Note: ENTRONYX CLOUD is a demonstration project. This text is simulated and has no legal effect; in particular, it does not replace legal review.
1.Controller
Paragraph 1: The controller responsible for the processing described on this website and within the scope of our services within the meaning of Art. 4 No. 7 GDPR is:
Controller
ENTRONYX Deutschland GmbHRobert-Perthel-Str. 71-7350739 CologneGermany- Brand
- ENTRONYX CLOUD
- Privacy enquiries
- datenschutz@entronyx.cloud
- Data protection officer
- dsb@entronyx.cloud
Paragraph 2: If you use our infrastructure to process your own personal data, you are the controller for this processing and we are the processor. The details are set out in section 14 of this policy.
2.Data protection officer
Paragraph 1: We have appointed an external data protection officer. You can reach them at dsb@entronyx.cloud or by post at our address with the addition “Data protection officer — confidential”.
Paragraph 2: Post addressed to the data protection officer is forwarded unopened. They are bound to secrecy, including towards the management.
3.Principles of our processing
Paragraph 1: We only process personal data insofar as this is necessary to provide a functional website and our services, or if a legal basis permits this.
Paragraph 2: We do not evaluate content data that you store or transmit on our infrastructure. We do not look at files in your volumes, objects in your buckets, or the content of your traffic, except in the exceptional cases mentioned in section 14 paragraph 4.
Paragraph 3: We do not sell or rent personal data. We do not profile for advertising purposes and do not integrate third-party analytics or advertising networks.
4.Processing purposes, legal bases and storage periods
Paragraph 1: The following overview lists all processing operations that we carry out as a controller. The stated storage periods begin when the respective processing purpose ceases to apply.
Processing according to Art. 13 para. 1 and 2 GDPR Purpose Data categories Legal basis Storage period Provision of the website IP address, date and time, requested resource, status code, transferred data volume, referrer, browser user identifier Art. 6(1)(f) GDPR — legitimate interest in stable and secure operations 30 days Attack mitigation IP address, request pattern, signature matches of the filter Art. 6(1)(f) GDPR — legitimate interest in the integrity of the systems 90 days Audience measurement of the website with Google Analytics Visited pages, time on site, origin of the visit, device and browser details, approximate location, events in the checkout process, random identifier in the cookie; for logged-in customers a user identifier (checksum of the customer number); aggregated data on age, gender and interests with Google signals Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG — consent, revocable at any time 14 months, cookies 13 months Website audience measurement without a cookie (custom method) Visited pages, time on site, referring domain, campaign identifier, device class, browser, operating system, language, country; instead of the IP address, a daily changing checksum Art. 6(1)(f) GDPR — legitimate interest in improving the service; objection possible at any time 400 days Registration and management of the customer account Name, company, address, email, telephone, VAT ID, registry data, login logs Art. 6(1)(b) GDPR — performance of pre-contractual measures and the contract Contract term, followed by commercial law retention periods Identity verification for business customers Commercial register extract, ID data of the authorised representative Art. 6(1)(c) GDPR in conjunction with Sec. 154 AO and legitimate interest in fraud prevention 5 years after the end of the contract Provision of infrastructure services Resource identifiers, usage data, consumption values, operations logs Art. 6(1)(b) GDPR — performance of a contract 12 months, consumption values 36 months Billing and accounting Invoice data, payment data, bank details, dunning history Art. 6(1)(b) and (c) GDPR in conjunction with Sec. 147 AO and Sec. 257 HGB 10 years Processing of support requests Ticket content, contact details, technical details, log extracts if applicable Art. 6(1)(b) GDPR, for requests without a contract Art. 6(1)(f) GDPR 36 months after completion Access control in data centres Name, ID data, time of access, biometric reference pattern (palm vein) Art. 6(1)(f) GDPR, biometric data only with consent according to Art. 9(2)(a) GDPR Access logs 24 months, biometric reference until revocation Video surveillance of the data centres Image recordings of the outdoor areas, entrances and technical areas Art. 6(1)(f) GDPR — protection against unauthorised access and property damage 90 days Sending of status messages Email address, selected services and regions, sending log Art. 6(1)(b) GDPR for contract-related messages, otherwise Art. 6(1)(a) GDPR Until cancellation, sending log 6 months Application process Application documents, interview notes, assessments Sec. 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR 6 months after completion, with consent 24 months Fulfilment of reporting obligations Affected data of the respective incident Art. 6(1)(c) GDPR in conjunction with Art. 33 GDPR and the requirements of the NIS2UmsuCG 3 years Commercial and tax retention obligations under Section 257 HGB and Section 147 AO take precedence over deletion. Affected data is blocked for further processing and deleted after the period expires. Paragraph 2: Where we rely on a legitimate interest under Art. 6 para. 1 lit. f GDPR, we have carried out a balancing test. We will provide you with the result of this balancing test upon request.

