flenski.ioLegal
/
๐Ÿ‡ฉ๐Ÿ‡ช Servers in GermanyISO/IEC 27001-certified data centers โ†—100% local AIUS providers DPF-certified onlyDPA included
On this page1. Controller and Contact2. Description of the Platform and Definitions3. Allocation of Roles: Flenski, Creators, and Members4. Privacy-Friendly System Architecture5. What Data Is Processed6. Purposes of Processing and Legal Bases7. Registration, Login, and One-Time Codes8. Payment Processing9. Hosting and Infrastructure10. CDN, Security, and DDoS Protection11. Media and File Storage12. Error Analysis and Monitoring13. Email Delivery, SMS Delivery, and Push Notifications14. AI Features15. MCP Interface โ€” External AI Access Authorized by the Creator16. Third-Party Services Connected by the Creator17. Cookies and Similar Technologies18. Further Processing in the Operation of the Platform19. Retention Periods20. Recipients and Subprocessors21. International Data Transfers and the Controller's Registered Office22. Security Measures23. Your Rights as a Data Subject24. Minors25. Changes to This Privacy Policy26. Contact27. Flenski's Marketing Websites (Separate from the Platform)

Privacy Policy for flenski.io#

Last updated: 1 August 2026

This English translation is provided for convenience only. The German version is the legally binding version and prevails in case of discrepancies.

Protecting personal data is a high priority for Flenski. We process personal data exclusively within the framework of applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This Privacy Policy informs you about the nature, scope, and purposes of the processing of personal data in connection with the use of the flenski.io platform.

1. Controller and Contact#

The controller within the meaning of Art. 4(7) GDPR is:

Flenski FZCO (registered with the International Free Zone Authority (IFZA), Dubai) Building A1, Dubai Digital Park Dubai Silicon Oasis Dubai United Arab Emirates

Email (general contact and support): support@flenski.io

You can also reach us at any time via the official Flenski Community: https://app.flenski.community/flenski/starte-hier

Data protection contact: For all data protection matters, you can reach us at finn@flenskiteam.com. The contact person and point of contact for data protection matters is Finn Hansen. Finn Hansen is neither a representative within the meaning of Art. 27 GDPR nor a data protection officer, but the central point of contact. The appointment of an external data protection officer has been initiated (planned: later this year); once appointed, they will be named here.

Representative in the European Union (Art. 27 GDPR): Flenski FZCO has no establishment in the European Union but offers its services to individuals in the EU. The appointment of an external EU representative has been initiated; the representative will be named here once the appointment is complete. Until then, our data protection contact is your point of contact for all matters that would fall within the EU representative's remit: Finn Hansen, finn@flenskiteam.com.

You can contact the controller โ€” and, once appointed, the EU representative โ€” at any time with any questions relating to the processing of your personal data.

2. Description of the Platform and Definitions#

Flenski is a cloud-based software-as-a-service platform (the "Platform") for digital communities, member areas, online courses, digital products, communication, downloads, events, automations, and AI-powered features. Flenski provides the technical platform and infrastructure only.

Scope: This Privacy Policy applies to the websites and services operated by Flenski itself โ€” in particular flenski.io (homepage), app.flenski.io (login and administration for Creators), flenski.community (Discover directory), app.flenski.community/flenski (Flenski Academy), and legal.flenski.io (legal pages; the former address imprint.flenski.io redirects here) โ€” as well as to the technical platform on which the Memberapps run. Memberapps are accessible under subdomains of the form name.flenski.app (for existing customers name.flenski.net; in the future also under additional platform domains) or under the Creators' own domains; for the processing carried out there under the responsibility of the respective Creator, that Creator's own privacy policy additionally applies (Section 3).

In this Privacy Policy:

3. Allocation of Roles: Flenski, Creators, and Members#

Understanding the allocation of roles is essential for this Privacy Policy:

Flenski โ†” Creator: Flenski provides the Creator with the technical platform only. For the personal data that the Creator itself provides as Flenski's contractual partner (the Creator's and its team members' account, billing, and usage data), Flenski is the controller within the meaning of the GDPR. Flenski plans are purchased via the respective merchant of record (currently Digistore24 GmbH, see Section 8).

