FARION.AI
  • Home
  • Product
      • Platform
      • Platform overview
      • Exploitability Analysis
      • Supply Chain Security
      • Vulnerability Management
      • Active Verification
      • Software License Compliance
      • Solutions
      • Cyber Resilience Act
      • NIS2 Compliance
      • SaaS Application Security
      • AI-Generated Code Security
      • Container Security
      • Pricing
      • Plans & pricing
      • About
      • Technology overview
      • Contact us
      • Imprint
      • Privacy
      • Farion dashboard
        Start free now
  • About
Sign in
Start free now

This is an informational, AI-generated translation of the German privacy policy. It is not legally binding; the German version applies.

Privacy policy

Last updated: 1 October 2026

1. Data protection at a glance

General information

The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on data protection can be found in the privacy policy below this text.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. The operator's contact details can be found in the legal notice (Impressum) of this website.

How do we collect your data?

Some data is collected when you provide it to us, for example when you write to us by email or book a call through our website. Other data is collected automatically, or after your consent, by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system or time of the page visit).

What do we use your data for?

Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

2. General information and mandatory disclosures

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.

We point out that data transmission over the internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.

Controller

The controller responsible for data processing on this website is:

Nexode Consulting GmbH
Oberwallstraße 6
10117 Berlin, Germany

Phone: +49 30 4397375 0
Email: info@nexode.de

The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

Retention period

Unless a more specific retention period is stated in this privacy policy, your personal data remains with us until the purpose for the data processing no longer applies. If you assert a justified request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data; in the latter case, deletion takes place once those reasons cease to apply.

Legal bases for data processing

Where we have obtained your consent to the processing of personal data, Art. 6(1)(a) GDPR is the legal basis. Where processing is necessary for the performance of a contract to which you are a party, Art. 6(1)(b) GDPR is the legal basis. Where there is a legal obligation to process, Art. 6(1)(c) GDPR applies. In all other cases (in particular legitimate interests), Art. 6(1)(f) GDPR applies.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected by the withdrawal.

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

3. Rights of data subjects

Information, deletion and correction

Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to correction or deletion of this data. You can contact us at any time about this and about further questions on the subject of personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing.
  • If the processing of your personal data was or is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of processing instead of deletion.
  • If you have lodged an objection under Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of processing.

Objection to promotional emails

We hereby object to the use of contact data published as part of the legal notice obligation for sending unsolicited advertising and information material. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, such as spam emails.

4. Data collection on this website

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser transmits to us automatically. These are:

  • browser type and browser version
  • operating system used
  • referrer URL
  • host name of the accessing computer
  • time of the server request
  • IP address

This data is not merged with other data sources. The data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website. Server log files are stored for 30 days and then deleted.

Cookies

Our website uses technically necessary cookies or comparable storage technologies that are required to operate the site, for example to store your language choice and your cookie decision and to maintain your session after signing in. In addition, and only with your consent, we use analytics cookies or comparable technologies for reach and product analysis and for error and performance analysis (see the sections "Web analytics with PostHog" and "Error and performance analysis with Grafana Faro").

Technically necessary cookies are stored on the basis of Art. 6(1)(f) GDPR; the operator has a legitimate interest in a functional, user-friendly website. Where cookies are not technically necessary, they are set only with your consent (Art. 6(1)(a) GDPR). You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases or to exclude them in general.

Web analytics with PostHog

On the basis of your consent (Art. 6(1)(a) GDPR), we use PostHog, a product and reach analytics tool. PostHog helps us understand how our website and our service are used, in order to improve both. The data collected includes in particular event and usage data (e.g. pages visited and actions triggered), device and browser information, a truncated IP address and a pseudonymous identifier; for signed-in users, a user identifier may additionally be assigned.

Data is collected via a reverse proxy under our own domain. Processing and storage take place in PostHog's EU cloud (eu.i.posthog.com) with servers located in the European Union (Frankfurt, AWS eu-central-1). Session replay is disabled by default; if it is enabled, sensitive input such as passwords and form contents is masked.

