privacy

Privacy policy

What Fleetless stores, where it runs, who else touches it and how long any of it is kept. Written from the system as it actually runs, not from a template.

Who we are and how to reach us

The controller for the processing described here is:

Dehne Robotik GmbH
Rosentwiete 1
25355 Groß Offenseth-Aspern
Germany

Telephone: +49 4123 80 699 60
E-mail: hello@dehne-robotik.de

Data protection enquiries reach us at the same address. We have not appointed a data protection officer; we are not required to.

This policy covers the public site at fleetless.dev, the documentation at docs.fleetless.dev, the developer console at console.fleetless.dev and the API and realtime services behind them.

What data we process

Developer account data. Your e-mail address, a password hash, the organisation and groups you belong to and the roles assigned to you. Actions that change something are written to an audit log; an audit entry names the acting user’s e-mail address, the affected resource and what changed.

End-user account data. Apps built on Fleetless can sign in their own end users. Their e-mail addresses, group memberships and role assignments are processed on the developer’s behalf — the developer is the controller for them, we are the processor.

Robot telemetry. Datapoint values published by a robot’s bridge, each carrying the bridge’s own capture time. What a robot exposes, and how long each datapoint is kept, is configured by the developer.

Camera data. Live video is relayed between the robot and the viewer and is not recorded. A snapshot is held in memory until the next frame replaces it, so several viewers asking at once are served from one capture; nothing is written to permanent storage.

Usage metering. Per organisation and billing period: the high-water mark of connected robots, live-video minutes and stored asset bytes. Aggregates, not per-person records.

Waiting list. While Fleetless is in closed beta, the sign-up form on the landing page stores the e-mail address you submit and the time of submission.

Server logs. Every request to the API is logged with a timestamp, a request id, the method, the full URL, the host, the client IP address, the status code and the response time. Request and response bodies are not logged, cookies are not logged, and no user agent is recorded. The static hosts fleetless.dev and docs.fleetless.dev keep no access log.

Job history. Commands sent to a robot are recorded with the acting user’s e-mail address, the target and the outcome.

  • Art. 6(1)(b) GDPR — performance of a contract: your developer account, the console and the API services you use.
  • Art. 6(1)(f) GDPR — legitimate interests: server logs, the audit log and the job history, for operating the service, diagnosing faults and detecting abuse.
  • Art. 6(1)(a) GDPR — consent: the waiting list. You may withdraw it at any time, with effect for the future, by writing to the address above; we then delete the entry.

Where we process end-user data for a developer’s app, the developer’s own legal basis applies and we act under Art. 28 GDPR.

Where data is hosted and for how long

Everything runs on servers rented from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in Hetzner’s German data centres. No production data is stored outside Germany.

Data Kept
Developer and end-user account data until the account is deleted, then until the last backup containing it expires
Robot telemetry the retention configured for each datapoint by the developer
Camera snapshots a short-lived cache only; live video is never recorded
Audit log and job history 90 days
Server logs until the application container is replaced, which happens at the next deploy
Database backups taken daily, kept for 14 days
Waiting-list entries until the closed beta opens, or earlier on request

Processors and subprocessors

  • Hetzner Online GmbH (address above) — hosting and backups, in Germany, under a data processing agreement.
  • Our own mail server — transactional e-mail (invitations, password resets, verification) is sent from mail.dehne-robotik.de, operated by us on the same infrastructure. No third-party mail provider receives your address.
  • Cloudflare, Inc. — authoritative DNS for the fleetless.dev zone only. Proxying is switched off, so no request, no page and no API traffic passes through Cloudflare; it answers name lookups and nothing else.

There is no analytics, no advertising, no tag manager, no third-party font or script host and no embedded third-party content on any Fleetless page.

International transfers

Stored data is not transferred outside the EU.

The one named exception is DNS: a lookup for a fleetless.dev name is answered by Cloudflare, Inc., which may serve it from a node outside the EU. Such a query carries the name being looked up and the IP address of the asking resolver — usually your provider’s, not yours — and no page content, no account data and no request body.

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw a consent you have given (Art. 7(3)) with effect for the future.

To exercise any of them, write to hello@dehne-robotik.de.

You may also complain to a supervisory authority. The one competent for us is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Holstenstraße 98
24103 Kiel
Germany

If your app’s end-user data is concerned, address the developer whose app you use — they are the controller for it.

Cookies and local storage

Fleetless sets no advertising and no analytics cookies. The complete list of what any Fleetless surface stores in your browser:

Name Set by Purpose Lifetime
fl_session console.fleetless.dev keeps a developer signed in to the console (session tokens, org and user) 30 days
fl_auth_flow console.fleetless.dev carries the sign-in handshake (PKCE verifier, state, return path) between the console and the auth portal 10 minutes
fleetless_console_signup_proof_<id> auth portal binds the two sign-up steps to one browser 10 minutes
fleetless_consent_proof_<id> auth portal binds an app’s consent screen to the browser that signed in 10 minutes
fleetless_mcp_consent_proof_<id> auth portal binds the AI-tool consent screen to the browser that signed in 10 minutes
nuxt-color-mode (localStorage) console.fleetless.dev theme preference until cleared
fleetless-theme (localStorage) docs.fleetless.dev (read by fleetless.dev as well) theme preference until cleared

Names ending in <id> carry a per-interaction suffix, one per sign-in or consent screen.

Every entry above is either strictly necessary for a function you asked for — signing in, completing a consent screen — or a preference you set yourself. None of them requires consent, so this site shows no cookie banner. The public site at fleetless.dev and the documentation at docs.fleetless.dev store nothing but the theme preference.

Changes to this policy

We change this page when the system changes. The last updated date at the foot of the page is the announcement; there is no separate notification. Earlier versions are available on request at hello@dehne-robotik.de.

last updated 2026-09-04