Zum Inhalt springen
DRK Logo

ExecutiveOS

Führungsstab

Privacy Policy

This policy applies to production operation at eos.fielen.de and describes concretely which personal data is processed where.

1. Controller

German Red Cross, District Association StädteRegion Aachen (DRK-Kreisverband StädteRegion Aachen e.V.), Henry-Dunant-Platz 1, 52146 Würselen, Germany. Phone: +49 2405 6039100.

Email: Info@DRK-Aachen.de

2. Purpose and basis of processing

ExecutiveOS is an internal leadership tool for the board of the German Red Cross District Association StädteRegion Aachen. It condenses work-related communication and notes into leadership objects (threads, cases, risks, decisions, commitments). The source data is drawn from the executive management’s work Microsoft 365 account. The application is accessible only to authenticated, authorised persons; there is no self-registration.

3. Hosting and transmission

The application runs on a virtual server operated by Hetzner Online GmbH (data centres in Germany). The database (PostgreSQL) and cache/job queue (Redis) run inside the server’s internal Docker network and are not reachable from outside. The connection is encrypted end to end via TLS (certificates from Let’s Encrypt, terminated by the self-operated Caddy reverse proxy). No TLS is terminated by third parties.

4. Session cookie

A single strictly necessary cookie is set for signing in: the encrypted session (iron-session). It is HttpOnly (no JavaScript access), SameSite=lax, Secure in production and carries the __Host- prefix; it is signed/encrypted server-side and expires after 30 days. A further cookie, valid for only five minutes, secures the passkey sign-in flow. No tracking, analytics or marketing cookies are used.

5. Sign-in (passkey)

Sign-in is passwordless using a passkey (WebAuthn). For this, the name, the passkey’s public key and a counter are stored — never a password. Sign-in attempts are rate-limited (10 attempts per minute per IP); all sign-in and registration events are recorded in an audit log.

6. Microsoft 365 / Microsoft Graph

With explicit authorisation, ExecutiveOS connects via Microsoft Graph to the executive management’s work Microsoft 365 account to import emails, calendar and contacts in READ-only mode (delegated permissions to read mail, calendar and contacts, plus offline_access). No data is written back to Microsoft; email drafts are only ever created as Outlook drafts and are never sent automatically. Access tokens are stored encrypted (AES-256-GCM). Microsoft acts as a processor within the scope of the association’s existing Microsoft 365 usage.

7. AI evaluation (OpenRouter) and redaction

To evaluate text (e.g. summaries and suggestions), ExecutiveOS uses the AI gateway OpenRouter (OpenRouter, Inc., USA) — a deliberately documented exception to the principle of "no US services". It is bound to mandatory safeguards: before every external call, the text passes through a redaction gate. Names of known persons are replaced with deterministic pseudonyms (form "Person_" + short hash), and email addresses and phone numbers are masked — no plain text with real names ever leaves the system. Model inference is preferentially routed to an EU provider (Mistral AI, France), and use of the data for training purposes is prohibited. Every AI generation as well as every acceptance, edit or rejection is audited. AI results are labelled assessments, not facts, and take effect only after human confirmation.

8. AI model files (Hugging Face CDN)

For the optional local speech transcription, your browser downloads static AI model files (Whisper/pyannote) once from the Hugging Face CDN and stores them locally on your device. No personal data and never any audio recordings are transmitted in the process — it is a pure file download, like a software update.

9. Local transcription (audio)

Voice notes and conversation recordings are stored exclusively on your device and transcribed there (Whisper in the browser). The raw audio never leaves the device. Only the transcript text that you have reviewed and released is handed to the server. Recordings require the consent of all participants, documented on the device (Section 201 of the German Criminal Code).

10. Storage, retention and backups

Imported and generated data is stored in the PostgreSQL database on the server in Germany. Daily database backups are created and automatically rotated (deleted) after 14 days. Data is deleted once it is no longer needed for the leadership purpose or at the request of a data subject.

11. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. As ExecutiveOS is an internal tool without self-registration, please direct such requests to the controller named above; access and erasure are then carried out by the administration.

12. Processors

Processors used: Hetzner Online GmbH (hosting, Germany), Microsoft (Microsoft 365, within the association’s existing usage) and OpenRouter, Inc. (AI gateway, USA — documented exception with redaction, see section 7). Data processing agreements (DPAs) are in place with, or are being concluded with, the processors.

13. Open source

The entire source code of this application is publicly available and auditable.

14. Changes

This privacy policy may be adjusted when the application changes. The current version is always available at /datenschutz.