14-day trial – test cloud infrastructure for free!

    Privacy Policy

    Protecting your personal data is important to us.

    1. Controller and General Information

    This Privacy Policy explains how focusnet GmbH processes personal data in connection with this website, our forms, online tools, registration flows, and business communications.

    1. The controller is focusnet GmbH, Bismarckstr. 82, 10627 Berlin, Germany.
    2. You can contact our Data Protection Officer at Datenschutz@focusnet.de.
    3. We process personal data on the basis of Article 6(1)(a) GDPR where you have given consent, Article 6(1)(b) GDPR for contracts and pre-contractual steps, Article 6(1)(c) GDPR for legal obligations, and Article 6(1)(f) GDPR for legitimate interests such as security, abuse prevention, communication, and improvement of our services.
    4. Where we use service providers as processors, we conclude agreements pursuant to Article 28 GDPR and require appropriate technical and organizational safeguards.

    2. Website Delivery, Security, and Consent Management

    2.1 Hosting and Technical Delivery

    Our website is delivered via Cloudflare Workers, Cloudflare static assets, CDN, routing, and security services. During website delivery, technical access data may be processed, including IP address, date and time of access, requested URL, referrer, browser and device information, transferred data volume, status codes, and security events. Processing is necessary to provide the website securely and reliably and is based on Article 6(1)(f) GDPR.

    Individual backend functions are routed to internal service origins for billing, registration, provisioning, chat, CMS, and media delivery. We use these services only for the respective requested function.

    2.2 Server and Security Logs

    We process technical logs to ensure operation, troubleshoot errors, prevent misuse, and secure our systems. Log data is retained only as long as required for these purposes, usually 7 to 30 days; security-relevant logs may be retained for up to 90 days where necessary.

    2.3 Consent Management

    We use our own consent management to document your cookie and service choices. Technically necessary consent information is stored in your browser, including the consent state and selected preferences. The configured validity period is 180 days. You may change or withdraw optional consent at any time with effect for the future.

    3. Optional Analytics, Chatbot, and External Content

    3.1 Matomo

    We use Matomo, self-hosted on a server in Germany, for statistical analysis of visitor access. We do not use cookies or comparable storage technologies for this purpose. Your IP address is shortened by the last two octets before processing and can therefore no longer be attributed to you. Data is not transferred to third parties. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in statistical reach measurement.

    3.2 Leadfeeder / Dealfront

    If you consent to analytics and marketing cookies, we may use Leadfeeder/Dealfront to understand which companies interact with our website and to improve B2B communication. The service may process technical usage data, IP-derived company information, referrer and campaign parameters, and browser information. Processing is based on your consent pursuant to Article 6(1)(a) GDPR.

    3.3 Chatbot

    If you consent to functional services and use the chatbot, we process chat messages, timestamps, technical metadata, and any contact details you voluntarily provide in the chat. Processing is carried out to provide the requested chat function and to answer your request.

    3.4 Fonts, Media, and External Links

    We use web fonts and media assets to present the website. This currently includes Google Fonts and, on individual product pages, externally loaded partner media. Where content is loaded from external providers, your browser may transmit technical request data to those providers. Some pages may link to external websites; this Privacy Policy does not apply to third-party websites.

    4. Forms, Quote Requests, and Registration Flows

    4.1 Contact and Partner Forms

    When you contact us via a form or email, we process the information you provide, such as name, email address, company, phone number, subject, message, consent confirmation, and the voluntary source information you provide. We also process lead attribution information such as source URL, UTM parameters, and referrer where available. Processing is based on Article 6(1)(b) GDPR for pre-contractual communication and Article 6(1)(f) GDPR for internal lead classification and communication improvement.

    4.2 ROI Calculator and NIS2 Compliance Checker

    When you use our ROI Calculator or NIS2 Compliance Checker, entries and calculated results may initially be processed locally in your browser. If you request a report by email or ask us to contact you, we process your contact details, company details, entered values, calculated results, consent information, and lead attribution data to provide the requested report and follow-up consultation.

