Privacy Policy
Information pursuant to Art. 13 & 14 GDPR
1. Controller
The controller for data processing on this website is:
Mirko Daether – Xypher Cyber Labs
Glambecker Straße 1, 17235 Neustrelitz
Email: daether@xyphercyberlabs.ai • Phone: +49 155 67620492
2. General information on data processing
I only process personal data to the extent necessary to provide a functioning website and my content and services, or where you have consented. Your data is not transferred to US services; processing takes place on servers in Germany or the EU.
3. Hosting
This website is hosted by Hostinger. The data is processed on servers within the European Union.
Provider: Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. A data processing agreement (Art. 28 GDPR) is in place with the provider. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a secure and efficient provision of the website).
Server log files
When the website is accessed, information that your browser transmits is automatically recorded (so-called server log files):
- Browser type and version
- Operating system used
- Referrer URL
- Host name of the accessing computer / shortened IP address
- Time of the server request
This data is not merged with other data sources and serves technical security and stability. Legal basis: Art. 6 (1) (f) GDPR.
4. Contact form
If you send me enquiries via the contact form, your details from the form (name, company, email address, phone number, message) are stored with me to process the enquiry and in case of follow-up questions.
The technical processing of the form takes place via an automation solution (n8n) operated by me on a server in Germany. No form data is transmitted to providers outside the EU.
The legal basis for enquiries related to a contract is Art. 6 (1) (b) GDPR; otherwise your consent (Art. 6 (1) (a) GDPR) and my legitimate interest in responding (Art. 6 (1) (f) GDPR). The data remains with me until the purpose of storage no longer applies or you request deletion; statutory retention periods remain unaffected.
5. Recipients and processors
To provide this website and process enquiries, I use carefully selected service providers. These include in particular the hosting provider of this website and the provider of the server (VPS) in Germany on which my automation solution (n8n) runs, and – where necessary for delivery – an email service. Data processing agreements pursuant to Art. 28 GDPR are in place with these providers. For AI-supported processing, the AI Model Hub of IONOS Cloud (inferencing in a Berlin data centre) is additionally used as a sub-processor; the staff involved in processing there are contractually bound to confidentiality, including the protection of the secrets of professionals with a duty of confidentiality under § 203 StGB. Personal data is not transferred to countries outside the EU/EEA unless the requirements of Art. 44 et seq. GDPR are met.
6. Processing as part of client orders
Where I act as a processor for you (Art. 28 GDPR) and process personal data of your customers on your behalf, this is done exclusively on the basis of a separate data processing agreement and according to your instructions. Processing takes place on servers in Germany.
7. Storage period
Personal data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations (e.g. under commercial or tax law) prevent this.
8. Your rights
Within the statutory provisions, you have the following rights:
- Access to your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
An informal message to daether@xyphercyberlabs.ai is sufficient to exercise these rights.
9. Right to complain to a supervisory authority
You have the right to complain to a data protection supervisory authority. Responsible bodies include the State Commissioner for Data Protection and Freedom of Information Mecklenburg-Vorpommern, Werderstraße 74a, 19055 Schwerin.
10. SSL/TLS encryption
For security reasons, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in your browser’s address bar.
11. Status
This privacy policy is dated July 2026. Further development of the website or changed legal requirements may make an update necessary.