Creator โ†” Member: The Creator is the sole provider and contractual partner of its members and the controller of their data under data protection law. Every Memberapp requires the Creator's own legal texts (Legal Notice, Privacy Policy, and, where applicable, terms and conditions and a cancellation policy). Flenski provides the "Legal Pages" feature for this purpose; the demo texts supplied expressly do not replace the Creator's own legal texts.

Flenski โ†” Member: There is no contractual relationship between Flenski and members regarding content or offerings. To the extent that Flenski processes personal data of members, contacts (leads), or visitors of a Memberapp, it does so as a processor of the respective Creator pursuant to Art. 28 GDPR. The Data Processing Agreement (DPA) is a mandatory part of the contractual relationship between Flenski and the Creator; it is concluded and retrievable in the workspace settings.

If you are a member of a Memberapp: Your first point of contact for exercising your data subject rights (Section 21) is the respective Creator as the controller. If you send Flenski a request concerning the data of a Memberapp, we will forward it to the responsible Creator or support the Creator in responding.

4. Privacy-Friendly System Architecture#

Flenski follows a privacy-by-design approach pursuant to Art. 25 GDPR. The Platform is designed so that access to personal data is limited to the necessary minimum:

No staff access without authorization: Flenski does not operate a support backend with access to customer data. Flenski staff can access internal community areas, member content, course areas, chats, and protected content only if the respective Creator expressly authorizes this access; the authorization is granted via the specific "Allow Flenski Team access" toggle in the workspace settings. Access then technically takes the form of a login as a moderator appointed by the Creator โ€” in particular for technical support, error analysis, setup assistance, or handling support requests. Such an authorization can be revoked at any time. Only if the Creator expressly requests and authorizes this in an individual case can authorized access also take place from locations outside the EU (see Section 21); without such an express, documented case-by-case authorization, no access from outside the EU takes place.

Authorization toggle "Allow Flenski Team access" in the workspace settings
Authorization toggle "Allow Flenski Team access" in the workspace settings

Automated technical processing: Independently of the above, the Platform processes uploaded content in an automated manner to the extent technically necessary for its features. This includes in particular: transcoding of videos, transcription of video and audio files, text recognition (OCR) from documents and images, indexing of content for search, related content, and GPT answers, as well as delivery via a content delivery network (CDN). This processing is performed system-side on servers in the EU; all AI-powered processing steps (transcription, OCR, indexing, summaries, and AI answers) run โ€” unless the Creator connects their own AI provider โ€” exclusively on a Flenski-owned server in Germany with locally installed AI (see Section 14).

5. What Data Is Processed#

Depending on how the Platform is used, the following personal data in particular may be processed:

The specific configuration โ€” which data is collected in a Memberapp (e.g. whether the phone number is a required field at registration) โ€” is determined by the respective Creator on their own responsibility.

We process personal data for the following purposes on the legal bases stated in each case:

Processing purposeLegal basis (Flenski as controller)
Providing the Platform, account and user management, community, course, and communication features for CreatorsArt. 6(1)(b) GDPR (performance of a contract)
Registration and login (including one-time codes via email or SMS, see Section 7)Art. 6(1)(b) GDPR
Technical support and error analysis (including authorized support access)Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (interest in stable operation)
IT security, abuse prevention, DDoS protection, bot defense, rate limitingArt. 6(1)(f) GDPR (interest in secure operation)
Monitoring and technical stability (error reports, see Section 12)Art. 6(1)(f) GDPR
Transactional emails, SMS, and push notifications (see Section 13)Art. 6(1)(b) GDPR; push additionally only with your permission in the browser/operating system
AI features (transcription, OCR, indexing, GPT answers; see Section 14)Art. 6(1)(b) GDPR
Compliance with legal obligations (e.g. retention, information requests)Art. 6(1)(c) GDPR
Processing based on consent (e.g. non-essential cookies, where used)Art. 6(1)(a) GDPR; Section 25(1) TDDDG

Legitimate interests within the meaning of Art. 6(1)(f) GDPR include in particular: the secure and stable operation of the Platform, abuse prevention, error analysis, and the commercial operation of the business.