    4.3 Registration, Offers, and Orders

    In registration and checkout flows, we process data required for product configuration, offer preparation, order processing, phone and email verification, billing, provisioning, and customer support. This may include contact details, company information, billing address, VAT ID, product configuration, partner code, selected term, technical configuration, and payment status. Processing is based on Article 6(1)(b) GDPR and, where required, Article 6(1)(c) GDPR.

    5. SMS and Email Verification

    For phone number verification and one-time password delivery, we use SMSAPI (LINK Mobility Poland sp. z o.o.). We transmit the phone number, message text containing the verification code, delivery metadata, and technical status information required to deliver and verify the SMS. SMS messages contain only the verification code and no sensitive contract or product details.

    Processing is carried out to secure registrations and prevent misuse on the basis of Article 6(1)(b) GDPR and Article 6(1)(f) GDPR. Verification codes are short-lived. Internal delivery and abuse-prevention logs are retained only for a limited period, generally 30 to 90 days, unless longer retention is required for legal claims or statutory obligations.

    For email verification and business email communication, we use email infrastructure provided by Host Europe. Provider-side POP3, IMAP, and SMTP connection logs are retained by Host Europe for 7 days; the content of business emails is retained according to the category of the communication and applicable commercial or tax retention duties.

    6. Payment, Captcha, CMS, and Email Hosting

    6.1 Stripe Checkout

    For paid orders, we may redirect you to Stripe Checkout. We transmit order and checkout data required to create the payment session. Payment details are entered directly with Stripe. Stripe processes payment data under its own responsibility where required by payment regulation and as our service provider for payment processing.

    6.2 Friendly Captcha

    For abuse prevention in selected flows, we use Friendly Captcha. The service provides a technical challenge and proof solution to distinguish legitimate use from automated misuse. Processing is based on our legitimate interest in protecting forms and registration flows pursuant to Article 6(1)(f) GDPR.

    6.3 CMS and Media Delivery

    Blog and media content may be retrieved from our CMS and object storage through our website infrastructure. Technical request data is processed to deliver this content and protect the service.

    7. Retention Periods

    We delete personal data when the processing purpose no longer applies, unless legal retention obligations, evidence requirements, or legitimate interests require longer retention. The following periods are standard criteria:

    1. Website and security logs: usually 7 to 30 days; security logs up to 90 days where necessary.
    2. Contact and partner inquiries without a contract: generally 6 to 24 months after the last communication.
    3. Verification codes: minutes to hours; delivery and abuse-prevention logs generally 30 to 90 days.
    4. Sent business offers and commercial correspondence: generally 6 years from the end of the calendar year.
    5. Contract, order, and customer support data: for the contract term and then according to limitation periods or statutory retention duties.
    6. Invoices, payment records, and booking documents: generally 8 years; records relevant to annual accounts and bookkeeping may be retained for 10 years.
    7. Backups: rolling retention, usually 30 to 90 days; deletion is implemented through backup rotation.

    8. Your Rights and Changes to This Policy

    Subject to the legal requirements, you have the following rights:

    1. Right of access pursuant to Article 15 GDPR
    2. Right to rectification pursuant to Article 16 GDPR
    3. Right to erasure pursuant to Article 17 GDPR
    4. Right to restriction of processing pursuant to Article 18 GDPR
    5. Right to data portability pursuant to Article 20 GDPR
    6. Right to object pursuant to Article 21 GDPR
    7. Right to withdraw consent at any time with effect for the future
    8. Right to lodge a complaint with a competent data protection supervisory authority

    We may update this Privacy Policy to reflect changes in legal requirements or our services. The updated version applies to future visits.

    Controller: focusnet GmbH, Bismarckstr. 82, 10627 Berlin, Germany
    Data Protection Officer: Datenschutz@focusnet.de
    Status: 30 April 2026