The provider is PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. The data is stored in the EU; insofar as PostHog, as a US company, obtains access, the transfer is safeguarded by certification under the EU-US Data Privacy Framework and additionally by EU standard contractual clauses. We have concluded a data processing agreement with PostHog.

You can withdraw your consent at any time with effect for the future by adjusting your cookie or consent settings. The lawfulness of the processing carried out until the withdrawal remains unaffected.

Error and performance analysis with Grafana Faro

On the basis of your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), we use Grafana Faro, open-source software for error and performance analysis in the browser (real user monitoring). It helps us detect and fix errors and loading problems on our website and in our service. The data collected includes in particular JavaScript errors, loading and response times (Web Vitals), pages visited and navigation events, browser and device information, the IP address and a pseudonymous session identifier, which is stored in your browser's session storage (sessionStorage) and expires when the browser is closed. For signed-in users, the user identifier may additionally be assigned.

We run Grafana Faro ourselves on our own infrastructure in the AWS region Frankfurt (eu-central-1) (see the section "Hosting"). No external analytics provider is involved; the data is transmitted neither to Grafana Labs nor to any other third party. Error and event data is stored for 30 days and performance traces for 7 days, after which they are deleted.

You can withdraw your consent at any time with effect for the future by changing your choice via the "Cookie settings" link in the page footer. On withdrawal, collection stops and the session identifier is removed from your browser. The lawfulness of the processing carried out until the withdrawal remains unaffected.

Contact by email

If you send us enquiries by email, your details, including the contact data you provide, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested.

Booking a call

You can book a call with us through our website. For this we process your name, your email address, the chosen time slot, your time zone and an optional message. The appointment is created as a calendar entry with an invitation and a video-conference link in our Google Workspace calendar (Google Calendar and Google Meet). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may also process the data on servers outside the EU; the transfer is safeguarded by certification under the EU-US Data Privacy Framework and additionally by EU standard contractual clauses. We have agreed Google's data processing terms for Google Workspace (Cloud Data Processing Addendum) with Google.

The legal basis is Art. 6(1)(b) GDPR (implementation of pre-contractual measures at your request). The data is deleted as soon as it is no longer required for holding the call and for any follow-up questions, unless statutory retention obligations prevent this.

5. Hosting

Amazon Web Services (AWS)

We host our website and our service with Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg ("AWS"). Operations take place in the AWS region Frankfurt (eu-central-1). When you visit our website, your personal data is processed on AWS servers.

AWS is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR.

We have concluded a data processing agreement with AWS. This agreement ensures that AWS processes the data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

6. Use of the Farion service

Account and usage data

For registration and use of the Farion platform, we process account and usage data (in particular name, email address, role and the technical access and audit data required for security and traceability). The legal basis is Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (operation and security of the service).

Processing of customer data on behalf of customers

Insofar as you, as a customer, provide your own data (e.g. source code and technical artefacts) as part of the security analysis, we process this data exclusively on your behalf and in accordance with your instructions. The separately concluded data processing agreement (AVV), including the technical and organisational measures described therein, is decisive in this respect. Customer data is not used to train AI models; AI-assisted analysis takes place within the AWS region Frankfurt (eu-central-1).

Customer data processed on a customer's instructions is governed by the data processing agreement (AVV, in German) including the technical and organisational measures.


FARION.AI

The Farion platform combines native SAST, exploitability-aware SCA with SBOM, VEX and license compliance, and SAST-informed active AI verification.

Platform
Platform overviewExploitability AnalysisSupply Chain SecurityVulnerability ManagementActive VerificationLicense Compliance
Solutions
Cyber Resilience ActNIS2 ComplianceSaaS Application SecurityAI-Generated Code SecurityContainer SecurityCompliance
Scanners
SASTSCADAST
Technology
Technology overviewVulnerability IntelligenceRoute & Data Flow AnalysisLanguages & FrameworksArchitecture & DeploymentIntegrations
Farion
About usPricingFAQsSecurityContact us
Legal
ImprintPrivacyTerms and Conditions (AGB)
Contact
sales@farion.ai

© All rights reserved.