Privacy Policy
Last updated: 31.08.2026
In short
This website sets no cookies, loads no fonts, scripts or maps from third parties and counts visitors anonymously on our own servers. If you only read here, you leave behind nothing more than a technical log entry. As soon as you do something yourself (submit a form, ask the AI assistant, click an external link), we process exactly what that requires. All the details:
1. Controller
The controller responsible for data processing on this website is:
Hashfox GmbH Gartenstraße 42 53859 Niederkassel Germany
Phone: +49 (0) 228 / 763 636 50 Email: info@hashfox.com
2. Hosting & server log files
This website runs on our own servers in Germany. When you visit, technically necessary server log files are processed (IP address, date and time, requested page, browser identifier). This data serves solely to ensure reliable operation and IT security (Art. 6 (1) (f) GDPR) and is deleted automatically after 14 days at the latest.
4. Web analytics with Umami
For reach measurement we use Umami, a privacy-friendly analytics tool running on our own servers. Umami works without cookies, creates no personal profiles and stores IP addresses only in anonymised form. Identification of individual visitors is not possible. The legal basis is our legitimate interest in statistical analysis of website usage (Art. 6 (1) (f) GDPR).
5. Contact & project form
When you write to us via the contact or project form, we process the data you provide (e.g. name, company, email address, phone number and your message) solely to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR (initiation of a contract) or Art. 6 (1) (f) GDPR.
Your form entries do not leave our infrastructure: the enquiry is assembled into an email on our server and delivered to our mailbox through our own mail server. No third-party form, newsletter or CRM service is involved. If you use the AI project dialogue instead, the next section applies in addition.
We store enquiries for as long as processing requires, at most until statutory retention periods expire (as a rule six or ten years under Section 257 German Commercial Code and Section 147 German Fiscal Code, where the enquiry leads to a business transaction). There is no newsletter and no marketing list.
6. AI assistant and AI project dialogue
On the home page you can try our AI assistant; on all other pages you can reach it through a window you open yourself. Under “Start a project” you can submit your enquiry in a dialogue with an AI instead of filling in a form. On the “Start a project” and “Contact” pages we deliberately hide the assistant. All of these features only start once you send a message yourself. Simply reading the page triggers nothing.
How it works: your message is received by our server and passed to a language model to generate the answer, which comes back to you the same way. Only the text of your messages, the assistant's previous replies and our system instruction are passed on. Not passed on: cookies, identifiers, a user account or your IP address; the request originates from our server, not from your browser.
Recipient: the answers are generated for us by weber.digital GmbH (trading as weber.cloud), Zollernstraße 49, 72336 Balingen, Germany, acting as our processor. The basis is a data processing agreement under Art. 28 GDPR; processing happens solely on our instructions and only to answer your enquiry. The language models run in the provider's data centre in Germany, so no transfer to a third country outside the EU takes place. Your input is not used to train AI models.
Legal basis: for the assistant on the home page, Art. 6 (1) (f) GDPR, our legitimate interest in giving prospects an immediate answer and in demonstrating our own work. For the AI project dialogue, Art. 6 (1) (b) GDPR, as it serves the initiation of a contract.
Retention: we do not store the conversations. They exist in your browser's memory and, for the duration of the response, on our server; closing the page removes them. Only when you expressly confirm and send a project enquiry do we store the conversation transcript as an email in our mailbox; the section on the contact and project form then applies.
Voluntary use: the AI features are optional and replace nothing. You can reach us equally well via the classic form, by email or by phone. Please do not enter credentials, confidential documents or special categories of personal data within the meaning of Art. 9 GDPR (such as health data) into the chat.
Right to object: you may object at any time to processing based on our legitimate interest, pursuant to Art. 21 GDPR. An informal message to info@hashfox.com is sufficient.
7. Spam protection (ALTCHA)
Our forms and the AI project dialogue are protected by ALTCHA. Before submission, your browser quietly solves a small computational puzzle, invisible to you, uneconomical for automated bulk requests. ALTCHA runs entirely on our own servers, sets no cookies, embeds no third-party content and transmits no data to third parties. Only a random check value and the time of the request are processed. We deliberately do not use an image or click CAPTCHA from a third-party provider. The legal basis is our legitimate interest in preventing spam and automated requests (Art. 6 (1) (f) GDPR).
8. Abuse protection
To protect our forms and AI features from overload and abuse, we briefly count how many requests arrive from an IP address. These counters exist only in our server's memory, are not stored permanently, are not combined with other data and are discarded after one hour at the latest. The legal basis is our legitimate interest in the security and availability of our systems (Art. 6 (1) (f) GDPR).
9. Fonts & media
All fonts, images and scripts on this website are served locally from our own servers. There is no embedding of Google Fonts, Google Maps, reCAPTCHA, content delivery networks or other third-party services. Simply viewing this website therefore establishes no connection from your browser to external servers. Only when you use an AI feature, click an external link or start a download does a request leave our infrastructure, and even then only after an action of yours.
10. Customer console
For our customers we operate a closed area at console.hashfox.com where systems, enquiries and documents can be viewed. It is technically separate from this website, runs on our own servers and is accessible only with credentials issued by us; there is no self-registration. The “Login” link in the page header merely points there; clicking it alone creates no further data.
Inside the signed-in area exactly one cookie is in use: the login session. It is strictly necessary for operation and therefore requires no consent (Section 25 (2) TDDDG). Processed there are your account details (name, email address, role), your systems and contracts as well as your enquiries and documents. The legal basis is Art. 6 (1) (b) GDPR (performance of the contract), and additionally Art. 6 (1) (f) GDPR for login security.
11. Remote support and downloads
On the “Contact” and “Cloud & Servers” pages we link to downloads of the TeamViewer software (TeamViewer Germany GmbH, Bahnhofsplatz 2, 73033 Göppingen, Germany). The download starts only after your click and is delivered directly from TeamViewer's servers; from that point on, the provider's privacy policy applies. A remote support session is established only if you actively give us the session ID and password. The legal basis for carrying out remote support is Art. 6 (1) (b) GDPR (performance of a support or maintenance contract).
12. Directions and external links
We embed no third-party map in our pages. The link “Open route in your maps app” takes you to Google Maps only after your click; from then on Google's privacy policy applies. The same goes for references to our profiles on LinkedIn, Instagram and Facebook: these are plain links, no social media plugins or trackers are embedded. Only when you click such a link do you leave our website.
13. Enquiries by email and phone
If you write or call us directly, we process the resulting data (your contact details and the content of your enquiry) to handle your request. The legal basis is Art. 6 (1) (b) GDPR where a contract is involved, otherwise Art. 6 (1) (f) GDPR. Email runs through our own mail server. The same retention periods apply as for form enquiries.
14. Encryption
This website is delivered exclusively over an encrypted connection (TLS/HTTPS), recognisable by the padlock icon in your browser. Enquiry emails to our mailbox are also transmitted with transport encryption. End-to-end encryption cannot be guaranteed throughout for email; for confidential documents, just ask and we will set up a secure transfer channel.
15. No automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. Our AI assistant answers questions and records project enquiries; decisions about your request, about proposals and about working together are always made by people.
16. Your rights
You have the right to access the personal data we process about you (Art. 15 GDPR), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing (Art. 21). Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3) GDPR). Simply contact info@hashfox.com, no justification required.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
17. Status & changes
This privacy policy is dated 31 August 2026. We will update it whenever the website or the legal situation changes; the current version is always available on this page.