rapidFOX Logo
rapidFOX
Smart Helpdesk
Zur Startseite

Privacy policy

Courtesy translation

This English version is provided for convenience only. The German version is the legally binding one; in the event of any discrepancy, the German text prevails.

As of 10 Sep 2026 · This privacy policy explains how personal data is processed when you use our website rapidfox.de and the rapidFOX web application (together, the “Service”).

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:

Entracon Projektservice GmbH
Springorumallee 10
44795 Bochum
Deutschland
Telephone: +49 234 5414010
Email: info@entracon.de

Represented by: Carsten Scholze und Dr.-Ing. Philipp Schwittek (Geschäftsführer).

2. Data protection officer

We have appointed a data protection officer. For all questions about data protection and for exercising your rights, you can reach them at:

Tobias Schwittek (Data Protection Officer)
c/o Entracon Projektservice GmbH
Springorumallee 10
44795 Bochum
Email: info@entracon.de

3. Principles of processing

We process our users’ personal data only insofar as this is necessary to provide a functioning service together with our content and offerings. Processing regularly takes place only with the consent of the data subject, or where processing is permitted by law. “Personal data” means any information relating to an identified or identifiable natural person (Art. 4 (1) GDPR).

Legal bases at a glance

  • Art. 6 (1) (a) GDPR – consent of the data subject.
  • Art. 6 (1) (b) GDPR – performance of a contract or pre-contractual measures.
  • Art. 6 (1) (c) GDPR – compliance with a legal obligation (for example commercial and tax retention duties).
  • Art. 6 (1) (f) GDPR – legitimate interests, unless overridden by the interests or fundamental rights of the data subject.

4. Roles: website visit, customer account and customer data

For the use of our website and for the registration and administration of the customer account (master data of contracting parties, billing, usage data) we are the controller under data protection law; this privacy policy applies to that.

Insofar as our customers process their own content when using rapidFOX – in particular personal data of their own end customers (in tickets, company records, chats, attachments or the knowledge base) – we act as a processor within the meaning of Art. 28 GDPR. The customer is the controller for that content. The basis for this is the data processing agreement (DPA) concluded with the customer.

5. Providing the website and server log files

Each time our Service is accessed, your browser automatically sends information to the server, which is stored temporarily in what are known as log files. The following is recorded without any action on your part:

  • the shortened or processed IP address of the requesting device,
  • the date and time of access,
  • the name and URL of the file retrieved,
  • the website from which access was made (referrer URL),
  • the browser used and, where applicable, the operating system and the name of your access provider.

This processing serves to establish the connection, ensure system security, carry out technical administration and optimise the Service. The legal basis is our legitimate interest in secure and functioning operation (Art. 6 (1) (f) GDPR). Log files are deleted as soon as they are no longer required for those purposes, and in any event after a short period, unless security-relevant incidents require longer storage.

6. Hosting and server location

Our Service runs on servers in Germany. We use the following technical service provider (processor):

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

A data processing agreement pursuant to Art. 28 GDPR is in place with this provider. Processing takes place exclusively within the European Union. The legal basis is Art. 6 (1) (f) GDPR (secure and efficient operation) and Art. 6 (1) (b) GDPR (performance of the contract).

7. Cookies and similar technologies

We use only technically necessary cookies and comparable storage techniques that are required to operate the Service – in particular a session cookie to maintain your login and a token to protect against cross-site request forgery (CSRF). These cookies contain no marketing or tracking functions. The legal basis is § 25 (2) no. 2 TDDDG in conjunction with Art. 6 (1) (f) GDPR. No consent banner is required for this.

8. Reach measurement (cookieless statistics)

To improve what we offer, we carry out data-minimising, cookieless reach measurement. We evaluate aggregated access information (for example pages viewed, approximate time, type of referral) without setting cookies and without building individual user profiles. No personal data is transmitted to third parties. The legal basis is our legitimate interest in designing the Service to meet demand (Art. 6 (1) (f) GDPR).

9. Registration and user account

Using rapidFOX requires a user account. In this context we process in particular names, business contact details (email address), access credentials (password in encrypted form), company and workspace data, and the number of seats selected. To secure the account we offer two-factor authentication. The processing serves to establish, perform and administer the user relationship. The legal basis is Art. 6 (1) (b) GDPR. We store this data for the duration of the contractual relationship; after it ends the data is deleted unless statutory retention obligations apply.

10. Contract and payment processing

In connection with paid use we process contract and billing data (including billing address, booking period, number of seats, payment status). Payments are handled by specialised payment service providers; the data required for payment is transmitted directly to the respective provider. We do not store complete card details ourselves.