Blocking is not deleting: data with an ongoing retention obligation remains stored, but is blocked for any other processing — it is only deleted when the final period has expired. The shortest period in this overview is 30 days — it applies to the website access logs. The longest fixed period is ten years, and it does not stem from data protection law, but from Section 147 AO and Section 257 HGB.
5.Server log files
Paragraph 1: When you visit this website, your browser automatically transmits information to the server. This is stored in a log file.
- truncated IP address (the last two octets for IPv4, the last 80 bits for IPv6 are removed before storage)
- date and time of access with time zone
- name and URL of the requested resource
- transferred data volume and HTTP status code
- referring address, if transmitted by the browser
- browser identification including version and operating system
Paragraph 2: Storage is required to ensure trouble-free operations and to investigate cases of abuse. The data is automatically deleted after 30 days. It is not merged with other data sets.
Paragraph 3: Notwithstanding this, logs required to investigate a specific attack are kept in full for up to 90 days. We document the decision for this, including the reason and scope.
7.Categories of recipients
Paragraph 1: Personal data is only passed on to the following categories of recipients and only insofar as this is necessary for the respective purpose:
- Processors according to Art. 28 GDPR, which are listed individually in section 14
- Google Ireland Limited as processor for reach measurement according to section 6 — only if you have consented
- Payment service providers and credit institutions for processing payments
- Tax consultancy and auditing within the scope of statutory audits
- Legal advice and debt collection service providers for the enforcement of claims
- Authorities and courts, insofar as a legal obligation exists
- Auditing companies within the scope of certification and attestation procedures
Paragraph 2: We examine official requests for information on a case-by-case basis for legal basis, jurisdiction and proportionality. Insofar as legally permissible, we inform the data subject or the affected customer account before disclosure.
8.Transfers to third countries
Paragraph 1: We process personal data exclusively in data centres in Germany and Finland, i.e. within the European Union. A transfer to a third country within the meaning of Chapter V GDPR only takes place in the cases of paragraph 2.
Paragraph 2: The contractors listed in section 14 process within the European Union. There are three exceptions. The first is payment processing: our payment service provider Stripe Payments Europe, Ltd. (Ireland) uses sub-processors in the USA for this, in particular Stripe, Inc. The basis for the transfer are standard contractual clauses according to Art. 46 para. 2 lit. c GDPR as well as the certification under the EU-US Data Privacy Framework. This exclusively affects payment and invoice data — never content or usage data of your systems. The second is the sending of emails: our dispatch service provider Plus Five Five, Inc. (USA, service “Resend”) receives the recipient address, subject and content of the messages sent by this website and the customer account, as well as their delivery status; dispatch is via servers in Ireland. The basis for the transfer are standard contractual clauses according to Art. 46 para. 2 lit. c GDPR. This never affects data from your systems either. The third exception only applies with your consent: when measuring the reach of this website with Google Analytics (section 6 paragraphs 3 to 7), Google LLC in the USA may gain access to the measurement data; the basis is the adequacy decision on the EU-US Data Privacy Framework. Without consent, this transfer does not take place, and it never affects data from your systems. We announce further changes according to section 14 paragraph 5 at least 30 days in advance.

