Skip to content

Privacy Policy

This policy informs you in accordance with Art. 13 and 14 of the General Data Protection Regulation about which personal data we process, for what purpose, on what legal basis and for how long — and what rights you have in this regard.

Section 14 separately regulates data processing according to Art. 28 GDPR in the event that you use our infrastructure to process your own personal data. Section 6 lists each cookie used individually with its purpose and term.

Controller
ENTRONYX Deutschland GmbH
Version
3 October 2026
Supervisory authority
LDI NRW
Contact
datenschutz@entronyx.cloud

Note: ENTRONYX CLOUD is a demonstration project. This text is simulated and has no legal effect; in particular, it does not replace legal review.

  1. 1.Controller

    Paragraph 1: The controller responsible for the processing described on this website and within the scope of our services within the meaning of Art. 4 No. 7 GDPR is:

    Controller

    ENTRONYX Deutschland GmbHRobert-Perthel-Str. 71-7350739 CologneGermany
    Brand
    ENTRONYX CLOUD
    Privacy enquiries
    datenschutz@entronyx.cloud
    Data protection officer
    dsb@entronyx.cloud

    Paragraph 2: If you use our infrastructure to process your own personal data, you are the controller for this processing and we are the processor. The details are set out in section 14 of this policy.

  2. 2.Data protection officer

    Paragraph 1: We have appointed an external data protection officer. You can reach them at dsb@entronyx.cloud or by post at our address with the addition “Data protection officer — confidential”.

    Paragraph 2: Post addressed to the data protection officer is forwarded unopened. They are bound to secrecy, including towards the management.

  3. 3.Principles of our processing

    Paragraph 1: We only process personal data insofar as this is necessary to provide a functional website and our services, or if a legal basis permits this.

    Paragraph 2: We do not evaluate content data that you store or transmit on our infrastructure. We do not look at files in your volumes, objects in your buckets, or the content of your traffic, except in the exceptional cases mentioned in section 14 paragraph 4.

    Paragraph 3: We do not sell or rent personal data. We do not profile for advertising purposes and do not integrate third-party analytics or advertising networks.

  4. 4.Processing purposes, legal bases and storage periods

    Paragraph 1: The following overview lists all processing operations that we carry out as a controller. The stated storage periods begin when the respective processing purpose ceases to apply.

    Processing according to Art. 13 para. 1 and 2 GDPR
    PurposeData categoriesLegal basisStorage period
    Provision of the websiteIP address, date and time, requested resource, status code, transferred data volume, referrer, browser user identifierArt. 6(1)(f) GDPR — legitimate interest in stable and secure operations30 days
    Attack mitigationIP address, request pattern, signature matches of the filterArt. 6(1)(f) GDPR — legitimate interest in the integrity of the systems90 days
    Audience measurement of the website with Google AnalyticsVisited pages, time on site, origin of the visit, device and browser details, approximate location, events in the checkout process, random identifier in the cookie; for logged-in customers a user identifier (checksum of the customer number); aggregated data on age, gender and interests with Google signalsArt. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG — consent, revocable at any time14 months, cookies 13 months
    Website audience measurement without a cookie (custom method)Visited pages, time on site, referring domain, campaign identifier, device class, browser, operating system, language, country; instead of the IP address, a daily changing checksumArt. 6(1)(f) GDPR — legitimate interest in improving the service; objection possible at any time400 days
    Registration and management of the customer accountName, company, address, email, telephone, VAT ID, registry data, login logsArt. 6(1)(b) GDPR — performance of pre-contractual measures and the contractContract term, followed by commercial law retention periods
    Identity verification for business customersCommercial register extract, ID data of the authorised representativeArt. 6(1)(c) GDPR in conjunction with Sec. 154 AO and legitimate interest in fraud prevention5 years after the end of the contract
    Provision of infrastructure servicesResource identifiers, usage data, consumption values, operations logsArt. 6(1)(b) GDPR — performance of a contract12 months, consumption values 36 months
    Billing and accountingInvoice data, payment data, bank details, dunning historyArt. 6(1)(b) and (c) GDPR in conjunction with Sec. 147 AO and Sec. 257 HGB10 years
    Processing of support requestsTicket content, contact details, technical details, log extracts if applicableArt. 6(1)(b) GDPR, for requests without a contract Art. 6(1)(f) GDPR36 months after completion
    Access control in data centresName, ID data, time of access, biometric reference pattern (palm vein)Art. 6(1)(f) GDPR, biometric data only with consent according to Art. 9(2)(a) GDPRAccess logs 24 months, biometric reference until revocation
    Video surveillance of the data centresImage recordings of the outdoor areas, entrances and technical areasArt. 6(1)(f) GDPR — protection against unauthorised access and property damage90 days
    Sending of status messagesEmail address, selected services and regions, sending logArt. 6(1)(b) GDPR for contract-related messages, otherwise Art. 6(1)(a) GDPRUntil cancellation, sending log 6 months
    Application processApplication documents, interview notes, assessmentsSec. 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR6 months after completion, with consent 24 months
    Fulfilment of reporting obligationsAffected data of the respective incidentArt. 6(1)(c) GDPR in conjunction with Art. 33 GDPR and the requirements of the NIS2UmsuCG3 years
    Commercial and tax retention obligations under Section 257 HGB and Section 147 AO take precedence over deletion. Affected data is blocked for further processing and deleted after the period expires.