  • Stripe: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
  • PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, 2449 Luxembourg.

The payment methods offered through Stripe (including card, SEPA direct debit and “Link”) are processed by Stripe. If wallet payment methods are used, data is additionally transmitted to the respective provider: Apple Pay (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA) or Google Pay (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Which payment methods are actually available depends on the device, country and amount, and is shown during checkout.

The legal basis is Art. 6 (1) (b) GDPR (performance of the contract) and Art. 6 (1) (c) GDPR (compliance with legal obligations, in particular under tax and commercial law). We retain invoice-relevant data in accordance with the statutory retention periods (as a rule 6 to 10 years).

11. Contacting us and support

If you contact us by email or through our support functions, we process the data you provide in order to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR where the enquiry serves the performance of a contract, and otherwise Art. 6 (1) (f) GDPR (interest in responding to enquiries). We delete this data as soon as it is no longer required for that purpose and no retention obligations apply.

12. Processing of content within the application

rapidFOX enables the management of support cases. In doing so, our customers may process personal data of third parties (for example requesters, contact persons, the content of emails and attachments). We process this data exclusively on the customer’s instructions within the framework of processing on their behalf (see section 4 and the DPA). The customer is responsible for that data as the controller.

13. Email integration

At the customer’s request, rapidFOX retrieves email from a mailbox configured by the customer (IMAP) and sends replies (SMTP), in order to create cases from email and answer them. Credentials and content are processed exclusively to provide this function. Responsibility for the content lies with the customer; processing takes place within the framework of processing on their behalf.

14. AI assistant

rapidFOX offers an optional AI assistant that is processed on a server operated by us (a local language model). For AI-supported functions, ticket content is processed on that server and is not transmitted to external AI services. The AI only ever produces suggestions; a human always approves the content. No automated decision-making with legal effect within the meaning of Art. 22 GDPR takes place. The AI assistant can be switched on and off globally, per company and per function.

15. Internal chat and video calls

For internal collaboration, rapidFOX provides a chat as well as audio and video calls. Where calls are handled via an external video platform (for example Jitsi Meet), that provider’s privacy information additionally applies to the transmission. The operator may use its own video instance hosted in Germany. The legal basis is Art. 6 (1) (b) or (f) GDPR.

16. Recipients and processors

Your data is passed on to third parties only where this is legally permissible or necessary for the performance of the contract. We use carefully selected service providers with whom, where required, data processing agreements pursuant to Art. 28 GDPR are in place – in particular for hosting, payment processing and email delivery. We provide contract customers with a current overview of the sub-processors used as part of the DPA.

17. Transfers to third countries

As a rule, personal data is not transferred to countries outside the European Union or the European Economic Area. Where, in individual cases (for example with payment service providers), processing takes place in a third country, this occurs only on the basis of appropriate safeguards within the meaning of Art. 44 et seq. GDPR, in particular the European Commission’s standard contractual clauses or an adequacy decision.

18. Retention period

We process and store personal data only for as long as is necessary to achieve the respective purpose, or for as long as statutory retention periods require. Once the purpose no longer applies or the periods have expired, the data is routinely deleted or blocked.

19. Your rights as a data subject

Under the GDPR you have in particular the following rights:

  • Access to the data processed about you (Art. 15 GDPR),
  • Rectification of inaccurate data (Art. 16 GDPR),
  • Erasure of your data, unless retention obligations apply (Art. 17 GDPR),
  • Restriction of processing (Art. 18 GDPR),
  • Data portability (Art. 20 GDPR),
  • Objection to processing on grounds relating to your particular situation (Art. 21 GDPR),
  • Withdrawal of a consent given, with effect for the future (Art. 7 (3) GDPR).

To exercise your rights, an informal message to info@entracon.de is sufficient. Registered users can also exercise some of their rights (for example data export and deletion) directly through the functions in their account.

20. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
(the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

21. Obligation to provide data

Concluding a contract and using the Service requires certain data to be provided (in particular account and billing data). Without that data we cannot conclude the contract or provide the Service.

22. Automated decision-making

No automated decision-making, including profiling, with legal effect within the meaning of Art. 22 GDPR takes place.

23. Data security

We take technical and organisational measures to protect your data against loss, misuse and unauthorised access – including transport encryption (TLS/HTTPS), access restrictions, strict tenant separation and regular backups. Details for contract customers are set out in the DPA.

24. Currency and amendment of this privacy policy

This privacy policy is currently valid and carries the date given above. Further development of our Service, or changed legal or regulatory requirements, may make it necessary to amend this policy. The current version can be accessed on this page at any time.