Loading...

Privacy Policy

Effective Date: 15 April 2025

1.1. Who We Are

ValidFlow ("we", "us", "our") is operated by Max Henkes, Infanteriestraße 14A, Munich, Germany. Contact: henkes2max@gmail.com.

1.2. Scope

This Privacy Policy explains how we collect, use, share and protect personal data when you use ValidFlow (the "Service"). It is drafted to meet the requirements of the EU General Data Protection Regulation (GDPR).

1.3. Data We Process

CategoryExamplesPurposeLegal Basis
Account DataName (optional), email address, hashed password, Stripe customer IDAccount creation & log‑inArt. 6 (1)(b) GDPR – contract performance
Business Idea Inputs & FilesText you submit describing an ideaCore AI analysisArt. 6 (1)(b) GDPR – contract performance
Generated ReportsPDF & dashboard outputProvide service & historyArt. 6 (1)(b)
Payment DataCard details (processed directly by Stripe)BillingArt. 6 (1)(b)
Usage Data / CookiesIP address, device type, pages visited (via Google Analytics & Vercel logs)Analytics, securityArt. 6 (1)(f) – legitimate interests (service improvement) / Art. 6 (1)(a) – consent (non‑essential cookies)

1.4. Automated Processing & AI

We transmit your inputs to OpenAI LLC and Anthropic PBC to generate validation results. Processing is automated; no solely‑automated decision produces legal effects concerning you.

1.5. Retention

  • Account & idea data: kept until you delete the project or request erasure.
  • Generated PDF reports: same as above.
  • Billing records: 10 years (German tax law).
  • Server logs & backups: 30 days.

1.6. Sub‑processors & International Transfers

ProviderRoleLocationSafeguard
Supabase Inc.Auth & DBEU DC + US backupStandard Contractual Clauses (SCCs)
Vercel Inc.HostingEU & USSCCs
OpenAI LLCAI inferenceUSSCCs
Anthropic PBCAI inferenceUSSCCs
Stripe Payments Europe Ltd. / Stripe Inc.PaymentsEU/USIntra‑group SCCs
Google LLC (Analytics)AnalyticsUSSCCs
Resend Inc.Transactional emailsUSSCCs

Transfers outside the EEA rely on SCCs under Art. 46 GDPR.

1.7. Your Rights

You may access, rectify, erase, restrict, object to processing, or receive a copy of your data (data portability). Contact us at the address above. You have the right to lodge a complaint with the Bavarian Data Protection Authority or your local supervisory authority.

1.8. Security

We use TLS encryption in transit, AES‑256 at rest (Supabase), role‑based access, and least‑privilege keys.

1.9. Children

The Service is not directed to anyone under 16 years. We do not knowingly collect data from children under 16; parents may contact us to delete such data.

1.10. Changes

We may update this Privacy Policy. Material changes will be announced by email or in‑app notice at least 14 days before they take effect.


Last updated: April 15, 2025