Dosar.app
Privacy Policy
Last updated: August 31, 2026
This Privacy Policy explains how the operator of the Dosar.app service ("Dosar.app", "we", "us", or "our"), processes personal data in connection with the website (dosar.app), Telegram bot, and paid subscriptions. This document is intended to comply with the EU General Data Protection Regulation (GDPR) and the Romanian implementation thereof.
1. Data Controller
The controller of your personal data is a Georgian individual entrepreneur registered with the LEPL Revenue Service of Georgia. The controller's legal name, registered address, and further identification details are set out in Section 19 (Contact) at the bottom of this page and in our Impressum at dosar.app/en/impressum.
For all data-protection matters you may reach us at support@dosar.app.
2. EU Representative (Article 27 GDPR)
Because the controller is established outside the European Union but processes personal data of individuals in the EU, an EU representative under Article 27 GDPR is being appointed. Until the appointment is finalised, data subjects in the EU may contact us directly at support@dosar.app for any matter that would normally be addressed to the EU representative; we will update this section as soon as the representative is designated.
3. Scope
- the Dosar.app website (dosar.app);
- the Dosar.app Telegram bot;
- paid subscriptions delivered through the website and processed by our payment provider;
- related communications and support interactions.
4. Categories of Personal Data We Process
Website subscribers: email address; interface language; hashed session identifier; consent records (timestamp, IP, user-agent, text version); subscription tier and status; monitored dossier numbers you enter; optional text labels you attach to each dossier.
Telegram bot users: Telegram user ID; Telegram profile fields provided by the Telegram platform (username, first name, language code); interface language preference; dossier numbers you look up or track; referral relationships you initiate.
Payment records: Dodo Payments customer identifier, subscription identifier, transaction status. We do not receive, store, or process your full card number, CVV, or bank account details — these are processed exclusively by our Merchant of Record (Dodo Payments).
Technical data: IP address (truncated where possible), browser type, device information, operating system, referring URL, timestamps, request/response metadata, security and diagnostic logs.
5. Special Categories of Personal Data (Article 9 GDPR)
We recognise that information about your Romanian citizenship application may, indirectly, reveal information about your ethnic or national origin, and therefore falls within the special categories of personal data listed in Article 9(1) GDPR. This position aligns with the Court of Justice ruling in Case C-184/20.
We process such data only where you have given your explicit consent under Article 9(2)(a) GDPR. Consent is captured through a dedicated, clearly labelled checkbox at checkout, stored together with a timestamp, IP address, and the exact version of the consent wording accepted, and is available on request.
You may withdraw this consent at any time by writing to support@dosar.app. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
6. Legal Bases
We process personal data on the following legal bases:
- Article 6(1)(b) — performance of a contract, for account management, subscription delivery, monitoring the dossier(s) you subscribed to, and sending you notifications;
- Article 6(1)(c) — compliance with legal obligations, in particular tax, accounting and consumer-protection duties;
- Article 6(1)(f) — our legitimate interests, for service security, fraud prevention, product improvement, and answering support enquiries;
- Article 6(1)(a) — your consent, for optional analytics cookies and any communication that is not strictly necessary;
- Article 9(2)(a) — your explicit consent, for the special-category processing described in Section 5.
7. Purposes of Processing
- operating the manual dossier lookup on the website and Telegram bot;
- processing paid subscriptions and delivering monitoring/notification features;
- authenticating users through passwordless magic links;
- detecting fraud, abuse, or degradation of service quality;
- responding to your support requests and complaints;
- measuring aggregate usage and improving the service (where consent is given);
- complying with legal obligations and, where necessary, defending legal claims.
8. Sub-processors and Recipients
We rely on the following sub-processors, each contractually bound by data-protection obligations equivalent to those required under Article 28 GDPR:
- Dodo Payments (Merchant of Record) — subscription payments, invoicing, KYC/tax compliance;
- Railway Corp. — hosting infrastructure (databases, application containers);
- Resend — transactional email delivery (magic-link sign-in, receipts);
- Telegram FZ-LLC — delivery of bot messages, notifications, AND processing of Telegram Stars payments as merchant of record. Telegram Stars payment metadata (transaction id, timestamp, amount in XTR) is processed by Telegram FZ-LLC under their own Terms of Service and Payment Policy;
- Google LLC (Google Analytics / Google Tag Manager) — aggregate usage analytics, only where you have accepted analytics cookies.
