LEGAL · PRIVACY

Privacy Policy

As of 07/2026 Version 1.05 GDPR-compliant DE · EU

How User Flow processes personal data, transparent, complete and in accordance with the requirements of the GDPR. This English version is a convenience translation, in the event of any discrepancies, the German version shall prevail. Use the table of contents to jump straight to a section.

Contents

1. Controller

The controller within the meaning of Art. 4(7) GDPR for the processing of personal data in connection with the use of the website user-flow.de, the web-based application app.user-flow.de and all services offered through them is:

User Flow LT UG (haftungsbeschränkt) i.G.

Alt-Möllner-Straße 37–42, Gebäude B

23879 Mölln

Germany

E-mail: info@user-flow.de

Website: https://user-flow.de

CRM application: https://app.user-flow.de

Wherever the terms „User Flow“, „we“, „us“ or „our“ are used in this privacy policy, they always refer to User Flow LT UG (haftungsbeschränkt) as the controller within the meaning of Art. 4(7) GDPR.

A data protection officer has not been appointed at present, as the statutory requirements for such an appointment are not currently met. Should a data protection officer be appointed in the future, their contact details will be published at this point.

For any questions regarding the processing of personal data and for the exercise of your data protection rights, you may contact us at any time using the contact options stated above.

Please note: This privacy policy applies both to the public User Flow website and to the CRM application, unless different provisions are set out below.

2. Scope

This privacy policy applies to all digital services offered by User Flow LT UG (haftungsbeschränkt), insofar as personal data is processed in the course of their use.

It applies in particular to the following offerings:

  • the company website at https://user-flow.de including all its subpages,
  • the web-based CRM application at https://app.user-flow.de,
  • all functions, modules and services within the CRM application,
  • all channels of communication between users and User Flow, in particular by e-mail and via official support channels,
  • and future extensions of the platform, insofar as they are referred to in this privacy policy or make reference to this privacy policy.

This privacy policy applies irrespective of whether our services are used on a desktop computer, a notebook, a tablet, a smartphone or any other internet-enabled device.

It likewise applies irrespective of the country in which a user is located. Personal data is processed exclusively in accordance with the requirements of the General Data Protection Regulation (GDPR) and the other applicable data protection provisions of the Federal Republic of Germany and the European Union.

Our services are aimed at users in various countries. For this reason we make this privacy policy available in German and in English.

Should there be differences of interpretation or discrepancies in translation between the various language versions, only the German version of this privacy policy shall be authoritative.

This privacy policy describes both processing operations in which User Flow itself acts as controller and processing operations which User Flow carries out on behalf of its customers.

Insofar as User Flow processes personal data exclusively on behalf of a customer, that customer remains the controller within the meaning of the GDPR. In such cases, the processing by User Flow is additionally governed by the data processing agreement concluded between User Flow and the respective customer and by the customer's documented instructions.

For independent processing by third-party providers or operators of supported third-party platforms, their respective privacy policies apply in addition.

3. Definitions

For the sake of clarity, the following terms are used consistently throughout this privacy policy.

Where personal designations are used in the masculine form only in this privacy policy, this serves solely to improve readability. They refer equally to persons of all genders.

3.1 User Flow

User Flow refers to the software platform operated by User Flow LT UG (haftungsbeschränkt), including the company website at user-flow.de, the web-based CRM application at app.user-flow.de and all associated functions, modules and services.

3.2 User

Users are all persons who access the website or the CRM application or who use the services of User Flow.

Depending on their permissions, users may act within the platform in particular as an agency, a creator or a chatter.

3.3 Agency

An agency is a trader or company that manages one or more creators within User Flow and may employ staff or external chatters for this purpose.

The agency manages the creator accounts assigned to it and is responsible for setting up and managing the chatters assigned to it.

3.4 Creator

A creator is the person or company whose account on a supported third-party platform is managed within User Flow.

A creator may manage their account themselves or transfer its management in whole or in part to an agency.

3.5 Chatter

A chatter is a person authorised by an agency or a creator who carries out communication tasks within User Flow.

Chatters are granted access exclusively to the areas assigned to them by the respective agency or creator and hold only the permissions granted to them in each case.

3.6 Fan

Fan refers to users of supported third-party platforms with whom creators or chatters communicate or interact within the platform.

Fans are not users of User Flow in the actual sense. However, personal data of fans may be processed in the course of using the software, insofar as this is necessary for the use of the functions offered.

3.7 Supported third-party platforms

Supported third-party platforms are external online platforms operated by independent third-party providers which can be connected to User Flow.

User Flow is neither the operator nor the provider of these third-party platforms and does not determine their independent data processing.

A supported third-party platform is connected exclusively at the instigation of the respective user, in order to provide the desired functions within User Flow.

Depending on the technical design and the available functions of the respective third-party platform, different types of personal data may be processed, displayed or synchronised. The specific scope depends on the functions used by the user and on the technical capabilities of the respective third-party platform.

As at the date of this privacy policy, User Flow supports in particular the following third-party platforms:

  • Maloum
  • 4Based

Further third-party platforms may be added in the future.

3.8 CRM

CRM (Customer Relationship Management System) refers to the web-based software provided by User Flow.

The CRM serves in particular to manage creator accounts, to organise communication processes, to analyse activities and to provide further product-related functions.

3.9 Personal data

Personal data means any information relating to an identified or identifiable natural person.

This includes in particular names, e-mail addresses, IP addresses, user identifiers, communication data, location data, online identifiers or any other information that can be attributed to a natural person directly or indirectly.

3.10 Processing

Processing means any operation performed on personal data, whether or not by automated means.

This includes in particular the collection, storage, organisation, structuring, retrieval, use, transmission, synchronisation, archiving, restriction, erasure or destruction of personal data.

3.11 Controller

The controller is the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.

The controller within the meaning of this privacy policy is User Flow LT UG (haftungsbeschränkt).

3.12 Processor

A processor is a natural or legal person which processes personal data on behalf of a controller and, as a matter of principle, in accordance with that controller's documented instructions.

User Flow may itself act as a processor for its customers, insofar as personal data within the CRM application is processed exclusively in accordance with the instructions of the respective customer.

In addition, User Flow may itself engage external processors, in particular for hosting, server and database infrastructure, e-mail dispatch, technical security or comparable infrastructure services.

The specific allocation of data protection roles depends on the actual design of the respective processing operation.

3.13 Bot

Bot refers to optional automation functions within User Flow which, depending on the supported third-party platform in question, can assist with various workflows.

These may include in particular functions for finding, organising and managing users, for creating and managing lists and for carrying out communication or interaction processes automatically.

The specific scope of functions depends on the third-party platforms supported in each case, on the functions activated by the user and on the technical capabilities of the respective platform.

The bot is used exclusively at the instigation of the respective user.

3.14 Translator

Translator refers to an optional function within User Flow for the automated translation of communication content.

Insofar as users make use of this function, the content required to carry out the translation may be transmitted to a translation service engaged for this purpose.

The specific scope of functions and the translation service used in each case may change in the course of the technical further development of User Flow.

The translator is used exclusively at the express instigation of the respective user.

4. Principles of data processing

The protection of personal data is of great importance to User Flow. All processing of personal data takes place exclusively in accordance with the applicable data protection provisions, in particular the General Data Protection Regulation (GDPR) and the other applicable statutory provisions.

In the development, operation and further development of our services, we take care to process personal data only to the extent necessary for the provision of our services. In doing so, we are guided in particular by the following data protection principles.

4.1 Lawfulness of processing

Personal data is processed only where there is a legal basis for doing so.

Depending on the processing operation, processing takes place in particular

  • for the performance of a contract or in order to take steps prior to entering into a contract (Art. 6(1)(b) GDPR),
  • on the basis of legal obligations (Art. 6(1)(c) GDPR),
  • on the basis of legitimate interests of User Flow or of a third party (Art. 6(1)(f) GDPR),
  • or on the basis of consent given voluntarily (Art. 6(1)(a) GDPR), where such consent is required.

The legal basis applicable in each case is explained separately for the respective processing operation in the following sections of this privacy policy.

4.2 Purpose limitation

Personal data is processed exclusively for the purposes described in this privacy policy.

Processing for other purposes takes place only where there is a separate legal basis for it or where the data subject has expressly consented.

4.3 Data minimisation

We process exclusively that personal data which is necessary for the provision, the secure operation and the continuous further development of our services.

Where individual details may be provided voluntarily, we expressly indicate this.

4.4 Accuracy of data

We endeavour to keep personal data up to date and factually accurate.

Users may correct inaccurate or outdated data at any time using the available functions or contact our support in this regard.

4.5 Storage limitation

As a matter of principle, personal data is stored only for as long as is necessary for the respective purpose of processing.

Beyond that, storage may take place insofar as statutory retention obligations exist, legitimate interests justify further storage or the data subject has consented to it.

The specific retention periods are explained in the respective sections of this privacy policy.

4.6 Integrity and confidentiality

We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access, disclosure or other unlawful processing.

These include in particular measures for access restriction, encryption, authentication, logging of security-relevant operations and further security mechanisms in line with the state of the art.

Further information on the security measures in place can be found in the section „Data security“ of this privacy policy.

4.7 Transparency

It is important to us to set out comprehensibly which personal data is processed, for what reasons this takes place and what rights data subjects have.

This privacy policy is intended to provide as complete and understandable an overview as possible of all material processing operations within the services offered by User Flow.

Should questions regarding the processing of personal data remain despite this privacy policy, data subjects may contact us at any time using the contact options named in the section „Controller“.

5. Visiting the website

When you visit our website https://user-flow.de, certain information is processed automatically which is technically necessary in order to provide the website, to ensure its stability and security and to analyse and rectify errors.

This data is processed irrespective of whether you register or subsequently use our services.

