Skip to content

chore(legal): sync in-app DE privacy policy & terms to RUCH June 2026 finals#729

Open
TaprootFreak wants to merge 1 commit into
stagingfrom
feature/legal-docs-sync-2026-06
Open

chore(legal): sync in-app DE privacy policy & terms to RUCH June 2026 finals#729
TaprootFreak wants to merge 1 commit into
stagingfrom
feature/legal-docs-sync-2026-06

Conversation

@TaprootFreak

Copy link
Copy Markdown
Contributor

Summary

Syncs the in-app DE legal documents to the final versions David Lehner (RUCH Legal) circulated on 05 Jun 2026 (260605_Datenschutzerklaerung_App_final.docx, 260605_Nutzungsbedingungen_App_final.docx). Pure asset content update — no code, no UI.

Datenschutzerklärung (privacy_policy_de.md)

  • Yapeal AG added as data recipient; Sanctions-Screening added to the DFX AG entry
  • Legal basis restated (Vertrag + gesetzliche Pflichten; DSGVO Art. 6(1)); explicit consent + special-category note for biometric KYC data
  • Cross-border disclosure clause (SCC / DSG Art. 16f, DSGVO Art. 44ff)
  • Additional DSGVO rights (Art. 18/20/21) + supervisory authority (EDÖB)
  • Data-retention clause
  • Stand: Februar 2026Juni 2026

Nutzungsbedingungen (terms_of_use_de.md)

  • Tightened eligibility/geography clause (CH/UK/EEA residents + CH/DE/LIE/AT nationals; public offer CH/LIE/DE only; OFAC/embargo exclusion via the onboarding country & sanctions check) — aligns with the AML framework
  • DFX AGB URL; OR Art. 100(1) liability carve-out; material-change notice; mandatory-venue/consumer-protection reservation; contact email
  • Naming unified to RealUnit Aktientoken

Notes

  • Handbook legal-downloads block stays in sync (titles unchanged → assemble-handbook-legal.py produces no diff). The PDF/DOCX downloads are rebuilt by pandoc at deploy.
  • The legal_document golden uses an inline stub decoupled from the live asset → no golden regeneration needed.
  • Non-golden legal tests green locally (31 passed).

Deferred

  • EN finals (*_en.md) — David supplied DE only. Left unchanged; needs the English versions from RUCH.

Test plan

  • Analyze & Test green
  • Visual Regression green (no rendered change expected)
  • Handbook Build Check green
  • Legal reviewer (David) confirms wording matches the final docx

… finals

Brings assets/legal/{privacy_policy,terms_of_use}_de.md in line with the
final versions David Lehner (RUCH Legal) circulated on 05 Jun 2026.

Privacy policy:
- Add Yapeal AG as a data recipient and the sanctions/embargo screening to
  the DFX AG entry.
- Restate the legal basis (contract + statutory duties; DSGVO Art. 6(1));
  add explicit consent + special-category note for biometric KYC data.
- Add the cross-border disclosure clause (SCC / DSG Art. 16f, DSGVO Art. 44ff)
  and the additional DSGVO data-subject rights + supervisory authority.
- Add the data-retention clause.

Terms of use:
- Tighten the eligibility/geography clause (CH/UK/EEA residents + CH/DE/LIE/AT
  nationals; public offer CH/LIE/DE only; OFAC/embargo exclusion via the
  onboarding country & sanctions check).
- Reference the DFX AGB URL; add the OR Art. 100(1) liability carve-out, the
  material-change notice clause, mandatory-venue/consumer-protection reservation
  and the contact email.
- Unify naming to "RealUnit Aktientoken".

EN finals were not supplied by RUCH — assets/legal/*_en.md stay unchanged and
are tracked as a follow-up pending the English versions.
@TaprootFreak TaprootFreak marked this pull request as ready for review June 9, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant