Privacy policy
Last updated: September 2026
1. Privacy at a glance
This policy explains what happens to your personal data when you visit this website. It covers the website only; how the modelflow product handles documents is governed by the agreements with our customers.
The short version: no tracking or analytics scripts, no advertising, and fonts are served from our own server. One small cookie remembers your language, and only if you change it. What you send through the contact form is used to answer you.
2. Responsible party
The party responsible for data processing on this website is the provider named in the imprint. For any questions about data protection, you can reach us using the contact details given there.
3. Hosting
This website runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When you visit the site, the server processes your IP address and technical request data in order to deliver the pages.
We use Hetzner on the basis of our legitimate interest in operating this website reliably and securely (Art. 6 (1) (f) GDPR). A data processing agreement under Art. 28 GDPR is in place with Hetzner.
4. Server log files
When pages are requested, technical data is logged: IP address, date and time, requested page, referrer, browser and operating system. These logs serve only to keep the website secure and running, are not merged with other data and are deleted as soon as they are no longer needed for that purpose (Art. 6 (1) (f) GDPR).
5. Cookies
This website sets a single cookie named “lang”, and only when you switch the language. It stores “en” or “de” for one year so that the site keeps showing the language you chose. It is strictly necessary to provide the function you requested and therefore does not require consent (§ 25 (2) no. 2 TDDDG).
There are no other cookies, no tracking or analytics scripts and no advertising. All fonts are served from our own server.
6. Contact form
If you send us a message through the contact form, we process the details you enter (name, email address, company if given, your selection and your message) to answer your enquiry and any follow-up questions.
The message is delivered to our mailbox through Microsoft 365. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, acting as our processor under a data processing agreement (Art. 28 GDPR). Microsoft may also process data in the USA and is certified under the EU-U.S. Data Privacy Framework.
The legal basis is Art. 6 (1) (b) GDPR where your enquiry relates to a contract or to pre-contractual steps, and otherwise our legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR). We delete your details once your enquiry has been dealt with, unless statutory retention obligations apply.
The form contains an invisible field that catches automated spam, and the number of messages that can be sent from one IP address in a short time is limited. No third-party spam protection service is used.
7. Your rights
You have the right to receive information about the origin, recipients and purpose of your stored personal data free of charge at any time, and to have this data corrected or deleted. You can contact us about this and any other data protection question at any time.
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
8. Supervisory authority
The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Heilbronner Str. 35, 70191 Stuttgart, Germany.
9. Encryption
This website is only available over an encrypted connection (TLS).