Privacy · Version: 15/12/2025

Privacy Policy

This Privacy Policy explains how MVPWERK (Flaaq Holding GmbH) processes personal data — including hosting via Vercel, data processing via Supabase, and tracking via Google Tag Manager & Google Analytics (GA4).

Overview

Controller
Flaaq Holding GmbH
Hosting
Vercel (web hosting/edge/logs)
App/DB/Auth
Supabase (DB, Auth, Storage)
Tracking
Google Tag Manager & Google Analytics (GA4)
Consent
Tracking usually only after consent (cookie/consent banner)
Important
We generally configure tracking/conversion tracking so it only activates after your consent (if technically set up). Without consent, only technically necessary processing takes place (e.g., server logs).

1. Controller

Flaaq Holding GmbH
Dammstr. 6G, 30890 Barsinghausen
Managing director: Christoph Pfad

A data protection officer has not been appointed unless legally required.

2. Data types & purposes

  • Usage/log data (e.g., IP address, timestamp, visited page) for technical delivery & security.
  • Contact/communication data (e.g., name, email, message) to handle inquiries.
  • Analytics/marketing data (e.g., events/conversions) for reach measurement & optimization — usually only after consent.
  • App data (when using a demo/app) in Supabase (Auth/DB/Storage), depending on features.

3. Legal basis

  • Art. 6(1)(b) GDPRPerformance of a contract / pre-contract steps (e.g., project inquiry).
  • Art. 6(1)(f) GDPRLegitimate interest (security, stability, abuse prevention).
  • Art. 6(1)(a) GDPRConsent (e.g., analytics/marketing/conversion tracking).

4. Hosting (Vercel) & server logs

This website is provided via Vercel. For delivery and protection of the site, technically necessary data is processed (e.g., server logs, IP address, user agent, referrer, timestamp).

Purpose: provide the website, analyze errors, defend against attacks (e.g., DDoS), optimize delivery. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

5. Supabase (Auth/DB/Storage)

For app features (e.g., login/accounts, database, file storage) we use Supabase. Depending on use, this may include account data (email), technical metadata, and content/data stored in the database.

Purpose: provide authentication, data storage, file storage, and app logic. Legal basis: Art. 6(1)(b) GDPR (contract/pre-contract) and/or Art. 6(1)(f) GDPR (operation/security).

6. Contacting us

If you contact us (e.g., by email, phone, or contact form), we process the data you provide to handle your request and follow-up questions.

Legal basis: Art. 6(1)(b) GDPR (pre-contract/contract) or Art. 6(1)(f) GDPR (general communication/organization).

7. Cookies & consent

Depending on your selection in the consent/cookie banner, we use cookies or similar technologies. Technically necessary cookies may be set without consent. Analytics/marketing usually only takes place with consent.

8. Google Tag Manager

We use Google Tag Manager to manage website tags centrally. Tag Manager itself generally does not create user profiles, but may technically transmit data (e.g., IP address) to deliver tags.

Legal basis: Art. 6(1)(a) GDPR (consent) — unless configured as purely technically necessary. We recommend controlling Tag Manager via consent management.

9. Google Analytics (GA4) & conversion tracking

We use Google Analytics (GA4) to analyze website usage and measure conversions (e.g., “contact sent”). Events are captured and evaluated.

Legal basis: Art. 6(1)(a) GDPR (consent). Without consent, analytics/conversion tracking is not executed or only in a restricted manner (depending on technical configuration).

  • Purposes: reach measurement, funnel optimization, performance measurement of campaigns.
  • Scope: page views, interactions, technical parameters (browser/device), events/conversions.

10. Third-country transfers

When using services such as Google, processing of data in third countries (e.g., USA) cannot be ruled out. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses and/or applicable certification mechanisms).

11. Retention period

We store personal data only as long as necessary for the respective purposes or as required by statutory retention obligations. Contact inquiries are generally deleted once fully processed, unless legal obligations require otherwise.

12. Your rights

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR)

13. Objection & withdrawal

You can withdraw consent at any time with effect for the future. You can also object to processing based on legitimate interests if reasons arising from your particular situation apply.

To do so, write to us at info@mvpwerk.de.

14. Updates to this policy

We reserve the right to update this Privacy Policy if legal requirements, services, or data processing change. The current version published on this page applies.

Get in touch →
Flaaq Holding GmbH · 30890 Barsinghausen
Campaign-ready · live fast · maintainable

Build your SaaS, software, or web app — without friction.

You get a clean Next.js/React implementation — with a clear roadmap, weekly demos and a setup that can scale from day one.

Clear process
Kickoff → MVP → Live → Iteration
Transparency
Weekly demo + clear milestones
Ownership
You own the code
Performance
Fast, clean, Lighthouse-ready
MVPWERK
Free first assessment
Usually same-day reply
In 30 minutes we clarify:
  • • What you actually need (and what you don’t)
  • • How to go live fast
  • • Cost & realistic timeline
No spam · no obligation · Made in Germany
Privacy Policy – MVPWERK | MVPWERK