The processing location is fixed with the order: five locations in Germany and Finland, all in the legal area of the European Union. The platform does not process outside this legal area; the three exceptions — payment data, the sending of emails and the measurement of the website with consent — are in paragraph 2. Paragraph 3: Decisive for access by an authority is not only the location of storage, but the law to which the operating company is subject. This company is based in Germany; there is no parent company and no intermediary company in a third country. An explanation of the legal situation, including the US CLOUD Act, can be found under Security and Compliance.
9.Customer account, contract performance and support
Paragraph 1: A customer account is required to use our services. Mandatory fields are marked in the registration form; without them, a contract cannot be concluded.
Paragraph 2: We log login attempts with the time, truncated IP address and result to detect unauthorised access. We retain these logs for twelve months and display them to you in the customer panel. Employees who manage customer accounts can see in our internal administration which customer accounts are currently logged in and active, and when a customer account was last active (account name, time of last activity, browser and operating system), so that they can offer assistance and answer questions while you are working on your account. We do not record which pages you visit in the customer panel. The legal basis is our legitimate interest in providing timely support (Art. 6 (1) (f) GDPR); you can object to this display.
Paragraph 3: We store support requests with their history so that follow-up questions can be processed without you having to explain the issue again. Please do not submit personal data of third parties in tickets unless it is necessary for processing.
10.Job applications
Paragraph 1: We process application documents exclusively for carrying out the application process on the basis of Section 26 (1) BDSG.
Paragraph 2: After the process is complete, we delete the documents after six months. This period takes into account the deadline for filing a lawsuit under Section 61b ArbGG in conjunction with Section 15 AGG. With your explicit consent, we will add you to an applicant pool for 24 months.
Paragraph 3: We do not use automated pre-selection or software to evaluate application videos or voice recordings.
11.Status reports and notifications
Paragraph 1: As a contract customer, you receive operationally necessary notifications about disruptions, maintenance windows and security-relevant events. These notifications are part of the service and cannot be unsubscribed from, provided they concern resources you actually use.
Paragraph 2: You will only receive additional notifications — such as for regions or products you do not use — if you explicitly select them in the customer panel. You can change this selection at any time.
Paragraph 3: We do not measure open rates or clicks in our emails. No tracking pixels or redirected links are used.
12.Your rights
Paragraph 1: You have the following rights regarding us. Please send requests to datenschutz@entronyx.cloud; we will respond within one month in accordance with Art. 12 (3) GDPR.
Data subject rights under Chapter III GDPR
- Art. 15 — Access
- You can request information about whether and which personal data we process about you, for what purposes, to which recipients it is disclosed and how long it is stored. We will provide a copy upon request.
- Art. 16 — Rectification
- We rectify incorrect data without delay. You can have incomplete data completed. You can change the master data of your account yourself at any time in the customer panel.
- Art. 17 — Erasure
- You can request erasure, provided there is no statutory retention obligation to the contrary. We restrict the further processing of documents subject to commercial and tax retention obligations instead.
- Art. 18 — Restriction
- Instead of erasure, you can request the restriction of processing, for example while we verify the accuracy of contested data.
- Art. 20 — Data portability
- We will provide you with data that you have provided to us in a structured, commonly used and machine-readable format. We also provide an export via the API for your content data.
- Art. 21 — Objection
- You can object to processing based on a legitimate interest on grounds relating to your particular situation. We will then stop the processing unless we can demonstrate compelling legitimate grounds.
- Art. 7 para. 3 — Withdrawal of consent
- You can withdraw your consent at any time with effect for the future. The lawfulness of the processing carried out up to that point remains unaffected.
- Art. 22 — No automated decision-making
- There is no solely automated decision-making with legal effect. The credit check before granting a credit limit is finally assessed by a person.
Paragraph 2: For identity verification, we may request additional information if there are reasonable doubts about your identity. We only request information that is necessary for identification.