To the extent that Flenski processes data of members, contacts, and visitors of a Memberapp as a processor, the legal basis is to be determined by the respective Creator as the controller; the Creator's privacy policy governs.

7. Registration, Login, and One-Time Codes#

You can sign in to the Platform and to Memberapps with a password or a one-time code (OTP). One-time codes are sent by email or โ€” if a phone number is stored on the account โ€” by SMS. The codes are held only in a short-lived cache and are not stored permanently; the same mechanism is used to confirm new email addresses and phone numbers and to confirm an account deletion.

Stay signed in (login persistence): After a successful login, you remain signed in on the device used. For this purpose, we set the first-party cookies accessToken (30 days) and refreshToken (90 days), each with a rolling lifetime (Section 17) โ€” each active use extends the lifetime, and after extended inactivity you are signed out automatically; they serve authentication only โ€” no tracking, no advertising, no sharing with third parties. On your first login, we inform you that you will remain signed in on this device, and your profile permanently contains the "Stay signed in" toggle (active by default): if you turn it off, your login will in future end with the session, and existing long-lived tokens become invalid. Because passwordless login runs via one-time codes, staying signed in saves you a new code being sent every time you return โ€” it is therefore a core part of the passwordless login concept.

Whether the phone number is a required field at registration in a Memberapp is decided by the respective Creator (toggle in the registration form). If it is a required field, providing it is necessary to register in that app; without it, registration there cannot be completed (Art. 13(2)(e) GDPR). Without a stored phone number, the SMS login path is not available; the email and password path remains open.

8. Payment Processing#

Purchase of Flenski plans: Flenski plans are currently sold exclusively through Digistore24 GmbH as merchant of record. Digistore24 is your contractual partner for the purchase, payment, term, and any reversals; its privacy policy additionally applies. Flenski itself does not process any payment data as a payment service provider or seller.

Creators' payment providers: Creators can connect their own external payment providers and checkout systems within the Platform, in particular Digistore24, Elopage, CopeCart, SamCart, ThriveCart, and Stripe. These providers are contractual partners or service providers of the respective Creator, not of Flenski (see Section 16). Payment processing and the associated data processing are governed by the privacy policy of the respective provider and the Creator's privacy policy. Flenski receives from the payment provider only the data required to assign the purchase to an access plan (e.g. product ID, buyer assignment).

9. Hosting and Infrastructure#

The main processing of personal data takes place on servers in Germany. The hosting provider is Hetzner Online GmbH (Germany); purpose: hosting the Platform infrastructure, including the Flenski-owned AI server (see Section 14.1).

10. CDN, Security, and DDoS Protection#

To secure and deliver the Platform, we use Cloudflare, Inc. (USA); purpose: content delivery network (CDN), security measures, bot defense, and DDoS protection. In the course of this, connection data (in particular IP address, technical request data) may also be processed by Cloudflare in the USA. The transfer is based on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR): Cloudflare, Inc. is actively certified under the EU-U.S. Data Privacy Framework (including the UK Extension) and the Swiss-U.S. Data Privacy Framework. Should the certification lapse or the adequacy decision be declared invalid, the transfer will alternatively be based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary technical and organizational measures, as agreed in the data processing addendum with Cloudflare. Cloudflare also sets strictly necessary cookies (see the table in Section 17).

11. Media and File Storage#

For storing and delivering media content (videos, images, audio files, downloads), we use BUNNYWAY d.o.o. (bunny.net, Slovenia); purpose: media storage and CDN delivery. The storage location and delivery regions are contractually restricted to Germany and the EU respectively.

12. Error Analysis and Monitoring#

For technical stability and error analysis, Flenski operates a self-hosted instance of the error analysis software Sentry on the Flenski-owned server at Hetzner in Germany. Error reports and technical device data are processed exclusively on this own infrastructure; no external service provider is involved for this function, and no third-country transfer takes place. Error reports are retained for 30 days; reports on critical errors are, by way of exception, retained until the error is fixed (Section 19).

