v1.0 · 08.08.2026
Status: 14.08.2026 Scope: GDPR Art. 13, 14 Controller: flowgeist
The Controller within the meaning of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) is:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Data Protection Officer: Pursuant to Art. 37 GDPR and § 38 BDSG, no Data Protection Officer has been appointed at this time, as the requirements under § 38 para. 1 BDSG are not met. Contact person for data protection matters: datenschutz@flowgeist.de (interim).
This Privacy Policy informs you about the processing of personal data when using the DIRIGENT platform (B2B orchestration platform). DIRIGENT is a multi-tenant SaaS platform for B2B process orchestration, comprising workflow management across nine process phases (Lead → Opportunity → RolloutCase → CustomerRelationship) with handover checklists (Ü1/Ü2/Ü3) and quality gates (QG-1 to QG-9), a booking service (MS365 Bookings + Graph Calendar, planned), notifications (email via MS365 Graph API, planned; in-app), an integration hub with connectors to SuperOffice, Jira, and work4all (mock connectors level 1), and an ISO 27001-compliant audit trail.
We process personal data in compliance with the provisions of the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). This Privacy Policy applies exclusively to the processing of data in the context of using the DIRIGENT platform.
In the context of providing and using DIRIGENT, we process the following categories of personal data:
| Category | Description | Examples |
|---|---|---|
| Master data | Information on identity and company | Name, first name, email address, company name, address |
| Access data | Data for authentication | Password hash (Argon2id/bcrypt), MFA/TOTP secret, SSO claims |
| Customer/CRM data | Data on customers and contacts | Customer data, contact persons, sales contacts (rollout@atbas.de, Support@atbas.de) |
| Workflow data | Data on process orchestration | Process phases, handover checklists (Ü1/Ü2/Ü3), quality gates (QG-1 to QG-9), timers, override audit |
| Booking data | Data on booking management | Booking appointments, participants, MS365 Calendar events (planned) |
| Audit data | Logging in accordance with ISO 27001 A.12.4 | Timestamp, User-ID, Tenant-ID, action, resource, IP address, User-Agent, Trace-IDs |
| Support data | Data in the context of support processing | Support requests, communication history |
Note: As DIRIGENT is a purely B2B platform, no payment data is processed. No payment transactions take place.
We process personal data for the following purposes:
The processing of personal data is based on the following legal bases:
Your personal data will be disclosed to the following recipients:
| Recipient | Location | Purpose | Third-country transfer |
|---|---|---|---|
| Hetzner Online GmbH | Germany (Falkenstein) | Hosting, database (PostgreSQL 18), Redis, backup, internal observability (OpenTelemetry/Loki/Tempo/Grafana) | No third countries |
| Microsoft (MS365 Graph API) | Ireland / USA | Booking service, notifications (email) — planned | EU-US Data Privacy Framework + SCC |
Hetzner Online GmbH: As a hosting provider, Hetzner Online GmbH processes personal data in Germany (Falkenstein). No transfer to third countries takes place. Hetzner acts as a Processor in accordance with Art. 28 GDPR. The internal observability stack (OpenTelemetry, Loki, Tempo, Grafana) runs on the same Hetzner server; no transmission to external recipients takes place.
Microsoft (MS365 Graph API): For the planned booking service and the planned email notifications, processing is carried out via the MS365 Graph API. Microsoft Ireland Operations Ltd. is based in Ireland. The parent company Microsoft Corporation is based in the USA. Data transfer to the USA takes place on the basis of the EU-US Data Privacy Framework and supplementary Standard Contractual Clauses (SCC). Microsoft acts as a Processor in accordance with Art. 28 GDPR.
No further external recipients: No further external recipients are actively involved. In particular, no external AI services and no web analytics services are used.
The primary processing of your personal data takes place in Germany. The servers of Hetzner Online GmbH are located in Falkenstein (Germany). The entire observability stack (OpenTelemetry, Loki, Tempo, Grafana) is operated internally on the same Hetzner server. No transfer to third countries takes place in this respect.
In the context of the planned booking service and the planned email notifications, data is transferred to Microsoft (MS365 Graph API). Microsoft Ireland Operations Ltd. processes data in Ireland; the US parent company Microsoft Corporation (USA) may have access. The transfer to the USA takes place on the basis of the EU-US Data Privacy Framework, under which Microsoft Corporation is registered as a certified company. Supplementary Standard Contractual Clauses (SCC) are agreed in accordance with Art. 46 para. 2 lit. c GDPR. Further information on the EU-US Data Privacy Framework and the Standard Contractual Clauses can be found at https://www.dataprivacyframework.eu and https://privacy.microsoft.com.
We process and store personal data only for the period necessary to achieve the storage purpose, or insofar as this is required by law. After the purpose ceases to apply, the data is deleted or pseudonymized.
| Data category | Storage duration | Justification |
|---|---|---|
| Master data | 30 days after termination | Processing and evidentiary purposes |
| Workflow data | 30 days after termination | Processing and evidentiary purposes |
| Audit logs | 3 years | ISO 27001 A.12.4, security, abuse detection, statutory retention obligations |
| Contracts/documents | 10 years | Statutory retention obligation (§ 147 AO, § 14b UStG) |
As a data subject, you have the following rights under the statutory conditions:
You have the right to request from us information about the personal data processed about you, the processing purposes, the categories of data processed, the recipients or categories of recipients, the planned storage duration, and the rights available to you.
You have the right to request the immediate rectification of inaccurate personal data concerning you. You may also request the completion of incomplete data.
You have the right to request from us the immediate erasure of personal data concerning you, provided that one of the reasons set out in Art. 17 GDPR applies and no statutory retention obligations conflict therewith.
You have the right to request the restriction of processing if one of the conditions set out in Art. 18 GDPR is met.
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another Controller.
You have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you that is carried out on the basis of Art. 6 para. 1 lit. f GDPR. In the event of an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR.
To exercise the rights mentioned above, you may contact us at any time:
We will process your request without undue delay, but no later than within one month of receipt, and will provide you with information. If processing takes longer, we will inform you of the reasons and the expected duration within one month of receipt of your request.
Automated decision-making within the meaning of Art. 22 GDPR does not take place. We do not use any procedures that result in automated decisions with legal effect or similarly far-reaching assessments for you. The platform does not use any external AI services.
The DIRIGENT platform uses exclusively technical cookies that are necessary for the operation of the platform and authentication (session and authentication cookies). These cookies are necessary to enable you to use the platform and to ensure the security of your session.
We do not use analytics cookies, tracking, advertising cookies, or third-party cookies. No profiling takes place.
To protect your personal data, we implement the following technical and organizational measures:
We reserve the right to adapt this Privacy Policy so that it always reflects current legal requirements or to reflect changes to the service or new functions of the platform. The current version is available on the website at https://digitallydriven.flowgeist.de. In the event of material changes affecting the processing of your personal data, we will inform you in advance.
If you have questions regarding data protection, the processing of your personal data, or the exercise of your data subject rights, please contact:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
You have the right to lodge a complaint with the competent data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. The competent supervisory authority is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW) Postfach 20 04 44 40102 Düsseldorf Germany
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 14.08.2026 | Initial version for DIRIGENT |
© 2026 flowgeist – Ralf Carsjens · All rights reserved