5.1 Data processed

When our website is accessed, the following personal data in particular may be processed automatically:

  • IP address of the requesting device,
  • date and time of access,
  • time zone,
  • pages and files accessed,
  • HTTP status code,
  • referrer URL (the previously visited web page, insofar as transmitted by the browser),
  • browser type and browser version,
  • operating system used,
  • language settings of the browser,
  • device information,
  • access logs (server logs),
  • and further technically necessary connection data.

As a matter of principle, this data is not combined with other personal data, unless this is necessary to ensure the security of our systems or on account of legal obligations.

5.2 Purposes of processing

The processing takes place in particular for the following purposes:

  • provision and delivery of our website,
  • ensuring the functionality of our systems,
  • ensuring IT security,
  • detection and prevention of attacks or misuse,
  • error analysis and technical maintenance,
  • stability and performance optimisation,
  • documentation of security-relevant events,
  • enforcement and defence of legal claims, insofar as necessary.

5.3 Legal basis

The processing takes place on the basis of Art. 6(1)(f) GDPR.

Our legitimate interest lies in providing our website securely, stably, in working order and protected against attacks.

Insofar as individual processing operations take place on account of legal obligations, the processing additionally takes place on the basis of Art. 6(1)(c) GDPR.

5.4 Retention period

As a matter of principle, server log data is stored only for the period necessary to ensure the security and stability of our systems.

Longer storage takes place exclusively

  • insofar as statutory retention obligations exist,
  • insofar as this is necessary to investigate security incidents,
  • or insofar as this is necessary for the establishment, exercise or defence of legal claims.

The specific retention periods may vary depending on the type of log data in question.

5.5 Recipients of the data

In the course of operating our website, personal data may be processed in particular by technical service providers who support us with hosting and with the operation of our infrastructure.

These include in particular hosting and infrastructure service providers, whose engagement is explained in more detail in the section „Service providers engaged“ of this privacy policy.

Any disclosure of personal data beyond this takes place only where there is a legal basis for it.

5.6 Cloudflare Turnstile

In order to protect our website and the registration process against automated access and abusive requests, we use Cloudflare Turnstile.

Cloudflare Turnstile serves to distinguish between human users and automated requests and thereby to ensure the security and availability of our services.

In the course of using Cloudflare Turnstile, technical connection data, information about the browser and device used, the IP address and further technically necessary information in particular may be processed, insofar as this is necessary to carry out the security check.

The processing takes place on the basis of Art. 6(1)(f) GDPR.

Our legitimate interest lies in protecting our website and the CRM application against abusive use, automated attacks and other security-relevant incidents.

Further information on the processing of personal data by Cloudflare can be found in the privacy notices of the respective provider.

5.7 Obligation to provide data

The provision of the technical data named in this section is technically necessary for the operation of our website.

Without this data, our website cannot be provided, or can be provided only to a limited extent.

6. Cookies and technical storage

User Flow uses cookies and comparable technical storage mechanisms insofar as this is necessary for the operation of the website, for logging in, for the use of the CRM application and for the security of the platform.

In addition, analytics, statistics and marketing technologies may be used on the public website (landing page) in order to measure the reach of our website, to evaluate advertising campaigns and to provide interest-based advertising.

Cookies are small text files that are stored on the user's device. Comparable technical storage mechanisms may be used in particular in the user's browser in order to provide sessions, language settings or security-relevant information on a technical level.

6.1 Technically necessary cookies

User Flow uses technically necessary cookies in order to provide the basic functions of the website and the CRM application.

These include in particular cookies or comparable storage mechanisms for:

  • logging in and authentication,
  • managing active sessions,
  • ensuring system security,
  • storing technical settings,
  • preventing misuse,
  • providing protected areas within the CRM application.

These cookies are necessary in order for the website and the CRM application to function properly.

6.2 Session cookies and authentication

Following successful login, session cookies or comparable technical storage mechanisms may be set.

These serve to recognise the user during use of the CRM application and to keep them logged in.

As a matter of principle, session cookies cease to be effective once their validity expires, after logout or once the session has ended.

6.3 Local storage and comparable storage technologies

Insofar as technically necessary, User Flow may also use the local storage or comparable storage technologies of the browser.

This may be necessary in particular in order to provide technical settings, session information or security-relevant information within the CRM application.

6.4 Analytics and marketing technologies

Analytics and marketing technologies may additionally be used on the public website.

These serve in particular to

  • evaluate the use of the website statistically,
  • measure the effectiveness of advertising campaigns,
  • trace conversion events,
  • display interest-based advertising,
  • optimise marketing activities.

Services of the following providers in particular may be used for this purpose:

  • Meta Platforms Ireland Limited (Facebook Pixel / Meta Pixel)
  • Google Ireland Limited (e.g. Google Analytics, Google Ads conversion tracking or comparable services)

These technologies are used exclusively where the legally required consent of the user has been given.

6.5 Cookie consent

Insofar as the use of cookies or comparable technologies is not technically necessary, they are used exclusively following prior consent of the user via the consent management system (cookie banner) used on the website.

Consent may be withdrawn or adjusted at any time with effect for the future.

6.6 Legal bases

The storage of information on the user's device or access to information already stored there takes place in accordance with Section 25 TDDDG (German Digital Services Data Protection Act).

Insofar as cookies or comparable storage mechanisms are strictly necessary in order to provide a digital service expressly requested by the user, they are used on the basis of Section 25(2) no. 2 TDDDG.

The subsequent processing of personal data takes place on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for the performance of the user agreement, or on the basis of Art. 6(1)(f) GDPR, insofar as it serves the secure, stable and functioning provision of the website or CRM application.

Analytics, statistics and marketing technologies which are not technically necessary are used exclusively following prior consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.

Consent that has been given may be withdrawn or adjusted at any time with effect for the future.

6.7 Obligation to provide data

The use of technically necessary cookies is required in order to be able to provide the website and the CRM application in full.

If technically necessary cookies are disabled in the browser, individual functions of the website or the CRM application cannot be used, or can be used only to a limited extent.

7. Registration of a user account

Use of the CRM application app.user-flow.de requires the creation of a user account.

Registration requires that the user acts in the course of their commercial, freelance or other independent professional activity. User Flow is aimed exclusively at traders within the meaning of Section 14 BGB (German Civil Code).

By completing registration, the user confirms that they are of legal age and that they use the platform exclusively in the course of an entrepreneurial or self-employed activity.

7.1 Data processed

In the course of registration, the following personal data in particular may be processed:

  • e-mail address,
  • password (exclusively in encrypted or hashed form),
  • display name or user name,
  • role within the platform (e.g. agency or chatter),
  • date and time of registration,
  • IP address at the time of registration,
  • information on acceptance of the applicable general terms and conditions as well as on the provision of, or the taking note of, the applicable privacy policy including the respective version number,
  • technical registration information,
  • and further data required to create and manage the user account.

The processing takes place exclusively to the extent necessary for setting up and managing the user account.

7.2 Purposes of processing

The processing takes place in particular for the following purposes:

  • creation and management of the user account,
  • authentication of the user,
  • provision of the services booked,
  • management of roles and permissions,
  • evidence of acceptance of our general terms and conditions and of the provision of, or the taking note of, this privacy policy,
  • compliance with statutory documentation obligations,
  • protection of the registration process against automated registrations and abusive use,
  • prevention of misuse and fraud,
  • ensuring the security of our platform,
  • handling of support requests,
  • carrying out technical maintenance measures.

7.3 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for the performance of the user agreement.

Insofar as individual processing operations serve to comply with legal obligations, the processing additionally takes place on the basis of Art. 6(1)(c) GDPR.

The storage of acceptance of our general terms and conditions and of this privacy policy additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR, in order to be able to provide evidence of effective acceptance.

7.4 Registration of chatters

Agencies may invite further users as chatters within the platform.

For this purpose, an invitation is first sent to the e-mail address specified by the agency owner.

The invited chatter then creates their user account independently.

Chatters must also expressly accept the applicable general terms and conditions and this privacy policy in the course of their registration.

Chatters must also accept the applicable general terms and conditions in the course of their registration. The applicable privacy policy is made available to them before or in the course of registration.

7.5 Acceptance of the general terms and conditions and provision of the privacy policy

In the course of registration, every user must expressly accept the applicable general terms and conditions. At the same time, the applicable privacy policy is made available to the user.

In this context, the following information in particular may be stored:

  • date and time of acceptance,
  • IP address,
  • version of the general terms and conditions accepted,
  • version of the privacy policy provided or taken note of.

This data serves exclusively as evidence of the acceptance given.

7.6 Retention period

The data processed in the course of registration is, as a matter of principle, stored for the duration of the existing user account.

Once the contractual relationship has ended, the user account is initially archived.

Personal account data is, as a matter of principle, stored for up to 24 months after the end of the contract in order to enable the user account to be restored later at the request of the former user.

If the user account is not reactivated within this period, the personal data is erased or anonymised, provided that no statutory retention obligations or other legitimate interests preclude erasure.

Statutory retention obligations, in particular requirements under commercial and tax law, remain unaffected by this.

7.7 Recipients of the data

In order to provide and manage the user account, personal data may be processed by technical service providers who support User Flow in operating the platform.

Further information on the service providers engaged can be found in the corresponding sections of this privacy policy.

Personal data is disclosed to other third parties only where there is a legal basis for it.

7.8 Obligation to provide data

The provision of the personal data required in the course of registration is a prerequisite for setting up and using a user account.

Without this data, no user account can be created and the CRM application cannot be used.

7.9 Referral and affiliate programme

Insofar as this function is offered, users may take part in a referral or affiliate programme operated by User Flow.

In the course of participation, the following personal data in particular may be processed:

  • user and customer identifier,
  • referral code,
  • attribution between the referring and the referred user,
  • time of attribution or registration,
  • information on referred contract conclusions and subscriptions,
  • commission claims and commission status,
  • discounts granted,
  • billing and payout-related information,
  • and information to prevent misuse or inadmissible multiple attributions.

