LEGAL
PRIVACY
How FOCX GmbH processes personal data when you use driftmirror.com and DRIFTMIRROR.
1. CONTROLLER
FOCX GmbH
Wörthstraße 47
72764 Reutlingen
Germany
Managing Director: Serkan Elbasan
Telephone: +49 7121 7532962
Email: support@focx.store
2. SCOPE
This notice covers the public DRIFTMIRROR website and the DRIFTMIRROR product. Customer-specific processing terms, instructions and processor obligations are supplemented by the applicable customer agreement and, where required, a Data Processing Agreement under Art. 28 GDPR.
3. WEBSITE AND SERVER REQUEST DATA
When the website is requested, the hosting/runtime infrastructure necessarily processes technical request data needed to deliver and secure the service, such as IP address, request time, requested resource, browser/user-agent information and technical response data where generated by the hosting environment.
This project does not state that advertising or analytics tracking is used where the deployed site does not actually implement it.
4. ACCOUNT AND WORKSPACE DATA
Where product access is provided, DRIFTMIRROR processes account and workspace membership information required for authentication, authorization, customer administration and service operation.
5. CRM, SOURCE AND IMPORT DATA
DRIFTMIRROR may process CRM deal identifiers, deal state/history fields, pipeline and stage information, owner identifiers, relevant sales timestamps, amounts/currency, source associations and other source evidence required by the configured canonical evidence model.
HubSpot is connected read-only. Optional granted scopes can add metadata for contacts, companies, meetings, calls, tasks and CRM email engagements. Email bodies and call transcripts are not required or stored for the HubSpot connector.
CSV/XLSX imports retain source provenance. Unresolved source fields remain unresolved rather than being silently inferred.
6. HUMAN OBSERVATIONS
Users may enter operational observations into DRIFTMIRROR. These are stored as product evidence with workspace context and provenance. An observation does not become recurrence evidence merely because it was entered; the product keeps unresolved or unlinked evidence separate.
7. PURPOSES AND LEGAL BASES
Personal data is processed to provide and administer the contracted service, connect permitted source systems, reconstruct comparable operating evidence, operate security and authorization controls, provide support, fulfill customer instructions, and maintain legally or operationally required accountability.
Depending on the relationship and processing activity, the legal basis may be Art. 6(1)(b) GDPR for contract or pre-contract steps, Art. 6(1)(f) GDPR for legitimate interests in secure and reliable service operation, Art. 6(1)(c) GDPR for legal obligations, and consent under Art. 6(1)(a) GDPR only where consent is actually required and obtained.
8. PROCESSORS, RECIPIENTS AND CONNECTED SOURCES
The current production architecture uses Supabase for authentication, PostgreSQL, storage and Edge Functions, and OpenAI API for limited server-side candidate-generation/planning processing. Production hosting/runtime providers are documented for the deployed environment.
Customer-connected CRM systems such as HubSpot are source systems selected by the customer and are addressed separately in the customer-specific data-flow and contractual review. See the Subprocessor List.
9. MODEL PROCESSING BOUNDARY
Server-side model calls are limited to DRIFTMIRROR candidate-generation and planning functions. They receive explicitly constructed structural context for that function. HubSpot OAuth tokens are not supplied to the model, and the product does not require email bodies or call transcripts for these calls.
10. INTERNATIONAL TRANSFERS
Where use of a processor involves a transfer to a third country, the applicable contractual and legal safeguards are documented in the customer DPA and subprocessor/onboarding information for the deployed environment. This page does not invent provider-specific transfer arrangements that have not been verified.
11. RETENTION, EXPORT AND DELETION
Customer workspace data is retained according to the applicable contract, customer policy and documented production configuration. DRIFTMIRROR includes workspace export and deletion processes. Workspace deletion removes customer workspace, source, evidence, mechanic, rule and test data belonging to that workspace.
Minimal security or privacy accountability records may be retained only where required by the documented legal or security retention policy. No generic fixed retention period is asserted here.
12. YOUR GDPR RIGHTS
Subject to the statutory conditions, data subjects may have rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, consent may be withdrawn for the future. You also have the right to lodge a complaint with a competent data protection supervisory authority.
13. AUTOMATED ANALYSIS
DRIFTMIRROR performs structural analysis of operating evidence. It does not build employee scores or psychological profiles. Product analysis and suggested rule changes remain decision-support outputs; customer authority controls determine who may act on them.
14. SECURITY
DRIFTMIRROR uses workspace isolation, authorization controls, server-side credential handling, encrypted HubSpot OAuth credential storage, data minimization, separate security auditing and customer privacy operations as described in the Security Center.
15. CONTACT
Privacy requests concerning DRIFTMIRROR can be sent to support@focx.store.