13. Email Delivery, SMS Delivery, and Push Notifications#

Email (SMTP): Transactional emails (e.g. login codes, notifications) are sent by default via the shared Flenski delivery service. For this, we use Mailgun Technologies, Inc. (Sinch group), 112 E. Pecan Street #1135, San Antonio, Texas 78205, USA (primary delivery service) and Elastic Email Inc., Unit 107, 1208 Wharf Street, Victoria, BC V8W 3B9, Canada (failover backup); with both providers, the EU region is booked, and delivery data is processed in the EU (for the transfer bases covering any residual access, see Section 20). Creators can connect their own SMTP server in the workspace settings; delivery via a Creator's own SMTP service is the Creator's responsibility (see Section 16).

SMS: One-time codes by SMS are sent via the German SMS gateway smsflatrate.de operated by Kloppe Media GmbH, Ansbacher Str. 85, 91541 Rothenburg ob der Tauber, Germany; Creators do not connect their own provider for this. The data processed is the recipient's phone number and the message content (one-time code).

Push notifications: Push notifications are delivered only if you have expressly allowed them in your browser or operating system; you can revoke this permission there at any time. Without your permission, no push subscription is created and no notification is sent.

Technically, Memberapps can be installed as Progressive Web Apps (PWA); delivery takes place as web push via Google Firebase Cloud Messaging (FCM) and the push services of the respective browser and operating system vendors. The data processed is your device's push token and technical delivery data. The contractual partner for customers in the EEA is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; data processing may also be carried out by Google LLC (USA). Any transfer to the USA is based on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) โ€” Google LLC is actively certified, including its wholly owned US subsidiaries โ€”; in addition, the Standard Contractual Clauses agreed in the Firebase Data Processing and Security Terms apply (Art. 46(2)(c) GDPR). Push notifications also contain notification content โ€” that is, personal content such as the title or an excerpt of the triggering message โ€” which is transmitted via the push services named above for delivery.

14. AI Features#

The Platform includes AI-powered features. By default, all AI features run on Flenski's own, locally installed AI on a dedicated server in Germany (Sections 14.1 and 14.3). Alternatively, the Creator can store their own API keys for external AI providers (BYOK, Section 14.2); in that case, the respective feature runs via the provider chosen by the Creator.

14.1 Local Flenski AI: AI Processing in Germany#

Uploaded video and audio files are automatically transcribed; text is extracted from documents and images via OCR. This processing runs entirely on a Flenski-owned server at Hetzner in Germany with locally installed AI. This means:

The generated transcripts and OCR texts are stored, assigned to the content (e.g. as a transcript tab of a lesson, if the Creator enables this), and split into sections and indexed. The indexing (embeddings), the AI summaries, and the GPT answers also run โ€” unless the Creator has stored their own API key โ€” on the local Flenski AI in Germany. This index powers search, related content suggestions, and the knowledge base of the GPTs (Section 14.4).

14.2 BYOK โ€” the Creator's Own Stored API Keys#

Creators can store their own API keys for external AI providers in the workspace settings (Integrations โ†’ LLM) โ€” supported are Claude (Anthropic), ChatGPT (OpenAI), DeepSeek, and Gemini (Google) โ€” and run the AI features (GPTs/AI Coach, admin assistant) through them. In that case:

14.3 Built-in Flenski Model#

As an alternative to the Creator's own API key, a built-in Flenski model is available โ€” depending on the booked plan โ€” for GPTs/AI Coach, the admin assistant, and the AI page builder. The built-in Flenski model is the locally installed AI on the Flenski-owned server at Hetzner in Germany (Section 14.1). No external AI provider is involved; no third-country transfer takes place for this feature, and user content is not used to train AI models.

14.4 AI Coach / GPTs โ€” AI Assistants for Members#

Creators can publish AI assistants ("GPTs", the "AI Coach" feature) in their Memberapps. Members chat with these assistants; the answers draw on the knowledge areas of the respective app that the Creator has enabled (e.g. courses, articles, community posts, events, downloads, helpdesk, groups, public channels, and pages โ€” based on the index of transcripts and OCR texts, Section 14.1) as well as on knowledge files uploaded directly to the GPT. The following applies:

15. MCP Interface โ€” External AI Access Authorized by the Creator#

The admin or owner of a workspace can connect an external AI tool โ€” currently connectable are Claude (Anthropic) and ChatGPT (OpenAI) โ€” to exactly one Memberapp via the MCP interface (Model Context Protocol). The connection is set up and authorized by the Creator themselves; the connected tool can then work in that app on behalf of the authorizing user, in particular create and delete content. Active sessions are displayed on the MCP screen with their last activity and can be revoked there individually.

