Privacy Policy
Last updated: September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data on this website is:
Egor Iskhakov
Essenheimer str 131
Mainz 55128
Germany
For privacy questions or to exercise your rights you can reach me at: main@w-flow.tech
This website (w-flow.tech) is operated by me. Where third-party services are integrated (see the sections below), they are named explicitly.
2. Hosting / VPS
This application runs on a dedicated server (virtual private server, VPS) or — for a self-installed copy — on the machine or server of the respective operator. The hosting provider I use is:
STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin, Deutschland
Deutschland
The hosting provider supplies computing power, storage and network access and processes the technical connection data required for this (in particular IP address and time of the request). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
Purpose: providing and operating this website.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (legitimate interest in secure and stable operation).
3. Cloudflare
This website is delivered and protected through the network of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA). As a reverse proxy, Cloudflare provides DNS resolution, TLS encryption and protection against attacks (including DDoS protection and a web application firewall).
For every request Cloudflare processes the technically necessary connection data, in particular the IP address, time, requested URL, browser and operating system details and security metadata. This data is used for operation, security and attack analysis.
Purpose: secure, fast and resilient delivery of the website.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in security and availability).
Processor: a data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare.
4. PostgreSQL / database
User accounts, sessions, workflows, execution logs, settings and encrypted credentials are stored in a database. By default this is a SQLite file on the same server; alternatively a PostgreSQL database can be used — for a self-installed copy, on your own server if you wish.
Credentials and secrets (e.g. API keys) are stored encrypted (AES-256-GCM); passwords are stored only as a hash. The database operator has no access to decrypted secrets without the installation's key.
SQLite-Datenbank auf dem eigenen STRATO-Server in Deutschland
Purpose: storing and providing your data.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract), Art. 6 (1) lit. c GDPR (statutory retention) and Art. 6 (1) lit. f GDPR (security of operation).
5. User registration
Using the workflow builder requires registration. The following data is collected:
- e-mail address
- password (stored only as a hash, never in plain text)
- Anzeigename sowie freiwillige Profilangaben (Bio, Website, Avatar)
- time of registration
Providing this data is necessary for use; without it no account can be created.
Purpose: providing the user account, attributing your workflows and agents, abuse prevention.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract / pre-contractual measures) and Art. 6 (1) lit. f GDPR (abuse prevention).
Retention period: until the account is deleted (see sections 10 and 11).
6. Login / authentication
Sign-in uses a secure server-side process: your password is verified with a salted procedure (scrypt); only the hash is stored. After a successful sign-in a session is created and set as a technically necessary session cookie (ein technisch notwendiges Session-Cookie (HttpOnly) sowie die lokale Speicherung Ihrer Cookie-Auswahl).
The session cookie is used solely to keep you signed in. Optionally, Google or GitHub login (OAuth) can be used; in that case only the data needed to sign in (provider, identifier, e-mail) is processed.
For password resets and e-mail confirmation, single-use tokens are generated that become invalid after a short time.
Purpose: authentication and maintaining the session.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (security).
Retention period: 14 Tage bzw. bis zur Abmeldung
7. Confirmation e-mails
When you create an account, reset your password or confirm your e-mail address, the server sends an e-mail to the address on file. The message contains a single-use link or code.
For delivery I use an e-mail service provider or my own SMTP server. The data transmitted includes your e-mail address, the time of sending and technical metadata of the mail server.
checkdomain GmbH (E-Mail-Postfach der Domain w-flow.tech)
Purpose: confirming the e-mail address, account security, password reset.
Legal basis: Art. 6 (1) lit. b GDPR (performance of a contract) and Art. 6 (1) lit. f GDPR (account security).
Processor: a data processing agreement pursuant to Art. 28 GDPR is in place with the delivery provider.
8. IP addresses / server logs
On every visit to the website and every execution through the API, the server automatically records technical access data:
- IP address of the requesting device
- date and time of the request
- page, file or API endpoint accessed
- amount of data transferred and status code
- browser type, browser version and operating system
- referrer URL
This data serves to ensure trouble-free operation, error analysis and defence against attacks. It is not combined with other data sources or evaluated for marketing purposes.
Purpose: operational security, error analysis, abuse and attack detection.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in secure and stable operation).
