Privacy Policy
How Dorium collects, uses and protects personal data when you use our THG platform, dashboard and related services.
This Privacy Policy explains how Dorium (“we”, “us”) processes personal data when you visit our website, create an account, submit a THG application or contact support. It is written for users in Germany / the EU and is intended to align with the GDPR.
Last updated: July 2026. This page is product demo content and should be reviewed by counsel before production use.
1. Controller
Dorium operates the platform available at this website. For privacy requests, use the contact form and mark the subject as “Privacy”.
2. Data we process
Account & profile
- Name, email, password hash, account type (individual / business)
- Optional company details (tax IDs, representative) for business accounts
- IBAN and payout-related banking data when you provide them
Applications & documents
- Vehicle data (VIN, plate, registration details, class selection)
- Uploaded Fahrzeugschein files and review metadata
- UBA-related fields completed during admin review
- Contract and payout status history
Usage & communications
- Session cookies required to keep you signed in
- In-app notifications and optional email notices about status changes
- Support messages you send via contact forms
We process documents only to verify eligibility, fulfil contracts and meet regulatory reporting needs related to THG workflows.
3. Purposes & legal bases
Purpose | Examples | Typical basis |
|---|---|---|
Provide the service | Account, applications, contracts, payouts | Contract (Art. 6 (1)(b)) |
Compliance | Record keeping, fraud prevention | Legal obligation / legitimate interests |
Product improvement | Aggregated usage insights | Legitimate interests |
Support | Responding to contact requests | Legitimate interests / contract |
4. Recipients
We may share data with processors that host infrastructure, send transactional email, or support document storage — under appropriate agreements. Where THG settlement requires intermediaries or authorities, we share only what is necessary for that purpose.
International transfers
If a processor is located outside the EEA, we use appropriate safeguards (such as Standard Contractual Clauses) where required.
5. Retention
- Account data — while your account is active and for a limited period afterwards as needed for disputes or legal retention.
- Application & document files — for the lifetime of the claim workflow and applicable retention rules.
- Support messages — for handling your request and internal quality control.
6. Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and object to certain processing. You may also lodge a complaint with a supervisory authority.
How to exercise rights
Contact us via /contact. We may need to verify your identity before fulfilling a request.
7. Cookies
Essential cookies keep sessions secure after login. We do not use advertising cookies on the core application flows described here.
8. Changes
We may update this policy. Material changes will be reflected on this page with a revised “Last updated” date.
Related: Terms of Service · AGB · About Us.