v1.0 · 08.08.2026
Status: 08.08.2026 Scope: GDPR Art. 13, 14, Art. 9 GDPR Controller: flowgeist
The Controller within the meaning of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) is:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: info@flowgeist.de Web: https://flowgeist-kita.de
Data Protection Officer: Pursuant to Art. 37 GDPR and § 38 BDSG, no Data Protection Officer has been appointed at this time, as the conditions under § 38 (1) BDSG (as a rule, more than 20 persons engaged in the automated processing of personal data) are not met. Contact person for data protection matters: datenschutz@flowgeist.de (interim).
This Privacy Policy informs about the processing of personal data by the flowgeist KITA platform. The platform serves to manage children’s data, parent communication, and the organization of daycare centers. Particular emphasis is placed on the processing of special categories of personal data pursuant to Art. 9 GDPR, in particular health data and data concerning children as vulnerable persons.
This Privacy Policy is addressed both to the legal guardians and to the daycare staff and the administrators of the platform. Where data of minors is concerned, the rights of the affected children are exercised by their legal guardians.
The flowgeist KITA platform processes special categories of personal data within the meaning of Art. 9 (1) GDPR. These include in particular:
The processing of these special categories of personal data is based on the following legal grounds pursuant to Art. 9 (2) GDPR:
The obtaining and documentation of consents is the responsibility of the respective daycare provider as Controller. flowgeist as Processor processes this data exclusively on the instructions of the Controller.
The platform processes the following categories of personal data:
| Data Category | Description | Affected Persons |
|---|---|---|
| Master data – children | Last name, first name, date of birth, address, gender | Children |
| Master data – parents/legal guardians | Last name, first name, address, phone number, email address | Legal guardians |
| Health data | Allergies, medication plans, chronic illnesses, emergency medication | Children (Art. 9 GDPR) |
| Attendance data | Presence and absence times, drop-off and pick-up times | Children |
| Documents | Care agreements, medication plans, consent declarations | Children, legal guardians |
| Staff data | Name, qualifications, working hours, training | Daycare staff |
| Access data | Password hash (Argon2id), MFA/TOTP secret, email address | All users |
The processing of personal data serves the following purposes:
The processing of personal data is based on the following legal grounds:
Recipients of personal data are:
| Recipient | Location | Function | Third Country |
|---|---|---|---|
| Hetzner Online GmbH | Falkenstein, Germany | Hosting, database, backup | None |
No other recipients are used. In particular, no external analytics or tracking services, no social media plugins, and no external payment providers are used. Redis is operated as an in-memory cache locally on the server and does not constitute an external recipient.
A transfer of personal data to countries outside the European Union or the European Economic Area (third countries) does not take place. All processing operations, including hosting, database, and backup, are carried out in Germany (Hetzner Online GmbH, Falkenstein data center).
The storage duration is determined by statutory retention obligations and contractual requirements. Upon expiry of the respective periods, the data is deleted, unless other statutory retention obligations conflict therewith.
| Data Category | Storage Duration |
|---|---|
| Children’s master data | After end of care + statutory retention period (in particular under KitaG NRW), then deletion |
| Health data | After end of care + statutory retention period, then deletion |
| Attendance data | Current daycare year + previous daycare year, then deletion |
| Staff data | 30 days after the employee’s departure, provided no longer statutory periods apply |
| Audit logs | 3 years from creation, then deletion |
| Documents | In accordance with statutory retention obligations (in particular care agreements, medication plans) |
As a person affected by the processing of personal data, you have the following rights under the GDPR:
10.1 Right of Access (Art. 15 GDPR) You have the right to request from the Controller confirmation as to whether personal data concerning you is being processed. If this is the case, you have the right to access such personal data and to the information set out in detail in Art. 15 (1) GDPR.
10.2 Right to Rectification (Art. 16 GDPR) You have the right to request the immediate rectification of inaccurate personal data concerning you. Furthermore, you have the right to request the completion of incomplete personal data.
10.3 Right to Erasure (Art. 17 GDPR) You have the right to request from the Controller the immediate erasure of personal data concerning you, provided one of the reasons set out in Art. 17 (2) GDPR applies and the processing is not necessary for the exercise of the right to freedom of expression and information, for the fulfillment of a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.
10.4 Right to Restriction of Processing (Art. 18 GDPR) You have the right to request from the Controller the restriction of processing if one of the conditions set out in Art. 18 (1) GDPR is met.
10.5 Right to Data Portability (Art. 20 GDPR) You have the right to receive the personal data concerning you, which you have provided to the Controller, in a structured, commonly used, and machine-readable format, and you have the right to transmit such data to another Controller.
10.6 Right to Object (Art. 21 GDPR) You have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you which is based on Art. 6 (1) lit. f GDPR. The Controller shall no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing serves the establishment, exercise, or defense of legal claims.
10.7 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR) You have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR.
Note regarding children’s data: Where the rights of minors are concerned, requests are submitted by the legal guardians. Identity verification is carried out in accordance with the applicable procedures.
To exercise the rights listed above, you may contact the Controller at any time:
Your request will be processed in accordance with Art. 12 (3) GDPR no later than within one month of receipt. If processing takes longer, you will be informed within one month of the reasons and the expected duration.
Automated decision-making within the meaning of Art. 22 GDPR does not take place. No profiling-based automated procedures are used that produce legal effects concerning data subjects or similarly significantly affect them.
The flowgeist KITA platform uses exclusively technically necessary cookies that are required for the operation of the platform and the maintenance of the session and authentication. The legal basis for this is Art. 6 (1) lit. b GDPR.
No analytics cookies, no tracking cookies, no marketing cookies, and no third-party cookies are used. Cookie data is not shared with third parties.
To protect your personal data, the following technical and organizational measures (TOMs) pursuant to Art. 32 GDPR are employed:
The Controller reserves the right to adapt this Privacy Policy so that it always reflects current legal requirements or changes to the service. The current version is available on the website at https://flowgeist-kita.de. In the event of material changes affecting the processing of personal data, affected users will be informed in advance.
If you have questions regarding data protection, the processing of personal data, or the exercise of your data subject rights, please contact:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: datenschutz@flowgeist.de
If you consider that the processing of your personal data infringes the GDPR, you have the right to contact a data protection supervisory authority. The competent supervisory authority is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Postfach 20 04 44 40102 Düsseldorf Web: https://www.ldi.nrw
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version for flowgeist KITA |
© 2026 flowgeist – Ralf Carsjens · All rights reserved