Privacy Policy
Last updated: July 2026
1. Controller
The controller within the meaning of Article 4(7) GDPR is: starnode solutions GmbH Zeppelinstraße 81 81669 Munich Germany Represented by Managing Director Frederik Haller Email: [email protected] You can use these contact details for any data protection request.
2. Website delivery and server logs
When you access the website, our hosting provider processes connection data required for delivery. This includes the IP address, time, requested address, amount of data transferred, referrer, browser, operating system, and HTTP status. Processing serves website delivery, stability, and the detection and prevention of attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website. The recipient is our hosting and infrastructure provider Vercel Inc. Log data is deleted when it is no longer needed for operation and security, normally no later than 30 days unless a security incident requires longer retention.
3. Privacy settings
We store your selection for optional services under the key “cookie-consent” in your browser's Local Storage. The selected categories, time, expiry date, and notice version are stored. This information remains on your device and expires after 180 days. Storage is necessary to apply and demonstrate your choice and is based on Section 25(2)(2) TDDDG and Article 6(1)(c) and (f) GDPR. You can change your choice at any time using “Privacy settings” in the footer.
4. Audience measurement and browser error reports
We load Vercel Web Analytics and, where configured, Plausible Analytics only with your consent. The legal bases are Section 25(1) TDDDG where information on your device is accessed and Article 6(1)(a) GDPR. The purpose is statistical audience measurement and improvement of the website. Vercel Web Analytics processes data including the page visited, referrer, time, filtered URL parameters, approximate location, browser, operating system, and device type. Vercel does not use analytics cookies; its daily visitor identifier is discarded after 24 hours. Plausible processes data including the page, referrer, time, country, browser, operating system, and device type. Plausible does not use cookies or persistent identifiers. The IP address and user agent are used only to create a daily-changing identifier and are not stored permanently; processing and storage take place in the EU. Only with the same consent may Sentry receive browser error reports and sampled performance data. These can contain the URL, time, browser and device information, technical execution data, and error contents. We configure Sentry so that no browser reports are sent without this choice. Error and performance data is stored according to the configured retention period, for no longer than 90 days. You can withdraw consent at any time. Withdrawal stops future collection; non-personal aggregated statistics lawfully created before withdrawal remain available.
5. Zoho Bookings
The external appointment calendar is loaded only when you select “Load Zoho calendar” or consent to the “Zoho Bookings” category. When it loads, the Zoho group processes data including the IP address, time, referrer, browser and device information and may use cookies or similar storage. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. If you book an appointment, Zoho additionally processes the contact, appointment, and communication details you enter as our processor. This processing is necessary for pre-contractual steps under Article 6(1)(b) GDPR. We normally delete booking data 24 months after the last business contact unless statutory retention duties or an ongoing contractual relationship require longer storage. Direct access to bookings.fluxplatform.de is additionally subject to the information displayed there.
6. Contact form and email
If you use the contact form, we process your name, email address, optional company, subject, message, time, and temporarily the IP address for abuse prevention. Required fields are needed to handle your request. The message is sent to our email inbox through Resend, Inc. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual requests and otherwise Article 6(1)(f) GDPR based on our interest in handling your request and preventing abuse. IP-based rate-limit data expires after one hour. We normally delete correspondence six months after final resolution unless contractual or statutory retention periods apply.
7. Checkout and Zoho Billing
When you order a plan, we process data including company, name, email address, plan, billing period, and number of users and transmit it to Zoho Billing. You enter payment data directly on the payment page provided by Zoho. Processing is necessary to enter into and perform the contract and is based on Article 6(1)(b) GDPR. We retain invoices and accounting records for the statutory commercial and tax retention period, generally ten years; the legal basis is Article 6(1)(c) GDPR.
8. Recipients and international transfers
Recipients of personal data are limited to the providers needed for each purpose: Vercel for hosting and Web Analytics, Plausible for optional audience measurement, Functional Software, Inc. (Sentry) for optional browser error reports, the Zoho group for booking and billing, and Resend for email transmission. We enter into Article 28 GDPR data processing agreements with processors. Where data is processed outside the European Economic Area, the transfer is based—depending on the provider and destination—on an adequacy decision, in particular the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses and supplementary safeguards. You can request information about the safeguards used by emailing [email protected].
9. Your rights
Subject to the statutory requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection to processing based on legitimate interests (Article 21). You can withdraw consent at any time with effect for the future; this does not affect processing lawfully carried out before withdrawal. To exercise your rights, email [email protected]. You may also lodge a complaint with a data protection supervisory authority. Our competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
10. Security and changes
We apply appropriate technical and organisational measures to protect personal data against loss, alteration, and unauthorised access. We update this policy if services, processing operations, or the law change. If optional purposes or providers change, we will request consent again; merely continuing to use the website does not constitute consent.