Privacy Policy
Effective: 2026-08-12
This English version is a convenience translation. In case of discrepancies, the German version prevails.
1. Controller
The controller within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR) is:
NexusFlow UG (haftungsbeschränkt)
Mühlenstraße 8a
14167 Berlin
Represented by the managing director: Carsten Koch
Data protection contact: legal@nxsflow.com
We are not required to appoint a data protection officer. Please address data protection enquiries directly to the managing director.
2. Scope
This privacy policy covers:
- our websites nxsflow.com, manufakt.io and nexflow.it,
- the software offered there — our desktop and web applications and, in the future, applications for mobile devices,
- the channels through which you download that software and through which it updates itself.
Where individual products process data differently, this is described in section 7.
3. When you visit our websites
When you open one of our websites, your browser transmits access data for technical reasons. Of that data we record only what we need for secure operation and for the question of how often our pages and products are used:
- the time of access
- the type of request
- the address requested
- the additional details passed along with that address
- whether the request succeeded
- the type of content delivered
- the identifier of the program that made the request (browser or bot)
Your IP address is expressly not among them. It is not stored. Nor do we otherwise store any identifier when you visit our websites by which a person or a device could be recognised again: no cookie, no entry in your browser's storage, no other identifier. The logs are not combined with other data sources and are deleted automatically after 30 days.
The description above applies equally to all three websites.
4. When you download or update our software
Downloading our software and checking for updates run through the same delivery as our websites. The same details arise as in section 3, and the same limits apply — in particular, no IP address is stored here either.
One point is specific to update checks: when the software itself — not a browser — asks us whether a newer version exists, it transmits a randomly generated installation identifier together with the update channel it uses. This lets us count how many distinct installations check for updates. The identifier is generated by the software itself, not assigned by us. We do not link it to any website visit, to any account or to any person.
5. Contact form
On manufakt.io and on nexflow.it we offer a form through which you can leave us your email address — for example to be notified when a product becomes available, or to tell us that you are interested in taking part in a trial programme.
Data processed: the email address you enter, the time of submission and, if you leave a message, its content. The form collects nothing further. Your IP address is not stored when you submit — neither in clear text nor as a hash value.
Purpose: answering your enquiry, notifying you about a product's availability and, where you ask for it, considering your participation in a trial programme.
Legal basis: Art. 6(1)(b) GDPR (taking steps at your request prior to entering into a contract).
Retention: until your enquiry has been dealt with, at most 24 months after receipt. You may request deletion at any time; an informal email to the address above is sufficient.
6. Signing in with Google
For some of our products we will offer signing in via Google as an identity provider in the future. It is voluntary: anyone who does not use it simply cannot open the areas concerned; no disadvantage arises for the rest of your use of our websites or products.
If you do sign in, Google transmits to us your email address, whether Google has verified that address, and the profile details Google supplies by default — at minimum the display name you have stored there. We store these details for the duration of your signed-in session. To decide whether you are granted access, we evaluate only the email address and its verification status.
Signing in also creates a process at Google itself, over which we have no influence; Google's own privacy policy applies to it. For signing in we also set technically necessary cookies (section 9).
Purpose: determining whether the person signing in may access a protected area.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting restricted areas against unauthorised access), or Art. 6(1)(b) GDPR where signing in serves the performance of a usage agreement.
7. When you use our software
Our desktop applications process your content locally on your device as a matter of principle. We receive none of it — apart from the details described in section 4 for downloads and update checks.
Differences arise for synchronisation between several devices:
nexus-flow provides a synchronisation mechanism that you set up yourself. If you choose a PostgreSQL database with a provider of your choosing, your data resides with that provider. We do not operate that database, have no access to it and are not the controller for it under data protection law; the privacy policy of the provider you selected applies. Choosing the provider and securing access to it are your responsibility.
manufakt.io and nexflow.it use nexus-flow under the hood but offer their own synchronisation, operated by us. If you use it, we process the synchronised content on your behalf; this privacy policy applies to that, in particular section 10 on where processing takes place and who receives the data.
8. Purposes and legal bases
The logs described in sections 3 and 4 serve undisturbed and secure operation (error analysis, abuse detection) and reach measurement: how often our pages are opened, how often our software is downloaded and checked for updates, and how many distinct installations are discernible in the process. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR.
The legal bases for the contact form, for signing in with Google and for synchronisation operated by us are stated in the respective sections.
9. Cookies
For an ordinary visit to our websites we set no cookies. The logging described in section 3 works without them.
We set cookies in two cases only, and both are technically necessary:
- When signing in (section 6): a short-lived cookie securing the path to Google and back, which expires once signing in completes, and a session cookie referring to your signed-in session. The session ends when you sign out; independently of that, the cookie expires in the browser after 30 days at the latest.
- On nexflow.it, a cookie named
preferredLanguage. It records the language your browser transmits and thereby controls which language version is delivered. It contains no identifier by which a person could be recognised, and it ends with the current browser session.
10. Hosting and data sharing
Our websites and the services we operate run on Amazon Web Services (AWS). AWS processes the data described here on our behalf as a processor.
Where the data is stored: in the eu-central-1 region (Frankfurt am Main, Germany) — the access logs as well as the data submitted through the contact form and the content of any synchronisation operated by us.
How pages and downloads reach you: we deliver through a worldwide content delivery network. Your request is therefore not received in Frankfurt but at the location technically closest to you; if you reach us from outside the EU, that is a location outside the EU. For the duration of the request your IP address is necessarily processed there — without it no response could be delivered to you. It is not stored there, and not by us either; what is stored is listed exhaustively in section 3. The only thing cached at those locations is our own content.
No disclosure to further third parties takes place unless we are legally obliged to do so. What applies to a database you selected yourself is set out in section 7.
11. Retention
The logs described in sections 3 and 4 are deleted automatically after 30 days. For the other processing operations, the periods are stated in the respective sections.
12. Your rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
To exercise your rights, please contact: legal@nxsflow.com
You also have the right to lodge a complaint with the competent supervisory authority:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219
10969 Berlin
https://www.datenschutz-berlin.de
13. Changes to this privacy policy
We reserve the right to adapt this privacy policy to changes in the law or changes to our offering. The current version is always available on this page.