Under data protection law:

16. Third-Party Services Connected by the Creator#

Creators can, on their own responsibility, integrate external services into their workspace and Memberapps, in particular:

For all of these services: they are recipients or the respective Creator's own processors, not Flenski's. The Creator's integration of a service constitutes the Creator's documented instruction; selecting the provider, the legal basis for the transfer, any required separate data processing agreement, and the assessment of third-country transfers rest with the Creator. Flenski transmits to the connected service only the data required for the respective function (for automations, e.g. the member or contact record with tags and lists).

Tracking and consent: For analytics and marketing technologies integrated by the Creator, the Creator alone is responsible โ€” including obtaining any required consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. For this purpose, the Platform provides, under "Tracking & Cookie Banner", a cookie banner with equally prominent "Accept"/"Decline" buttons and a settings view: if the Creator sets up their tracking codes with the banner enabled, consent-requiring codes are executed only after the visitor consents, and visitors can change or revoke their choice at any time via the "Cookie Settings" link in the footer of the Memberapp. If the Creator chooses the no-banner option for a tracking code, that code is executed without a consent prompt โ€” this option is intended exclusively for strictly necessary integrations; if the Creator uses it for consent-requiring services or integrates their own consent solution, the data-protection-compliant configuration is entirely the Creator's responsibility (Section 6 of the Terms of Service).

17. Cookies and Similar Technologies#

Flenski itself uses on the Platform only strictly necessary cookies and similar technologies that are required for secure and stable operation. Storing and reading this information is permitted without consent under Section 25(2) no. 2 TDDDG, as it is strictly necessary to provide the service you have expressly requested; consent via a cookie banner is not required for these cookies. They therefore cannot be disabled without the Platform losing its functionality.

Specifically, the Platform uses the following cookies:

NameProviderPurposeDurationCategory
accessTokenFlenski (first party)Stores the access token that keeps you signed in to the app; can be turned off via the "Stay signed in" toggle in your profile (Section 7). In embedded widgets, it is set with SameSite=None so the widget works inside an iframe.30 days, rolling (extended with each active use)Strictly necessary
refreshTokenFlenski (first party)Renews the access token so your session does not expire while you are using the app.90 days, rolling (extended with each active use)Strictly necessary
masqueradeAccessTokenFlenski (first party)Maintains a simulation session when an administrator โ€” or Flenski support after authorization โ€” views the app from a test user's perspective. Separate from the normal login session (accessToken/refreshToken).Cookie lifetime 30 days, rolling; the simulation session itself is limited to 1 hourStrictly necessary
masqueradeRefreshTokenFlenski (first party)Renews the simulation session described above within its validity.Cookie lifetime 90 days, rolling; session limited to 1 hourStrictly necessary
_\<hash\>Flenski (load balancer)Session affinity โ€” routes all your requests to the same backend server. For example _1d52e.SessionStrictly necessary
__cf_bmCloudflareDistinguishes humans from bots to protect the service against automated abuse.30 minutesStrictly necessary
_cfuvidCloudflareSeparates requests from the same IP address so rate limits apply per visitor.SessionStrictly necessary
cf_clearanceCloudflareRecords that a security check was passed so it does not appear again.30 min โ€“ 1 year (depending on configuration)Strictly necessary
__cfruidCloudflareSupports rate limiting and request attribution at the network edge.SessionStrictly necessary
__cflbCloudflareSession affinity at the network edge. Only when load balancing is enabled.Session โ€“ up to 24 hoursStrictly necessary
__cfwaitingroomCloudflareManages your place in the queue during high load. Only when Waiting Room is enabled.Depending on configurationStrictly necessary
cf_ob_info, cf_use_obCloudflareServes a cached version of the page when the origin server is unreachable. Only when Always Online is enabled.SessionStrictly necessary

In addition to the cookies in the table, a Memberapp's cookie banner stores your consent choice: for guests, as a local storage entry with the key "cookieConsent" in your browser (with no automatic expiry โ€” the entry remains until you clear your browser data); for signed-in members, in your user account in the Flenski database. Storing this choice is strictly necessary within the meaning of Section 25(2) no. 2 TDDDG so that your decision is respected and you are not asked again on every visit.

