Privacy policy
As of: 2026-08-11
Language note: this English version is provided for convenience. The authoritative version is the German version.
1. Controller
Controller within the meaning of the GDPR:
TesseraFlow, owner Thomas Hattert
Rombacher Straße 5E, 46049 Oberhausen, Germany
E-mail: support@tesseraflow.de
Please send privacy requests informally to the same e-mail address.
2. Scope
This policy covers the TesseraFlow marketing website (tesseraflow.de / tesseraflow.eu). Use of the TesseraFlow application itself is covered by a separate privacy notice available inside the application.
3. Core principle: no cookies, no tracking
This website sets no cookies and uses no tracking, analytics or advertising services, and therefore there is no cookie banner (§ 25 of the German TDDDG does not apply). Fonts are served from our own servers, and no third-party CDN content is embedded. No automated decision-making, including profiling (Art. 22 GDPR), takes place.
4. Hosting and server log files
The website runs on a server of Hetzner Online GmbH in Nuremberg (Germany) under a data processing agreement per Art. 28 GDPR. The data processed on that server remains in Germany. For e-mail delivery see section 7.
When you visit the site, the web server writes an access log. It records the IP address, the time of access, the requested address, the HTTP status code, the volume of data transferred, the referrer, browser type and version, and further technical connection details such as the request method and protocol and encryption parameters. The purpose is technical operation, error analysis and defence against attacks (Art. 6(1)(f) GDPR). Entries are deleted automatically after 14 days at the latest.
Two things are deliberately left out. The entire query part of the address, everything after the question mark, is stripped before writing. Neither search input nor invitation or password links therefore reach the log. Cookies and credentials are not recorded either.
In addition, technical operating logs of the services involved are produced. These contain no personal data in clear text such as names or e-mail addresses. They are rotated by size, at most 50 MB per service, and are continuously overwritten. No archiving beyond that takes place.
5. Trial request form
When you request a trial via the form, we process the details you provide: first and last name, business e-mail address, company, the number of people to schedule (size bracket), the industry template you select, optionally a phone number, and your message. The purpose is handling your enquiry and setting up the trial. If a trial is set up, we also contact you during the trial to support you and to gather your feedback on the product. The legal basis is Art. 6(1)(b) GDPR (pre-contractual step and running the trial) together with Art. 6(1)(f) GDPR (legitimate interest in sales contact and product improvement). Providing your details is neither legally nor contractually required. Without the mandatory fields, however, we cannot process your enquiry.
On the website itself your details are not stored in a database. They are delivered as an e-mail to our sales inbox, and you receive a confirmation e-mail. We use Resend (provider: Plus Five Five, Inc., USA) as processor per Art. 28 GDPR for e-mail delivery; processing takes place primarily in the USA, safeguarded as described in section 7. To handle and follow up on your enquiry, we keep your details in the sales inbox and in an internal, access-protected contact list within the EU. We do not pass them on to third parties for advertising purposes. They are kept until six months after the enquiry is closed.
Bot protection without third parties: the form is protected by a self-hosted proof-of-work check (Altcha) and a server-side honeypot field. No cookies are set and no data is sent to third parties. We deliberately do not use Google reCAPTCHA or comparable services.
6. Error diagnostics (error tracking)
To keep the service stable we record software errors during server-side processing (e.g. of form submissions) with Sentry (EU region) as processor. The legal basis is our legitimate interest in reliable operation (Art. 6(1)(f) GDPR). Personal content (form inputs, e-mail addresses) is excluded from transmission by technical filters. Only technical error data such as stack trace and request path is transmitted.
7. Third-country transfers
We generally process personal data in data centers in the EU. Some providers we use are based in the USA: e-mail delivery (Resend, provider Plus Five Five, Inc.) is processed primarily in the USA; error diagnostics (Sentry) is operated in the EU region, where access from a third country cannot be entirely ruled out. These transfers are safeguarded by EU standard contractual clauses per Art. 46 GDPR. Where the provider is certified, the adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) applies in addition; Resend is certified under the EU-U.S. Data Privacy Framework. You can obtain a copy of the standard contractual clauses on request via support@tesseraflow.de.
8. Data security
Transmission is encrypted via TLS. We apply technical and organisational measures per Art. 32 GDPR to protect the processed data against loss and unauthorised access.
9. Your rights
Regarding your personal data you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Right to object (Art. 21 GDPR): you have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data based on Art. 6(1)(f) GDPR.
An informal message to support@tesseraflow.de is sufficient to exercise your rights. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
10. Changes to this policy
We update this privacy policy when the data processing or the legal situation changes. The version published here applies.