Privacy policy

Last updated: 2026-07-30

1. Controller

The controller under the GDPR is: Flovien Web — Danylo Kobzar, Auf der Schanze 6, 37079 Göttingen, Deutschland. Phone: 015228476661, email: d.kobzar@b2b.flovien.com.

No data protection officer has been appointed, as the conditions of § 38 BDSG are not met.

2. General principles

We process personal data only where necessary to provide a functioning website and our content and services, or where you have consented. Legal bases are in particular Art. 6 (1) (a), (b), (c) and (f) GDPR.

3. Hosting and server log files

This website runs with a service provider operating servers in the EU and, via content delivery networks, worldwide. When you visit the site, technical data is transmitted automatically and stored in log files:

  • IP address (shortened or stored briefly)
  • date and time of access
  • page requested and volume of data transferred
  • browser type, operating system and referrer URL

The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in operational security, stability and abuse prevention. Log data is deleted after 30 days at the latest. Data processing agreements under Art. 28 GDPR are in place with our hosting and infrastructure providers; transfers to third countries rely on the EU standard contractual clauses.

4. Cookies and consent

We use strictly necessary cookies and local storage required to operate the site (e.g. client portal session, language preference, storing your cookie decision). The legal basis is § 25 (2) no. 2 TDDDG and Art. 6 (1) (f) GDPR.

All non-essential processing — in particular audience measurement — only takes place after your explicit consent in the cookie banner (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR). You may withdraw consent at any time with effect for the future via the “Cookie settings” link in the footer.

5. Audience measurement (consent only)

If you consent, we collect pseudonymised usage statistics (e.g. pages viewed, approximate region, device type) to improve our service. There is no cross-site tracking and no profiling for advertising. Data is deleted after 14 months at the latest.

6. Contact form and email

When you contact us via the form or by email we process your name, email address, optionally your company and your message in order to handle the enquiry. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR.

The data is stored in our database and deleted once it is no longer needed and no statutory retention periods (in particular § 147 AO, § 257 HGB) apply.

7. Client portal

We set up personal accounts for clients. We process email address, name, optionally company, credentials in hashed form, and project and status data. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).

For security we log failed sign-in attempts and temporarily lock the account concerned (Art. 6 (1) (f) GDPR). Accounts are deleted after the contract ends unless retention obligations apply.

8. Recipients and processors

We disclose personal data only where necessary to perform the contract, where you consented, or where legally required. We use hosting, database and email providers, each under a data processing agreement pursuant to Art. 28 GDPR.

9. Your rights

You have the following rights towards us:

  • access to the data processed (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
  • lodging a complaint with a supervisory authority (Art. 77 GDPR)

The competent supervisory authority is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hannover. Please send requests concerning your rights to d.kobzar@b2b.flovien.com.

10. Security and changes

The website is delivered exclusively over TLS encryption (HTTPS). We take technical and organisational measures under Art. 32 GDPR to protect your data against loss and unauthorised access.

We update this privacy policy whenever the legal situation or our processing changes. The version published here applies.