Privacy

Privacy Policy

How Sixfold OS collects, uses, and protects personal data, structured to Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679).

Last updated: 4 July 2026

This document is a template provided for information only. It is not legal advice and not a certification. Any remaining placeholders in square brackets must be completed, and the whole text reviewed by qualified counsel, before it is relied upon.

1. Controller and contact

The controller responsible for the processing of personal data on this website and across the Sixfold OS ecosystem, within the meaning of Article 4(7) GDPR, is:

  • Claus Nisslmüller e.U.
  • Mitterbergerweg 6
  • 4040 Linz
  • Austria
  • Email: admin@sixfoldux.com
  • Phone: +43 699 108 737 81

Data protection officer (where a DPO has been appointed under Article 37 GDPR): [DPO contact]. Questions about this policy or your rights can be sent to admin@sixfoldux.com.

2. Categories of personal data

Depending on how you interact with Sixfold OS, we process the following categories of personal data:

Account and identity data

Name, email address, and the identity attributes returned by our authentication provider (see Section 4). Sixfold OS mirrors only the minimal identity claims needed to establish a session and does not store passwords.

Authorization data

Role assignments and access scopes (for example workspace and module scopes) used to enforce role-based access control and tenant/workspace boundaries.

Usage and technical data

Server logs, IP address, device/browser metadata, and timestamps generated when you access the site or a module, used for security, diagnostics, and audit records.

Content and workspace data

Information you or your organization enter into a module workspace. This data is isolated per tenant, per workspace, and per module namespace.

Communications data

Messages, support requests, and contact-form submissions you send to us, including the contents and the metadata of that correspondence.

Where personal data is obtained from a source other than you (Article 14 GDPR) — for example identity attributes relayed by your organization's identity provider — the categories above still apply and the source is your organization or its chosen identity provider.

3. Purposes and legal bases

We process personal data for the following purposes and on the following legal bases under Article 6(1) GDPR:

Providing the service (Art. 6(1)(b))

Authenticating you, provisioning access, and operating the module workspaces you or your organization use, on the basis of the contract or pre-contractual measures.

Security and abuse prevention (Art. 6(1)(f))

Maintaining audit records, security event logging, and access controls, on the basis of our legitimate interest in operating a secure and accountable platform.

Legal compliance (Art. 6(1)(c))

Retaining records and responding to lawful requests where required by applicable law.

Communications and support (Art. 6(1)(b)/(f))

Responding to enquiries and providing support, on the basis of the contract or our legitimate interest in assisting users.

Consent-based processing (Art. 6(1)(a))

Any optional processing (for example non-essential analytics or marketing) is carried out only with your consent, which you may withdraw at any time.

4. Processors and recipients

Authentication is delegated to Auth0 (Okta, Inc.), which acts as a processor under Article 28 GDPR on the basis of a data processing agreement. Auth0 handles login, session issuance, and single sign-on; Sixfold OS receives only the minimal identity claims needed for a session.

Further processors and recipients may include:

  • [Hosting / infrastructure provider] — application and database hosting.
  • [Email / communications provider] — transactional email and support.
  • [Additional sub-processors — see the Security & Trust page for the current list].

We do not sell personal data. Data is shared with processors only under contract and only to the extent necessary to provide the service. A current list of sub-processors is maintained on the Security & Trust page.

5. International transfers

Where personal data is transferred to a country outside the European Economic Area, we rely on an appropriate safeguard under Chapter V GDPR — typically an adequacy decision or the European Commission's Standard Contractual Clauses, supplemented by additional technical and organizational measures where required.

Our authentication provider is configured in the European region (Auth0 EU tenant). Specific transfer mechanisms for each sub-processor are documented on request at admin@sixfoldux.com.

6. Retention

Personal data is retained only as long as necessary for the purposes for which it was collected, or as required by applicable law:

  • Account and authorization data — for the duration of the account, then deleted or anonymized within [retention period].
  • Security and audit records — retained for [retention period] to support accountability and incident investigation.
  • Workspace content — retained for the term of your organization's engagement and deleted or returned on termination, subject to [retention period] backups.
  • Communications — retained for [retention period] after the matter is closed.

7. Your rights

Subject to the conditions in the GDPR, you have the right to:

  • Access your personal data (Art. 15).
  • Rectify inaccurate data (Art. 16).
  • Erase data (Art. 17).
  • Restrict processing (Art. 18).
  • Data portability (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3)).

To exercise any of these rights, contact admin@sixfoldux.com. You also have the right to lodge a complaint with a supervisory authority (Art. 77). The competent authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Vienna.

Where Sixfold OS acts as a processor for your organization (for example over content you enter into a workspace), please direct data-subject requests to your organization as the controller; we will support them under our processing agreement.

8. Automated decision-making

Sixfold OS does not make decisions producing legal or similarly significant effects about you based solely on automated processing within the meaning of Article 22 GDPR. Where a module surfaces automated suggestions, these are informational outputs subject to human review — not legal advice or certification.