Privacy Notice
Last updated: 1 October 2026
This notice covers the website meshnode.com and its contact form. It does not cover services we provide to business customers under separate agreements. It applies to people in the European Union and the European Economic Area under the General Data Protection Regulation (GDPR) and to people in Switzerland under the Swiss Federal Act on Data Protection (FADP). For people in Switzerland, the corresponding FADP terms apply.
1. Controller
Airfy Inc.
201 W. 5th Street, 16th Floor
Austin, TX 78701
United States
Email: steffen@airfy.com
2. Visiting the website
When you open a page, our web server processes your IP address, date and time, the requested address, the status code, the amount of data transferred, the page you came from (referrer), your browser identifier (user agent) and the X-Forwarded-For header if your browser or a proxy sends it. It stores these data in log files. Error logs also contain your IP address.
Purpose: delivering the pages, secure operation, error analysis and defense against attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.
Retention: section 6.
The website sets no cookies. We use no analytics or advertising services. The pages load all content from our own web server. The only exception is Cloudflare Turnstile in the contact form (section 3).
3. Spam protection with Cloudflare Turnstile
The contact form uses Cloudflare Turnstile from Cloudflare, Inc. (USA). Turnstile tells requests from people apart from requests by programs. The Cloudflare script loads only when you use the form: when you click or tap into it, type in it, move into it with the Tab key, or submit it. It does not load when you open or scroll the page. Only once it loads does Cloudflare receive your IP address and technical details about your browser and connection. Turnstile stores one entry for challenges.cloudflare.com in your browser's storage (cf.turnstile.u). It sets no cookies. When you submit the form, our form service checks the result with Cloudflare.
Purpose: protecting the form against spam and abuse.
Legal bases: For storing and reading information in your browser, Art. 5(3) of Directive 2002/58/EC as implemented in national law (in Germany, Section 25(2) no. 2 TDDDG). This is strictly necessary for sending the form as you request. For all further processing, Art. 6(1)(f) GDPR. Our legitimate interest is keeping out automated requests.
Cloudflare processes these data on our behalf. Cloudflare also uses them as an independent controller to improve its bot detection. Cloudflare's notice applies to that: https://www.cloudflare.com/turnstile-privacy-policy/
You can prevent this by blocking scripts from challenges.cloudflare.com. You then cannot submit the form, but you can email us at steffen@airfy.com.
4. Contact form
When you submit the form, we process your name, your email address, your company if you provide it, the site brief you put together in the form as your message (environment, application, existing connectivity and nearest uplink, your role, timing and notes), and the website the request comes from, your IP address and the time of submission. For the spam check, the form service also evaluates technical values, such as the time between opening and submitting the form. It does not store them.
“Copy brief” and “Download .txt” work in your browser only. We receive nothing when you use them.
Our form service runs on a server in Germany. It does not store your request. It forwards your request as an email through the delivery service SendGrid of Twilio Ireland Limited to our ticket system. The ticket system and the mail server run on servers in Germany.
To prevent overload, the form service counts requests in memory only: per hour by a shortened hash of your IP address, and per day by website. Its own logs contain this hash, not your IP address. The web server in front of the form service logs each request with your IP address as described in section 2, but not the content of your request.
Messages that look like spam are discarded without an error message. If you do not hear from us, please email steffen@airfy.com.
If the form does not go through, the page lets you email us instead. Section 5 then applies.
Purposes and legal bases:
- Answering your request: Art. 6(1)(b) GDPR if you are seeking a contract with us yourself. Otherwise, for example for requests on behalf of a company, Art. 6(1)(f) GDPR. Our legitimate interest is answering business inquiries.
- Your IP address in the request: investigating spam and abuse, Art. 6(1)(f) GDPR.
Providing your details is voluntary. Without your name, your email address and at least one detail about your site or project we cannot answer your request.
Retention: section 6.
5. Emailing us
If you email us, the purpose and legal basis for answering your request in section 4 apply. We process emails to addresses at airfy.com in mailboxes at Google Workspace of Google LLC (USA). We process emails to addresses at airzen.io on our mail server and in our ticket system on servers in Germany.
6. Retention
We delete web server log files automatically after 14 days at most.
We delete the form service's logs after six weeks at most.
We have not yet set a fixed deletion period for requests and emails to us. They remain stored until we delete them. You may request deletion at any time (sections 10 and 11). Statutory retention duties take precedence.
If our mail server classifies a forwarded request or an email to an address at airzen.io as spam, it moves it to a spam folder. Purpose: protection against spam. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is secure email operation. Our ticket system does not fetch this folder. The folder is currently not emptied automatically.
Our mail server logs technical connection and delivery data when emails are received, sent and retrieved: the time, the sender and recipient addresses, the IP addresses and host names of the servers and devices involved, message and queue identifiers, the message size, the delivery status and delay including the receiving server's response, encryption parameters, the results of spam and sender authentication checks and, for mailbox access, the user name, IP address and session counters. It does not log the subject or content of emails. Purpose: delivery, troubleshooting and abuse prevention. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is reliable and secure delivery. We have not yet set a fixed maximum period for the log files on the mail server. The mail server replaces some of them by number and size of the files, not by their age. The existing log files go back to early 2023. Another copy in the mail server's system journal remains until the server next restarts. We delete the copy in our monitoring system after 30 days. A backup of this copy does not yet have a deletion period.
We back up the mail server and the ticket system daily. Purpose: recovery after an outage or data loss. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is being able to restore data after an outage. We do not currently delete these backups. Data we delete therefore remains in older backups.
7. Recipients
- AirZen Networks Lda., Portugal: operation of the web server, the form service, the mail server and the ticket system, on our behalf.
- Hetzner Online GmbH, Germany: servers and backup storage in data centers in Germany, on behalf of AirZen Networks Lda.
- Twilio Ireland Limited, Ireland: delivery of form requests (SendGrid), on behalf of AirZen Networks Lda. Twilio Ireland Limited uses Twilio Inc. (USA) for delivery.
- Cloudflare, Inc., USA: spam protection (Turnstile) on our behalf; as an independent controller for improving its bot detection (section 3).
- Google LLC, USA: mailboxes for addresses at airfy.com (Google Workspace), on our behalf.
8. Transfers to the United States
Recipients based in the United States are Cloudflare, Inc., Twilio Inc. and Google LLC. Each of them is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework (www.dataprivacyframework.gov). For people in the EU and the EEA, transfers to them rely on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023. For people in Switzerland, they rely on Annex 1 of the Swiss Data Protection Ordinance (DPO).
We, Airfy Inc., are based in the United States. From there we access the data that our service providers in the EU process for us. Implementing Decision (EU) 2023/1795 and Annex 1 of the DPO cover certified companies only. Airfy Inc. is not certified.
9. No automated decision-making
We make no automated decisions within the meaning of Art. 22 GDPR. If the spam check fails, you can email us.
10. Your rights under the GDPR
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17) and restriction of processing (Art. 18). Where we rely on Art. 6(1)(b) GDPR, you also have the right to data portability (Art. 20). Please write to steffen@airfy.com. You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).
11. People in Switzerland
You may request access (Art. 25 FADP). You may request the handover or transfer of the data you gave us where the conditions of Art. 28 FADP are met. You may request the correction of inaccurate data, object to the processing and request erasure (Art. 32 FADP). You may contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
12. Changes
We update this notice when our processing changes. The version published here applies.