Privacy policy
What Fleetless stores, where it runs, who else touches it and how long any of it is kept. Written from the system as it actually runs, not from a template.
Who we are and how to reach us
The controller for the processing described here is:
Dehne Robotik GmbH
Rosentwiete 1
25355 Groß Offenseth-Aspern
Germany
Telephone: +49 4123 80 699 60
E-mail: hello@dehne-robotik.de
Data protection enquiries reach us at the same address. We have not appointed a data protection officer; we are not required to.
This policy covers the public site at fleetless.dev, the documentation at docs.fleetless.dev, the developer console at console.fleetless.dev and the API and realtime services behind them.
What data we process
Developer account data. Your e-mail address, a password hash, the organisation and groups you belong to and the roles assigned to you. Actions that change something are written to an audit log; an audit entry names the acting user’s e-mail address, the affected resource and what changed.
End-user account data. Apps built on Fleetless can sign in their own end users. Their e-mail addresses, group memberships and role assignments are processed on the developer’s behalf — the developer is the controller for them, we are the processor.
Robot telemetry. Datapoint values published by a robot’s bridge, each carrying the bridge’s own capture time. What a robot exposes, and how long each datapoint is kept, is configured by the developer.
Camera data. Live video is relayed between the robot and the viewer and is not recorded. A snapshot is held in memory until the next frame replaces it, so several viewers asking at once are served from one capture; nothing is written to permanent storage.
Usage metering. Per organisation and billing period: the high-water mark of connected robots, live-video minutes and stored asset bytes. Aggregates, not per-person records.
Waiting list. While Fleetless is in closed beta, the sign-up form on the landing page stores the e-mail address you submit and the time of submission.
Server logs. Every request to the API is logged with a timestamp, a request id, the method, the full URL, the host, the client IP address, the status code and the response time. Request and response bodies are not logged, cookies are not logged, and no user agent is recorded. The static hosts fleetless.dev and docs.fleetless.dev keep no access log.
Job history. Commands sent to a robot are recorded with the acting user’s e-mail address, the target and the outcome.
Legal basis
- Art. 6(1)(b) GDPR — performance of a contract: your developer account, the console and the API services you use.
- Art. 6(1)(f) GDPR — legitimate interests: server logs, the audit log and the job history, for operating the service, diagnosing faults and detecting abuse.
- Art. 6(1)(a) GDPR — consent: the waiting list. You may withdraw it at any time, with effect for the future, by writing to the address above; we then delete the entry.
Where we process end-user data for a developer’s app, the developer’s own legal basis applies and we act under Art. 28 GDPR.
Where data is hosted and for how long
Everything runs on servers rented from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in Hetzner’s German data centres. No production data is stored outside Germany.
| Data | Kept |
|---|---|
| Developer and end-user account data | until the account is deleted, then until the last backup containing it expires |
| Robot telemetry | the retention configured for each datapoint by the developer |
| Camera snapshots | a short-lived cache only; live video is never recorded |
| Audit log and job history | 90 days |
| Server logs | until the application container is replaced, which happens at the next deploy |
| Database backups | taken daily, kept for 14 days |
| Waiting-list entries | until the closed beta opens, or earlier on request |
Processors and subprocessors
- Hetzner Online GmbH (address above) — hosting and backups, in Germany, under a data processing agreement.
- Our own mail server — transactional e-mail (invitations, password resets, verification) is sent from
mail.dehne-robotik.de, operated by us on the same infrastructure. No third-party mail provider receives your address. - Cloudflare, Inc. — authoritative DNS for the fleetless.dev zone only. Proxying is switched off, so no request, no page and no API traffic passes through Cloudflare; it answers name lookups and nothing else.
There is no analytics, no advertising, no tag manager, no third-party font or script host and no embedded third-party content on any Fleetless page.
International transfers
Stored data is not transferred outside the EU.
The one named exception is DNS: a lookup for a fleetless.dev name is answered by Cloudflare, Inc., which may serve it from a node outside the EU. Such a query carries the name being looked up and the IP address of the asking resolver — usually your provider’s, not yours — and no page content, no account data and no request body.
Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw a consent you have given (Art. 7(3)) with effect for the future.
To exercise any of them, write to hello@dehne-robotik.de.
You may also complain to a supervisory authority. The one competent for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Holstenstraße 98
24103 Kiel
Germany
If your app’s end-user data is concerned, address the developer whose app you use — they are the controller for it.
Cookies and local storage
Fleetless sets no advertising and no analytics cookies. The complete list of what any Fleetless surface stores in your browser:
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
fl_session |
console.fleetless.dev | keeps a developer signed in to the console (session tokens, org and user) | 30 days |
fl_auth_flow |
console.fleetless.dev | carries the sign-in handshake (PKCE verifier, state, return path) between the console and the auth portal | 10 minutes |
fleetless_console_signup_proof_<id> |
auth portal | binds the two sign-up steps to one browser | 10 minutes |
fleetless_consent_proof_<id> |
auth portal | binds an app’s consent screen to the browser that signed in | 10 minutes |
fleetless_mcp_consent_proof_<id> |
auth portal | binds the AI-tool consent screen to the browser that signed in | 10 minutes |
nuxt-color-mode (localStorage) |
console.fleetless.dev | theme preference | until cleared |
fleetless-theme (localStorage) |
docs.fleetless.dev (read by fleetless.dev as well) | theme preference | until cleared |
Names ending in <id> carry a per-interaction suffix, one per sign-in or consent screen.
Every entry above is either strictly necessary for a function you asked for — signing in, completing a consent screen — or a preference you set yourself. None of them requires consent, so this site shows no cookie banner. The public site at fleetless.dev and the documentation at docs.fleetless.dev store nothing but the theme preference.
Changes to this policy
We change this page when the system changes. The last updated date at the foot of the page is the announcement; there is no separate notification. Earlier versions are available on request at hello@dehne-robotik.de.
last updated 2026-09-04