NetLens by Eximia
Login Register

Privacy Policy (Datenschutzerklärung)

DRAFT — this privacy policy is a working draft and requires review by Eximia management and legal / data-protection counsel before publication.

1. Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) for data processed on this platform is:

[TO BE CONFIRMED BY EXIMIA] Company name and legal form
[TO BE CONFIRMED BY EXIMIA] Address
E-mail: [TO BE CONFIRMED BY EXIMIA]

2. Data we process

  • Account data — name, e-mail address, organisation and a salted password hash, provided when you register. Used to operate your account and to attribute uploads within your tenant (Art. 6(1)(b) GDPR — performance of a contract).
  • Uploaded network captures — PCAP/PCAPNG files you upload for analysis, and the analysis results derived from them (decoded packets, subscriber sessions, flows, anomalies). Captures may contain personal data of network subscribers (e.g. IMSI, MSISDN, IP addresses, SIP identities); you are responsible for having a lawful basis to upload such captures. Captures are stored in your tenant's isolated storage prefix and are never shared across tenants.
  • Usage and operational metrics — request logs (IP address, timestamp, requested path, trace id), job and quota metrics per tenant. Used to secure and operate the service (Art. 6(1)(f) GDPR — legitimate interest).

3. Processors and hosting

  • Google Cloud (Frankfurt, Germany, region europe-west3) — infrastructure hosting: compute, database and object storage. All customer data is stored in the EU.
  • DeepSeek — large-language-model provider used for the opt-in AI root-cause analysis feature. Only when you explicitly request an AI analysis are extracts of the relevant capture metadata transmitted for processing. If you do not use the AI analysis feature, no capture data leaves the EU hosting environment.
  • ntfy — operational alerting for the Eximia operations team (service health notifications). No customer capture content is transmitted; alerts carry technical identifiers only.

[TO BE CONFIRMED BY EXIMIA] Data-processing agreements (Art. 28 GDPR) and, where applicable, transfer mechanisms (Chapter V GDPR) for each processor.

4. Retention

Uploaded captures and derived analysis results are retained until you delete the corresponding analysis session or your tenant is offboarded, at which point they are removed from primary storage. Account data is retained for the lifetime of the account. Operational logs are retained for a limited period for security and troubleshooting. [TO BE CONFIRMED BY EXIMIA] Exact retention periods and backup expiry windows.

5. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17) and restriction of processing (Art. 18),
  • data portability (Art. 20),
  • object to processing based on legitimate interest (Art. 21),
  • lodge a complaint with a supervisory authority (Art. 77) — in Germany, the data-protection authority of the federal state in which the controller is established.

To exercise these rights, contact: [TO BE CONFIRMED BY EXIMIA] privacy contact address.

6. Cookies

NetLens uses only strictly necessary cookies: the authentication cookies that hold your login session (JWT access and refresh tokens, HttpOnly). No analytics, advertising or third-party tracking cookies are set, so no cookie consent banner is required.

© 2026 Eximia
Imprint · Privacy · Terms