AGENTCLOUD BY XYNATEC
Privacy Policy
This policy explains how personal data is handled when you visit agentcloud.xynatec.com or contact us about AgentCloud.
Last updated: 4 October 2026
1. Controller
The controller responsible for this website is Timo Zürner, operating under the brand Xynatec:
Timo ZürnerGerichtsstraße 13
9300 St. Veit an der Glan
Austria
service@xynatec.com
This policy covers the public website. Processing inside a customer’s managed Paperclip instance is governed separately by the applicable service and data processing arrangements.
2. Cloudflare hosting
This website is hosted using Cloudflare Workers. Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, provides delivery and security infrastructure.
Requests can contain your IP address, requested URL, access time, browser and device information, referring page and technical connection data. These are processed to deliver the website, maintain availability, identify errors and prevent abuse. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in operating a reliable and secure website.
Cloudflare operates a global network, so processing can take place outside the European Economic Area, including in the United States. Its Data Processing Addendum provides safeguards for applicable international transfers, including EU Standard Contractual Clauses. You can contact us for information about relevant safeguards. See also Cloudflare’s Privacy Policy.
3. Essential cookies only
We do not use advertising cookies or analytics cookies. The website code itself does not set cookies or store visitor identifiers in your browser.
Where Cloudflare security features require a cookie, it is used only for a necessary security function, such as remembering a successfully completed security check. Such cookies depend on the security features in use and are not set on every visit. Their expiry can be inspected in your browser; details are available in Cloudflare’s cookie documentation.
Storage or access strictly necessary for the service you request is covered by the exception in Section 165(3) of the Austrian Telecommunications Act 2021. Related personal data processing relies on Article 6(1)(f) GDPR for secure delivery. You can block cookies in your browser, although security checks may then stop working.
4. Self-hosted Plausible
We use Plausible Analytics at analytics.xynatec.com, hosted on our own server at STRATO in Germany. The infrastructure provider is STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. See STRATO’s privacy information.
Plausible measures page visits, referral sources, approximate location, device and browser categories, engagement, and configured interactions such as outbound link clicks and downloads. This helps us understand use of the site and improve it. It uses no analytics cookies or persistent browser identifiers.
Your IP address and browser information reach the analytics server as part of the request. Plausible uses them to derive a daily, site-specific identifier and does not store the raw IP address in its analytics records. Event and session records support the aggregate reports. The daily identifier is not a cross-site or permanent user profile. Infrastructure security logs are separate from these analytics records.
To the extent personal data is processed, we rely on Article 6(1)(f) GDPR: our legitimate interest in proportionate, privacy-conscious website measurement. You may object to this processing as described below. We do not send contact message contents or use these statistics for advertising profiles. Details of the software are described in the Plausible data policy; our instance is self-hosted rather than operated by Plausible’s cloud service.
5. Fonts and external links
Fonts, illustrations and provider logos are served with this website. Your browser does not contact Google Fonts to display the page. Links to other websites open only when you follow them; the destination site then handles your data under its own privacy policy.
6. Contact by email
If you email service@xynatec.com, we process your email address, name if supplied, message and any attachments to answer your enquiry. Our email infrastructure also handles the technical delivery data. Clicking a contact link opens your email application; this website does not submit a form or send a message automatically.
The legal basis is Article 6(1)(b) GDPR for enquiries connected with a possible or existing contract, or Article 6(1)(f) GDPR for other correspondence. Providing information is voluntary, but we need an address and sufficient details to respond. Please do not send passwords, API keys or other secrets by email.
7. Retention and recipients
We retain personal data only for the purpose for which it was collected. For enquiries, the relevant criteria are whether the request is resolved, whether follow-up or a contractual relationship remains necessary, and whether legal retention duties or the establishment or defence of claims require further storage. Statutory retention relies on Article 6(1)(c) GDPR.
Technical and security records are retained according to the applicable service settings and the time needed to investigate faults or abuse. Analytics retention is determined by the period needed to compare website usage and assess improvements. The daily identifier rotation described above does not mean that all analytics event records are deleted after one day. You can contact us for information about the retention applicable to a particular request.
Access is limited to the operator and service providers needed for website delivery, analytics infrastructure and email communication. Data may also be disclosed where required by law. We do not sell your personal data.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing and data portability. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation. Where processing relies on consent, you may withdraw that consent for the future.
Send requests to service@xynatec.com. We may need proportionate information to verify your identity. We do not make automated decisions with legal or similarly significant effects about website visitors.
9. Complaints
You may complain to a data protection supervisory authority, particularly in the country where you live, work, or believe an infringement occurred. In Austria, contact the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, or dsb@dsb.gv.at.