Data Protection & Privacy
Table of contents
Content is available in multiple languages. Only the German version is legally binding.
Your data belongs to you and no one else. The workplace management software Flexopus was developed in Germany in compliance with the highest standards and is a leader in data protection, data security, and privacy.
Data Processing Agreement (DPA)
We enter into a data processing agreement with all our customers in accordance with GDPR guidelines to contractually record the processing of personal data. The purpose of data processing, the type of data, the groups of data subjects, Flexopus sub-processors, and the rights of the data subjects are defined in this agreement.
Hosted in Germany (EU)
Your data is safe with us. Flexopus is operated exclusively on dedicated servers provided by our hosting partner, Hetzner Online GmbH, in the Federal Republic of Germany. This means your data is hosted in Germany by a German company. Hetzner is ISO 27001 certified, meeting the highest requirements for IT security procedures and information security management systems. We deliberately avoid hosting with hyperscalers like Amazon Web Services (AWS) or Google Cloud, as their parent companies are based in the USA, meaning third-party access cannot be fully ruled out due to regulations such as the Cloud Act.
GDPR-compliant
Flexopus meets GDPR guidelines and consistently implements the following policies in particular:
- Conclusion of data processing agreements (DPA) in accordance with Art. 28 (3) GDPR
- Anonymization and no storage of personal data without a specific purpose
- No data exchange with third parties or data transfers across national borders
- Regular training for all employees on data protection, data security, and privacy
- Continuous development of security standards through audits and the adaptation of our documentation, processes, structures, or functionalities, as well as technical and organizational measures
Flexopus is developed according to the concepts of "privacy by default" and "privacy by design," ensuring data protection is integrated from start to finish.
Purpose-bound data storage
Stored personal data is used exclusively for its intended purpose.
Data anonymization
With Flexopus, you determine the timeframe after which personal data is anonymized or removed from the system. For utilization analysis, booking details such as the start and end time of a booking are still retained.
However, these can no longer be traced back to a specific individual. This allows you to keep an overview of resource utilization to optimize your office while simultaneously protecting the sensitive data of your employees.
Employee privacy
With Flexopus, you decide whether bookings for workstations or other objects should be visible to all employees in your company. While we recommend this in a collaborative corporate environment, there may be specific cases where it makes sense to let users decide for themselves whether their booked seat is visible to others.
Careful selection of suppliers
Flexopus pays special attention to data protection and reliability when selecting sub-processors. We exclusively choose sub-processors from the EU:
- Server Provider: Hetzner Online GmbH
The application is hosted on a dedicated server cluster in Falkenstein. Our backup infrastructure is located in Nuremberg. - SMTP Provider
We use RapidMail, based in Germany, as our primary SMTP provider. We use MailJet, based in France, as our secondary SMTP provider. - Development Team
Our developers and software subcontractors are located exclusively within the EU.
Automated Deletion Routines
Flexopus allows for individually configurable deletion concepts in accordance with your internal data protection policies. For example, inactive user accounts can be removed automatically, and system or application logs can be deleted after a defined period. This ensures that personal data is only stored for as long as is necessary and permitted.
External Data Protection Officer
To protect your data, we have appointed an independent, external data protection officer: PROLIANCE GmbH. In addition, we operate a structured data protection management system (DPMS) that continuously monitors and develops compliance with all relevant data protection requirements.
Privacy Policies
Use our automatically generated privacy policy or upload your own document. You can also decide whether you want to require confirmation of consent from all employees.
Contracts under German Law
The company Flexopus GmbH is headquartered in Stuttgart, Germany. Contracts are concluded exclusively under German law. Made in Germany. Hosted in Germany.