Flenski itself does not, by default, set any of its own marketing, retargeting, analytics, or tracking cookies for advertising purposes.

Creators' cookies and trackers: If a Creator integrates their own analytics, marketing, or media services in their Memberapp (Section 16), additional cookies that are not strictly necessary may be set as a result. These require your consent under Section 25(1) TDDDG; the respective Creator is responsible for this and obtains consent via the provided cookie banner or their own consent solution.

18. Further Processing in the Operation of the Platform#

Support and admin sessions (product simulation/masquerade): Administrators of a Memberapp โ€” and Flenski support after express authorization (Section 4) โ€” can view the app from a test user's perspective, e.g. as a member with a specific access plan. This simulation session is limited to one hour and is separate from the normal login persistence (cookies accessToken/refreshToken, 30 and 90 days rolling); dedicated session cookies are set for it (see the table in Section 17).

Lead forms and contacts: Data collected via lead forms is stored as contacts at the Creator's workspace level. The Creator is the controller of this data; Flenski processes it as a processor.

Public certificate verification page: Certificates issued by Creators receive a nine-digit certificate ID (format 000-000-000); it appears on the certificate as a number, QR code, and verification URL. Via a public verification page accessible without login, third parties (e.g. employers) to whom the holder presents their certificate can verify its authenticity. Retrieval is possible only with knowledge of the complete certificate ID; there is no name search and no list of all certificates. For a valid ID, the page displays the holder's full name, the course title, the issue date, and the validity confirmation; for an unknown ID, nothing is displayed. The data processed for this is first and last name, course title, issue date, and certificate ID. Retrievals are currently limited to 20 per time window (rate limit); this makes mass trial-and-error probing of IDs more difficult. The data source is a public API; it is planned before release that this API will return only the name, issue date, and validity status โ€” no internal identifiers or account information. Also planned before release: the verification page will be excluded from search engines via noindex and robots.txt, so that names cannot be found via search engines, as well as an opt-out for the holder in their profile against the display of their name โ€” it takes effect immediately, including for certificates already issued; the certificate then remains verifiable as "valid" without the name being displayed. If the account is deleted, the name is no longer served. The legal basis for displaying the name is Art. 6(1)(f) GDPR โ€” the legitimate interest of the certificate holder and of the presenting third party in verifying the certificate's authenticity.

Discover directory: Creators can have their Memberapp listed in a public directory. The information displayed there comes from the Creator.

Exports: Creators can export the member and contact data of their workspace. Handling exported data is the Creator's responsibility.

19. Retention Periods#

Personal data is stored only for as long as necessary for the purposes stated or as required by statutory retention obligations. The data is then deleted or anonymized. Specifically:

Data categoryRetention period
Login tokens (cookies accessToken/refreshToken)30 and 90 days, rolling โ€” extended with each active use (see Section 17)
One-time codes (OTP)short-lived cache, no permanent storage
Server and access logs30 days
Error reports (self-hosted Sentry instance, Section 12)30 days; for critical errors, until the error is fixed
Daily backups30 days
Monthly backups (one backup per calendar month)12 months
Update/hotfix backups (before every release or manually before hotfixes)30 days
Content in the cloud trashuntil final deletion by the Creator; no automatic expiry
Data of deleted accounts30 days
Data of canceled or expiring workspacesno automatic deletion: upon deactivation or expiry of the plan, the account is downgraded to a free account; the data is retained until the user expressly deletes it themselves. Export remains possible at any time until then (statutory retention obligations remain unaffected).
Contacts (leads)until deletion by the Creator; no automatic periods โ€” responsibility for deletion rests with the Creator as controller
AI chat histories (GPTs/AI Coach, incl. BYOK conversations)currently no automatic expiry; deletion on request or as part of the deletion of the app or account (see the note below)

To the extent that Flenski acts as a processor, the retention period is governed by the Creator's instructions and the DPA; after the end of the contract, the data is deleted or returned in accordance with the DPA.

