection law.

If you wish to exercise any of these rights, please contact us at privacy@docomondo.com

We will respond to your request within one month. In case your request is complex or numerous, we may extend this period by an additional two months. If an extension is needed, we will notify you within the first month of receiving your request.

If you are dissatisfied with our response, you have the right to lodge a complaint with the competent data protection supervisory authority. For Panera Tec AG in Liechtenstein, the competent supervisory authority is the Liechtenstein Data Protection Authority (Datenschutzstelle Liechtenstein). In the United Kingdom, you may contact the Information Commissioner’s Office (ICO). If you are located in another EEA country, you may also contact the competent supervisory authority in your country of residence, workplace or the place of the alleged infringement, as provided by applicable law. A list is available via the European Data Protection Board (EDPB) at https://edpb.europa.eu.

10. Service Providers

We may employ third party companies and individuals to facilitate the operation of our Service ("Service Providers"). These Service Providers assist us with essential business functions, including but not limited to:

  • Data storage and hosting – including secure infrastructure for application data and user documents (e.g., AWS, Hetzner, Vercel);
  • Document and automated processing – including Amazon Textract for optical character recognition and document analysis, and Amazon Bedrock with Amazon Nova models for AI-assisted receipt processing in the Budget and Expense Services, as described in Section 2.1.
  • Payment and subscription processing  – including Stripe for payment handling and Revenue Cat for managing subscription status;
  • Analytics and tracking – including Google Analytics, PostHog, Facebook Pixel, and Sentry for usage analytics and error logging;
  • Customer support – handled via Intercom, which facilitates secure in-app communication and user inquiries;
  • Open banking integrations – for Users who choose to connect their bank accounts, SaltEdge enables the retrieval of financial transaction data authorised by the User under applicable open banking and PSD2 requirements. In order to establish a secure connection and retrieve the authorised data, we also transmit the User's verified email address to SaltEdge where necessary to create the required user session. This processing is necessary to provide the bank connection functionality requested by the User and is based on Article 6(1)(b) of the EU GDPR and UK GDPR. SaltEdge acts as an independent controller for the processing activities for which it determines the purposes and means and processes Personal Data in accordance with its own Privacy Policy.

To the extent that a Service Provider processes Personal Data on our behalf as a data processor, the processing is governed by contractual terms that meet the requirements of Article 28 of the EU GDPR and UK GDPR. The Service Provider may process such Personal Data only for the purposes agreed with us and within the scope of the applicable contractual arrangements, except where otherwise required by applicable law. Where a Service Provider acts as an independent or joint controller for particular processing activities, such processing is governed by applicable data protection law and, where applicable, the Service Provider's own privacy information. Appropriate safeguards are applied to international data transfers as described in Section 6.

AppProvided by
Functional Services Providers
React Native
Google ML Kit
iOS 13 Native OCR
Mac OS Catalina Project Catalyst
Hetzner
Vercel
PlanetScale
Axiom
Amazon Web Services (AWS), including Amazon Textract and Amazon Bedrock (Amazon Nova)
Account Management Providers
Stripe Integration
Revenue Cat
Amazon Web Services
Typescript
Intercom
Clerk
Analytics Services Providers
Google Tag Manager
Firebase
You can opt out via email.
Google Analytics
Sentry
PostHog
Meta (Facebook) Pixel
Open Banking Integration Providers
SaltEdge

Amazon Web Services – Document and AI Processing  In addition to the infrastructure services described above, Amazon Web Services (AWS) is used for automated document and receipt processing. Depending on the Service and functionality used, this includes Amazon Textract for optical character recognition and document analysis and, in the Budget and Expense Services, Amazon Bedrock with Amazon Nova models for AI-assisted receipt processing as described in Section 2.1.  Amazon Bedrock EU Geographic Cross-Region Inference may be used as described in Section 6. Information regarding the retention and processing of inputs and outputs by Amazon Bedrock and Amazon Nova is provided in Section 5.  According to AWS, customer inputs and model outputs for the Amazon Nova models used by docomondo are not used to train Amazon Nova or other Amazon Bedrock models. Panera has not enabled Amazon Bedrock Model Invocation Logging.

Data Transfers Outside the UK/EEA:

Some of our Service Providers may process Personal Data outside the United Kingdom or European Economic Area (EEA). Where such transfers occur, we apply the transfer mechanisms and safeguards required by applicable data protection law, as described in Section 6 of this Privacy Policy.

11. Links To Third-party Apps And Sites

Our Service may contain links to sites or apps that are not operated by us. If you click a third-party link, you will be directed to that third party’s site or app.

Third-party apps, websites or services may include providers that Panera intentionally integrates or links to in order to provide particular functionality, such as payment, subscription or open banking services. The fact that Panera integrates or redirects Users to such a third-party service does not make Panera responsible for the independently operated app, website or service, its content, availability, terms, security or data processing activities for which the third party acts as an independent controller, except to the extent otherwise required by applicable law. This does not affect Panera's own obligations under applicable data protection law in relation to the selection and use of Service Providers or the disclosure of Personal Data to them.

12. Children’s Privacy

The age requirements applicable to the use of the docomondo Services are set out in Section 3.2 of our Terms and Conditions and may vary depending on the User's country of residence. Users are responsible for ensuring that they meet the applicable age requirements and, where required, that the necessary consent or authorisation of a parent or legal guardian has been obtained.Panera does not routinely request or verify a User's age and therefore may not know whether a User is a minor. Where required by applicable law in connection with a processing activity based on consent, Panera may take reasonable measures to obtain or verify any required parental or guardian consent.If Panera becomes aware that a person is using the Services contrary to the applicable age requirements or that Personal Data has been provided or processed without any legally required parental or guardian consent, Panera may take appropriate measures, including requesting further information, restricting or terminating access to the Services and, where appropriate and legally permissible, deleting the relevant Personal Data. If you are a parent or legal guardian and believe that a minor is using the Services contrary to the applicable age requirements, please contact us at privacy@docomondo.com

13. Changes to This Privacy Policy

We may update our Privacy Policy from time to time.

We will notify you via email and/or a prominent notice on our Website, prior to the change becoming effective and update the effective date at the top of this Privacy Policy, but we encourage you to review this Privacy Policy periodically for any changes.

Changes to this Privacy Policy are effective when they are posted on this page.

14. Language Availability and Legal Interpretation

This Privacy Policy may be provided in multiple languages for the convenience of users across different jurisdictions. In the event of any inconsistency, ambiguity, or conflict between a translated version and the original English version, the English version shall prevail and be deemed the authoritative and legally binding version. We recommend referring to the English version for the most accurate and complete understanding of your rights and our obligations.

If you have any questions regarding the interpretation of this Privacy Policy or require further clarification, please contact us at privacy@docomondo.com.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at

Panera Tec AG
Im Besch 21
9494 Schaan
Liechtenstein
privacy@docomondo.com  

We ("Docomondo", "us", "we", or "our") are committed to protecting your privacy and ensuring transparency in how your personal data is collected and processed across all our services

This Privacy Policy applies to all users of the docomondo Service, which includes:

Arrow Icon