Privacy policy

Draft: this text is prepared but has not yet been reviewed by a lawyer.
This English version is a convenience translation. In case of doubt, the German version is the legally binding one.

1. Controller

x64 GmbH, Am Eisenstein 10, 45470 Mülheim an der Ruhr, Germany · Email: info@node64.de · Phone: +49 177 9333330

2. Principle: all data stays in Germany

All NODE64 servers – web, database and backups – run exclusively in Germany at Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen). A data processing agreement per Art. 28 GDPR is in place. We do not transfer data to third countries; the only exception is payment processing (section 8).

3. Principle: read-only, no intervention

The NODE64 agent reads the state of your systems and reports it – it changes nothing. It runs no commands on your devices, alters no files, settings or services, and does not intervene even on a detected security incident (such as a suspected ransomware infection): it deletes nothing, moves nothing and cuts no connection. There is no channel through which the platform could trigger anything on your systems; this read-only behaviour is built into the agent and is not a setting that could be flipped. Remediation advice reaches you as text, which you carry out yourself. Uploaded data is processed solely for the analysis described in this policy and deleted according to the retention periods stated below.

4. What we store – and where

Depending on how you use NODE64, we process the following data:

  • Account data (email address, language/theme preference, account role): in our database on Hetzner servers in Germany. Legal basis: Art. 6 (1) (b) GDPR.
  • Login data: magic-link tokens and session tokens are stored as hashes only; magic links expire after 15 minutes, sessions after 30 days. Optional: 2FA secret (encrypted) and recovery codes (hashed).
  • Device and system data (submitted by the NODE64 agent): system inventory (operating system, installed packages, services, open ports), basic telemetry (CPU, RAM, disks, uptime), hardware identifier and – only where required for active checks – defined configuration data. Transmission is TLS-encrypted throughout. Legal basis: Art. 6 (1) (b) GDPR.
  • Log signals (derived counts): the agent evaluates the monitored system's error logs locally and transmits counts only – the recognised pattern (e.g. "failed SSH login"), the number of occurrences within 24 hours, first and last occurrence, individual technical identifiers (service, process or disk name) and the number of distinct source networks. Log lines, message texts, usernames and IP addresses from the log are NOT transmitted. Purpose: detection of attack attempts and system faults. Legal basis: Art. 6 (1) (b) GDPR, supplemented by (f) (Art. 32 GDPR).
  • Upload/processing log per device (time, status, error reason if any) for troubleshooting.
  • Audit log of security-relevant account actions (login, device, team and API-key actions) including IP address. Legal basis: Art. 6 (1) (f) GDPR (security).
  • Server logs (IP address via reverse proxy, time, requested resource) for operational security; kept briefly, then deleted or anonymised. retained for 7 days, then deleted automatically. Legal basis: Art. 6(1)(f) GDPR (operational security).
  • Contact form: the details of your enquiry (name, email, message, plus IP address and time for abuse prevention) to process it; sent via our own mail server (mail.x64.de, Germany).
  • Measurement network “NODE64 Sonar” (only when explicitly enabled): we process measurement jobs and results (target address or domain, time, latency, packet loss, intermediate hops, DNS answers) as well as network metadata of the probe (country, autonomous system). Measurement traffic originates from the user’s IP address. Legal basis: Art. 6 (1) (b) or (f) GDPR. Publicly, a probe location is only shown coarsely (country/region/provider), never the IP address. Participation is voluntary, off by default and revocable at any time.

5. Retention / deletion

Device, check and history data is kept according to your plan: Free 7 days, Supporter 90 days, Business 365 days; after that it is deleted automatically. Database backups are kept for 14 days (encrypted, in Germany). Account data exists until the account is deleted.

6. Cookies

We only use strictly necessary cookies: lang (language), theme (appearance) and a session cookie. No tracking, no analytics, no advertising cookies – therefore no consent banner is required (§ 25 (2) TDDDG).

7. Email delivery

System emails (login links, invitations, notifications) and contact-form messages are sent via our own mail server (mail.x64.de, located in Germany, TLS-encrypted).

8. Registration & account

Passwordless sign-in via magic link; the account is created with the first confirmed login. Self-service account deletion (immediate, irreversible) and data export (JSON) are available in the settings at any time.

9. Payment processing (Stripe)

Paid plans are handled via Stripe (Stripe Payments Europe Ltd., Ireland; possibly transferred to Stripe Inc., USA on the basis of the EU-U.S. Data Privacy Framework or standard contractual clauses). Payment details are not stored on our servers but processed directly by Stripe. Legal basis: Art. 6 (1) (b) GDPR.

10. Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and the right to lodge a complaint with a supervisory authority – the competent one is LDI North Rhine-Westphalia. Contact for data protection matters: info@node64.de.

[Open before launch: final review of the Stripe section, clarify the legal entity as in the legal notice.]