    Paragraph 2: Where we rely on a legitimate interest under Art. 6 para. 1 lit. f GDPR, we have carried out a balancing test. We will provide you with the result of this balancing test upon request.

    Empty steel drawer, pulled completely out of a dark filing cabinet and photographed slightly from above; bare suspension rails on both long sides, the label holder on the front is blank.
    Blocking is not deleting: data with an ongoing retention obligation remains stored, but is blocked for any other processing — it is only deleted when the final period has expired.

    The shortest period in this overview is 30 days — it applies to the website access logs. The longest fixed period is ten years, and it does not stem from data protection law, but from Section 147 AO and Section 257 HGB.

  5. 5.Server log files

    Paragraph 1: When you visit this website, your browser automatically transmits information to the server. This is stored in a log file.

    • truncated IP address (the last two octets for IPv4, the last 80 bits for IPv6 are removed before storage)
    • date and time of access with time zone
    • name and URL of the requested resource
    • transferred data volume and HTTP status code
    • referring address, if transmitted by the browser
    • browser identification including version and operating system

    Paragraph 2: Storage is required to ensure trouble-free operations and to investigate cases of abuse. The data is automatically deleted after 30 days. It is not merged with other data sets.

    Paragraph 3: Notwithstanding this, logs required to investigate a specific attack are kept in full for up to 90 days. We document the decision for this, including the reason and scope.

  6. 6.Cookies and similar technologies

    Paragraph 1: We use cookies that are necessary for operations. Two further cookies are used for audience measurement with Google Analytics; they are only set if you consent. For non-essential cookies, we obtain your consent in accordance with Section 25 para. 1 TDDDG; you can revoke this at any time.

    Paragraph 2: Google Analytics is not loaded without your consent: no measurement cookies are set and no data is transmitted to Google. We do not run personalised advertising; the functions for this are disabled. Recognition across multiple websites only takes place if you also consent to Google Signals (paragraph 5).

    Cookies used with purpose and duration
    NamePurposeClassificationTerm
    enx_sessionSession identifier after login in the customer area; httpOnly, only via HTTPS. The server only knows a checksum of it. Without this cookie, login is technically impossible.Technically required12 hours, with “Keep me logged in” 30 days
    enx_kontoFirst name and customer identifier for the header after login. No secret, no session — just the label for the account entry.Technically requiredlike enx_session
    enx_2faIntermediate state between password and one-time code with active second factor; signed, without account data.Technically required10 minutes
    ex_csrfToken to prevent cross-site request forgery for forms in the panel.Technically requiredEnd of session
    ex_lbAssignment of the session to an application node behind the load balancer.Technically required4 hours
    ex_localeSelected language and number format of the interface.Technically required12 months
    ex_consentSaves your decision on optional cookies so that the prompt does not appear on every visit.Technically required12 months
    ex_cartContent of the cart in the configurator so that a started configuration is not lost.Technically required30 days
    enx_messung_ausRecord of your objection to cookieless audience measurement; is only set if you object.Technically required12 months
    _gaGoogle Analytics: random identifier by which this browser is recognised on subsequent visits. Only set if you consent.Optional, consent according to Sec. 25(1) TDDDG13 months
    _ga_TY33Z66ZEZGoogle Analytics: start, count and duration of the sessions of this browser. Only set if you consent.Optional, consent according to Sec. 25(1) TDDDG13 months
    All cookies are set with the attributes Secure, HttpOnly (where technically possible) and SameSite=Lax. The domain is restricted to entronyx.cloud.

