01
Controller and contact
The controller responsible for processing personal data on this website is:
Daniel Piringer, trading as HexonisSpalatinstr. 40A
81739 Munich
Germany
Email: [email protected]
02
Accessing and hosting this website
When your browser requests this website, the technical data required to deliver and secure the requested content are processed. Depending on the request and infrastructure, these data may include:
- IP address;
- date and time of the request;
- requested URL or file;
- referring page, if transmitted by your browser;
- browser, operating system and user-agent information;
- protocol, response status and amount of data transferred; and
- security, routing and error information.
Processing is necessary to provide the website, establish encrypted connections, cache content, prevent abuse and attacks, maintain availability and investigate technical faults. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of this corporate website.
The website and its server-side contact endpoint run on a virtual private server located in Germany and provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany ("Hetzner"). Hexonis administers the server, the Next.js application and the self-hosted Coolify deployment software. Hetzner processes technical request and infrastructure data on our behalf as a processor within the meaning of Article 28 GDPR, to the extent necessary to provide and secure the hosting infrastructure. The website provides no user accounts and the application does not store enquiries in a separate database.
Further information about processing by Hetzner is available in Hetzner's Data Privacy Policy.
03
Cloudflare services and international transfers
We use Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA ("Cloudflare") to deliver and protect this website. Cloudflare provides services such as DNS, TLS termination, content delivery, caching and protection against malicious traffic. Requests to hexonis.com pass through Cloudflare's global network. Cloudflare and Hetzner therefore process the technical request data described above as service providers acting on our behalf.
When you submit the contact form, Cloudflare relays the request, including the form fields and security token, to our hosting server. The server sends the security token and a randomly generated request reference to Cloudflare's Siteverify service; the form fields themselves are not included in that verification request.
Cloudflare Network Error Logging may instruct compatible browsers to send technical reports to a Cloudflare endpoint when network errors occur. Cloudflare Email Address Obfuscation may also deliver a same-origin script that decodes the displayed contact address in your browser and helps reduce automated email harvesting.
Because Cloudflare operates a global network, processing outside the European Economic Area may occur. According to Cloudflare's Data Processing Addendum, transfers to the United States rely, where applicable, on the EU-U.S. Data Privacy Framework and otherwise on the European Commission's Standard Contractual Clauses.
Further information is available in Cloudflare's Privacy Policy and Data Processing Addendum.
04
Cloudflare Turnstile
We use Cloudflare Turnstile to protect the contact form against automated submissions and abuse. The Turnstile script is loaded when you interact with the form. It runs technical challenges in your browser and processes signals that may include your IP address, TLS fingerprint, user-agent, the site key and its associated origin, and interaction or challenge data. Turnstile returns a short-lived token which our server-side contact endpoint sends to Cloudflare's Siteverify service. A message is delivered only after successful verification.
This processing is necessary to prevent spam, protect the availability of the form and keep the website secure. The legal basis for the processing is Article 6(1)(f) GDPR and our legitimate interest in those purposes. Access to information on your device, where it occurs, is strictly necessary to provide the security function and is based on section 25(2) TDDDG. We do not use Turnstile pre-clearance for this form.
Cloudflare states that it acts as our processor when it uses these signals to protect this website, and as a controller where it processes signals to improve Turnstile, relying on its legitimate interests. More information is available in Cloudflare's Turnstile Privacy Addendum.
05
Contact form and email
If you submit the contact form, we process your name, email address, company name (if provided), message, a randomly generated request reference and the time of submission. The form also contains an invisible field used to identify automated submissions. We use this information to deliver, review and respond to your enquiry and to manage any resulting business communication.
After successful Turnstile verification, our server-side contact endpoint sends your form details as a plain-text email through Google Workspace to the Hexonis contact mailbox. Google processes the message content and communication metadata on our behalf. The application does not store the enquiry in a separate database. The email does not include your IP address, browser information or Turnstile token.
If you contact us directly by email, we process the information you send, which may include your name, email address, message, attachments and communication metadata. Your email provider and Google Workspace process this information to transmit, deliver and manage the message.
Google may process customer data in countries where Google or its subprocessors maintain facilities. Where this results in a restricted transfer under European data protection law, Google applies an alternative lawful transfer solution or the applicable European Commission Standard Contractual Clauses under its Cloud Data Processing Addendum. Further information is available in Google's Cloud Data Processing Addendum.
We process contact-form and email enquiries under Article 6(1)(b) GDPR where this is necessary to take steps at your request before entering into a contract or to perform a contract. For other enquiries, including enquiries made on behalf of a business, Article 6(1)(f) GDPR applies. Our legitimate interest is handling enquiries and maintaining business relationships.
07
Retention
Technical request and security data may be recorded by Cloudflare and in server-side logs of the reverse proxy, container runtime and application on the Hetzner server. We do not maintain a separate analytics or long-term log archive. Under the standard Coolify Docker configuration used on the server, container output logs are rotated at 10 MB and no more than three log files are retained per container. Because this limit is size-based, the resulting retention period depends on log volume. Logs are deleted when rotated or when the relevant container is removed. They may be retained for longer where necessary to investigate a specific security incident or comply with legal obligations. The application itself does not create a separate visitor profile or analytics database.
Contact-form enquiries and related correspondence are stored in the Hexonis Google Workspace mailbox until they have been dealt with and are no longer required for follow-up. They may be retained for longer where necessary for contract performance, the establishment, exercise or defence of legal claims, or compliance with statutory retention duties. The applicable statutory retention or limitation period then determines how long the data are kept.
08
Your rights
Subject to the applicable legal requirements, you have the right to:
- access your personal data under Article 15 GDPR;
- rectify inaccurate data under Article 16 GDPR;
- erase data under Article 17 GDPR;
- restrict processing under Article 18 GDPR;
- receive portable data under Article 20 GDPR; and
- object to processing based on Article 6(1)(f) GDPR under Article 21 GDPR.
To exercise these rights, email [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for private-sector organisations in Bavaria is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany. The BayLDA provides an online complaint form.
You do not have to actively enter personal data to browse this website. Your browser automatically transmits technical request data, including the IP address, and these data are required to deliver the requested content. If you contact us, the information needed to understand and answer your enquiry is required for us to respond. We do not use automated decision-making or profiling within the meaning of Article 22 GDPR.
09
Changes to this notice
We update this notice when the website, its service providers or the legal requirements change. The date shown at the top identifies the current version.