Privacy Policy eos

Last updated: July 2026

Source (German original): https://console.eoscloud.io/de/privacy-policy/#inhaltsverzeichnis

Note: This is a convenience translation of the German original (“Datenschutzerklärung eos”). In case of any discrepancy or dispute, the German original version shall prevail.

We, eos GmbH, are glad you are interested in eos. We take the protection of your personal data seriously and comply with the applicable data protection laws. This privacy policy informs you about how we process your personal data in connection with your use of the eos platform. The terms used in this privacy policy correspond to the definitions in the General Data Protection Regulation (GDPR).

Table of Contents #

General #

Controller #

Responsible for the data processing described in this policy is:

eos GmbH
Feldkirchner Straße 140
9020 Klagenfurt, Austria

Company Registration Number: FN 663176i
Phone: +43-50-556
Email: contact@eoscloud.io

Data Protection Officer #

You can reach our Data Protection Officer at:

eos GmbH
Attn: Data Protection Officer
Feldkirchner Straße 140
9020 Klagenfurt

Email: data-protection@anexia-it.com

Scope: Content You Process on the Platform #

This privacy policy covers exclusively the data that we, as controller, process in connection with operating eos — that is, your account, organization, and billing data, as well as the technical data generated by your use of the platform.

For personal data that you yourself process on the platform — for example, data within the virtual machines, applications, or storage you operate — you are the controller within the meaning of the GDPR. We process this content solely on your instructions, acting as processor under an agreement pursuant to Art. 28 GDPR. You determine what data this is and how long it is stored.

Cookies and Similar Technologies #

We use cookies and similar technologies on our website. Cookies are small text files stored on your device. We use only technically necessary cookies.

Deletion and Retention of Data #

Personal data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations stand in the way. Commercial and tax-law retention periods under Section 132 of the Austrian Federal Fiscal Code (BAO) and Section 212 of the Austrian Commercial Code (UGB) are generally seven years. During these periods, we restrict processing to mere retention.

The specific storage periods can be found in the respective section.

Data Transfers to Third Countries #

No data is transferred to a third country.

Automated Decision-Making #

We do not carry out automated decision-making, including profiling. We do not make any decisions that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you. To the extent our payment service provider uses its own automated procedures for fraud or creditworthiness checks, this is done under its own responsibility.

Processing Activities #

Operation and Security of the Platform #

When you access the eos platform and its programming interfaces, your browser or client automatically sends information to our servers. The following data is stored in log files: IP address, date and time of access, resource accessed, referrer URL, browser or client and operating system used, as well as status codes and the amount of data transferred.

We process this data in order to provide and ensure the operation of the platform, to guarantee the stability and security of our systems, and to be able to pass on information to law enforcement authorities in the event of unlawful access to our systems.

The data is deleted or anonymized after fourteen days, unless it is still required for other purposes — such as defending against or asserting legal claims. The legal basis is our legitimate interest in the secure operation of the platform. [1]

Registration and User Account #

To use eos, you create your own user account. In doing so, we process your email address, first name, and last name. Your email address also serves as your login identifier and as the means by which we send you messages necessary for operating the platform.

We additionally process your access credentials, a second factor, the IP address, and the time of each login in order to ensure the security of your account and to detect misuse.

The legal basis is the performance of the usage agreement with you. [2] For logging logins, we rely on our legitimate interest in the security of the platform. [1]

Your account data is stored for as long as your user account exists. After the account is deleted, it is removed from our active systems and backup copies within 30 days, provided no statutory retention obligations or claims stand in the way.

Providing this data is required in order to use the platform. Without it, we cannot set up a user account.

Organizations and Permission Management #

In eos, you can create organizations and add other users as members. In doing so, we process the name of the organization, the assignment of user accounts to organizations, and the roles and permissions assigned in each case.

We process this data to enforce the access rights you have configured, to enable you to manage your organization, and to assign services to the respective organization.

The legal basis is the performance of the usage agreement. [2] The data is stored for as long as the organization exists.

If you are added as a member of an organization, your name and email address are visible to the administrators of that organization.

