Privacy statement
What flokpit.ai and the waitlist store, and why.
This statement covers the website flokpit.ai and the flokpit waitlist at waitlist.flokpit.ai. The controller is Dennis Jöst, address in the imprint; reach us at honk@flokpit.ai.
Visiting flokpit.ai
- Delivery: the pages are delivered by the content delivery network of BunnyWay d.o.o., Ljubljana, Slovenia (bunny.net), from the edge server nearest to you. Like every web server it processes your IP address, the requested page, the time and your browser's identification, and keeps access logs briefly to run the service and fend off abuse (Art. 6(1)(f) GDPR). No cookies, no analytics, no tracking.
- Fonts and scripts: everything the pages need is served from our own domains; nothing is loaded from Google or other third parties.
- Waitlist counter: the page asks the waitlist service how many people are on the list (no personal data). If you are signed in to the waitlist, it also shows your place, using the waitlist's session cookie; flokpit.ai and waitlist.flokpit.ai are one site.
What we store when you join the waitlist
- From your public GitHub profile: your GitHub user id, login, display name and avatar URL.
- About the waitlist: the time you joined (your place in the line follows from it), the time of your last login, and a session cookie so you stay signed in.
- Only with your opt-in: the primary email address of your GitHub account. We then ask GitHub for the
user:emailpermission; without the opt-in the login requests no permission at all and we never see an address. We record when you gave the opt-in. - Server logs: the server notes when a login joins or leaves the list, and keeps the usual technical access logs. They serve operations and security only, are rotated automatically within days and are never combined with your entry for any other purpose.
What we use it for
- Keeping the waitlist: your place in the line, the early-access seats and the free production months for the first 100.
- Letting you know when flokpit launches and when your early access is ready. Without a shared email we do this through GitHub only.
- Nothing else: no newsletter, no profiling, no automated decisions, no advertising, and we never sell or share the list.
Where the data is processed, and who sees it
- Hosting: the waitlist runs on a Kubernetes cluster rented from Rackspace Technology (Rackspace Spot) in a data centre in London, United Kingdom, a country the EU recognises as providing adequate data protection. Rackspace processes the data on our behalf as a processor.
- Backup copy: the list (login, GitHub id, join time, early-access status and, with your opt-in, the email address and consent time) is mirrored to a private storage zone of bunny.net (BunnyWay d.o.o., Slovenia) in Falkenstein, Germany, so it survives the cluster. Display names and avatars are not part of it.
- GitHub: GitHub, Inc. (USA, certified under the EU-US Data Privacy Framework) handles the login under its own privacy statement and learns that you signed in to flokpit. We drop the access token right after reading your profile.
- Only the flokpit operator sees the list. No other recipients.
Legal basis and your choices
- The waitlist entry itself is based on your request to join (Art. 6(1)(b) GDPR); the email address on your consent (Art. 6(1)(a) GDPR); the logs and the delivery of the pages on our legitimate interest in running the site securely (Art. 6(1)(f) GDPR). The two cookies are strictly necessary for the service you asked for (§ 25(2) TDDDG), so there is no cookie banner.
- You can withdraw the consent at any time with Stop sharing on the waitlist page: the address is deleted immediately and your place is kept. Withdrawing does not affect the lawfulness of the processing before it.
- Leave the waitlist deletes your whole entry, including the backup copy at the next sync. Signing in with GitHub again later puts you at the end of the line.
- You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability and to complain to a supervisory authority, for example the data protection authority of the German federal state you live in. Mail honk@flokpit.ai for anything the buttons do not cover.
Retention
Waitlist entries are kept until you leave, or until the waitlist is closed after the launch and everyone on it has been onboarded or informed; shared email addresses are deleted at the latest then. Sessions expire after 30 days.
Cookies
Two first-party cookies only: a short-lived one that protects the GitHub login (10 minutes) and the session cookie (30 days). No analytics, no third-party cookies.