The processing takes place in order to operate the referral or affiliate programme, to attribute referred users, to calculate and settle commissions and discounts and to prevent misuse and fraud.

The legal basis is Art. 6(1)(b) GDPR, insofar as the processing is necessary for the performance of the agreement on participation in the referral or affiliate programme. Insofar as the processing serves to prevent misuse and fraud or to defend legal claims, it additionally takes place on the basis of Art. 6(1)(f) GDPR.

As a matter of principle, the data is stored for the duration of participation and beyond, insofar as this is necessary for existing commission claims, settlements, statutory retention obligations or the establishment, exercise or defence of legal claims.

Insofar as payments or credits are processed via a payment service provider, the information in the section „Service providers engaged“ applies in addition.

8. Connection and display of a third-party platform account

Use of the essential functions of the CRM application requires an existing third-party platform account to be linked.

The link is established exclusively at the express instigation of the respective user.

User Flow does not itself provide a creator platform, but serves exclusively as an independent software solution for managing, organising and analysing workflows in connection with existing third-party platform accounts.

Use of the corresponding functions therefore requires the user to have an authorised third-party platform account or to have been authorised to use that account by the respective account holder.

Logging in to the User Flow user account takes place independently of logging in to the respective third-party platform, via User Flow's own authentication infrastructure.

Insofar as users connect their third-party platform account within the CRM application, a separate authentication takes place with the systems of the respective third-party platform. This serves exclusively to establish and maintain the connection between the respective third-party platform account and the User Flow CRM application.

Authentication with the respective third-party platform takes place exclusively in order to use the functions requested by the user and does not constitute an independent registration or user administration by User Flow within the systems of the respective third-party platform.

Own servers, technical intermediary services as well as network and proxy infrastructures may be used for the technical provision of the connection. Depending on the function used, communication may take place directly between the user's browser and the respective third-party platform or via technical systems of User Flow.

Insofar as users carry out actions within the CRM application, for example sending messages, retrieving content or using other functions of supported third-party platforms, the data required for this is transmitted to the respective third-party platform. In doing so, User Flow processes exclusively that data which is necessary for the provision of the functions used in each case.

For real-time functions, in particular for updating communication content, direct technical connections may be established between the user's browser and the respective third-party platform.

8.1 Data processed

In the course of linking a third-party platform account, the following personal data in particular may be processed:

  • access credentials of the third-party platform account, insofar as these are necessary for technical authentication,
  • technical authentication information,
  • account identifier,
  • creator ID,
  • user name,
  • profile information,
  • settings of the connected account,
  • technical synchronisation information,
  • information on the time the link was established,
  • information on the connection status,
  • technical connection information in connection with the use of the network or proxy infrastructures employed,
  • and further data required for the provision of the linked functions.

The data actually processed depends on the functions used in each case and on the interfaces provided by the respective third-party platform. In connection with the embedded display of third-party platform functions, technical session information, temporary access tokens, connection information and technically necessary cookies or comparable storage mechanisms may also be processed.

These serve exclusively to establish and maintain the authorised connection to the respective third-party platform securely and to provide the desired functions within the CRM application.

8.2 Purposes of processing

The processing takes place in particular for the following purposes:

  • establishing and maintaining the connection between User Flow and the respective third-party platform account,
  • authentication with the technical interfaces of the respective third-party platform,
  • synchronisation of the data required for the use of the CRM functions,
  • provision of the booked functions within the CRM application,
  • error analysis,
  • ensuring stable platform operation,
  • detection of technical faults,
  • ensuring system security,
  • use of technical network and proxy infrastructures for the secure and stable provision of the platform functions.

8.3 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, as it is necessary for the performance of the user agreement and for the provision of the functions requested by users.

Insofar as individual processing operations additionally serve to ensure the security or stability of our systems, the processing additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

8.4 Storage of access credentials

Insofar as it is necessary to store the access credentials required for authentication in order to use individual functions on an ongoing basis, these are stored exclusively in encrypted form.

Access to this information is technically restricted and possible exclusively to the extent required for that purpose.

Appropriate technical and organisational measures are taken to ensure the confidentiality and security of this data.

Access credentials and authentication information are processed exclusively on the server side, insofar as this is necessary in order to establish or maintain the connection to the respective third-party platform.

Insofar as temporary access tokens or session tickets are used, these serve exclusively for the secure technical connection and are used only for the period required for that purpose.

8.5 Synchronisation with the third-party platform

Following a successful link, data may be synchronised between User Flow and the connected third-party platform account, insofar as this is necessary for the functions used in each case.

The scope of synchronisation depends on the platform functions activated in each case and on the technical capabilities provided by the third-party platform.

Processing takes place exclusively within the scope of the use of the platform authorised by the respective user.

8.6 Responsibility

User Flow is not the operator of the supported third-party platforms.

The respective operator alone is responsible for the processing of personal data within the third-party platform in question.

Insofar as personal data is processed or synchronised between third-party platforms and User Flow in the course of using the CRM application, the respective processing takes place exclusively within the scope of the use of our services instigated by the user.

The privacy policies of the respective third-party platform remain unaffected by this.

8.7 Retention period

The data processed in connection with linking a third-party platform account is, as a matter of principle, stored for the duration of the existing user account.

Once the contractual relationship has ended, the retention and erasure periods described in the section „Retention periods and erasure“ apply.

8.8 Recipients of the data

Insofar as this is necessary for the provision of our services, personal data in connection with the technical link to the third-party platform account may be processed by technical service providers who support User Flow in operating the platform.

Any disclosure of personal data beyond this takes place exclusively on the basis of a statutory permission or express consent.

Insofar as this is technically necessary, personal data in connection with the provision of the connection may also be processed by providers of network or proxy infrastructures.

8.9 Obligation to provide data

The provision of the data required for the link is a prerequisite for the use of all functions that require a connection to a third-party platform account.

Without such a link, essential functions of the CRM application cannot be used.

9. Processing of CRM data

Following the successful linking of a third-party platform account, User Flow processes such personal data as is necessary for the provision of the CRM functions.

The processing takes place exclusively within the scope of the functions used by the respective user and of the permissions assigned to them.

Within the CRM application, agencies and authorised chatters can manage, organise, supplement and evaluate information in order to structure communication processes and make workflows more efficient.

9.1 Data processed

In the course of using the CRM application, the following categories of personal data in particular may be processed:

Master data

  • alias
  • nickname
  • user identifiers
  • creator attributions
  • internal attributions within the platform

CRM data

  • list memberships
  • individual tags
  • internal notes
  • status information
  • self-created information
  • internal categorisations
  • reminders
  • markings
  • priorities
  • individual CRM entries

Subscription and contract information

  • start of a subscription
  • status of a subscription
  • price of a subscription
  • automatic renewal
  • further subscription-related information

Revenue information

  • total revenue of a fan
  • most recent purchase amount
  • highest single payment
  • further statistical revenue information
  • cross-platform aggregated revenue and performance information, insofar as several supported third-party platforms are connected within the CRM application

Activity data

  • communication history
  • times of interactions
  • internal status changes
  • editing histories
  • attributions within the CRM application
  • online status information, insofar as this is provided by the respective third-party platform

Other information added by the user

Insofar as users add or store their own information within the CRM application, this data is also processed, insofar as this is necessary for the provision of the respective function.

9.2 Purposes of processing

The processing takes place in particular for the following purposes:

  • provision of the CRM application,
  • organisation of creator accounts,
  • management of communication processes,
  • management of fan relationships,
  • provision of individual CRM functions,
  • structuring and categorisation of contacts,
  • management of internal workflows,
  • support of agencies and chatters in their daily work,
  • provision of statistical overviews,
  • improvement of usability,
  • error analysis,
  • ensuring stable platform operation,
  • cross-platform consolidation and display of the information available within the CRM application, insofar as several supported third-party platforms are connected.

9.3 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for the performance of the user agreement and for the provision of the CRM functions.

Insofar as individual processing operations serve to ensure the security, stability or further development of the platform, the processing additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

Insofar as the personal data processed does not concern the contractual partner of User Flow but in particular fans or other data subjects, the substantive legal basis for the processing is determined by the respective controlling customer. Where the requirements for processing on behalf of a controller are met, User Flow processes this data exclusively on the basis of the data processing agreement and the customer's documented instructions.

9.4 Roles and permissions concept

Access to CRM data takes place exclusively in accordance with the permissions granted within the platform.

In particular, the following applies:

  • Agencies can manage the creators assigned to them.
  • Agencies can create and manage chatters and assign them to individual creators.
  • Chatters are granted access exclusively to the data and functions for which permissions have been granted to them by the respective agency.
  • Chatters are not granted access to data of other agencies or to areas that have not been released to them.
  • Permissions can be adjusted or withdrawn by the respective agency at any time.

User Flow uses a role-based permission system for this purpose in order to limit access to personal data to the extent necessary.

9.5 Storage of CRM data

As a matter of principle, CRM data is stored for the duration of the existing user account.

Once the contractual relationship has ended, personal CRM data is initially archived.

Insofar as no statutory retention obligations or other legitimate interests preclude this, personal CRM data is erased or anonymised no later than 24 months after the end of the contract.

Data whose further storage is necessary on account of legal obligations or for the establishment, exercise or defence of legal claims is exempt from erasure.

9.6 Recipients of the data

Within the CRM application, access to personal data is granted exclusively to those persons to whom corresponding permissions have been assigned.

In addition, technical service providers may process personal data exclusively to the extent necessary for the operation of the platform.

Disclosure to other third parties takes place exclusively on the basis of statutory provisions or a corresponding legal basis.

9.7 Obligation to provide data

The processing of the data described in this section is necessary in order to be able to provide the CRM application and its functions.