Billing Account and Invoicing #

Every organization is assigned a billing account. For this we process the following data:

We process this data in order to bill for your usage, create and send invoices, allocate payments, and contact you regarding billing inquiries.

The legal basis is the performance of the contract with you. [2] To the extent we retain billing data to comply with commercial and tax-law obligations, the legal basis is compliance with a legal obligation. [3]

Recipients of this data are our payment service provider, our tax advisor, and — where legally required — the tax authorities.

We retain invoice-relevant data for the duration of the statutory retention periods, generally seven years. We delete other billing data once the organization has been deleted and no outstanding claims exist.

Providing this data is necessary for concluding and performing the contract. Without it, we cannot provide paid services.

Payment Processing #

We use an external payment service provider to process payments. When a payment is made, the data required for this is transmitted to that provider: name and contact details of the billing contact, billing address, invoice amount and currency, invoice or customer number, and the payment method you selected.

You enter your complete payment data — such as card number or bank details — directly with the payment service provider. We do not receive this data; we only receive information as to whether a payment was successful, along with a reference for allocation purposes.

The legal basis is the performance of the contract with you. [2] The transfer to the payment service provider is necessary in order to carry out the agreed payment.

The payment service provider also processes your data under its own responsibility, in particular to fulfill its own regulatory, anti-money-laundering, and payment-services-law obligations, as well as for fraud prevention. Its own privacy policy applies in this respect.

Audit Log #

The system creates an audit log entry for every action on the platform. The following is recorded: the time of the action, the resource affected, the type of action, the parameters transmitted, and the user account that performed the action.

We process this data to make changes to your resources traceable, to be able to investigate misconfigurations and security incidents, to detect unauthorized access, and to comply with our accountability obligations.

Access to the entries is tiered: which user account performed an action is visible only to administrators of the respective organization and to users with the “Auditor” role. All other users additionally only see entries for resources for which they have at least read access.

The legal basis is our legitimate interest in the traceability and security of the platform, as well as the legitimate interest of organizations in controlling their own resources. [1]

We store audit log entries for the duration of the respective organization’s use of the platform. After that use ends, we delete the entries after three years; this period corresponds to the limitation period for damages claims under Section 1489 of the Austrian General Civil Code (ABGB) and serves the assertion, exercise, or defense of legal claims. Entries needed to investigate a specific incident or for ongoing proceedings are retained until their conclusion, and processing is restricted to mere retention during that time.

Error Analysis and System Monitoring #

We use Sentry to detect and fix errors and to trigger alerts in the event of disruptions. Technical error reports are collected, which, depending on the situation, may contain the following personal data: your user account identifier, your IP address, the resource accessed, details of the browser and operating system, and the technical context of the error.

Sentry is operated by Anexia Cloud Solutions GmbH; we share use of the instance. The operator acts on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Processing takes place on servers in Austria; no transfer to a third country occurs.

The legal basis is our legitimate interest in a stable, error-free, and secure operation of the platform. [1]

Error reports are deleted after 90 days.

Analysis of Usage Behavior During the Test Phase #

eos is currently in a free test phase. If you have been admitted as a participant in our tester pool, we additionally analyze your usage behavior on the platform beyond error tracking. This includes the views accessed, interactions triggered, navigation paths, and session duration, each linked to your user account identifier.

We process this data solely to identify usability problems, improve user guidance, and further develop the platform ahead of its general availability. No evaluation of you personally or of your performance takes place. We also use Sentry for this analysis; the information on the operator and server location from the preceding section applies here as well.

The legal basis is your consent, which you give when joining the tester pool. [4] Participation in the tester pool and the related consent are voluntary. You may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

This analysis ends together with the end of the test phase. The data collected is deleted no later than three months after the conclusion of the test phase, or aggregated in such a way that it can no longer be linked to a person.

Customer Surveys #

We occasionally conduct surveys among our customers to further develop our products, services, and support. In connection with such surveys, we process the information you provide. The surveys are used to evaluate your feedback, as well as reported bugs and suggestions for improving our products and services. We use the results solely to improve our offering.