    Audience measurement with Google Analytics

    Paragraph 3: With your consent, we use Google Analytics 4, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It shows us which pages are visited, where visits come from and at which point an order is abandoned. The following is recorded:

    • visited pages with time, duration and scroll depth
    • clicks on outbound links and downloaded files
    • the referring address and campaign identifiers of a visit
    • device type, operating system, browser, screen size and language
    • the approximate location (country, region, city); according to Google, the IP address is used for this and not stored
    • checkout events: a product in the cart, start and completion of an order with order number, items and amount
    • whether a request was sent, a customer account created or a login performed
    • for logged-in customers, a user identifier so that visits across multiple devices are assigned to the same customer account — a checksum of your customer number, not the customer number itself
    • a random identifier in the _ga cookie, by which your browser is recognised on subsequent visits

    Paragraph 4: We do not transmit name, email address, postal address, payment data and the customer number in plain text. Via the user identifier, we recognise in our analysis which visits belong to which customer account; Google cannot do this from the identifier alone. We shorten addresses of this website before transmission: access tokens, the identifier of the payment page as well as order, invoice and project identifiers in addresses of the customer area are removed, domain names in order items are shortened to their extension. Pages whose address contains an access token are not measured.

    Paragraph 5: If you also consent to Google signals, Google links the measurement data with information from your Google account — provided you are logged in there and have allowed personalised advertising. We only receive aggregated analyses from this: age groups, gender, interests and cross-device usage, never information about a single person. For this, Google reads its own cookies on its domains (google.com, doubleclick.net) and can thereby recognise your visit across multiple websites. What Google stores for this in your Google account can be viewed and deleted there under “My Activity”. Google signals can be rejected separately from the measurement.

    Paragraph 6: The legal basis is your consent according to Art. 6 (1) (a) GDPR and Sec. 25 (1) TDDDG. Google processes the data on our behalf according to Art. 28 GDPR. In doing so, Google LLC in the US may gain access; the basis is the adequacy decision of the European Commission on the EU-US Data Privacy Framework, under which Google LLC is certified, supplemented by standard contractual clauses. Google deletes data that can be assigned to an identifier after 14 months; aggregated analyses without an identifier are retained. The measurement cookies expire 13 months after the first visit.

    Paragraph 7: You can revoke your consent at any time with effect for the future or limit it to measurement without Google signals — at this point and with immediate effect: The revocation ends the transmission and deletes the measurement cookies in this browser.

    Your decision regarding measurement with Google Analytics

    Reach measurement without cookie

    Paragraph 8: Independent of Google Analytics, we count visits to this website using our own procedure. It does not set a cookie, stores nothing on your device and reads nothing from it. It runs on our own systems; third parties are not involved. We record:

    • the requested page without query string; identifiers and access tokens in addresses are replaced by a placeholder
    • time, active time spent and reading depth
    • the referring domain and campaign identifier of the first request of a visit; we do not store click identifiers from advertising networks
    • device class, browser and operating system without version details, the language of the browser and, if transmitted, the country
    • clicks on outbound links (only the target domain) and adding a product to the cart (only the product line)
    • that a registration, an order, a payment receipt or a request has taken place — for orders and payment receipts with order number and amount

    Paragraph 9: We do not store your IP address and the identifier of your browser. From both and a random value that changes daily, we form a checksum; by this we recognise which requests of a day belong to the same visit. We delete the random value after two days. After that, even we can no longer trace the checksum back to an address, and we do not recognise your browser across the day boundary.