Without this data, essential functions of the platform cannot be used, or can be used only to a limited extent.

10. Processing of communication data

An essential component of the CRM application consists in the management and display of communication processes between connected platform accounts and their fans.

Insofar as the user makes use of the corresponding functions, User Flow processes communication data relating to the conversations conducted via the respective third-party platform.

The processing takes place exclusively in order to provide the CRM functions used by the respective user.

10.1 Data processed

In the course of using the communication functions, the following categories of personal data in particular may be processed:

Communication content

  • text messages,
  • image messages,
  • other media content,
  • message histories,
  • and further content transmitted within the communication.

Communication metadata

  • time a message was sent,
  • time a message was received,
  • status information (e.g. read or delivered),
  • user identifiers involved,
  • technical message information,
  • attributions within the CRM application.

Communication-related CRM data

In connection with communication processes, internal CRM information may additionally be processed, in particular:

  • internal notes,
  • attributions,
  • reminders,
  • status information,
  • tags,
  • list memberships,
  • and further organisational information.

10.2 Purposes of processing

The processing takes place in particular for the following purposes:

  • provision of the chat functions within the CRM application,
  • display of existing communication histories,
  • synchronisation of communication data,
  • support of communication between creators, agencies, chatters and fans,
  • organisation of communication processes,
  • improvement of internal workflows,
  • error analysis,
  • ensuring stable platform operation,
  • ensuring system security.

10.3 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for the performance of the user agreement and for the provision of the communication functions.

Insofar as individual processing operations serve security, error analysis or technical further development, the processing additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

Insofar as the personal data processed does not concern the contractual partner of User Flow but in particular fans or other data subjects, the substantive legal basis for the processing is determined by the respective controlling customer. Where the requirements for processing on behalf of a controller are met, User Flow processes this data exclusively on the basis of the data processing agreement and the customer's documented instructions.

10.4 Storage of communication data

As a matter of principle, communication data is stored for the duration of the existing user account.

Once the contractual relationship has ended, personal communication data is initially archived.

Insofar as no statutory retention obligations or other legitimate interests preclude this, this data is erased or anonymised no later than 24 months after the end of the contract.

Statutory retention obligations and data whose further storage is necessary for the establishment, exercise or defence of legal claims remain unaffected by this.

10.5 Access permissions

Access to communication data is granted exclusively to those users to whom corresponding permissions have been assigned within the platform.

In particular, the following applies:

  • Agencies can access the communication data of the creators assigned to them.
  • Chatters can access exclusively that communication data for which a corresponding permission has been granted to them.
  • Access to communication data of other agencies or of creators not assigned to them is excluded.

User Flow uses a role-based permission system for this purpose.

10.6 Recipients of the data

Personal communication data is processed exclusively to the extent necessary for the provision of the respective functions.

Insofar as technical service providers are engaged for this purpose, their processing takes place exclusively within the framework of processing on behalf of a controller.

Any disclosure of personal communication data beyond this takes place exclusively on the basis of a legal obligation or a corresponding legal basis.

10.7 Special categories of personal data

In individual cases, communication content may contain information from which special categories of personal data within the meaning of Art. 9 GDPR may emerge.

This may include in particular information concerning the sex life or the sexual orientation of a natural person.

Insofar as communication content contains special categories of personal data within the meaning of Art. 9(1) GDPR, the respective controlling customer is responsible for ensuring that, in addition to a legal basis under Art. 6 GDPR, an applicable exception under Art. 9(2) GDPR also exists.

As a matter of principle, User Flow does not determine whether or which special categories of personal data are included in communication content by users. Insofar as User Flow acts as a processor, the processing takes place exclusively in accordance with the documented instructions of the respective controller.

Users may process special categories of personal data only if the data protection requirements for doing so are met.

User Flow processes such content exclusively insofar as it is processed by users within the communication functions and the processing is necessary for the provision of the services used by the respective user.

User Flow does not pursue any purpose of its own with the processing of this content and does not evaluate communication content in order to create personal profiles or for its own marketing purposes.

User Flow does not evaluate communication content in order to create its own personality profiles, behavioural profiles or marketing profiles of fans, chatters or other data subjects.

The processing takes place exclusively in order to provide the functions used by the respective user within the CRM application.

10.8 Obligation to provide data

The processing of the communication data described in this section is necessary in order to be able to provide the communication functions of the CRM application.

Without this processing, the corresponding functions cannot be used.

11. Processing of analytics and statistics data

In order to provide various evaluation and analysis functions, User Flow processes personal data which arises in connection with the use of the CRM application or which is synchronised with the connected third-party platform accounts.

This data serves exclusively to provide statistical functions within the platform and to support users in managing their business processes.

The processing takes place exclusively within the scope of the functions used in each case and of the permissions assigned to the respective user.

11.1 Data processed

In the course of the analytics and statistics functions, the following categories of personal data in particular may be processed:

Revenue and sales data

  • total revenue of individual fans,
  • most recent purchase amount,
  • highest single payment,
  • subscription-related revenue,
  • further revenue-related metrics.

Subscription data

  • status of existing subscriptions,
  • start of a subscription,
  • term,
  • price of a subscription,
  • automatic renewal,
  • further subscription-related information.

Communication statistics

  • number of conversations,
  • communication activities,
  • message statistics,
  • processing status,
  • further statistical evaluations.

Dashboard and analysis information

  • aggregated overviews,
  • charts,
  • evaluations,
  • metrics,
  • trend analyses,
  • comparative periods,
  • individually selectable statistical periods,
  • cross-platform consolidated evaluations and metrics, insofar as several supported third-party platforms are connected within the CRM application.

11.2 Purposes of processing

The processing takes place in particular for the following purposes:

  • provision of the dashboard functions,
  • creation of statistical evaluations,
  • analysis of business metrics,
  • support with entrepreneurial decisions,
  • management of creator accounts,
  • optimisation of internal workflows,
  • improvement of usability,
  • error analysis,
  • ensuring stable platform operation.

The statistical evaluations serve exclusively for use within the CRM application and are not used for automated decision-making within the meaning of Art. 22 GDPR.

11.3 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, as it is necessary for the provision of the CRM functions owed under the contract.

Insofar as individual processing operations serve the improvement, stability or security of our services, the processing additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

The analytics and statistics functions provided within the CRM application serve exclusively to support users in evaluating their data.

Automated decision-making based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR does not take place at User Flow.

Insofar as the personal data processed does not concern the contractual partner of User Flow but in particular fans or other data subjects, the substantive legal basis for the processing is determined by the respective controlling customer. Where the requirements for processing on behalf of a controller are met, User Flow processes this data exclusively on the basis of the data processing agreement and the customer's documented instructions.

11.4 Storage of analytics and statistics data

As a matter of principle, analytics and statistics data is stored for the duration of the existing user account.

Once the contractual relationship has ended, this data is initially archived.

Insofar as no statutory retention obligations or other legitimate interests preclude this, personal analytics and statistics data is erased or anonymised no later than 24 months after the end of the contract.

Data whose further storage is necessary on account of legal obligations or for the establishment, exercise or defence of legal claims is exempt from erasure.

11.5 Recipients of the data

Analytics and statistics data is displayed exclusively within the CRM application to the users authorised in each case.

In addition, technical service providers may process personal data exclusively to the extent necessary for the operation of the platform.

Disclosure to other third parties takes place exclusively on the basis of statutory provisions or a corresponding legal basis.

11.6 Obligation to provide data

The processing of the analytics and statistics data described in this section is necessary in order to be able to provide the corresponding dashboard and analysis functions within the CRM application.

Without this processing, the corresponding functions cannot be used, or can be used only to a limited extent.

12. Processing of activity and time-tracking data

User Flow may provide functions for recording and evaluating activity and working times within the CRM application.

These functions serve exclusively to document the actual use of the CRM application and to create statistical evaluations for agencies and authorised users.

Recording takes place exclusively during active use of the CRM application. No recording takes place outside active use of the CRM application. In particular, no keystrokes are logged, no screen recordings are created and no mouse movements are monitored.

12.1 Data processed

In the course of the activity and time-tracking functions, the following personal data in particular may be processed:

  • start of an active usage session,
  • end of an active usage session,
  • duration of individual usage sessions,
  • total duration of use within freely selectable periods,
  • times of activity interruptions,
  • user identifier of the respective chatter,
  • attribution to the respective creator,
  • statistical metrics calculated from this.

In addition, the following evaluations in particular may be created on the basis of this data:

  • total chat time,
  • average chat time,
  • revenue within a selected period,
  • average revenue per hour,
  • further statistical performance metrics.

12.2 Nature of the time recording

Time recording takes place exclusively during active use of the CRM application.

If no user activity is detected over a longer period, active time recording may be interrupted automatically.

Time recording is resumed only once user activity has been detected again.

No recording takes place outside active use of the CRM application.

User Flow does not carry out any background monitoring of devices, any keyboard monitoring, any mouse logging and any screen recordings.

12.3 Purposes of processing

The processing takes place in particular for the following purposes:

  • documentation of active use of the CRM application,
  • creation of statistical evaluations,
  • calculation of performance metrics,
  • support of agencies in organising their workflows,
  • creation of dashboard evaluations,
  • improvement of transparency within the platform,
  • error analysis,
  • ensuring stable platform operation,
  • creation of evaluations of the actual active use of the CRM application.

The data collected serves exclusively to provide the corresponding functions within the CRM application.

12.4 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for the provision of the contractually agreed functions.

Insofar as individual processing operations serve the security, stability or further development of our services, the processing additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

12.5 Access permissions

The activity and time-tracking data recorded is accessible exclusively to the users authorised in each case within the CRM application.

In particular, the following applies:

  • Agencies can view the activity and time-tracking data of the chatters assigned to them.
  • Chatters can view exclusively their own activity and time-tracking data.
  • Access to data of other agencies or of chatters not assigned to them is excluded.

