Compliance | D-App
Good to know

Not a federal government service.

The D-App is an independent, private initiative – by citizens, for citizens.

Who's behind it →
D App

Language

DEDeutsch ENEnglish
Log inSign up

Security, regulation, sovereignty

Compliance.Proven, not claimed.

Anyone handling income, rent and ID documents must be able to explain what happens to them. Here's what we adhere to, how far we've come and what's still missing. Every commitment refers to a chapter of our guidelines.

{{ nDone }}Implemented
{{ nWip }}In progress
{{ nPlan }}Planned

In short

Your data.Safe with us.

You're uploading your ID or rental agreement. Here are the answers to the questions you're asking yourself.

All 15 commitments in detail ↓

Where is my data stored?

In Germany.

Only in certified data centres run by German providers. Nothing leaves the country.

Implemented

Who sees my documents?

Only you and your office.

Your details only go to the office your application goes to. No one else.

Implemented

Do you sell my data?

No. Never.

Your data isn't our business model. No selling, no advertising.

Implemented

Can I delete my data?

Yes, any time.

You delete your account directly in the app. All documents and details are then removed completely.

Implemented

Is my Safe encrypted?

Yes, fully.

Documents are encrypted in transit and at rest. Without your consent, no one sees them – not even us.

Implemented

Who decides on my application?

Always the office.

The D-App helps you fill in and submit. The decision of the responsible office is binding.

Implemented
01

Security.Because it's your data.

Applications contain the most personal information there is about you. We protect it as if it were our own, and have that audited externally.

Guidelines, chapter 2
Zusagen, {{ secCount }}
{{ c.t }}

{{ c.d }}

Leitlinien {{ c.ref }}{{ c.basis }}

{{ c.s }}

No entries with this status.

02

Regulation.More than required.

We comply with current law and already follow rules that are yet to become binding. Where there's no obligation, we commit ourselves.

Guidelines, chapters 3 to 5
Zusagen, {{ regCount }}
{{ c.t }}

{{ c.d }}

Leitlinien {{ c.ref }}{{ c.basis }}

{{ c.s }}

No entries with this status.

03

Sovereignty.Made in Germany. And open.

Public services must not depend on a single corporation's platform. That's why your data stays in Germany and our foundation is open.

Guidelines, chapter 6
Zusagen, {{ souCount }}
{{ c.t }}

{{ c.d }}

Leitlinien {{ c.ref }}{{ c.basis }}

{{ c.s }}

No entries with this status.

Guidelines

One document.Every commitment.

Our guidelines set out how we handle security, law and dependencies. They apply to everyone at Verwaltungssprung GmbH and to every service provider we work with. We document every change here.

Versions

1.024.09.2026First publication
Contents
01Scope and principles
02Information security
03Privacy
04Artificial intelligence
05Regulatory context
06Technological sovereignty
07Transparency and disclosure
08Reporting channels and accountability

Found something? Tell us.

Report a vulnerability

Please report vulnerabilities to us before publishing them. We follow up on every report and keep you updated.

security@d-app.com
Privacy

Access, rectification, erasure or objection: exercise your GDPR rights here.

datenschutz@d-app.com
Your contact
Christian Aretz
Christian Aretz Information Security and Data Protection Officer
cra@d-app.com