    Paragraph 10: If you register or order, we note on your customer account and on the order how you came to us on that day: source, type of access, campaign, referring domain and landing page. We do not link a history of the pages you have visited with your account in this procedure.

    Paragraph 11: The legal basis is our legitimate interest according to Art. 6 para. 1 lit. f GDPR to understand the use of our offering and to improve it. We delete the measurement data after 400 days.

    Paragraph 12: You can object to this measurement at any time (Art. 21 GDPR) — right here and with immediate effect. If your browser sends the “Global Privacy Control” or “Do Not Track” signal, we evaluate this as an objection and do not measure. The switch places a note in the storage of your browser; it serves solely to respect your objection. We count orders and payment receipts even after an objection, but then without assignment to a visit.

    Your opt-out from audience measurement

    You have not opted out. Visits are counted without a cookie.

    Manage cookies in the browser

    Paragraph 13: You can delete or block cookies via your browser settings. If technically necessary cookies are blocked, logging into the customer panel is not possible.

  7. 7.Categories of recipients

    Paragraph 1: Personal data is only passed on to the following categories of recipients and only insofar as this is necessary for the respective purpose:

    • Processors according to Art. 28 GDPR, which are listed individually in section 14
    • Google Ireland Limited as processor for reach measurement according to section 6 — only if you have consented
    • Payment service providers and credit institutions for processing payments
    • Tax consultancy and auditing within the scope of statutory audits
    • Legal advice and debt collection service providers for the enforcement of claims
    • Authorities and courts, insofar as a legal obligation exists
    • Auditing companies within the scope of certification and attestation procedures

    Paragraph 2: We examine official requests for information on a case-by-case basis for legal basis, jurisdiction and proportionality. Insofar as legally permissible, we inform the data subject or the affected customer account before disclosure.

  8. 8.Transfers to third countries

    Paragraph 1: We process personal data exclusively in data centres in Germany and Finland, i.e. within the European Union. A transfer to a third country within the meaning of Chapter V GDPR only takes place in the cases of paragraph 2.

    Paragraph 2: The contractors listed in section 14 process within the European Union. There are three exceptions. The first is payment processing: our payment service provider Stripe Payments Europe, Ltd. (Ireland) uses sub-processors in the USA for this, in particular Stripe, Inc. The basis for the transfer are standard contractual clauses according to Art. 46 para. 2 lit. c GDPR as well as the certification under the EU-US Data Privacy Framework. This exclusively affects payment and invoice data — never content or usage data of your systems. The second is the sending of emails: our dispatch service provider Plus Five Five, Inc. (USA, service “Resend”) receives the recipient address, subject and content of the messages sent by this website and the customer account, as well as their delivery status; dispatch is via servers in Ireland. The basis for the transfer are standard contractual clauses according to Art. 46 para. 2 lit. c GDPR. This never affects data from your systems either. The third exception only applies with your consent: when measuring the reach of this website with Google Analytics (section 6 paragraphs 3 to 7), Google LLC in the USA may gain access to the measurement data; the basis is the adequacy decision on the EU-US Data Privacy Framework. Without consent, this transfer does not take place, and it never affects data from your systems. We announce further changes according to section 14 paragraph 5 at least 30 days in advance.

    Centre aisle of a data centre hall: two rows of black server cabinets converge towards a vanishing point, narrow copper-coloured status lights in the perforated metal doors, cable trays in parallel tracks above, the floor made of polished concrete.
    The processing location is fixed with the order: five locations in Germany and Finland, all in the legal area of the European Union. The platform does not process outside this legal area; the three exceptions — payment data, the sending of emails and the measurement of the website with consent — are in paragraph 2.

    Paragraph 3: Decisive for access by an authority is not only the location of storage, but the law to which the operating company is subject. This company is based in Germany; there is no parent company and no intermediary company in a third country. An explanation of the legal situation, including the US CLOUD Act, can be found under Security and Compliance.

  9. 9.Customer account, contract performance and support

    Paragraph 1: A customer account is required to use our services. Mandatory fields are marked in the registration form; without them, a contract cannot be concluded.