Access takes place exclusively in accordance with the permissions granted within the platform.

12.6 Retention period

As a matter of principle, activity and time-tracking data is stored for the duration of the existing user account.

Once the contractual relationship has ended, this data is initially archived.

Insofar as no statutory retention obligations or other legitimate interests preclude this, personal activity and time-tracking data is erased or anonymised no later than 24 months after the end of the contract.

Data whose further storage is necessary on account of legal obligations or for the establishment, exercise or defence of legal claims is exempt from erasure.

12.7 Recipients of the data

The processing takes place exclusively within the CRM application.

Insofar as technical service providers are engaged for this purpose, their processing takes place exclusively within the framework of processing on behalf of a controller.

Disclosure to other third parties takes place exclusively on the basis of statutory provisions or a corresponding legal basis.

12.8 Obligation to provide data

The processing of the activity and time-tracking data is necessary in order to be able to provide the corresponding functions within the CRM application.

If these functions are not used or are not available within the respective user account, no corresponding processing takes place.

13. Roles and permissions system

User Flow uses a role-based permission system in order to ensure that personal data is accessible exclusively to those users who require that data in order to perform their respective tasks.

Access to personal data is governed exclusively by the permissions granted within the platform.

13.1 Roles within the platform

The following roles in particular may exist within the CRM application:

  • agency
  • creator
  • chatter

Each user is granted exclusively those permissions which correspond to their respective role and to the access rights granted by the agency.

13.2 Agencies

Agencies can manage the creators assigned to them within the CRM application.

Depending on their use of the platform, agencies can in particular:

  • manage creators,
  • invite chatters,
  • activate or deactivate chatters,
  • assign chatters to individual creators,
  • grant or withdraw permissions,
  • view communication and CRM data of the creators assigned to them,
  • use dashboard and statistics functions,
  • view time-tracking evaluations of the chatters assigned to them.

Access to data of other agencies is excluded.

13.3 Chatters

Chatters are granted access exclusively to those creators and functions that have been assigned to them by the respective agency.

Depending on the permission granted, chatters can in particular:

  • process communication data,
  • manage CRM entries,
  • process messages,
  • add internal information,
  • use the dashboard functions released to them.

Access to data of other agencies or of creators not assigned to them is excluded.

13.4 Granting of permissions

Permissions are granted, changed and withdrawn exclusively by the responsible agency in each case.

Agencies can adjust or completely withdraw permissions at any time.

In doing so, User Flow processes exclusively the personal data required to implement the respective permissions.

13.5 Administrator access

For error analysis, maintenance, technical support or the handling of support requests, it may in individual cases be necessary for authorised administrators of User Flow to access user accounts.

Such access takes place exclusively insofar as this is necessary for the performance of contractual obligations, for rectifying errors, for ensuring the security of our systems or at the express request of the respective user.

Administrators are not granted access beyond what is necessary for the respective purpose.

All administrator access is logged and may contain in particular information on the time of access, the administrator accessing and the user account concerned.

User accounts are accessed exclusively by administrators expressly authorised to do so and only insofar as this is necessary for the respective purpose. Unauthorised access to user accounts, or access without cause, does not take place.

13.6 Purposes of processing

The processing of personal data within the framework of the roles and permissions system takes place in particular for the following purposes:

  • management of user accounts,
  • implementation of individual access rights,
  • ensuring data security,
  • prevention of unauthorised access,
  • support of agencies in managing their chatters,
  • handling of support requests,
  • error analysis,
  • ensuring secure platform operation.

13.7 Legal basis

The processing takes place on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for the provision of the contractually agreed functions.

Insofar as individual processing operations serve the security or protection of our systems, the processing additionally takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

13.8 Retention period

Information on roles, permissions and administrator access is, as a matter of principle, stored for the duration of the existing user account.

Once the contractual relationship has ended, the general retention and erasure periods described in this privacy policy apply.

13.9 Obligation to provide data

The processing of the personal data described in this section is necessary in order to enable the secure use of the CRM application and the management of individual access rights.

Without this processing, the corresponding functions of the platform cannot be provided.

14. Recipients of personal data

User Flow discloses personal data exclusively insofar as this is necessary for the provision of the services offered, a legal obligation exists or another data protection legal basis permits it.

No disclosure of personal data beyond this takes place.

14.1 Technical service providers (processors)

In order to provide the CRM application, User Flow engages various technical service providers.

These process personal data exclusively on behalf of User Flow and on the basis of corresponding data processing agreements pursuant to Art. 28 GDPR.

These include in particular the following categories of service providers:

  • hosting and server service providers
  • database providers
  • e-mail service providers
  • payment service providers
  • infrastructure and security service providers
  • software and development service providers
  • monitoring and logging service providers
  • network and proxy service providers

The specific technical service providers engaged may change over time, insofar as this is necessary for the operation, security or further development of our services. The current overview of the material service providers engaged is set out in the section „Service providers engaged“ of this privacy policy. Insofar as new categories of service providers are engaged in this context, this privacy policy will be adjusted accordingly.

14.2 Payment service providers

Payment service providers are engaged for the processing of chargeable services.

Payment processing takes place directly via the respective payment service provider.

In doing so, User Flow receives exclusively that information which is necessary for the attribution and administration of the respective payment.

Further information on the processing of personal data by the respective payment service provider can be found in the privacy notices of the respective provider.

14.3 Communication service providers

External e-mail service providers may be engaged for the dispatch of transactional e-mails.

These include in particular e-mails concerning:

  • registration,
  • password reset,
  • invitations,
  • security-relevant notifications,
  • contract information,
  • technical notices,
  • and further system-related communications.

Use for advertising purposes takes place exclusively within the framework of the statutory requirements and, where applicable, on the basis of corresponding consent.

14.4 Service providers of the users

In the course of using the CRM application, personal data may be processed within the organisational structure set up by the respective user.

These may include in particular:

  • agencies,
  • chatters,
  • further persons authorised by the respective user.

These recipients are granted access exclusively to the data expressly assigned to them within the roles and permissions system.

14.5 Legal obligations

Personal data is also disclosed insofar as User Flow is obliged to do so on account of statutory provisions.

This concerns in particular transmissions to:

  • courts,
  • law enforcement authorities,
  • supervisory authorities,
  • tax authorities,
  • and other public bodies, insofar as there is a legal obligation to do so.

14.6 Corporate restructuring

In the event of a corporate restructuring, merger, sale of parts of the business or a comparable operation, personal data may be transmitted to the companies involved in each case or to their advisers, insofar as this is necessary for carrying out the respective transaction and the data protection requirements are complied with.

14.7 No disclosure for advertising purposes

User Flow does not sell personal data to third parties.

Personal data is not disclosed for third parties' own advertising purposes.

14.8 Legal bases

Insofar as personal data is disclosed to recipients, this takes place in particular on the basis of:

  • Art. 6(1)(b) GDPR (performance of a contract),
  • Art. 6(1)(c) GDPR (legal obligation),
  • Art. 6(1)(f) GDPR (legitimate interest),
  • or on the basis of corresponding consent pursuant to Art. 6(1)(a) GDPR.

14.9 Processing on behalf of a controller

Insofar as external service providers process personal data on behalf of User Flow, this takes place exclusively on the basis of a data processing agreement pursuant to Art. 28 GDPR.

User Flow ensures that all processors engaged implement appropriate technical and organisational measures to protect personal data.

15. Transfers of data to third countries

User Flow endeavours, as a matter of principle, to process personal data within the European Union (EU) or the European Economic Area (EEA).

In individual cases, however, it may be necessary to transmit personal data to service providers, or to have it processed by service providers, whose registered office or data processing is located outside the European Union or the European Economic Area.

Any such transfer takes place exclusively in compliance with the applicable data protection provisions.

15.1 Legal bases for international data transfers

Insofar as personal data is transferred to countries outside the European Union or the European Economic Area, this takes place exclusively on the basis of one of the safeguards provided for by law.

These include in particular:

  • an adequacy decision of the European Commission pursuant to Art. 45 GDPR,
  • standard contractual clauses of the European Commission pursuant to Art. 46 GDPR,
  • binding corporate rules,
  • or another legal basis permissible under the GDPR.

15.2 Service providers engaged

Depending on the function used, personal data may be processed in particular in connection with the following categories of service provider:

  • hosting and cloud infrastructure,
  • e-mail services,
  • payment service providers,
  • security, network and proxy infrastructure,
  • software and development services,
  • analytics and monitoring services.

Which specific service providers are engaged is set out in the respective sections of this privacy policy.

15.3 Security measures

Before transferring data to a third country, User Flow carefully examines whether the statutory requirements for such a transfer are met.

Where necessary, appropriate technical, organisational and contractual measures are taken in order to ensure an adequate level of data protection.

These include in particular the conclusion of the standard contractual clauses provided by the European Commission and further supplementary protective measures, insofar as these are necessary.

15.4 Further information

Data subjects may at any time request further information on the safeguards existing in the individual case for international data transfers, using the contact options named in this privacy policy.

16. Service providers engaged

16.1 General

In order to provide our services, User Flow engages various technical service providers.

These support us in particular with hosting, with the operation of the database and server infrastructure, with e-mail dispatch, with payment processing, with securing our website, with the provision of network and proxy infrastructures, with software development and with the provision of optional translation functions.

Which personal data is processed by a service provider depends on the function used in each case and on the specific extent of the technical integration.

Insofar as service providers process personal data on behalf of User Flow, this takes place on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Insofar as a service provider exceptionally processes personal data under its own responsibility, the processing takes place on the basis of the data protection provisions applicable to it.

Insofar as personal data is transferred to a third country in connection with a service provider, the provisions of the section „Transfers of data to third countries“ apply in addition.

16.2 Hetzner Online GmbH

Purpose

Provision and operation of the server, hosting, storage and database infrastructure of User Flow.

