Privacy Notice
Heedvane data protection information
§ 1 Controller
The controller within the meaning of Art. 4 No. 7 GDPR for the processing of personal data on this website and in the Heedvane application is:
| Company | FlowConAI UG (haftungsbeschränkt) |
| Address | Aachener Str. 392, 50933 Köln, Deutschland |
| info@flowconai.com | |
| Represented by | Andre Machon, Geschäftsführer |
§ 2 Data Protection Coordination
FlowConAI UG has a Data Protection Coordination Team. For questions or concerns regarding data protection, please contact us by email with the subject line „For the attention of: Data Protection“ at info@flowconai.com.
We endeavour to respond to all data protection enquiries as promptly as possible. For requests pursuant to Art. 15 et seq. GDPR (data subject rights), Art. 12(3) GDPR applies (response within one month).
§ 3 General Principles of Data Processing
3.1 Principles
FlowConAI UG processes personal data in accordance with the provisions of the GDPR and the BDSG. We collect and process your data exclusively for specific, legitimate purposes and within the framework of the principle of data minimisation (Art. 5 GDPR). No processing of personal data takes place without a legal basis.
3.2 Legal Bases
The following provisions apply as legal bases for the processing of personal data in particular:
- Art. 6(1)(a) GDPR: consent of the data subject;
- Art. 6(1)(b) GDPR: performance of a contract or pre-contractual measures (e.g. provision of the Heedvane application, processing of demo requests);
- Art. 6(1)(c) GDPR: compliance with a legal obligation (e.g. statutory retention periods under commercial and tax law);
- Art. 6(1)(f) GDPR: legitimate interests of the controller or a third party, provided the interests or fundamental rights of the data subject do not override these (e.g. technically necessary cookies, server log files, IT security).
Where cookies or similar technologies are used, the permissibility of access to terminal equipment is additionally governed by § 25 TDDDG.
3.3 Data Processing Outside the EEA
Where we transfer personal data to service providers or other third parties outside the European Economic Area (EEA), we ensure through appropriate safeguards that a level of data protection equivalent to European standards is maintained. Depending on the recipient, this is based on an adequacy decision of the European Commission (Art. 45 GDPR) or on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR in conjunction with a data processing agreement and, where necessary, supplementary measures. The applicable transfer mechanism for each service is set out in our list of sub-processors, which is available on request (§ 7.5).
3.4 Retention Periods and Erasure
Personal data are erased or blocked as soon as the purpose of storage ceases to apply. Further retention takes place only where required by German or European legislation or where statutory retention obligations (in particular under HGB and AO of up to 10 years) preclude erasure.
3.5 No Automated Individual Decision-Making
FlowConAI UG does not make decisions based solely on automated processing (including profiling) within the meaning of Art. 22 GDPR that produce legal effects concerning data subjects or similarly significantly affect them. The automated code analysis described in § 7 produces advisory findings for review; it does not make decisions about data subjects.
§ 4 Server Log Files
Each time the website or application is accessed, data are temporarily stored that may allow identification, including: date and time of access, IP address, the referring website, the page or endpoint accessed, the HTTP status, the volume of data transferred, browser type and version, and operating system. For authenticated sessions, the IP address and user-agent associated with a sign-in are also stored as part of session management.
The temporary storage of these data is necessary to deliver the service and to ensure the functionality and security of the IT systems; this is also our legitimate interest. The data are processed on the basis of Art. 6(1)(f) GDPR and are erased as soon as they are no longer required for the purpose for which they were collected.
§ 5 Hosting and Infrastructure
The Heedvane application is hosted on servers operated by Hetzner Online GmbH in Germany. Application and analysis data are stored in a managed PostgreSQL database provided by Supabase, hosted within the European Union (AWS region eu-west-1, Ireland). These providers process the data on our behalf as processors pursuant to Art. 28 GDPR; the legal basis for the underlying processing is Art. 6(1)(f) GDPR (our legitimate interest in providing a secure and available service) and, where the processing serves the performance of the customer contract, Art. 6(1)(b) GDPR. Transactional emails (e.g. email verification and team invitations) are sent via an email delivery provider over SMTP.
§ 6 Cookies
The Heedvane application uses technically necessary cookies, in particular session and authentication cookies required to keep you signed in and to protect the application. The legal basis for these necessary cookies is § 25(2)(2) TDDDG in conjunction with Art. 6(1)(f) GDPR.
If you consent, we also use PostHog analytics and privacy-masked session replay to understand application page views, navigation, feature interactions, and conversion starts. Analytics is rejected by default until you accept it in the cookie banner, and you can withdraw or change that choice through the cookie preferences control. We do not intentionally send passwords, access tokens, authentication headers, API keys, form values, private repository data, source code, prompts, generated reports, personal messages, or raw error responses to PostHog.
