ID cards, vehicle papers, SEPA mandates: how Zevra protects your customers' data
A registration case contains your customer's ID copy, registration certificate, bank details and signature. This page describes specifically where this data is stored, how it is encrypted, who sees it and when it is deleted.
Can I hand customer data to an online registration service at all?
Yes – processing is explicitly provided for in the i-Kfz procedure: the applicant authorises the registration service, and the Vehicle Registration Ordinance governs power of attorney, identification and data transmission. Zevra processes the data as a processor on your behalf.
What matters is how the service handles it. Zevra has been in operation since 2026 and names procedures and figures here instead of seals: field encryption, hash chain in the log, backups in 3 locations, 14 days of recovery, deletion periods by law.
Where the data is stored – and how it is protected
Hosting at Hetzner Online GmbH
Operated on servers of Hetzner Online GmbH (Gunzenhausen, Germany) in an EU data centre (Finland). The GDPR applies there without restriction; encrypted backup copies are additionally stored in Nuremberg.
Fields and documents encrypted
Personal fields are stored encrypted in the database (Fernet: AES with HMAC), uploaded documents encrypted on disk. Passwords exist only as scrypt hashes.
Transport encrypted only
TLS for portal and website, HSTS valid for 2 years, Content Security Policy, no embedding in third-party pages (X-Frame-Options DENY).
Access
Two-factor login (TOTP) can be enabled per user, limit of 5 login attempts per minute (protection against password guessing), staff accounts with roles, activity log in the portal.
What happens technically with a power of attorney
From signature to audit – every stage leaves a trace.
Signature by QES
Power of attorney and SEPA mandate are signed with a qualified electronic signature under the eIDAS Regulation (EU) No 910/2014 via Verimi.
Stored on the case
The signed power of attorney is stored encrypted on the case and available for review and audit.
Log with hash chain
Every step is logged; every row carries an HMAC over its predecessor. The chain is checked automatically every day at 04:10.
Transmission to the authority
The application goes via the large-customer interface of the KBA to the competent registration authority – not by e-mail, not by fax.
Backup, deletion, access
Daily backup, 3 locations
Every night at 03:30 an encrypted backup of database and documents, recoverable 14 days back, in 3 storage locations – recovery is tested.
Delete by purpose, keep by law
Invoice data stays for 8 years (§ 147 AO). ID copies are not accounting records and are kept no longer than necessary after the case is closed.
Access and export
Dealers can export their data as an Excel file; we answer access requests under Art. 15 GDPR within the statutory period of 1 month (Art. 12 GDPR).
Who besides Zevra sees your data
- The competent registration authority and the Kraftfahrt-Bundesamt – as recipients of the application in the i-Kfz procedure.
- Verimi as trust service provider for your customer's qualified electronic signature.
- Sunstone UG (haftungsbeschränkt), Bielefeld, as cooperation partner for the connection to the large-customer interface – involved as a processor.
- Hetzner Online GmbH as hosting provider. No advertising networks, no trackers, no third-party analytics – neither in the portal nor on this website.
Imprint · Privacy · Car dealerships · Wissen
Frequently asked questions about data security
Are the servers in Germany?
Is Zevra certified to ISO 27001?
Does my dealership need a data processing agreement?
What happens to the ID copy after registration?
Can I document cases and powers of attorney for an audit?
Read more
Zevra is the B2B platform for digital vehicle registration for car dealers, registration services and fleets: cases are entered in the dealer portal and filed nationwide by power of attorney with qualified electronic signature – from €10 per registration, no base fee, no minimum volume.