13.Right to lodge a complaint with the supervisory authority
Paragraph 1: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
Paragraph 2: The authority responsible for us is:
Competent supervisory authority
State Commissioner for Data Protection and Freedom of Information North Rhine-WestphaliaKavalleriestraße 2-440213 DüsseldorfParagraph 3: A complaint to the supervisory authority does not require you to have contacted us first. However, we recommend doing so, as most issues can be resolved more quickly this way.
14.Data processing agreement under Art. 28 GDPR
Paragraph 1: If you use our infrastructure to process personal data, we act as a data processor. The data processing agreement (DPA) is concluded with the main contract and is part of the contract without a separate request. There is no additional charge for this.
Subject matter and scope
Paragraph 2: The subject matter is the provision of computing, storage and network capacity. You determine the nature and purpose of the processing, the categories of data subjects and the type of data; we have no influence on this and do not take note of the content.
Paragraph 3: We process data exclusively according to your documented instructions. Text form is sufficient. If we consider an instruction to be unlawful, we will inform you and may suspend execution until the matter is clarified.
Paragraph 4: Content data is only accessed in three cases: upon your explicit instruction as part of a support request, to avert a specific and acute threat to operations, or on the basis of a valid official order. Every access is logged and displayed to you in the customer panel.
Sub-processors
Paragraph 5: By concluding the contract, you grant general authorisation to engage the following sub-processors. We will announce changes at least 30 days in advance; you can object within this period and terminate the contract extraordinarily if we do not remedy the objection.
Sub-processors under Art. 28 (2) and (4) GDPR — as of 3 October 2026 Contractor Country of residence Service Scope Basis ENTRONYX Deutschland GmbH Germany Platform operations, control plane, support All locations in Germany and Finland Main contractor, Art. 28 GDPR Stripe Payments Europe, Ltd. Ireland Processing of card payments, direct debits and bank transfers, invoicing Billing address, email address, payment data; no content or usage data Art. 28 GDPR; subcontractors in the US based on standard contractual clauses (Art. 46(2)(c) GDPR) and the EU-US Data Privacy Framework Plus Five Five, Inc. (“Resend” service) USA Sending confirmations, invoices, security and status messages by email Email address, subject, message content, delivery status; no content or usage data of your systems Art. 28 GDPR; transfer to the US based on standard contractual clauses (Art. 46(2)(c) GDPR); sending via servers in Ireland Provider for credit reports Germany Check before granting a credit limit from €10,000 Company data, address, no usage data Art. 6(1)(f) GDPR, information contract Certified waste management companies Germany and Finland Material recycling of decommissioned hardware No personal data; data carriers are previously wiped and destroyed Art. 28 GDPR External auditing companies Germany Conducting audits according to ISO 27001, ISO 50001 and BSI C5 Inspection of logs and configurations as part of the audit Confidential commissioning, non-disclosure agreement The current version of this list is available in the customer panel and can be subscribed to as a notification. We also list contractors who do not have access to IT systems — transparency is more important to us than a short list. Audit rights and evidence
Paragraph 6: You can satisfy yourself that we are complying with our obligations. As evidence, we provide the C5 attestation, the ISO 27001 certificate with scope, and the documentation of technical and organisational measures under Art. 32 GDPR.
Paragraph 7: An on-site audit is possible during normal business hours with 30 days' notice, at most once per calendar year, unless there is a specific reason. Access to operational areas requires compliance with our access rules; recordings are not permitted there.
Deletion and return
Paragraph 8: After the end of the contract, we delete your data. Before this, there is a grace period of 30 days during which you can export data; upon request, we can shorten this period to zero. Block and object storage is deleted by destroying the key and subsequently overwriting it.
The technical and organisational measures under Art. 32 GDPR are described in detail under Security and compliance, including encryption, key management, tenant isolation and reporting deadlines for incidents.
15.Changes to this policy
Paragraph 1: We will adapt this policy if the legal situation, our services or the processing change. Each version bears a date; we will provide previous versions upon request.
Paragraph 2: We will also inform contract customers of material changes affecting your rights by email. A mere notice on the website is not sufficient for us.