This includes in particular:

  • hosting of the website and the CRM application,
  • operation of the application servers,
  • operation of the database infrastructure,
  • storage of files and application data,
  • technical data backup and restoration,
  • provision of the infrastructure required for secure platform operation.

Data processed

Depending on the function used in each case, the following data in particular may be processed:

  • user account and registration data,
  • CRM data,
  • communication data,
  • creator and fan data,
  • role and permission information,
  • analytics and statistics data,
  • time-tracking data,
  • technical connection data,
  • IP addresses,
  • server and security logs,
  • stored files and media,
  • database content,
  • backup copies and backups.

Place of processing

Germany or the European Union, in accordance with the server and storage infrastructure selected by User Flow.

Legal bases

Art. 6(1)(b) GDPR, insofar as the processing is necessary for the provision of the services owed under the contract.

Art. 6(1)(f) GDPR, insofar as the processing serves the secure, stable and economical operation of our technical infrastructure.

16.3 Stripe Payments Europe Ltd.

Purpose

Processing of payments, administration of subscriptions and handling of payment-related operations.

Data processed

This may include in particular:

  • name and contact details,
  • customer number,
  • invoice data,
  • payment information,
  • payment method selected,
  • payment amount,
  • currency,
  • payment status,
  • information on subscriptions,
  • transaction identifiers,
  • technical connection information,
  • information for the prevention of fraud and misuse.
  • commission- or discount-related billing information, insofar as this is processed in connection with the affiliate or referral programme.

The entry and processing of complete payment data takes place, as a matter of principle, directly via Stripe. User Flow receives in particular that information which is necessary for the attribution, confirmation and administration of the respective payment or the respective subscription.

Legal bases

Art. 6(1)(b) GDPR.

Art. 6(1)(c) GDPR, insofar as the processing serves to comply with statutory, commercial or tax law obligations.

Art. 6(1)(f) GDPR, insofar as the processing serves fraud prevention and the security of payment processing.

16.4 Resend

Purpose

Dispatch of transactional and system-related e-mails.

This includes in particular:

  • registration confirmations,
  • e-mails for resetting passwords,
  • invitations of users,
  • security-relevant notifications,
  • contract and subscription information,
  • technical notices,
  • support and service communications.

Data processed

  • e-mail address,
  • name, where available,
  • user or account attribution,
  • content of the respective e-mail,
  • time of dispatch,
  • delivery status,
  • technical dispatch information,
  • information on failed deliveries or bounces.

According to the provider information currently published, the provider of the service is Plus Five Five, Inc.

Legal bases

Art. 6(1)(b) GDPR, insofar as the dispatch is necessary for the performance of the user agreement.

Art. 6(1)(f) GDPR, insofar as the dispatch serves the security, administration or technical provision of our services.

Art. 6(1)(a) GDPR, insofar as a message is sent exclusively on the basis of consent.

16.5 GitHub

Purpose

Management, versioning and further development of the source code as well as support of technical development and deployment processes.

Data processed

In the course of software development, the following data in particular may be processed:

  • user and contact data of developers,
  • commit and version information,
  • technical configuration information,
  • error descriptions,
  • development documentation,
  • technical logs,
  • other information required for software development.

Production user, CRM and communication data is not stored in GitHub as a matter of routine.

Should technical information exceptionally be processed in the course of an error analysis, it is to be anonymised or pseudonymised as far as possible before transmission.

Legal basis

Art. 6(1)(f) GDPR.

Our legitimate interest lies in the secure development, maintenance, versioning and continuous improvement of our software.

16.6 Cloudflare Turnstile

Purpose

Protection of the website, of the registration process and of further input or login processes against automated access, abusive requests and security-relevant attacks.

Cloudflare Turnstile serves in particular to distinguish human users from automated access and to prevent abusive use.

Data processed

In the course of the security check, the following data in particular may be processed:

  • IP address,
  • date and time of the request,
  • browser and device information,
  • operating system information,
  • technical connection data,
  • HTTP headers,
  • information on the interaction with the website,
  • security and check results,
  • technically necessary identifiers and tokens.

The specific scope of the processing depends on the technical design and configuration of Cloudflare Turnstile.

Legal basis

Art. 6(1)(f) GDPR.

Our legitimate interest lies in protecting our website and CRM application against automated registrations, attacks, spam and other abusive use.

16.7 Decodo

Provider

UAB „Data troops“, trading under the brand Decodo.

Purpose

Provision of network and proxy infrastructures for technical communication with supported third-party platforms.

These are used in particular in order to technically provide and stabilise the connection to supported third-party platforms instigated by the user and to transmit the requests required for this.

Data processed

Depending on the function used in each case, the following data in particular may be processed technically via the proxy infrastructure:

  • IP addresses,
  • connection and network data,
  • date and time of technical requests,
  • target address or service addressed,
  • volumes of data transmitted,
  • technical request and response information,
  • session and authentication information,
  • third-party platform identifiers,
  • content, insofar as this technically forms part of the respective transmission.

Decodo is not granted independent access to the User Flow user account. The processing takes place within the framework of the technical transmission of the connections instigated by the user.

Whether and for how long individual technical information is stored by the provider depends on the scope of services agreed with User Flow, on the technical configuration and on the contractual and statutory requirements applicable to the provider.

Legal bases

Art. 6(1)(b) GDPR, insofar as the proxy infrastructure is necessary for the provision of the functions requested by the user.

Art. 6(1)(f) GDPR, insofar as its use serves the stable, secure and technically reliable operation of the platform.

16.8 Provider of the Grok API

Provider

For the optional translation function, User Flow currently uses the Grok API.

The specific contractual partner follows from the contractual relationship existing in each case between User Flow and the provider of the Grok API.

Purpose

Technical performance of automated translations within the CRM application.

A transmission takes place exclusively where the respective user uses a translation function or has activated a corresponding automatic translation function.

Data processed

Depending on the translation function used, the following data in particular may be processed:

  • message content to be translated,
  • texts entered by the user,
  • source and target language,
  • technical request information,
  • time of the request,
  • technically necessary identifiers,
  • further information required to carry out and return the translation.

The texts transmitted may contain personal data of users, creators, chatters or fans, insofar as such information forms part of the content to be translated.

The data is transmitted to the translation service exclusively to the extent necessary to carry out the translation requested in each case.

The specific processing and retention period at the provider depends on the contractual terms applicable in each case, on the API settings selected and on the provider's data protection terms.

Legal basis

Art. 6(1)(b) GDPR, insofar as the translation function forms part of the service booked and requested by the user.

Insofar as User Flow processes personal data on behalf of a customer, the use additionally takes place within the framework of the data processing agreement existing between User Flow and the respective customer.

16.9 Changes to the service providers engaged

User Flow may change technical service providers or engage further service providers, insofar as this is necessary for secure, economical or technical operation, for further development or for the provision of new functions.

A change or addition of service providers takes place exclusively in compliance with the applicable data protection requirements.

Insofar as a new service provider is engaged as a processor, a data processing agreement pursuant to Art. 28 GDPR is concluded before processing begins, provided that this is required by law.

This privacy policy will be adjusted insofar as the change or addition of a service provider results in material changes to the processing of personal data described herein.

17. Retention period and erasure of personal data

As a matter of principle, User Flow processes personal data only for as long as this is necessary for the respective purposes of processing or as statutory, contractual or data protection reasons justify further storage.

The specific retention period depends in particular on whether User Flow processes personal data under its own responsibility or as a processor on behalf of a customer.

Once the respective purpose of processing ceases to apply, personal data is erased, anonymised or, insofar as User Flow acts as a processor, returned or erased in accordance with the instructions of the respective controller.

17.1 Storage during the contractual relationship

As a matter of principle, personal data is stored for the duration of the existing contractual relationship, insofar as this is necessary for the provision of the services used in each case.

This may include in particular the following data:

  • user account and registration data,
  • contract and subscription information,
  • CRM data,
  • communication data,
  • creator, chatter and fan data,
  • analytics and statistics data,
  • activity and time-tracking data,
  • role and permission information,
  • technical connection and security data,
  • and further information required for the provision of the platform.

The processing takes place only within the scope of the purposes, permissions and contractual agreements determined in each case.

17.2 Data processing under our own responsibility

Personal data which User Flow processes in order to perform and administer its own contractual relationship may initially be archived after the end of the contract.

This may include in particular:

  • user account and registration data,
  • master data of the contractual partner,
  • contract and subscription information,
  • information on participation in referral and affiliate programmes, in particular referral codes, referred users, commission claims, discounts granted and billing-relevant information,
  • invoice and payment information,
  • evidence of acceptance of the general terms and conditions and the privacy policy,
  • support and contract communication,
  • security and misuse information,
  • technical administrative information.

The archiving may serve in particular the following purposes:

  • handling of subsequent support or contract enquiries,
  • restoration of a user account at the request of the former user,
  • compliance with statutory documentation and retention obligations,
  • establishment, exercise or defence of legal claims,
  • prevention of misuse and fraud,
  • ensuring orderly platform operation.

During archiving, the data is, as a matter of principle, no longer used for the active provision of the platform.

Insofar as no statutory retention obligations or other lawful grounds for storage preclude this, this data is erased or anonymised no later than 24 months after the end of the contractual relationship.

17.3 Data processed on behalf of a customer

Insofar as User Flow processes personal data on behalf of a customer, the storage, return and erasure of that data is governed by the data processing agreement concluded between User Flow and the respective customer and by the customer's documented instructions.

This may include in particular:

  • CRM data,
  • fan data,
  • communication content,
  • third-party platform data,
  • creator and chatter data,
  • internal notes, lists and attributions,
  • analytics and statistics data,
  • activity and time-tracking data,
  • content processed by bot or translation functions.

