Last updated: 2026.09.09
DeepXplore Labs GmbH ("we", "our", or "us") is the controller of personal data processed in connection with the DeepXplore website and customer accounts, unless stated otherwise below. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit deepxplore.io or use our Services.
DeepXplore Labs GmbH
Friedrich-Neumeyer-Weg 4
84453 Mühldorf am Inn
Germany
Commercial register: HRB 35651, Amtsgericht Traunstein
Email: [email protected]
Phone: +49 8631 6970521
See also our Impressum.
We are the controller for website usage, marketing pages, account administration, billing metadata we receive from Paddle, and support communications.
We are the processor for Customer Environment Data — metrics, logs, traces, configuration, and repository or ticket context that you connect so we can provide Performance Tests, Root Cause Analysis, and DeepXplore Code. You (or your organization) remain the controller of that data. A data processing agreement (DPA) is available on request.
When you register or contact us we may process name, email address, company name, and similar business contact details. Account authentication is handled by Auth0. We sync identifiers such as name and email into our own database to operate the Services.
Payments are processed by Paddle as merchant of record. We do not store credit card numbers. Paddle may share billing name, email, tax location, plan, and transaction status with us so we can provision the subscription. See Paddle’s privacy policy.
We may process IP address, device and browser type, timestamps, and similar logs needed to operate and secure the website and application. DNS resolution, content delivery, bot protection, and encrypted tunnelling are provided by Cloudflare and may involve processing of IP addresses, request metadata, and related security telemetry.
If you connect clusters, observability tools, or source-control systems, we process telemetry and related technical content you designate (for example metrics, logs, traces, and configuration). This data is intended to be operational, not consumer personal data. You must not send special categories of personal data or unnecessary production personal data into the Services. Metrics and results from performance tests are retained for three weeks, then deleted.
On app.deepxplore.io we use Vercel Web Analytics to understand product usage (pages viewed, referrers, coarse location, operating system, and browser). Details are in our Cookie Policy.
We process personal data only where a legal basis applies:
AI features (root-cause explanations, test generation, proposed code changes) are advisory. We do not make solely automated decisions that produce legal or similarly significant effects on you (GDPR Art. 22).
Payments are processed by Paddle. DeepXplore does not store credit card information. Please refer to https://paddle.com/legal/privacy.
Accounts are authenticated by Auth0. We sync certain information such as name and email to our database. See Auth0’s documentation: https://auth0.com/docs/secure/data-privacy-and-compliance.
We use cookies and similar technologies as described in our Cookie Policy. That page covers necessary cookies (including Cloudflare security cookies where used), Auth0 session cookies on the app, Paddle checkout cookies, and Vercel Web Analytics on app.deepxplore.io (cookieless request hashing, still disclosed as analytics processing).
We do not sell personal data. We share information with service providers under contract, including:
We may also disclose information if required by law or to protect our rights, users, or the public.
Some providers process data in the United States or other countries outside the EEA (notably Auth0, Paddle, Google Cloud, Vercel, and Cloudflare). Where required, transfers are based on the European Commission’s Standard Contractual Clauses or another GDPR-approved mechanism, together with supplementary measures those providers document.
Metrics and results from performance tests are kept for three weeks, then deleted. When a subscription is cancelled, or a fee is not paid in time, we permanently delete the organization at the end of the already-paid term, together with remaining Customer Data, configurations, telemetry, and other information we are not required to keep by law. Billing and invoice-related records are kept as required by German commercial and tax law (typically up to ten years). Support correspondence may be kept as long as needed to document the relationship or a legal claim. You may also request deletion as described below, subject to those legal retention duties.
If the GDPR applies, you may have the right to:
To exercise these rights, email [email protected]. You also have the right to lodge a complaint with a supervisory authority. For Bavaria, that is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA). You may also contact the authority of your usual place of residence or work.
We use industry-standard measures appropriate to the risk, including encryption in transit, access controls, and least-privilege practices. No system is completely secure. Please protect your login credentials and use least-privilege tokens when connecting Customer Environments.
The Services are offered to businesses, not to children. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it.
We may update this Privacy Policy. We will change the date above and, for material changes, provide additional notice (for example by email) where reasonably practicable. Continued use of the Services after the effective date means you have read the updated policy.
Email: [email protected]
Website: https://deepxplore.io