9. Cookies / local storage
This website uses technically necessary cookies and your browser's local storage (localStorage). Specifically:
- session cookie for sign-in (technically necessary)
- cookie and local entry storing your cookie choice (honours your decision)
- local editor settings (e.g. auto-save, maximum log entries)
- language choice of the legal pages
On your first visit a notice banner asks whether you allow optional preferences in addition to the technically necessary cookies. You can change your decision at any time in the settings. Technically necessary cookies are required for operation and are set on the basis of Art. 6 (1) lit. b and lit. f GDPR; optional storage is based on your consent pursuant to Art. 6 (1) lit. a GDPR.
Workflows übermitteln nur die Daten, die Sie selbst in einem Knoten konfigurieren, an den dort gewählten Dienst (z. B. KI-Anbieter, E-Mail-, Chat- oder Cloud-Dienste). Diese Übermittlung erfolgt in Ihrem Auftrag.
Retention period: 14 Tage bzw. bis zur Abmeldung
10. Data deletion
You can delete your account at any time. Deleting it removes the account, your workflows, agents, credentials, variables, data tables and execution logs. Published templates can also be removed individually from your profile.
You can delete your account via: die Kontoeinstellungen (Einstellungen → Konto) oder eine formlose E-Mail. Alternatively, a message to main@w-flow.tech is sufficient; I will then delete the data without undue delay, unless statutory retention obligations apply.
Where statutory retention obligations exist (e.g. commercial or tax law for paid services), the affected data is kept for the duration of the obligation and deleted afterwards.
Legal basis: Art. 6 (1) lit. c GDPR (statutory retention) and Art. 17 GDPR (right to erasure).
11. Storage periods
I store personal data only for as long as is necessary for the stated purposes or as required by law:
- account data: until the account is deleted
- workflows, agents and configurations: until they or the account are deleted
- execution logs: until they or the account are deleted
- sessions: 14 Tage bzw. bis zur Abmeldung
- cookie choice: until withdrawn, at most 180 days
Server-Logs: 7 Tage; automatische Datenbank-Sicherungen: 14 Tage; Konto-, Workflow- und Ausführungsdaten: bis zur Löschung des Kontos
Once the respective period expires, the data is deleted or anonymised so that it can no longer be attributed to you.
12. Legal bases
The processing of personal data is based on the following legal bases of the GDPR:
- Art. 6 (1) lit. a GDPR — consent (e.g. optional cookies, social login via a third party)
- Art. 6 (1) lit. b GDPR — performance of a contract or pre-contractual measures (account, workflow builder, e-mail confirmation)
- Art. 6 (1) lit. c GDPR — compliance with legal obligations (in particular retention obligations)
- Art. 6 (1) lit. f GDPR — legitimate interests (operational security, error analysis, abuse prevention)
No processing of special categories of personal data (Art. 9 GDPR) takes place. Where you run your own workflows that process personal data, you are responsible for them; the builder and the services you configure process data solely on your instructions.
13. Data-subject rights
As a data subject you have the following rights:
- Art. 15 GDPR — access to the data processed
- Art. 16 GDPR — rectification of inaccurate or incomplete data
- Art. 17 GDPR — erasure of your data
- Art. 18 GDPR — restriction of processing
- Art. 20 GDPR — data portability (export in a common format)
- Art. 21 GDPR — objection to processing based on legitimate interests
- Art. 7 (3) GDPR — withdrawal of consent with effect for the future
To exercise these rights, a message to main@w-flow.tech is sufficient. An export of all your data is also available directly in the account settings. You also have the right to lodge a complaint with a supervisory authority (see section 15).
14. International data transfers
Some integrated services may process data outside the European Union or the European Economic Area (e.g. Cloudflare or an e-mail provider). Such a transfer only takes place where necessary for operation or permitted by law.
You can request a copy of the safeguards in place at main@w-flow.tech.
15. Supervisory authority / right to complain
Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority — in particular in the member state of your habitual residence, place of work or place of the alleged infringement.
You are welcome to raise any concerns with me first; I will then deal with your request without undue delay.
Weitere Maßnahmen: TLS-Verschlüsselung (HTTPS), verschlüsselt gespeicherte Zugangsdaten, Passwort-Hashing (scrypt), Firewall und tägliche Datensicherungen.