Once the processing on behalf of the controller has ended, this data is erased or returned in an agreed format at the choice and on the instruction of the respective controller, unless there is a legal obligation to store it further.

Existing copies are likewise erased, insofar as no statutory retention obligations preclude this.

Further storage for the purpose of restoring a complete customer data set takes place only insofar as this has been expressly agreed contractually, has been instructed by the customer or is permissible on another data protection basis.

17.4 Technical transitional and erasure periods

Erasure may require a reasonable processing time for technical and organisational reasons.

During such a transitional period, the personal data concerned is no longer used for the active provision of services and access is restricted to the group of persons technically and organisationally required.

Insofar as the return of personal data has been agreed, erasure may take place after successful provision or after expiry of an agreed retrieval period.

The details may be laid down in the data processing agreement or in supplementary contractual provisions.

17.5 Statutory retention obligations

Insofar as commercial, tax or other statutory retention obligations exist, the personal data affected by them is stored until the expiry of the respective statutory periods.

During this time, the data is processed exclusively for the purposes provided for by law.

After expiry of the respective retention period, the data is erased or anonymised, unless there is a further legal basis for storage.

17.6 Backups

Personal data may temporarily be contained in technical data backups.

Backups serve exclusively to restore systems and data sets in the event of technical faults, security incidents or data losses.

The personal data contained in backups is not used for other purposes as a matter of routine.

Following erasure in the production systems, personal data may still be contained in existing backups until they are overwritten or erased in the regular cycle.

The backups are overwritten or erased automatically in accordance with defined technical backup and erasure concepts.

Insofar as a backup has to be restored, data already erased or due for erasure is removed again from the production system as far as technically possible.

17.7 Anonymisation

Insofar as further use of information for statistical, technical or operational purposes is permissible and necessary, personal data may be anonymised.

Following successful anonymisation, it must no longer be possible to establish a link to a person by reasonable means.

Effectively anonymised information is no longer regarded as personal data within the meaning of the General Data Protection Regulation.

Mere pseudonymisation does not constitute anonymisation and does not replace a required erasure.

17.8 Erasure requests and restrictions

Data subjects may request the erasure of their personal data subject to the statutory requirements.

A corresponding request may be made using the contact options named in this privacy policy.

Insofar as User Flow processes the data concerned exclusively on behalf of a customer, the request is forwarded to the respective controller or handled in coordination with them. In such a case, User Flow may not decide independently on erasure without a corresponding instruction, unless there is a legal obligation to do so.

Immediate erasure may be excluded in particular insofar as:

  • statutory retention obligations exist,
  • the data is necessary for the establishment, exercise or defence of legal claims,
  • the data forms part of records required by law,
  • a return to the respective controller is still outstanding,
  • or further storage is necessary on account of other legal obligations.

Insofar as erasure cannot take place temporarily, the processing is restricted to the extent required by law.

18. Rights of data subjects

Insofar as personal data is processed, data subjects have the rights described below under the General Data Protection Regulation (GDPR), subject to the statutory requirements.

Insofar as User Flow processes personal data under its own responsibility, these rights may be exercised directly vis-à-vis User Flow.

Insofar as User Flow processes personal data exclusively as a processor on behalf of a customer, the respective customer is, as a matter of principle, responsible as controller for handling the data subject request. User Flow supports the controller in fulfilling data subject rights in accordance with the statutory and contractual requirements.

Requests may be addressed to User Flow using the contact options named in this privacy policy.

18.1 Right of access

Data subjects have the right to request information as to

  • whether personal data is being processed,
  • which personal data is being processed,
  • for what purposes the processing takes place,
  • to which recipients data has been or is being transmitted,
  • how long the data is stored,
  • and further information pursuant to Art. 15 GDPR.

Subject to the statutory requirements, a copy of the personal data undergoing processing is made available.

18.2 Right to rectification

Data subjects have the right to request the immediate rectification of inaccurate personal data and the completion of incomplete personal data.

18.3 Right to erasure

Subject to the statutory requirements, there is a right to request the erasure of personal data.

This right exists in particular where

  • the personal data is no longer necessary for the original purposes,
  • consent given has been withdrawn and there is no other legal basis,
  • or the processing is unlawful.

The right to erasure does not exist insofar as statutory retention obligations or other statutory grounds preclude erasure.

18.4 Right to restriction of processing

Subject to the statutory requirements, it may be requested that the processing of personal data be restricted.

During the restriction, personal data may, as a matter of principle, only be stored or processed on the basis of statutory requirements.

18.5 Right to data portability

Data subjects have the right to receive the personal data concerning them in a structured, commonly used and machine-readable format or, insofar as technically feasible, to request its transmission to another controller.

This right exists exclusively within the scope of the statutory requirements.

18.6 Right to object

Insofar as personal data is processed on the basis of a legitimate interest pursuant to Art. 6(1)(f) GDPR, there is the right to object at any time to such processing on grounds relating to the data subject's particular situation.

User Flow will then no longer process the personal data concerned, unless there are compelling legitimate grounds for the processing or the processing serves the establishment, exercise or defence of legal claims.

18.7 Withdrawal of consent

Insofar as personal data is processed on the basis of consent, that consent may be withdrawn at any time with effect for the future.

The lawfulness of the processing carried out up to the withdrawal remains unaffected by this.

18.8 Right to lodge a complaint with a supervisory authority

Data subjects have the right to lodge a complaint with a data protection supervisory authority about the processing of their personal data.

This applies in particular to the data protection supervisory authority of the Member State of their habitual residence, place of work or the place of the alleged infringement of data protection law.

18.9 Exercise of data subject rights

User Flow may be contacted at any time in order to exercise the rights described in this section.

Insofar as User Flow is itself the controller for the processing concerned, the request is examined in accordance with the statutory requirements and handled within the statutory time limits.

Insofar as the personal data concerned is processed exclusively on behalf of a customer, the request is forwarded to the respective controller or handled in coordination with them. User Flow supports the controller in this within the scope of the statutory requirements and of the existing data processing agreement.

Insofar as a request is addressed directly to the controlling customer, that customer may instruct User Flow with the technical implementation or with the provision of the necessary information.

Before personal data is released, rectified, transmitted or erased, a reasonable verification of the identity of the requesting person may be necessary. Additional information may be requested for this purpose, insofar as this is necessary to prevent unauthorised disclosure or alteration of personal data and is permitted by law.

As a matter of principle, data subject requests are handled free of charge. In the case of manifestly unfounded or excessive requests, a reasonable fee may be charged or the handling of the request refused in accordance with the statutory provisions.

19. Data security

The protection of personal data is of great importance to User Flow.

User Flow takes appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access, unauthorised disclosure or other unlawful processing.

The security measures in place are reviewed on an ongoing basis in line with technological developments and adjusted where necessary.

19.1 Technical protective measures

In order to protect personal data, User Flow employs appropriate technical security measures in particular.

These include in particular:

  • encrypted data transmissions (TLS/SSL),
  • access restrictions on systems and databases,
  • role-based permission concepts,
  • authentication procedures,
  • storage of passwords exclusively in hashed form,
  • encryption of access credentials requiring particular protection,
  • logging of security-relevant operations,
  • data backups,
  • and further security measures in line with the state of the art,
  • measures to secure and monitor the network and system infrastructure.

19.2 Organisational measures

User Flow restricts access to personal data to those persons who require that data in order to perform their respective tasks.

Employees and service providers engaged are authorised to handle personal data exclusively to the extent necessary.

Insofar as external service providers process personal data on behalf of User Flow, this takes place exclusively on the basis of a data processing agreement pursuant to Art. 28 GDPR. Personal data is processed exclusively within the framework of a role- and permission-based access concept. Access is restricted to those persons who require that data in order to perform their respective tasks.

19.3 Handling of security incidents

User Flow has organisational and technical processes in place for detecting, assessing and handling security-relevant incidents.

Where security incidents are identified, appropriate measures are taken to limit possible effects and to restore the security of our systems.

Insofar as required by law, notifications are made to the competent supervisory authorities or to data subjects in accordance with the General Data Protection Regulation.

19.4 Access to user accounts

Access to user accounts by administrators of User Flow takes place exclusively

  • insofar as this is necessary in order to handle a support request,
  • for error analysis,
  • to ensure the secure operation of the platform,
  • or on account of a legal obligation.

Administrator access is logged and restricted to the extent necessary.

19.5 No absolute security

Despite all technical and organisational measures in place, no transmission of data over the internet or electronic storage system can guarantee complete protection against all security risks.

User Flow continuously improves its security measures in line with the current state of the art.

19.6 Reporting security incidents

Should users identify indications of security vulnerabilities, unauthorised access or other security-relevant incidents, User Flow asks that these be reported without delay using the contact options named in this privacy policy.

This enables possible risks to be identified more quickly and appropriate countermeasures to be initiated.

20. Processing when using the translator

20.1 General

User Flow optionally provides a translation function („translator“).

The translator serves exclusively to support communication within the CRM application and enables communication content to be translated between different languages.

The translator is used exclusively at the instigation of the respective user. The function may be activated, deactivated or left unused at any time.

User Flow may engage external technical translation or AI services in order to carry out the translation.

The service providers engaged in each case are set out in the section „Service providers engaged“ of this privacy policy.

20.2 Data processed

Insofar as the translator is used, the following personal data in particular may be processed:

  • communication content to be translated,
  • technically necessary contextual information, insofar as this is necessary to improve translation quality,
  • language information,
  • technical request and response information,
  • times of processing,
  • technically necessary identifiers,
  • and other information technically necessary to carry out the respective translation.

Only that information which is necessary for the provision of the respective translation function is processed or transmitted to the translation service engaged.

20.3 Purposes of processing

The processing takes place in particular for the following purposes:

  • provision of the translation function,
  • support of communication between users of different languages,
  • improvement of the readability and comprehensibility of communication content,
  • technical performance of the requested translation,
  • ensuring a stable and functioning translation service,
  • error analysis and technical further development of the translation function.