9. International Transfers
Our sub-processors operate in the European Union, the United Kingdom, the United States, and other jurisdictions. Where personal data is transferred outside the European Economic Area (EEA) to a country without a European Commission adequacy decision, we rely on the Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914, supplemented by technical and organisational measures (encryption in transit and at rest, access restrictions, audit logging).
The data controller is established in Georgia (see Section 19 for identity details). Georgia is not covered by a European Commission adequacy decision. We rely on SCCs between the controller and each EU-based user (incorporated by reference into these Terms) together with a Transfer Impact Assessment. A copy of the SCCs and the assessment is available on request at support@dosar.app.
10. Retention
We retain personal data only as long as necessary to fulfil the purposes described above, unless a longer retention is required by law:
- Account and email address — for the lifetime of the account and 90 days after deletion (for backup rotation);
- Consent records (Article 9 consent, 14-day waiver) — 10 years after collection, for evidential purposes;
- Payment and billing records — 10 years, as required by tax law;
- Telegram bot activity logs — 12 months rolling;
- Website security and diagnostic logs — 90 days rolling;
- Support correspondence — 3 years after last message;
- Monitored-dossier subscriptions — until you cancel or delete the item, plus 30 days.
11. Your Rights
Subject to the conditions of the GDPR, you have the right to:
- access the personal data we hold about you (Article 15);
- have inaccurate personal data corrected (Article 16);
- have your personal data erased in certain circumstances (Article 17);
- have processing restricted (Article 18);
- receive your personal data in a portable format (Article 20);
- object to processing based on legitimate interests (Article 21);
- withdraw any consent you have given (Article 7(3));
- lodge a complaint with a supervisory authority (Article 77) — in the EU, this is your national Data Protection Authority. A directory is available at edpb.europa.eu/about-edpb/about-edpb/members_en.
12. Exercising Your Rights
To exercise any of the rights listed above, please write to support@dosar.app. We will respond within one month of receipt of your request, extendable by two further months for complex requests (in which case we will inform you within the first month). To protect your account, we may ask you to verify your identity before disclosing personal data.
There is no charge for exercising your rights unless the request is manifestly unfounded or excessive.
13. Automated Decision-Making
We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR that produces legal or similarly significant effects on you.
14. Children
The Service is not directed at children. You must be at least 18 years old to create an account or purchase a subscription. If we become aware that we hold personal data of a person under 18, we will delete it without undue delay.
15. Cookies
The website uses cookies and similar technologies. A separate Cookie Policy at dosar.app/en/cookies explains which cookies are used, their purpose, their duration, and how to manage your preferences.
The consent banner shown when you first visit the site records your choice for one year. You can withdraw or update your consent at any time via the same banner.
16. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest for databases, access controls, activity logging, isolation of production data from development environments, and regular review of sub-processors.
No security measure is perfect. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 GDPR.
17. Data Protection Officer
Given the scale and nature of processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. Data-protection matters are handled by the controller directly and by the EU representative referenced in Section 2.
For any question about this Policy, write to support@dosar.app.
18. Changes to This Privacy Policy
We may update this Policy from time to time. Material changes will be notified through the service (banner or email) at least 30 days before they take effect. The date of the most recent revision is shown at the top of this page.
19. Contact
Data controller (as recorded with the LEPL Revenue Service of Georgia):
ინდივიდუალური მეწარმე გრიგორიი ჩემერის (IE Grigorii Chemeris)
Registered address:
საქართველო, თბილისი, ნაძალადევის რაიონი, ც. დადიანის ქუჩა, N34, კორპუსი 7, კომერციული ფართი, შენობა N10, 0160
(Ts. Dadiani Street N34, Block 7, Commercial Space, Building N10, Nadzaladevi District, 0160 Tbilisi, Georgia)
Email: support@dosar.app
EU representative: being appointed. Contact us at support@dosar.app in the meantime.