FixControl
Privacy

Privacy Policy

This privacy statement explains how FixControl processes personal data through the public website and the FixControl service.

Last updated: 2026-07-08

01Who is responsible?

FixControl is a trade name of FixControl B.V. i.o.. For the public website, FixControl B.V. i.o. is the data controller.

For data that customers process within the FixControl service, FixControl may act as a processor on behalf of the customer, depending on the agreements made. In some situations FixControl B.V. i.o. may itself be the data controller. Which role applies depends on the context and is, where necessary, recorded in a data processing agreement (DPA) or customer contract.

02Which personal data do we process?

Depending on how you use FixControl and which integrations are enabled, we may process the following categories of data. Not every customer uses all components, so not all of this data is always applicable.

Contact and company data

Name, email address, organisation, job title and the content of your message.

Account and user data

Name, email address, role and permissions, and links to a tenant, project or workspace.

Support, issue and workflow data

Tickets, issues, messages via Slack, Freshdesk, Jira, Linear, GitHub or GitLab (depending on the integrations used), approvals, audit events and workflow statuses.

Technical and security data

IP address, browser and user-agent data, log files, error messages, and audit and security events.

Website data

Pages visited and referrer. Aggregate, privacy-friendly analytics may be used if enabled at a later stage.

Integration data

Metadata and content required to make connected systems work. Tokens and secrets are processed securely and are not shown publicly.

AI-related data

Prompts, context and outputs required to execute workflows, only to the extent that customers or users provide these within the service.

Depending on the customer configuration, we may also process codebase or repository metadata, to the extent necessary to deliver the service.

03Why do we process data?

  • responding to contact requests;
  • delivering the FixControl service;
  • creating and managing accounts, tenants and projects;
  • processing support and engineering workflows;
  • displaying and executing approvals;
  • running integrations with customer tools;
  • security, audit logging and fraud prevention;
  • improving the website and the product experience;
  • complying with legal obligations.

04Legal bases

We process personal data on the following GDPR legal bases:

  • the performance of a contract;
  • a legitimate interest, for example security, audit logging and product improvement;
  • compliance with a legal obligation;
  • your consent where necessary, for example for non-essential cookies or certain marketing communications;
  • pre-contractual communication for a demo or contact request.

05AI processing

FixControl uses AI features to support workflows, for example for triage, summaries, plan proposals, draft replies or remediation proposals. Human approval remains part of high-risk actions.

Which AI services or models are used may depend on the customer configuration. Customer data is used only to deliver the service and is not sold.

Depending on the configuration, AI service providers may be engaged as processors. Customer agreements may set out additional terms regarding which AI services are used and which data is shared with them.

06Integrations and third parties

To deliver the service we may rely on processors and other third parties. Which parties these are depends on the customer configuration. Categories include, among others:

  • hosting and infrastructure providers;
  • email and communication providers;
  • an analytics provider, if enabled;
  • AI service providers;
  • integration platforms such as Slack, Microsoft Teams/Office 365, Google (Gmail), Freshdesk, Jira, Linear, GitHub, GitLab and Kubernetes/Argo, depending on the customer configuration;
  • payment or administration providers, if relevant at a later stage.

Independent of the customer configuration, we rely on the following subprocessors by default for the core functionality of the service:

  • TransIP B.V. (hosting, the Netherlands) — hosts the FixControl service and stored data on infrastructure in the European Union;
  • Anthropic, PBC (AI language models) — processes prompts, context and outputs to the extent necessary to deliver the AI features of the service;
  • Resend, Inc. (transactional email) — handles email sent from the service, such as notifications and approval requests.

We may update this list of subprocessors from time to time. The current list is always available in this privacy statement; in the event of significant changes, we may actively inform customers.

We share data only to the extent necessary to deliver and secure the service, to comply with legal obligations, or based on the customer configuration. Specific processors and arrangements may be recorded in a data processing agreement (DPA) or in the customer contract.

07International transfers

The FixControl service itself is hosted on infrastructure in the European Union (Netherlands).

Some processors, including the AI and email service providers named above, may be located outside the European Economic Area (EEA). Where that is the case and necessary, appropriate safeguards are used, such as standard contractual clauses or comparable mechanisms.

08Retention periods

We do not retain data longer than necessary. The retention period depends on the type of data and the purpose:

  • contact requests: for as long as needed for follow-up and business administration;
  • account data: for as long as the account is active or as long as required for legal or contractual obligations;
  • audit and security logs: for as long as needed for security, compliance and dispute handling;
  • customer data: in accordance with the customer contract, the configuration or the data processing agreement;
  • website analytics: aggregated and for as short a period as is practically appropriate.

09Security

We take appropriate technical and organisational measures to protect personal data, including:

  • access control and roles;
  • scope per tenant and project;
  • logging and audit trails;
  • encryption where appropriate;
  • secure management of secrets;
  • human approvals for high-risk workflows;
  • monitoring and security measures.

10Cookies and analytics

FixControl uses privacy-friendly, aggregated website analytics to understand which public pages are visited. We do not use session replay or advertising tracking on the public website unless explicitly stated.

  • necessary and functional cookies may be used to make the website and the service work;
  • limited, privacy-friendly analytics may be used to measure the performance of the public website;
  • tracking cookies, advertising pixels or session replay are not used, unless explicitly stated and where required with consent;
  • you can manage cookies through your browser settings.

11Your rights

Under the GDPR you have, among others, the following rights:

  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to object;
  • the right to data portability;
  • the right to withdraw consent you have given;
  • the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Would you like to exercise one of these rights? Please contact us at contact@fixcontrol.ai.

12Contact

Do you have questions about this privacy statement or about the processing of your data? Please get in touch with us.

FixControl
a trade name of FixControl B.V. i.o.
Italiaanse Zeedijk 122 C
1621 AK Hoorn
Nederland

13Changes

We may amend this privacy statement from time to time. The most recent version is always available on this page. In the event of significant changes, we may actively inform you.