20. Recipients and Subprocessors#

Flenski uses the following service providers to deliver its services. This list is identical to Annex 3 of the Data Processing Agreement:

Service providerRegistered officeProcessing locationPurposeData categoriesTransfer basis
Hetzner Online GmbHGermanyGermanyHosting of the Platform, the Flenski-owned AI server, and the self-hosted error analysis (Sentry instance)all platform dataโ€” (EU)
Cloudflare, Inc.USAEU/worldwide (edge network); processing in the USA possibleDDoS protection, CDN, delivery and security of the PlatformTechnically required connection and request data, in particular IP addressesEU-U.S. Data Privacy Framework โ€” Cloudflare, Inc. is actively certified (adequacy decision, Art. 45 GDPR); alternatively Standard Contractual Clauses (Art. 46(2)(c) GDPR) per the Cloudflare DPA together with supplementary measures
BUNNYWAY d.o.o.SloveniaGermany/EU (contractually restricted)Media storage and deliveryMedia content, delivery dataโ€” (EU)
Kloppe Media GmbH (smsflatrate.de), Ansbacher Str. 85, 91541 Rothenburg ob der TauberGermanyGermanyDelivery of one-time codes by SMSPhone number, message content (one-time code)โ€” (EU)
Mailgun Technologies, Inc. (Sinch group), 112 E. Pecan Street #1135, San Antonio, Texas 78205USAEU (EU region booked; EU data centers incl. in Germany)Email delivery for workspaces without their own SMTP access (primary delivery service)Email addresses, names, email contentProcessing in the EU (EU region booked); for any residual access by the US parent company: EU-U.S. Data Privacy Framework โ€” Mailgun Technologies, Inc. is certified (Art. 45 GDPR); alternatively Standard Contractual Clauses per the Sinch Email DPA
Elastic Email Inc., Unit 107, 1208 Wharf Street, Victoria, BC V8W 3B9CanadaEU (EU region booked)Email delivery for workspaces without their own SMTP access (backup delivery service)Email addresses, names, email contentProcessing in the EU (EU region booked); otherwise the European Commission's adequacy decision for Canada (Decision 2002/2/EC, limited to commercial organizations subject to PIPEDA); alternatively Standard Contractual Clauses per the Elastic Email DPA
Google Ireland Limited (Firebase Cloud Messaging; contracting entity for the EEA), Gordon House, Barrow Street, Dublin 4Ireland; data processing also by Google LLC (USA)EU/worldwide; processing in the USA possibleDelivery of web push notifications (including with PWA installation)Push tokens, notification content (may contain personal content, e.g. message excerpts), technical delivery dataEU-U.S. Data Privacy Framework โ€” Google LLC is actively certified, including its wholly owned US subsidiaries (Art. 45 GDPR); additionally Standard Contractual Clauses (Art. 46(2)(c) GDPR) per the Firebase Data Processing and Security Terms

The error analysis (Sentry) runs as a self-hosted instance on the Hetzner infrastructure (Section 12) and is therefore not an external subprocessor.

The current version of this list is available as a standalone subprocessor list at https://legal.flenski.io/en/subprocessors.html (German version: https://legal.flenski.io/subprozessoren.html); Creators are informed of changes in advance in accordance with Section 9 of the Data Processing Agreement.

This list does not include the services that the respective Creator connects themselves (Sections 8, 14.2, 15, 16) โ€” they are recipients or processors of the Creator. Authorities receive data only where a legal obligation exists.

21. International Data Transfers and the Controller's Registered Office#

Personal data is processed on servers in the European Union, as a rule in Germany. Transfers to third countries take place only in the cases named in this Policy (Cloudflare โ€” Section 10; Google Firebase for web push โ€” Section 13; support access from outside the EU expressly authorized by the Creator โ€” see below) and only on the basis of appropriate safeguards (an adequacy decision pursuant to Art. 45 GDPR or Standard Contractual Clauses pursuant to Art. 46 GDPR together with supplementary measures). If a Creator connects their own services (e.g. BYOK AI providers, MCP clients, US trackers), the Creator is responsible for the third-country transfers this triggers.