    Paragraph 2: We log login attempts with the time, truncated IP address and result to detect unauthorised access. We retain these logs for twelve months and display them to you in the customer panel. Employees who manage customer accounts can see in our internal administration which customer accounts are currently logged in and active, and when a customer account was last active (account name, time of last activity, browser and operating system), so that they can offer assistance and answer questions while you are working on your account. We do not record which pages you visit in the customer panel. The legal basis is our legitimate interest in providing timely support (Art. 6 (1) (f) GDPR); you can object to this display.

    Paragraph 3: We store support requests with their history so that follow-up questions can be processed without you having to explain the issue again. Please do not submit personal data of third parties in tickets unless it is necessary for processing.

  10. 10.Job applications

    Paragraph 1: We process application documents exclusively for carrying out the application process on the basis of Section 26 (1) BDSG.

    Paragraph 2: After the process is complete, we delete the documents after six months. This period takes into account the deadline for filing a lawsuit under Section 61b ArbGG in conjunction with Section 15 AGG. With your explicit consent, we will add you to an applicant pool for 24 months.

    Paragraph 3: We do not use automated pre-selection or software to evaluate application videos or voice recordings.

  11. 11.Status reports and notifications

    Paragraph 1: As a contract customer, you receive operationally necessary notifications about disruptions, maintenance windows and security-relevant events. These notifications are part of the service and cannot be unsubscribed from, provided they concern resources you actually use.

    Paragraph 2: You will only receive additional notifications — such as for regions or products you do not use — if you explicitly select them in the customer panel. You can change this selection at any time.

    Paragraph 3: We do not measure open rates or clicks in our emails. No tracking pixels or redirected links are used.

  12. 12.Your rights

    Paragraph 1: You have the following rights regarding us. Please send requests to datenschutz@entronyx.cloud; we will respond within one month in accordance with Art. 12 (3) GDPR.

    Data subject rights under Chapter III GDPR

    Art. 15 — Access
    You can request information about whether and which personal data we process about you, for what purposes, to which recipients it is disclosed and how long it is stored. We will provide a copy upon request.
    Art. 16 — Rectification
    We rectify incorrect data without delay. You can have incomplete data completed. You can change the master data of your account yourself at any time in the customer panel.
    Art. 17 — Erasure
    You can request erasure, provided there is no statutory retention obligation to the contrary. We restrict the further processing of documents subject to commercial and tax retention obligations instead.
    Art. 18 — Restriction
    Instead of erasure, you can request the restriction of processing, for example while we verify the accuracy of contested data.
    Art. 20 — Data portability
    We will provide you with data that you have provided to us in a structured, commonly used and machine-readable format. We also provide an export via the API for your content data.
    Art. 21 — Objection
    You can object to processing based on a legitimate interest on grounds relating to your particular situation. We will then stop the processing unless we can demonstrate compelling legitimate grounds.
    Art. 7 para. 3 — Withdrawal of consent
    You can withdraw your consent at any time with effect for the future. The lawfulness of the processing carried out up to that point remains unaffected.
    Art. 22 — No automated decision-making
    There is no solely automated decision-making with legal effect. The credit check before granting a credit limit is finally assessed by a person.

    Paragraph 2: For identity verification, we may request additional information if there are reasonable doubts about your identity. We only request information that is necessary for identification.

  13. 13.Right to lodge a complaint with the supervisory authority

    Paragraph 1: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

    Paragraph 2: The authority responsible for us is:

    Competent supervisory authority

    State Commissioner for Data Protection and Freedom of Information North Rhine-WestphaliaKavalleriestraße 2-440213 Düsseldorf

    Paragraph 3: A complaint to the supervisory authority does not require you to have contacted us first. However, we recommend doing so, as most issues can be resolved more quickly this way.

  14. 14.Data processing agreement under Art. 28 GDPR

    Paragraph 1: If you use our infrastructure to process personal data, we act as a data processor. The data processing agreement (DPA) is concluded with the main contract and is part of the contract without a separate request. There is no additional charge for this.