We may use personalized invitation links and/or ask for email addresses or names. If you leave this field blank, we are unable to link your answers to you personally. When you access the survey, your IP address is technically transmitted to our processor; the processor does not link it to your answers and does not pass it on to us. Where necessary to prevent multiple participation, the processor stores the IP address only in the form of a cryptographic hash value. Otherwise, we process the answers to the survey questions and your entries in free-text fields. Please do not enter any information in free-text fields that would allow conclusions to be drawn about you personally.

For the technical implementation of our surveys, we use the service Lamapoll (Lamano GmbH & Co. KG, Frankfurter Allee 69, 10247 Berlin). The provider processes the data exclusively on our behalf and in accordance with our instructions, under a data processing agreement pursuant to Art. 28 GDPR. Processing takes place on servers in Germany; no transfer to a third country occurs. The legal basis for conducting our surveys and evaluating the responses is our legitimate interest in improving our products and services. [1]

To the extent you voluntarily provide your company name or customer number, this data is processed on the basis of your consent. [4] You may withdraw this consent at any time with effect for the future. We store the survey results until the respective evaluation is completed and then delete them. Voluntarily provided identifying data (company name/customer number) is deleted once the follow-up inquiry has been resolved or the purpose no longer applies, but no later than twelve months.

Platform Metrics #

To monitor and further develop the platform, we collect operational metrics and evaluate them using Grafana. These include technical metrics on the platform’s performance and availability, as well as usage metrics at the organization level — for example, which user accounts are assigned to an organization and which resources are operated to what extent.

We process this data to plan capacity, detect disruptions early, assess the platform’s performance, and further develop our offering.

We operate Grafana and the underlying data storage ourselves on our own infrastructure. The evaluations are accessible only internally and are not made available to customers or third parties. No transfer to a third country occurs.

The legal basis is our legitimate interest in the reliable operation and further development of the platform. [1]

Metrics with personal reference are deleted after 13 months, or aggregated in such a way that personal reference is removed.

Customer Support and Contact Inquiries #

When you contact our support team or send us any other inquiry — via the contact form, our ticketing system, email, or phone — we process the following data:

We process this data to handle your request, ask follow-up questions if needed, document the matter, and identify and fix recurring issues.

To handle technical inquiries, it may be necessary for our staff to access the configuration of your resources. Such access occurs only to the extent necessary to handle your request and is logged in the audit log.

The legal basis is the performance of the contract with you, to the extent your inquiry relates to it. [2] In all other cases — for example, general inquiries prior to registration — we rely on our legitimate interest in efficient processing and in being able to demonstrate how the matter was handled. [1]

Providing your contact details is voluntary; however, without them we cannot respond to your inquiry.

We delete inquiries and the related correspondence three years after final processing, unless statutory retention obligations apply or the data is still required for the assertion, exercise, or defense of legal claims.

Your Rights #

Your Rights as a Data Subject #

You have the following rights regarding your personal data:

To exercise your rights, please contact us or our Data Protection Officer using the contact details given above.

Right to Object #

Where we process your data on the basis of legitimate interests, you have the right to object at any time to this processing for reasons arising from your particular situation. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing serves to assert, exercise, or defend legal claims.

Right to Lodge a Complaint with a Supervisory Authority #

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. The supervisory authority responsible for us is:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna

Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at

Appendix #

The reference numbers [1]–[4] used in this privacy policy refer to the following legal bases under the GDPR:

No. Legal Basis Provision Applications
[1] Legitimate interest Art. 6(1)(f) GDPR Operation and security of the platform, registration and user account (login logs), audit log, error analysis and system monitoring, customer surveys, platform metrics, customer support and contact inquiries
[2] Performance of a contract Art. 6(1)(b) GDPR Registration and user account, organizations and permission management, billing account and invoicing, payment processing, customer support and contact inquiries
[3] Legal obligation Art. 6(1) lit. c GDPR Billing account and invoicing (commercial and tax-law retention)
[4] Consent Art. 6(1)(a) GDPR Analysis of usage behavior during the test phase, customer surveys