TRANSPARENCY
Where your data is located, who accesses it, and how long we keep it.
Anyone purchasing cybersecurity must first be able to trust the provider. This page answers questions from data protection audits and procurement in advance - with legal bases, deletion periods, and contractual commitments for each service.
Four principles that apply to every project
EU only
Our entire infrastructure is operated at Hetzner in Germany. No US cloud, no third-country transfers, no exceptions for individual components.
Contract before access
Before the start of the project, we conclude a data processing agreement in accordance with Art. 28 GDPR. We do not process any data without a signed DPA.
data minimization
We process metadata, logs, and events - no clinical content. Patient data fundamentally does not leave your environment.
Defined deletion
For each data category, there is a defined retention period and documented erasure. No indefinite retention.
What we process per service - and for how long
The four services differ significantly in terms of the data they generate. Therefore, they are broken down separately here rather than in a generalized statement.
Phishing Simulation
PROCESSED DATA
Email addresses of the participants, click and reporting events.
STORAGE
Personal data will be completely deleted no later than 14 days after the end of the campaign.
SPECIAL FEATURE
Evaluation solely on an aggregated basis. No individual assessment, no basis for personnel measures.
Awareness training
PROCESSED DATA
Participation status, module, date, duration.
STORAGE
Verification period according to your audit requirements.
SPECIAL FEATURE
Aggregation at the department level. We do not create individual evaluations of employee performance.
Vulnerability Management
PROCESSED DATA
Asset inventory, configuration, and vulnerability data.
STORAGE
Contractually agreed project period.
SPECIAL FEATURE
Raw scan data is transmitted in encrypted form. Access is restricted to named individuals and is fully audited.
Incident D&R
PROCESSED DATA
Log and telemetry data, incident documentation.
STORAGE
Depends on your regulatory requirements, typically 12 to 24 months, followed by secure deletion.
SPECIAL FEATURE
Encrypted transmission and storage, role-based access, and comprehensive logging.
On which legal basis we operate
Data Processing Agreement, Art. 28 GDPR
We act as a data processor in all four services. You remain the data controller within the meaning of the GDPR and retain the authority to issue instructions. The Data Processing Agreement (DPA) is concluded before the start of the project and regulates the purpose, scope, sub-contracting relationships, and deletion.
Legitimate interest, Art. 6 (1) lit. f GDPR
The legal basis for the phishing simulation is the legitimate interest in IT security. The prerequisite is a clean implementation: anonymized evaluation, no individual sanctions, and transparent prior information for the workforce. All three conditions are part of our standard procedure.
Codetermination, Sec. 87 para. 1 no. 6 BetrVG
Phishing simulations are subject to co-determination because they can be considered a technical system for monitoring behavior. We provide a complete model works agreement as well as all data protection proof right from the initial consultation. In the public sector, the same applies in accordance with the respective state Staff Representation Act (Landes-PersVG).
Which standards we align ourselves with
Entropy CS was founded in 2024 and does not currently perform its own certifications. Our procedures are aligned with the following frameworks.
NIS2 / BSIG - our services generate evidence in line with the measures from § 30 BSIG
GDPR - Data processing in accordance with Art. 28, reporting processes in accordance with Art. 33
BSI B3S Medical Care - sector-specific security standard for the healthcare industry
ISO/IEC 27001 - Structure of our internal information security management
IEC 80001-1 - Risk management for IT networks incorporating medical devices
HHS 405(d) - Best Practice for Managing Connected Medical Devices
Participant of the Alliance for Cyber Security of the BSI.
Confidentiality and collaboration
Confidentiality
All employees and deployed freelancers are contractually bound to confidentiality. This obligation continues to apply beyond the end of the collaboration.
NDA on request
For discussions prior to entering into a contract, we can provide a mutual confidentiality agreement upon request. This is not required for the free risk assessment - we do not collect any sensitive technical details there.
Reference mention only with approval
We do not disclose customer names without express written consent. Even anonymized case studies are coordinated with you beforehand.
Access principle
Access to customer data is granted exclusively to individuals who require it for service delivery. Access is logged.
What happens to your information during the free risk assessment
What we collect
Your details from the 30-minute conversation regarding organization, system landscape, and current security status. No access data, no technical scans, no access to your systems.
What you get
A written report with a maturity assessment, NIS2 classification, and prioritized immediate measures - in a format ready to be shared with management, the board, or the supervisory board.
What it costs
Nothing. No hidden costs, no subsequent obligation, no automatic transition into a contractual relationship.
What happens to the data
We use your details exclusively to generate your report and to contact you. No sharing with third parties. Upon request, we will delete everything after delivering the report - an informal note by email is sufficient.
The assessment provides an initial orientation and does not replace a comprehensive technical audit.
Questions about data processing?
For questions regarding data processing, deletion periods, or our DPA, you can reach us directly at: info@entropy-cybersecurity.com · +49 30 863283641
The processing of data when visiting this website is described separately in our privacy policy.