    Subject matter and scope

    Paragraph 2: The subject matter is the provision of computing, storage and network capacity. You determine the nature and purpose of the processing, the categories of data subjects and the type of data; we have no influence on this and do not take note of the content.

    Paragraph 3: We process data exclusively according to your documented instructions. Text form is sufficient. If we consider an instruction to be unlawful, we will inform you and may suspend execution until the matter is clarified.

    Paragraph 4: Content data is only accessed in three cases: upon your explicit instruction as part of a support request, to avert a specific and acute threat to operations, or on the basis of a valid official order. Every access is logged and displayed to you in the customer panel.

    Sub-processors

    Paragraph 5: By concluding the contract, you grant general authorisation to engage the following sub-processors. We will announce changes at least 30 days in advance; you can object within this period and terminate the contract extraordinarily if we do not remedy the objection.

    Sub-processors under Art. 28 (2) and (4) GDPR — as of 3 October 2026
    ContractorCountry of residenceServiceScopeBasis
    ENTRONYX Deutschland GmbHGermanyPlatform operations, control plane, supportAll locations in Germany and FinlandMain contractor, Art. 28 GDPR
    Stripe Payments Europe, Ltd.IrelandProcessing of card payments, direct debits and bank transfers, invoicingBilling address, email address, payment data; no content or usage dataArt. 28 GDPR; subcontractors in the US based on standard contractual clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework
    Plus Five Five, Inc. (“Resend” service)USASending confirmations, invoices, security and status messages by emailEmail address, subject, message content, delivery status; no content or usage data of your systemsArt. 28 GDPR; transfer to the US based on standard contractual clauses (Art. 46(2)(c) GDPR); sending via servers in Ireland
    Provider for credit reportsGermanyCheck before granting a credit limit from €10,000Company data, address, no usage dataArt. 6(1)(f) GDPR, information contract
    Certified waste management companiesGermany and FinlandMaterial recycling of decommissioned hardwareNo personal data; data carriers are previously wiped and destroyedArt. 28 GDPR
    External auditing companiesGermanyConducting audits according to ISO 27001, ISO 50001 and BSI C5Inspection of logs and configurations as part of the auditConfidential commissioning, non-disclosure agreement
    The current version of this list is available in the customer panel and can be subscribed to as a notification. We also list contractors who do not have access to IT systems — transparency is more important to us than a short list.

    Audit rights and evidence

    Paragraph 6: You can satisfy yourself that we are complying with our obligations. As evidence, we provide the C5 attestation, the ISO 27001 certificate with scope, and the documentation of technical and organisational measures under Art. 32 GDPR.

    Paragraph 7: An on-site audit is possible during normal business hours with 30 days' notice, at most once per calendar year, unless there is a specific reason. Access to operational areas requires compliance with our access rules; recordings are not permitted there.

    Deletion and return

    Paragraph 8: After the end of the contract, we delete your data. Before this, there is a grace period of 30 days during which you can export data; upon request, we can shorten this period to zero. Block and object storage is deleted by destroying the key and subsequently overwriting it.

    The technical and organisational measures under Art. 32 GDPR are described in detail under Security and compliance, including encryption, key management, tenant isolation and reporting deadlines for incidents.

  15. 15.Changes to this policy

    Paragraph 1: We will adapt this policy if the legal situation, our services or the processing change. Each version bears a date; we will provide previous versions upon request.

    Paragraph 2: We will also inform contract customers of material changes affecting your rights by email. A mere notice on the website is not sufficient for us.

Version

Document status

Effective since
Replaces the version dated

We will also inform contract customers of material changes to this policy by email. Previous versions and the list of sub-processors in their respective versions are available at datenschutz@entronyx.cloud.

Etched metal plaque on a concrete wall: milled nodes and lines as a network diagram, with the ENTRONYX CLOUD wordmark in the header.

Section 14 names six contractors, each with their country of establishment, service, scope and basis; with the exception of payment processing (Section 8 paragraph 2), none of them process outside the European Union. We will announce any changes to this list at least 30 days in advance; within this period you can object and, if we do not remedy the objection, terminate extraordinarily.

Section 14 · Data processing