Privacy policy
Last updated
Draft — not yet legally reviewed
This document is a structural scaffold, not legal advice, and it is excluded from search indexing until it is finished. Placeholders are written in angle brackets and must be replaced before launch. Have a qualified lawyer review it before taking payment from customers.
This policy explains what personal data TreeFlow processes, on what legal basis, and what rights you have under the General Data Protection Regulation (GDPR).
Controller
The controller responsible for processing personal data on this site and in the TreeFlow application is the entity named in the imprint.
What we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account data (name, email, password hash) | Providing the service, authentication | Art. 6(1)(b) GDPR — performance of a contract |
| Workspace content (trees, evidence, comments) | Providing the service | Art. 6(1)(b) GDPR — performance of a contract |
| Billing data (company, address, VAT ID, payment status) | Invoicing and tax obligations | Art. 6(1)(b) and 6(1)(c) GDPR |
| Server logs (IP address, user agent, timestamp) | Operating and securing the service | Art. 6(1)(f) GDPR — legitimate interest |
| Product analytics | Understanding usage to improve the product | Art. 6(1)(a) GDPR — consent |
Retention
<State how long each category is kept. Account and workspace data are typically retained until the account is deleted; invoices must be kept for ten years under German commercial and tax law; server logs are usually deleted after a short period.>
Recipients and subprocessors
We use a small number of processors to operate the service. Each is bound by a data processing agreement. The current list, including what each one processes and where, is published on the subprocessors page.
Transfers outside the EU
<Describe any transfers to third countries and the safeguards relied upon, for example EU standard contractual clauses or an adequacy decision. Stripe in particular involves a US transfer.>
Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16), to have it deleted (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future.
You can export your data and delete your account from within the application. For anything else, contact us at the address in the imprint.
Right to complain
You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is <competent Landesdatenschutzbehörde>.