Privacy Policy

Personal data are processed when using foxondo:

1. Data processing when working with foxondo

If you work with foxondo as a user, personal data are processed for the following purposes:

  • Provision of the system
  • Granting user rights
  • Logging of foxondo usage for audit and system security reasons

The following data categories are being processed about users:

  • Name
  • Business email address
  • Employer
  • Rights and user settings in foxondo
  • Which data you have entered, changed or deleted when in foxondo
  • Your Mr.FOX-points In addition, personal data about other people may be processed if users enter them in input fields in foxondo.

If these data were not collected by the user himself, it was provided by the employer or colleagues or calculated within foxondo.

The data can be viewed by your employer and, if applicable, employees within your own group. Service providers who provide or maintain the IT infrastructure and who are separately bound to confidentiality can also view the data.
The storage period depends on the above-mentioned purposes and, if applicable, on the statutory retention periods.

The legal basis for data processing is the fulfilment of your contractual obligations to your employer (Art. 6 Para. 1 Letter b GDPR) as well as the legitimate interests of your employer (and, if applicable, the external data protection officer) in the audit-proof documentation of the current status within the organisation (Art. 6 Para. 1 Letter f GDPR).

2. Data processing for the technical provision of foxondo

For the technical provision of the service it is necessary to process personal data:

  • Server log files
    The provider and the system collect and store information that your browser automatically transmits to us. These are mainly browser type and version, operating system used, referrer URL (originating address), host name of the accessing computer, the requested files with date and time and the IP address.
    These data are not merged with other data sources.
    The basis for data processing is Art. 6 Para. 1 Letter f GDPR, which permits the processing of data on the basis of legitimate interest. In this case, there is a legitimate interest in a secure and functioning operation of the web server. In order to ensure this, the administration must be able to detect and trace attacks and malfunctions of the system via server log files. In order to be able to recognize attack patterns, accesses to the server must be stored. As soon as these data are no longer needed, they are deleted. For technical reasons, the data is disclosed to the IT service providers, who are bound by instructions and contract to us.

  • Cookies
    foxondo sometimes uses cookies. They serve to make the offer more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser. The cookies used here are so-called “session cookies” to enable access to the site. They are automatically deleted at the end of your visit.
    You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for specific cases or in general and activate the automatic deletion of cookies when closing the browser. If you deactivate cookies, the functionality of this website may be limited. The cookies are required for the electronic communication process and are stored on the basis of Art. 6 Para. 1 Letter f GDPR. We have a legitimate interest in the storage of cookies for the technically error-free and optimised provision of our services. Insofar as other cookies are stored for other purposes, these are explained separately in this privacy policy.

  • Notifications by e-mail
    The user will be notified automatically by e-mail about important events in foxondo. This includes, for example, when a question of a module assigned to him or her receives the status “action required” or when the approval of a module is requested.
    The notification serves to make the system more user-friendly and is in the legitimate interest of the controller. If the user does not want to receive these notifications, they can deactivate them via the settings in the burger menu (and also reactivate them if they wish).

  • Error Detection
    To detect technical errors foxondo uses services from AppSignal B.V. (The Netherlands) and Rapid7 (USA). Although it is not the services main purpose to process personal data, in individual cases the transmission of personal data (e.g., a log-in name or IP address) cannot be ruled out, if prior pseudonymization is not possible in the individual case. The legal basis for this data processing is Art. 6 Para. 1 Letter f GDPR (if necessary, in combination with EU Standard Contractual Clauses). The legitimate interest lies in the detection and correction of technical errors and optimisation of the functionality of the website.

  • Newsletter
    foxondo users can subscribe to the foxondo newsletter. To do so, they can register with their e-mail address. The legal basis is consent (Art. 6 Para. 1 Letter a GDPR).
    You can unsubscribe at any time, for example by clicking on the unsubscribe link in the footer of the e-mail or by sending an e-mail to We use technical service providers to send the newsletter. We do not evaluate the usage or click behaviour on a personal basis.

3. Responsibility

Your employer is responsible for data processing by foxondo.
If your employer has appointed an external data protection officer, the employer and the company of the external data protection officer are joint controllers.
The contact details, including those of the data protection officer, can be found after logging in on the “Help & Contact” page.

4. Your rights

As a data subject, you are entitled to the following rights, provided that the legal requirements are met:

  • Right to be informed, Art. 15 GDPR
  • Right to rectification, Art. 16 GDPR
  • Right to erasure, Art. 17 GDPR
  • Right to restriction of processing, Art. 18 GDPR
  • Right to data portability, Art. 20 GDPR
  • Right to object, Art. 21 GDPR If the data processing is based on your consent, you may revoke this consent at any time with effect for the future. If the data processing is based on legitimate interests, you can assert your right to object. You must give reasons for your objection. You also have the right to complain about the data processing to the data protection supervisory authority. If you have any further questions about how and for what purposes we process your data, please contact us.