20.4 Legal bases

The processing takes place on the basis of Art. 6(1)(b) GDPR, insofar as the use of the translator forms part of the services requested by the user or owed under the contract.

Insofar as User Flow processes personal data exclusively on behalf of a customer, the use of the translator additionally takes place on the basis of the data processing agreement existing between User Flow and the respective customer and of the documented instructions of the respective controller.

20.5 Recipients

In order to carry out the translation function, the personal data required for this purpose may be transmitted to a translation or AI service engaged.

The transmission takes place exclusively to the extent technically necessary to carry out the respective translation.

The service providers engaged in each case are set out in the section „Service providers engaged“ of this privacy policy.

Insofar as personal data is transferred to third countries in this context, the provisions of the section „Transfers of data to third countries“ apply in addition.

20.6 Retention period

Translation content may be stored temporarily, insofar as this is necessary for the technical provision of the translation function, to avoid repeated translations or to ensure consistent use within an active usage session.

Further storage takes place only insofar as there is a statutory, contractual or other data protection basis for it.

For the general retention period of personal data, the provisions of the section „Retention period and erasure of personal data“ apply in addition.

20.7 Privacy-friendly configuration

Insofar as this is technically supported by the translation service engaged in each case, User Flow uses privacy-friendly configuration and processing settings in order to limit the storage or other further use of transmitted content to the extent necessary for the provision of the translation function.

The specific scope of these measures depends on the technical possibilities and on the translation services engaged in each case.

21. Processing when using the bot

21.1 General

User Flow optionally provides automated functions to support workflows in connection with supported third-party platforms („bot“).

The bot may be used in particular to promote reach and activity for connected accounts within supported third-party platforms, to collect and organise profiles and information that are publicly accessible or accessible to the user, and to carry out communication and interaction processes in accordance with the user's specifications.

The specific scope of functions depends on the third-party platforms supported in each case, on the technical capabilities of the platform concerned, on the scope of services booked and on the settings selected by the user.

The bot is used exclusively at the instigation of the respective user. Once activated, the bot may carry out the operations configured by the user continuously or repeatedly until the respective automation is paused, terminated or deactivated.

All actions carried out by the bot take place within the configuration determined by the user and, as a matter of principle, in the name of the connected third-party platform account. In doing so, User Flow does not act as an independent sender or communication partner vis-à-vis the data subjects concerned.

21.2 Data processed

When the bot is used, the following personal data in particular may be processed:

  • profile and account information of persons on supported third-party platforms,
  • user names, aliases, platform identifiers and comparable identifying features,
  • profile information that is publicly accessible or retrievable for the connected third-party platform account,
  • communication content and communication metadata,
  • comments and other interaction content,
  • lists, attributions and organisational information,
  • information on persons already collected, contacted or managed,
  • message, comment or communication templates stored by the user,
  • search, selection and configuration settings,
  • status information on automated operations,
  • times and results of actions carried out,
  • technical connection, session and platform information,
  • and other data required for the provision of the automation function activated in each case.

As a matter of principle, the bot processes only such information as is available within the respective third-party platform, accessible to the connected account, provided by the user or generated in the course of using the bot.

21.3 Purposes of processing

The processing takes place in particular for the following purposes:

  • provision and performance of the automation functions activated by the user,
  • support in building reach, visibility, activity and contact opportunities on supported third-party platforms,
  • finding and collecting relevant profiles or users,
  • creation and management of lists, attributions and organisational overviews,
  • support and automation of communication and interaction processes,
  • dispatch or publication of communication and interaction content specified by the user,
  • avoidance of unnecessary or repeated processing of information already collected,
  • documentation of the status and results of automated operations,
  • technical control and monitoring of running automations,
  • error analysis, prevention of misuse and ensuring stable platform operation,
  • further development and improvement of the bot functions.

21.4 Control by the user

The user decides on their own responsibility whether, when and to what extent the bot is used.

In particular, the user determines which supported third-party platform accounts are connected, which automation functions are activated and which settings, search criteria, content or templates are used for execution.

Activated automations can, as a matter of principle, be paused, terminated or deactivated at any time.

Deactivating the bot ends the further execution of the automation concerned. Information already processed beforehand or stored within the CRM application is not automatically erased as a result.

For the erasure of data already stored, the provisions of the section „Retention period and erasure of personal data“ apply.

21.5 Legal bases

Insofar as the processing of personal data is necessary for the provision of the bot functions requested by the user, it takes place on the basis of Art. 6(1)(b) GDPR.

Insofar as the processing serves technical security, stability, prevention of misuse, error analysis or the further development of the bot functions, it takes place on the basis of Art. 6(1)(f) GDPR.

The legitimate interest of User Flow lies in the secure, reliable and economical provision as well as the technical improvement of the automation functions offered.

Insofar as User Flow processes personal data exclusively on behalf of a customer, the processing additionally takes place on the basis of the data processing agreement existing between User Flow and the respective customer and of the documented instructions of the respective controller.

Classification as processing on behalf of a controller requires that the respective customer determines the purposes and essential means of the processing and that User Flow acts within the documented instructions. The allocation of roles between controller and processor is always governed by the actual design of the respective processing operation.

21.6 Communication and interactions via third-party platforms

Insofar as the bot sends messages, publishes comments or carries out other interactions, this takes place via the connected third-party platform account in each case and within the configuration made by the user.

In doing so, content, templates, media attributions, recipient criteria and technical status information stored by the user in particular may be processed.

The communication or interaction operations carried out via the bot may be stored or displayed on the respective third-party platform and within the CRM application.

For the processing by the respective third-party platform, its own terms and privacy notices apply in addition.

User Flow has no full influence over how the respective third-party platform independently processes, stores or uses the information transmitted or published there.

21.7 Lists and organisational information

In the course of using the bot, profiles, platform identifiers, status information, attributions and further organisational details may be stored in lists or comparable overviews within the CRM application.

This storage may be necessary in particular in order to:

  • identify persons already collected,
  • attribute ongoing or completed operations,
  • avoid repeated or unwanted processing,
  • display the status of communication and interaction operations,
  • and provide the workflows selected by the user technically and organisationally.

The lists and attributions stored may be retained within the CRM application even after an individual automated operation has been completed, insofar as this is necessary for the further use of the bot or CRM functions.

21.8 Recipients and technical infrastructure

In order to provide the bot functions, personal data may be transmitted to, or retrieved from, the connected third-party platform in each case.

Depending on the technical design, hosting, server, network, proxy, security and other technical service providers may also be involved in the processing.

Processing by such service providers takes place only insofar as this is necessary for the provision of the respective bot function, for the transmission of the operations instigated by the user or for the secure and stable operation of the technical infrastructure.

Further information can be found in the sections:

  • „Connection with third-party platform accounts“,
  • „Recipients of personal data“,
  • „Transfers of data to third countries“,
  • and „Service providers engaged“.

21.9 Retention period

Personal data processed in the course of using the bot is, as a matter of principle, stored for as long as this is necessary for the provision of the functions activated by the user, for the management of ongoing or completed operations or for further use within the CRM application.

In particular, lists, attributions, communication information and status data generated in the course of using the bot may also be stored permanently within the active customer account, insofar as these form part of the CRM or automation functions requested by the user.

Once the contractual relationship or the processing on behalf of the controller has ended, erasure, return or anonymisation is governed by the provisions of the section „Retention period and erasure of personal data“ and by the existing contractual agreements and documented instructions of the respective controller.

By way of derogation, technical status and log data may be stored for a limited period, insofar as this is necessary to ensure system security, for error analysis, for the prevention of misuse or for the establishment, exercise or defence of legal claims.

21.10 Responsibility of the user

The user is responsible for using the bot exclusively within the scope of the applicable statutory provisions, of the contractual agreements with User Flow and of the terms of the respective third-party platform.

This includes in particular responsibility for:

  • the selection of the connected third-party platform accounts,
  • the lawfulness of the search and selection criteria used,
  • the admissibility of the personal data processed and stored,
  • the content of the messages, comments and templates used,
  • the selection of the persons addressed,
  • and the configuration, activation and monitoring of the automated operations.

Insofar as the user processes personal data of third parties via the bot, they are responsible for ensuring that an appropriate legal basis exists for this and that the necessary information and other data protection obligations are fulfilled.

User Flow provides the technical infrastructure and the automation functions selected by the user, but does not, as a matter of principle, decide independently which specific persons are addressed, which content is sent or which interactions are carried out.

22. Changes to this privacy policy

User Flow reserves the right to adjust this privacy policy insofar as this becomes necessary on account of technical developments, new functions, changed statutory requirements or other data protection requirements.

The current version of the privacy policy is available at any time within the platform and on the website.

Insofar as required by law, users will be informed of material changes in an appropriate manner.

22.1 Applicable version

As a matter of principle, the version of this privacy policy published at the time of the respective processing applies to the processing of personal data.

Earlier versions of this privacy policy may be archived internally for evidentiary, documentation and compliance reasons.

23. Data protection contact

Controller within the meaning of the General Data Protection Regulation (GDPR):

User Flow LT UG (haftungsbeschränkt) i.G.

Alt-Möllner-Straße 37–42, Gebäude B

23879 Mölln

Germany

E-mail: info@user-flow.de

23.1 Data protection enquiries

Questions on data protection and requests concerning the exercise of data subject rights may be addressed to User Flow at any time using the contact options stated above.

Requests are handled in accordance with the statutory requirements.

23.2 Data protection officer

Insofar as required by law, User Flow will appoint a data protection officer.

In that case, the contact details of the data protection officer will be published in an appropriate place and added to this privacy policy.

At present there is no statutory obligation to designate a data protection officer.

24. Status of this privacy policy

Status: 07/2026

Version: 1.05