Support access and our registered office in the UAE. Flenski has no central software backend; staff access to a Memberapp is possible only if the Creator expressly authorizes it via the "Allow Flenski Team access" toggle (revocable at any time, Section 4). Such support access takes place as a rule from the EU/EEA. Only if the Creator expressly requests and authorizes this in an individual case can support access also take place from outside the EU/EEA (e.g. from the UAE). For this exceptional case, we have agreed with the Creator in the Data Processing Agreement the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module 2) as an appropriate safeguard under Art. 46(2)(c) GDPR. The data itself remains stored on servers in Germany throughout.

22. Security Measures#

Flenski takes technical and organizational measures pursuant to Art. 32 GDPR to protect personal data. These include in particular: encryption in transit, encryption at rest, access controls and a role/permission system (owner, admin, team member), tenant separation (app and GPT knowledge isolation), admin login with password plus an additional one-time code by email, encrypted storage of stored API keys, staff support access only after express, revocable authorization, logging of moderator access, firewalls and DDoS protection, monitoring via a self-hosted error analysis (Section 12), tiered backups (daily and monthly, and at releases), and security updates. The full description of the measures is contained in Annex 2 of the Data Processing Agreement.

23. Your Rights as a Data Subject#

You have the following rights vis-ร -vis the controller responsible for you:

Responsibility: If your request concerns data that Flenski processes as a controller (in particular Creator accounts), contact finn@flenskiteam.com or the EU representative (Section 1). If your request concerns your data as a member, contact, or visitor of a Memberapp, the respective Creator is the controller and your first point of contact; Flenski supports the Creator in responding as a processor.

Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). In particular, you can contact the supervisory authority of the EU Member State in which you habitually reside, in which you work, or in which the alleged infringement took place. Since Flenski has no establishment in the EU, there is no "lead" supervisory authority; you can lodge your complaint with any EU supervisory authority. In Germany, this is, for example, the data protection supervisory authority of your federal state; in Austria, the Austrian Data Protection Authority. The European Data Protection Board publishes an overview of all EU supervisory authorities at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.

No automated decision-making: Flenski does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

24. Minors#

The Platform is a B2B offering aimed at Creators and is not directed at persons under 16 years of age. Which target groups an individual Memberapp is aimed at, and whether minors' consent plays a role there (Art. 8 GDPR), is determined by and the responsibility of the respective Creator.

25. Changes to This Privacy Policy#

Flenski will amend this Privacy Policy when technical changes, legal requirements, new features, or organizational changes require it. The version published on this page applies in each case; you will find the last-updated date at the top of the page.

26. Contact#

For questions about data protection, you can reach us at: finn@flenskiteam.com (point of contact: Finn Hansen). General inquiries: support@flenski.io.

27. Flenski's Marketing Websites (Separate from the Platform)#

Strictly separate from the Platform (app operations, Memberapps, customer data) are Flenski's own marketing websites โ€” in particular the homepage flenski.io and its subpages. They serve to provide information about Flenski and to acquire new customers. Data from the Platform โ€” in particular member, customer, and content data of the Creators and their Memberapps โ€” is not processed on the marketing websites and is not linked to any tools used there.

The marketing websites are operated at Vercel Inc. (USA; hosting of the marketing pages, not of the Platform); technically required connection data (including the IP address) may be processed in the course of this. Any transfer to the USA is based on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) โ€” Vercel is certified under the DPF (including the UK Extension and the Swiss-U.S. DPF; certified since June 2024, verifiable via the participant list at dataprivacyframework.gov and vercel.com/security) โ€”; alternatively, the Standard Contractual Clauses agreed in the Vercel Data Processing Addendum apply (Art. 46(2)(c) GDPR).

On the marketing websites, marketing and analytics services may be used โ€” in each case only after your consent via the cookie banner there (Section 25(1) TDDDG, Art. 6(1)(a) GDPR) โ€” currently or in the future in particular: KlickTipp (email marketing), Calendly (appointment booking), FunnelCockpit (landing pages/funnels), WebinarJam (webinars), Google Analytics, Google Ads, Meta Pixel, and TikTok Pixel. The cookie banner of the respective page is authoritative for the services actually used at any time; services that are not technically necessary are loaded only after consent. Details on the individual services will be added here when they are activated.