§ 7 The Heedvane Application
7.1 GitHub Integration and Source-Code Processing
To provide its analysis, Heedvane connects to your source-code repositories through GitHub (via OAuth and a GitHub App that you install for your organisation). We store metadata about the connection and the selected repositories. Such as the installation and account identifiers, repository owner, name, visibility, and default branch. And metadata about analysed pull requests (title, branch references, commit identifiers, and status).
When an analysis runs, the relevant source code is cloned into an ephemeral, read-only, isolated workspace and the working copy is discarded once the run completes. We do not retain a second persistent copy of your source code. Instead, we persist the results of the analysis. Findings, structural metadata, and minimal evidence snippets (the smallest excerpt needed to substantiate a finding). Together with their status over time. The legal basis for this processing is Art. 6(1)(b) GDPR (performance of the contract for the service).
7.2 Automated Code Analysis and AI Sub-processors
The analysis is performed with the assistance of third-party large-language-model (LLM) providers acting as our processors. For this purpose, code excerpts and the minimal evidence snippets described above may be transmitted to these providers. Where such processing takes place outside the EEA, it is safeguarded by the transfer mechanisms described in § 3.3. We also use the LLM-observability service Langfuse Cloud to record technical traces of analysis runs for debugging and quality purposes. The providers used and the applicable safeguards are set out in our list of sub-processors, which is available on request (§ 7.5). The legal basis is Art. 6(1)(b) GDPR.
7.3 Account and Authentication Data
To create and operate an account, we process your name, email address, profile image (if provided), and role, as well as authentication data such as sign-in identifiers, federated-login tokens, and, for email/password sign-in, a securely hashed password. For team functionality, we process organisation membership and the email addresses used to send invitations. The legal basis is Art. 6(1)(b) GDPR (provision of the service) and Art. 6(1)(f) GDPR (account security). These data are retained for the duration of the account relationship and deleted thereafter, subject to statutory retention obligations.
7.4 Billing and Payments
For paid subscriptions we use the payment service provider Stripe. We store billing metadata such as the Stripe customer and subscription identifiers, the selected plan, subscription status and billing period, and invoice references; payment-card data are handled by Stripe and are not stored on our systems. The legal basis is Art. 6(1)(b) GDPR (performance of the subscription contract) and Art. 6(1)(c) GDPR for the retention of invoicing records under statutory commercial and tax-law obligations (HGB, AO).
7.5 Sub-processors
We engage carefully selected processors to provide the service, including for hosting, database, email delivery, source-code integration, automated analysis, and payments. Each is bound by a data processing agreement pursuant to Art. 28 GDPR. A current list of sub-processors, including their function, location, and the applicable third-country transfer safeguards, is available on request and will be published here.
§ 8 Rights of Data Subjects
You have the following rights vis-à-vis FlowConAI UG with respect to your personal data. To exercise your rights, please contact us as described in § 2.
8.1 Right of Access (Art. 15 GDPR)
You have the right to request confirmation as to whether and which personal data we process about you, including the purposes, the categories of data, the recipients, and the planned retention period.
8.2 Right to Rectification (Art. 16 GDPR)
You have the right to request the immediate rectification of inaccurate personal data concerning you and the completion of incomplete data.
8.3 Right to Erasure (Art. 17 GDPR)
You have the right to request the erasure of personal data concerning you, provided the conditions of Art. 17 GDPR are met. Statutory retention obligations may preclude the right to erasure.
8.4 Right to Restriction of Processing (Art. 18 GDPR)
Subject to the conditions of Art. 18 GDPR, you have the right to request restriction of the processing of your personal data.
8.5 Right to Data Portability (Art. 20 GDPR)
Where the processing is based on consent or a contract and carried out by automated means, you have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
8.6 Right to Object (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to processing carried out on the basis of Art. 6(1)(f) GDPR. Where personal data are processed for direct marketing, you may object at any time without giving reasons.
8.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
8.8 Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority of your choice. The authority with jurisdiction over the controller is the Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), https://www.ldi.nrw.de/kontakt/ihre-beschwerde.
§ 9 Technical and Organisational Security Measures
FlowConAI UG implements technical and organisational measures to protect your personal data against accidental or intentional manipulation, loss, destruction or unauthorised access; these are continuously reviewed and improved in accordance with the state of the art. For the protection of confidential content, this website uses TLS encryption, recognisable by the https:// prefix and the padlock symbol in your browser.
§ 10 External Links
Our website contains links to external third-party websites whose content we do not control. The respective provider or operator is always responsible for their content. Upon becoming aware of legal violations, such links will be removed immediately.
§ 11 Protection of Minors
The services of FlowConAI UG are directed exclusively at companies and professionals (B2B). They are not intended for persons under the age of 18, and we do not knowingly collect data from them.
§ 12 Amendments to this Privacy Notice
FlowConAI UG reserves the right to amend this Privacy Notice to adapt it to changes in the legal framework or technical circumstances. The current version is available on this page.
| Version | 2026-07-22 |
| Effective from | 22 July 2026 |