TRANSPARENCY

Where your data is located, who accesses it, and how long we keep it.

Anyone purchasing cybersecurity must first be able to trust the provider. This page answers questions from data protection audits and procurement in advance - with legal bases, deletion periods, and contractual commitments for each service.

Four principles that apply to every project

EU only

Our entire infrastructure is operated at Hetzner in Germany. No US cloud, no third-country transfers, no exceptions for individual components.

Contract before access

Before the start of the project, we conclude a data processing agreement in accordance with Art. 28 GDPR. We do not process any data without a signed DPA.

data minimization

We process metadata, logs, and events - no clinical content. Patient data fundamentally does not leave your environment.

Defined deletion

For each data category, there is a defined retention period and documented erasure. No indefinite retention.

What we process per service - and for how long

The four services differ significantly in terms of the data they generate. Therefore, they are broken down separately here rather than in a generalized statement.

Phishing Simulation

PROCESSED DATA

Email addresses of the participants, click and reporting events.

STORAGE

Personal data will be completely deleted no later than 14 days after the end of the campaign.

SPECIAL FEATURE

Evaluation solely on an aggregated basis. No individual assessment, no basis for personnel measures.

Awareness training

PROCESSED DATA

Participation status, module, date, duration.

STORAGE

Verification period according to your audit requirements.

SPECIAL FEATURE

Aggregation at the department level. We do not create individual evaluations of employee performance.

Vulnerability Management

PROCESSED DATA

Asset inventory, configuration, and vulnerability data.

STORAGE

Contractually agreed project period.

SPECIAL FEATURE

Raw scan data is transmitted in encrypted form. Access is restricted to named individuals and is fully audited.

Incident D&R

PROCESSED DATA

Log and telemetry data, incident documentation.

STORAGE

Depends on your regulatory requirements, typically 12 to 24 months, followed by secure deletion.

SPECIAL FEATURE

Encrypted transmission and storage, role-based access, and comprehensive logging.

On which legal basis we operate

Data Processing Agreement, Art. 28 GDPR

We act as a data processor in all four services. You remain the data controller within the meaning of the GDPR and retain the authority to issue instructions. The Data Processing Agreement (DPA) is concluded before the start of the project and regulates the purpose, scope, sub-contracting relationships, and deletion.

Legitimate interest, Art. 6 (1) lit. f GDPR

The legal basis for the phishing simulation is the legitimate interest in IT security. The prerequisite is a clean implementation: anonymized evaluation, no individual sanctions, and transparent prior information for the workforce. All three conditions are part of our standard procedure.

Codetermination, Sec. 87 para. 1 no. 6 BetrVG

Phishing simulations are subject to co-determination because they can be considered a technical system for monitoring behavior. We provide a complete model works agreement as well as all data protection proof right from the initial consultation. In the public sector, the same applies in accordance with the respective state Staff Representation Act (Landes-PersVG).

Which standards we align ourselves with

Entropy CS was founded in 2024 and does not currently perform its own certifications. Our procedures are aligned with the following frameworks.

NIS2 / BSIG - our services generate evidence in line with the measures from § 30 BSIG

GDPR - Data processing in accordance with Art. 28, reporting processes in accordance with Art. 33

BSI B3S Medical Care - sector-specific security standard for the healthcare industry

ISO/IEC 27001 - Structure of our internal information security management

IEC 80001-1 - Risk management for IT networks incorporating medical devices

HHS 405(d) - Best Practice for Managing Connected Medical Devices

Participant of the Alliance for Cyber Security of the BSI.

Confidentiality and collaboration

Confidentiality

All employees and deployed freelancers are contractually bound to confidentiality. This obligation continues to apply beyond the end of the collaboration.

NDA on request

For discussions prior to entering into a contract, we can provide a mutual confidentiality agreement upon request. This is not required for the free risk assessment - we do not collect any sensitive technical details there.

Reference mention only with approval

We do not disclose customer names without express written consent. Even anonymized case studies are coordinated with you beforehand.

Access principle

Access to customer data is granted exclusively to individuals who require it for service delivery. Access is logged.

What happens to your information during the free risk assessment

What we collect

Your details from the 30-minute conversation regarding organization, system landscape, and current security status. No access data, no technical scans, no access to your systems.

What you get

A written report with a maturity assessment, NIS2 classification, and prioritized immediate measures - in a format ready to be shared with management, the board, or the supervisory board.

What it costs

Nothing. No hidden costs, no subsequent obligation, no automatic transition into a contractual relationship.

What happens to the data

We use your details exclusively to generate your report and to contact you. No sharing with third parties. Upon request, we will delete everything after delivering the report - an informal note by email is sufficient.

The assessment provides an initial orientation and does not replace a comprehensive technical audit.

Questions about data processing?

For questions regarding data processing, deletion periods, or our DPA, you can reach us directly at: info@entropy-cybersecurity.com · +49 30 863283641

The processing of data when visiting this website is described separately in our privacy policy.

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.

FREE RISK ASSESSMENT

30 minutes. An honest picture of your security posture.

Every conversation begins with a free risk assessment — 30 minutes, no obligation. You will then receive a written report with your cybersecurity maturity level, risk areas, and immediate measures.