Skip to main content

Privacy Policy

Last updated: 25 June 2026 — Panthera Media GmbH

The German version of this privacy policy is legally authoritative; this English text is a courtesy translation.

Protecting your personal data is important to us. Below we inform you in accordance with Art. 13, 14 GDPR about the processing of personal data when using the “FlowCoding” platform.

1. Controller

The controller within the meaning of the GDPR is:

Panthera Media GmbH, Kolonnenstraße 8, 10827 Berlin, Germany

Managing Director: Marc Wendland

Phone: +49 30 76687955 · Email: info@panthera-media.de

No data protection officer is required by law. For any data protection questions, please contact us using the details above.

2. General Information on Processing

We process personal data only insofar as this is necessary to provide a functioning platform and our content and services, or where you have consented.

Legal bases are in particular Art. 6(1)(a) GDPR (consent), (b) (performance of a contract and pre-contractual steps), (c) (legal obligation) and (f) (legitimate interest).

3. Hosting and Server Log Files

Our platform and database are operated on servers within the European Union.

When you access the platform, information your browser transmits is automatically recorded in server log files: IP address, date and time of access, page accessed, volume of data transferred, referrer URL, and browser and operating system information.

Processing is based on Art. 6(1)(f) GDPR to ensure stable and secure operation. Log files are deleted after a short period unless needed to investigate security incidents.

4. User Account and Registration

To use paid and certain free features, you can create a user account. We process your email address, your (encrypted) password, first and last name and optionally a profile picture.

For login we use authentication tokens (JWT) stored in your browser's local storage and renewed upon expiry.

The legal basis is Art. 6(1)(b) GDPR. The data is processed until your account is deleted.

5. Contact and Project Inquiries

If you contact us via a form or by email, we process the data you provide, in particular email address, name, company (if any), phone number, message and project-related details (project name, project description, budget range).

Processing serves to handle your request on the basis of Art. 6(1)(b) or (f) GDPR. The data is deleted as soon as it is no longer required and no statutory retention obligations apply.

6. Use of the Platform and Estimates

To create estimates we process your input (e.g. selected modules, project details) and the results calculated from it. These are stored in association with your user account.

The legal basis is Art. 6(1)(b) GDPR.

7. Payment Processing

For processing paid orders we use the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland). During checkout, the data required for payment (e.g. email address, payment data) is processed and transmitted to Stripe. Payment data such as card numbers is processed exclusively by Stripe; we do not receive it in plain text.

The legal basis is Art. 6(1)(b) GDPR. Stripe's privacy policy applies additionally.

8. Newsletter

If you subscribe to our newsletter, we process your email address to send information and offers. Subscription is based on your consent (Art. 6(1)(a) GDPR).

You can unsubscribe at any time and withdraw your consent with effect for the future, e.g. via the unsubscribe link in every email or by message to info@panthera-media.de.

9. Cookies and Local Storage

We do not use classic HTTP cookies for tracking purposes. To operate the platform we store technically necessary information in your browser's local storage or session storage, such as login tokens, your language setting, your theme (light/dark), your estimate draft and your consent settings.

Storage access that is not technically necessary (e.g. for usage analysis) occurs only with your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can make and change your choices at any time via our consent banner.

10. Usage Analysis

To improve our offering we collect – only with your consent – pseudonymous usage data (e.g. pages accessed, actions triggered, a random session identifier). This data is processed on our own infrastructure within the EU; no third-party tracking (e.g. Google Analytics) takes place.

The legal basis is Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the consent banner.

11. Recipients and Processors

To provide our services we use carefully selected providers that process personal data on our behalf (Art. 28 GDPR). These are in particular:

  • Stripe Payments Europe, Ltd. (Ireland) – payment processing.
  • HubSpot, Inc. (USA) – customer relationship management (CRM): processing of contact data and sales activities.
  • Brevo (Sendinblue SAS, France) – sending of transactional and, where applicable, newsletter emails.
  • Sentry (Functional Software, Inc., USA) – technical error and stability analysis.

Where providers process data in a third country outside the EU/EEA (in particular the USA), this is done on the basis of appropriate safeguards under Art. 44 et seq. GDPR, in particular EU Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework.

12. Storage Period

We process personal data only for as long as required for the respective purposes or as prescribed by statutory retention periods (in particular commercial and tax obligations). Thereafter the data is deleted or blocked.

13. Your Rights

As a data subject you have the following rights:

  • Access to the data stored about you (Art. 15 GDPR).
  • Rectification of inaccurate data (Art. 16 GDPR).
  • Erasure of your data (Art. 17 GDPR).
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR).
  • Objection to processing (Art. 21 GDPR).
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).
  • Lodging a complaint with a supervisory authority (Art. 77 GDPR).

14. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany.

15. Data Security

We take technical and organisational measures to protect your data against loss, misuse and unauthorised access. Transmission via our platform is encrypted (TLS/SSL).

16. Currency and Changes to this Privacy Policy

This privacy policy is currently valid. As the platform develops or due to changed legal requirements, it may become necessary to amend this privacy policy. The current version can be accessed at any time on this page.