W flow LEGAL ← Back to the app
DeutschEnglishРусский

Privacy Policy

Last updated: September 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data on this website is:

Egor Iskhakov
Essenheimer str 131
Mainz 55128
Germany

For privacy questions or to exercise your rights you can reach me at: main@w-flow.tech

This website (w-flow.tech) is operated by me. Where third-party services are integrated (see the sections below), they are named explicitly.

2. Hosting / VPS

This application runs on a dedicated server (virtual private server, VPS) or — for a self-installed copy — on the machine or server of the respective operator. The hosting provider I use is:

STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin, Deutschland
Deutschland

The hosting provider supplies computing power, storage and network access and processes the technical connection data required for this (in particular IP address and time of the request). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.

Purpose: providing and operating this website.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (legitimate interest in secure and stable operation).

3. Cloudflare

This website is delivered and protected through the network of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA). As a reverse proxy, Cloudflare provides DNS resolution, TLS encryption and protection against attacks (including DDoS protection and a web application firewall).

For every request Cloudflare processes the technically necessary connection data, in particular the IP address, time, requested URL, browser and operating system details and security metadata. This data is used for operation, security and attack analysis.

Purpose: secure, fast and resilient delivery of the website.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in security and availability).
Processor: a data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare.

4. PostgreSQL / database

User accounts, sessions, workflows, execution logs, settings and encrypted credentials are stored in a database. By default this is a SQLite file on the same server; alternatively a PostgreSQL database can be used — for a self-installed copy, on your own server if you wish.

Credentials and secrets (e.g. API keys) are stored encrypted (AES-256-GCM); passwords are stored only as a hash. The database operator has no access to decrypted secrets without the installation's key.

SQLite-Datenbank auf dem eigenen STRATO-Server in Deutschland

Purpose: storing and providing your data.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract), Art. 6 (1) lit. c GDPR (statutory retention) and Art. 6 (1) lit. f GDPR (security of operation).

5. User registration

Using the workflow builder requires registration. The following data is collected:

Providing this data is necessary for use; without it no account can be created.

Purpose: providing the user account, attributing your workflows and agents, abuse prevention.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract / pre-contractual measures) and Art. 6 (1) lit. f GDPR (abuse prevention).
Retention period: until the account is deleted (see sections 10 and 11).

6. Login / authentication

Sign-in uses a secure server-side process: your password is verified with a salted procedure (scrypt); only the hash is stored. After a successful sign-in a session is created and set as a technically necessary session cookie (ein technisch notwendiges Session-Cookie (HttpOnly) sowie die lokale Speicherung Ihrer Cookie-Auswahl).

The session cookie is used solely to keep you signed in. Optionally, Google or GitHub login (OAuth) can be used; in that case only the data needed to sign in (provider, identifier, e-mail) is processed.

For password resets and e-mail confirmation, single-use tokens are generated that become invalid after a short time.

Purpose: authentication and maintaining the session.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (security).
Retention period: 14 Tage bzw. bis zur Abmeldung

7. Confirmation e-mails

When you create an account, reset your password or confirm your e-mail address, the server sends an e-mail to the address on file. The message contains a single-use link or code.

For delivery I use an e-mail service provider or my own SMTP server. The data transmitted includes your e-mail address, the time of sending and technical metadata of the mail server.

checkdomain GmbH (E-Mail-Postfach der Domain w-flow.tech)

Purpose: confirming the e-mail address, account security, password reset.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (account security).
Processor: a data processing agreement pursuant to Art. 28 GDPR is in place with the delivery provider.

8. IP addresses / server logs

On every visit to the website and every execution through the API, the server automatically records technical access data:

This data serves to ensure trouble-free operation, error analysis and defence against attacks. It is not combined with other data sources or evaluated for marketing purposes.

Purpose: operational security, error analysis, abuse and attack detection.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in secure and stable operation).

9. Cookies / local storage

This website uses technically necessary cookies and your browser's local storage (localStorage). Specifically:

On your first visit a notice banner asks whether you allow optional preferences in addition to the technically necessary cookies. You can change your decision at any time in the settings. Technically necessary cookies are required for operation and are set on the basis of Art. 6 (1) lit. b and lit. f GDPR; optional storage is based on your consent pursuant to Art. 6 (1) lit. a GDPR.

Workflows übermitteln nur die Daten, die Sie selbst in einem Knoten konfigurieren, an den dort gewählten Dienst (z. B. KI-Anbieter, E-Mail-, Chat- oder Cloud-Dienste). Diese Übermittlung erfolgt in Ihrem Auftrag.

Retention period: 14 Tage bzw. bis zur Abmeldung

10. Data deletion

You can delete your account at any time. Deleting it removes the account, your workflows, agents, credentials, variables, data tables and execution logs. Published templates can also be removed individually from your profile.

You can delete your account via: die Kontoeinstellungen (Einstellungen → Konto) oder eine formlose E-Mail. Alternatively, a message to main@w-flow.tech is sufficient; I will then delete the data without undue delay, unless statutory retention obligations apply.

Where statutory retention obligations exist (e.g. commercial or tax law for paid services), the affected data is kept for the duration of the obligation and deleted afterwards.

Legal basis: Art. 6 (1) lit. c GDPR (statutory retention) and Art. 17 GDPR (right to erasure).

11. Storage periods

I store personal data only for as long as is necessary for the stated purposes or as required by law:

Server-Logs: 7 Tage; automatische Datenbank-Sicherungen: 14 Tage; Konto-, Workflow- und Ausführungsdaten: bis zur Löschung des Kontos

Once the respective period expires, the data is deleted or anonymised so that it can no longer be attributed to you.

12. Legal bases

The processing of personal data is based on the following legal bases of the GDPR:

No processing of special categories of personal data (Art. 9 GDPR) takes place. Where you run your own workflows that process personal data, you are responsible for them; the builder and the services you configure process data solely on your instructions.

13. Data-subject rights

As a data subject you have the following rights:

To exercise these rights, a message to main@w-flow.tech is sufficient. An export of all your data is also available directly in the account settings. You also have the right to lodge a complaint with a supervisory authority (see section 15).

14. International data transfers

Some integrated services may process data outside the European Union or the European Economic Area (e.g. Cloudflare or an e-mail provider). Such a transfer only takes place where necessary for operation or permitted by law.

You can request a copy of the safeguards in place at main@w-flow.tech.

15. Supervisory authority / right to complain

Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority — in particular in the member state of your habitual residence, place of work or place of the alleged infringement.

You are welcome to raise any concerns with me first; I will then deal with your request without undue delay.

Weitere Maßnahmen: TLS-Verschlüsselung (HTTPS), verschlüsselt gespeicherte Zugangsdaten, Passwort-Hashing (scrypt), Firewall und tägliche Datensicherungen.