Skip to content

Legal

Privacy Policy

Last updated: 17 July 2026

This privacy policy informs you in accordance with Articles 13 and 14 GDPR about the processing of personal data by fastmon labs UG (haftungsbeschränkt) in connection with visiting our websites and using our Software-as-a-Service offering "fastmon" (Real User Monitoring).

1. Controller

fastmon labs UG (haftungsbeschränkt)
Stresemannallee 4, 30173 Hannover, Germany
Hannover Local Court, HRB 230880
Managing Directors: Kamil Adrian Czujowski, Lucas Röhrs
Privacy contact: privacy@fastmon.eu

2. Data Protection Officer

A Data Protection Officer is not required under Article 37 GDPR. The central contact for privacy enquiries is privacy@fastmon.eu.

3. Supervisory Authority

The competent supervisory authority is the State Commissioner for Data Protection Lower Saxony (LfD Niedersachsen), Prinzenstraße 5, 30159 Hannover, Germany.

4. Processing when visiting our websites

Each time you access one of our websites, our reverse proxy collects technical data (timestamp, requested resource, HTTP status, referrer category, derived country code). Source IP addresses are not stored in logs but stripped at the edge. Logs are retained for a maximum of 7 days and serve technical purposes only (security, error analysis).

Legal basis: Article 6 (1) f GDPR (legitimate interest in technical operation).

Our websites do not use tracking cookies or web-analytics tools that process personal data.

5. Real User Monitoring (fastmon service)

When you visit a website that has the fastmon beacon script embedded, technical performance metrics are collected. The controller for this processing is the respective website operator with whom we have entered into a data processing agreement pursuant to Article 28 GDPR.

5.1 What is collected

In the default mode "anonymous", only aggregated, data-minimised telemetry is collected:

  • Core Web Vitals (LCP, INP, CLS, TTFB, FCP) and other technical performance metrics
  • Browser family and major version, OS category, device class, viewport class
  • Country code (ISO 3166), derived from the IP address
  • Path of the visited page (query string and anchor are discarded)
  • Referrer category (e.g. "Google / search"), not the full referrer URL
  • UTM parameters (truncated to 64 characters), click-ID parameter name (not the value)

5.2 What is not collected

  • No cookies and no device access in default mode
  • No persistent identifiers, no user IDs, no cross-site identifiers
  • No raw IP address (discarded at edge within less than 1 second)
  • No raw User-Agent string
  • No personal names, email addresses, form inputs, page content, click heatmaps, mouse movements, keystrokes, session replays

5.3 Edge Stripping and Stitch Identifier

The IP address and raw User-Agent are processed exclusively at the edge server transiently (less than 1 second in memory) to derive country code and browser category. They are then irreversibly discarded. Storage in the application, database or logs does not occur at any time.

For cookieless counting of unique visitors within a browser session, a server-side computed hash value (Stitch) is used. This is an HMAC-SHA256 based on a secret salt that rotates every 24 hours and exists only in the memory of the edge server. Linking of page views is limited to a maximum of 24 hours, after which the recognition chain ends. Cross-site or cross-device recognition is technically impossible.

5.4 Retention

Default retention period for telemetry data is 90 days. On Enterprise plans, configurable per site up to 13 months.

5.5 ePrivacy / Consent

In the default mode "anonymous", nothing is stored on the end user's device; the storage limb of Section 25 (1) of the German Telecommunications-Digital Services Data Protection Act (TDDDG) is therefore not met. However, Section 25 TDDDG also covers read access to information on the device. Whether reading the browser's performance APIs falls under this provision has not been conclusively settled; under the prevailing interpretation it does. Assessing the consent requirement for a specific integration is the responsibility of the operator of the respective website.

In the optional modes "consent" and "full", session identifiers are stored in the browser's sessionStorage; in consent mode additionally a _fm_consent cookie. These modes are activated exclusively after opt-in via the website operator's consent management platform.

6. Dashboard usage (account data)

When you register as a customer with fastmon, we process the following data as controller:

  • Name, email address, password hash, organisation affiliation, login timestamps
  • Invoicing data: company name, address, VAT ID, contact person, invoice amount, payment data

Legal basis: Article 6 (1) b GDPR (performance of a contract), for invoicing data additionally Article 6 (1) c GDPR and Sections 257 HGB and 147 AO (10-year retention obligation).

7. Optional AI Chat function

In the dashboard, an optional AI chat function can be activated that enables LLM-based analysis. When activated, user prompts and account or telemetry context data are transmitted to Mistral AI SAS (Paris, France). Processing takes place exclusively at EU endpoints. Inputs and outputs are not used for model training. The function is disabled by default.

8. Processors and Recipients

We use the following processors and recipients. All are located in the EU or EEA.

ProviderLocationPurpose
Hetzner Online GmbHDEHosting, storage, backup
sevdesk GmbHDEAccounting, invoicing
Mollie B.V. (independent controller)NLPayment processing (PSD2)
Lettermint B.V.NLTransactional emails
Soverin B.V.NLBusiness mail hosting
Mistral AI SASFRLLM inference (opt-in only)
BunnyWay d.o.o. (bunny.net)SIAuthoritative DNS service
smoxy GmbHDEIngress
ScaleCommerce GmbHDEHosting
All Quiet GmbHDEOn-call tool (internal)

For internal purposes unrelated to customer or visitor data (source code management, project management, development tools) we use additional providers, including US-based providers (GitHub, Linear, Anthropic). They do not receive personal data of website visitors, customers or their end users. A full overview of all providers is available at fastmon.eu/en/subprocessors.

9. Third-country transfers

Within the processing operations described in this policy, no personal data is transferred to countries outside the EU or EEA. Third-country transfers occur only in compliance with Articles 44 et seq. GDPR; when a third-country provider is engaged, data subjects are informed in advance.

10. Your rights as data subject

  • Access to your processed data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Lodging a complaint with the supervisory authority (Art. 77 GDPR)

Note on Art. 11 GDPR: Due to our data-minimised architecture (edge stripping of IP and User-Agent, no persistent identifiers, 24-hour limit on the Stitch), direct attribution of telemetry data to a natural person is regularly not possible. An access or erasure request relating to telemetry data therefore requires that you provide additional information enabling identification.

Please direct enquiries to privacy@fastmon.eu.

11. Further documents