Skip to content
widefleet
Product
OverviewBuild, deploy and improve your apps. Auth & accessCompany login and app permissions. Data & storageDatabases and private files for every app. Deployments & logsPreviews, releases and runtime context.
Docs Self-hosting Cloud Coming soon
GitHub ↗ Get started

Legal

Privacy policy

How personal data is processed on the Widefleet website and docs.

Last updated: 9 October 2026.

1. Scope and controller

This notice covers widefleet.com, including /docs, and its previews. The controller under the General Data Protection Regulation (GDPR) is:

Everyday Systems 42 GmbH
Schillerstraße 17
89568 Hermaringen
Germany

Email: privacy@widefleet.com

See our imprint for company details. Independently operated, self-hosted installations are not covered. Widefleet Cloud is not yet available; its privacy information will be provided before launch.

2. Hosting and security

Cloudflare, Inc. hosts and delivers our website and docs. It processes IP addresses, requested URLs, timestamps, browser information and technical logs to deliver content, prevent abuse and diagnose faults. Protected previews also use Cloudflare Access, which processes sign-in details, such as your email address, and authentication cookies.

The legal basis is our legitimate interest in secure, reliable delivery and access control under Article 6(1)(f) GDPR. Strictly necessary device storage or access is based on section 25(2)(2) TDDDG. Cloudflare privacy information.

Cloudflare Workers Logs are kept for up to seven days. Access and other security logs have plan-dependent periods; the seven-day limit does not cover all Cloudflare-held data.

3. Optional analytics

Only after you select Allow do we load PostHog, Inc.'s analytics service to understand visits and interactions and improve our website and docs. Before your choice and after Decline, our integration sends no data to PostHog.

Analytics can include page URLs and query parameters, referring pages, timestamps, device and browser information, clicks, documentation searches and code-copy events. Cookie identifiers connect visits across the website and docs. We use PostHog's EU endpoint with IP anonymization enabled. PostHog receives your IP address when your browser connects to it. Session recording and named user profiles are disabled.

The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent is voluntary; both sites work without analytics. PostHog privacy information.

PostHog provides up to seven years of queryable event history, not a guaranteed deletion deadline. Browser-storage periods and withdrawal are described below.

4. Your choice and browser storage

A preference cookie remembers Allow or Decline for 180 days across the website and /docs on the same host. It contains your choice, not a unique visitor identifier. A browser-storage copy keeps the docs in sync; an expired cookie prompts you again. This necessary preference storage is based on section 25(2)(2) TDDDG and Article 6(1)(c), together with Article 7 GDPR.

After Allow, analytics cookies last up to 180 days and may be renewed during visits; browser storage also holds session information. Reopen Cookie settings in either footer and select Decline to withdraw consent. This stops analytics and clears its browser identifiers. Other open tabs apply the change when you return to them. Withdrawal does not affect earlier lawful processing or automatically delete events already collected.

5. Email contact

We use Google Workspace to receive, store and respond to email, including your address and message. The legal basis is Article 6(1)(b) GDPR for contractual enquiries, otherwise our legitimate interest in responding under Article 6(1)(f) GDPR. Google privacy information.

Email enquiries are retained until final resolution, unless statutory retention applies. Qualifying business correspondence is generally retained for six years and accounting vouchers for eight, starting at the relevant year-end.

6. International processing

Cloudflare, PostHog and Google may process data outside the European Economic Area, including in the United States. Transfers covered by the EU-US Data Privacy Framework rely on the EU's adequacy decision; EU Standard Contractual Clauses apply where required. Details: Cloudflare, PostHog and Google.

7. Your rights

Subject to the applicable requirements, you can request access, correction, erasure, restriction and data portability under Articles 15 to 20 GDPR. You can withdraw consent at any time. Where processing relies on legitimate interests, you can object on grounds relating to your situation under Article 21 GDPR. Contact privacy@widefleet.com to exercise these rights; we may need information to verify your identity or locate your data.

You can complain to a data protection supervisory authority, particularly where you live, work or believe an infringement occurred. We do not use website analytics for automated decisions with legal or similarly significant effects. Providing data for optional analytics is not required by law or contract.

8. External links and updates

External websites have their own privacy notices. Fonts and brand assets are served with this website. We update this notice when our processing changes; the date above identifies this version.

widefleet

Open-source platform for agent-built apps and workflows.

© 2026 Widefleet

Back to top
ProductOverviewAuth & accessData & storageDeployments & logs
Resources Docs Self-hosting Cloud Coming soon GitHub ↗
Legal Privacy policy Imprint