Last updated: 26 July 2026
This policy applies to the DuetFlow website and early-access list. The DuetFlow app is designed without a DuetFlow account or DuetFlow server; its separate App Store privacy information will describe app processing before release.
1. Controller
The controller for this website is:
Robert OberdorferAsternweg 49
32676 Lügde
Germany
Email: [email protected]
2. Website delivery and security logs
When you open this website, the hosting provider receives technical data needed to deliver and protect it. This may include your IP address, date and time, requested page or file, referrer, browser and operating system information, and the HTTP status code.
We use this data only to deliver the website, maintain stability and security, and prevent abuse. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in operating a secure and reliable website. We do not keep a separate copy of request logs in our database or our own log files. Cloudflare controls any service-side edge and security log retention under its agreement and retains those records only while needed to deliver and protect the service or meet legal obligations.
3. Cloudflare Pages, Functions, and D1
This website, its form processing, and the early-access database run on Cloudflare Pages, Cloudflare Pages Functions, and Cloudflare D1, services of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, with Cloudflare Germany GmbH, Rosenheimer Strasse 143C, 81671 Munich, Germany.
Cloudflare processes website requests and the information described in sections 2, 4, and 7 on our behalf under a data processing agreement based on Article 28 GDPR. Its globally distributed infrastructure may involve processing in the United States. Cloudflare states that it relies on the EU-US Data Privacy Framework and, where required, the European Commission’s Standard Contractual Clauses. Details are available in Cloudflare’s Privacy Policy and Data Processing Addendum.
4. Early-access registration and double opt-in
If you join early access, we process your email address; your selected email scope (private-beta invitations plus launch, or launch only); the required consent wording and version; a separate research-email consent wording and version only if you select it; registration, delivery, and confirmation timestamps; confirmation status; and a short campaign label from a same-site ref link if one was used. We never store the full referring URL. We also keep one-way hashes of the random confirmation token and the signed unsubscribe token, plus the delivery provider and its message identifier. The signed unsubscribe token can be recreated for future emails without storing it in readable form.
We send one confirmation email and add you to the list only after you explicitly confirm on the linked page. Private-beta and launch updates are one selectable purpose; launch-only updates are a narrower alternative. Permission to email product-research questions is separate and optional. The legal basis for each selected email purpose is your consent under Article 6(1)(a) and Article 7 GDPR. The email-preferences link in every update lets you turn off research questions while keeping your selected early-access updates, or withdraw all email consent. You can also withdraw consent through the contact form or by emailing [email protected]. Withdrawal does not affect processing that was lawful before withdrawal.
For abuse prevention, a keyed one-way hash of the requesting IP address is kept in an hourly rate-limit bucket for no longer than 24 hours. The raw IP address is not stored in the early-access database. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in protecting the forms and email infrastructure from automated abuse.
Unconfirmed registrations are deleted within 14 days after the confirmation email is sent. Confirmed registration data is kept until you withdraw consent or the early-access purpose ends, and never longer than 12 months after the last early-access email. If you turn off research emails only, the active research-email consent fields are cleared while your selected early-access updates remain active. If you unsubscribe from all emails, your email address and optional answers are removed without undue delay. A pseudonymous consent and withdrawal record may be kept for up to three years under Article 6(1)(f) GDPR so we can demonstrate compliance and defend legal claims.
5. Email delivery through Resend
Confirmation, early-access, and contact-form emails are delivered through Resend, operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. Depending on the message, Resend receives the early-access recipient’s email address or the contact-form visitor’s email address as the reply-to address, the email content, and technical delivery information such as delivery, bounce, and complaint events.
Resend processes this data on our behalf under its Data Processing Addendum. Processing may take place in the United States; Resend’s DPA incorporates the European Commission’s Standard Contractual Clauses for transfers that require them. Resend retains delivery and security data only as long as needed for the service, security, and legal obligations described in its agreement and policy. More information is available in Resend’s Privacy Policy, Data Processing Addendum, and subprocessor list.
6. Optional product-research answers
After confirmation, you may optionally tell us which task system you use, which coordination problem matters most, which devices both of you use, whether both of you would try one shared system for a week, and whether the planned one-time price feels reasonable. These answers are linked to your early-access registration so we can decide whom the product helps and what to test first. Leaving any or all answers blank has no effect on your registration. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in validating the product with people who voluntarily choose to answer. You may object at any time, and the deletion and retention rules in section 4 apply.
7. Contact messages
If you use the contact form, we process your email address and message; your name is optional. We use the information only to answer and handle your request. The legal basis is Article 6(1)(b) GDPR where your message concerns steps before a contract, and otherwise Article 6(1)(f) GDPR: our legitimate interest in responding to enquiries and keeping a record of the response.
The form is processed by Cloudflare and sent through the active email delivery provider named in section 5 to our mailbox at Posteo in Germany. We do not store the name, email address, or message in D1. The message and normal email metadata remain in the delivery systems and our mailbox. We delete the mailbox copy no later than six months after the request is resolved unless a longer statutory retention period or an ongoing legal claim requires it.
8. Information you must provide
Joining early access is voluntary. An email address, one early-access email scope, the required consent, and double-opt-in confirmation are necessary for us to add you to the list; without them, we cannot send the requested updates. Research-email consent and all product-research answers are optional. For the contact form, an email address and message are necessary so we can receive and answer the request; a name is optional.
9. No advertising or behavioural tracking
This website does not intentionally set cookies or use browser storage, load advertising, run third-party analytics scripts, fingerprint devices, or embed third-party fonts, videos, or social widgets. Form submissions are handled directly by our Cloudflare-hosted endpoint. Cloudflare may set a strictly necessary security cookie if its network presents a security challenge. We do not use that cookie for analytics or advertising. No consent banner is required because the website does not store or access non-essential information on your device; strictly necessary security storage is covered by section 25(2) TDDDG.
10. Direct marketing and your right to object
Early-access messages are sent only after consent and double opt-in. You may withdraw that consent at any time. Where processing is based on legitimate interests, you may object for reasons relating to your particular situation under Article 21 GDPR. You may object to direct marketing at any time without giving reasons; we will then stop using your data for that purpose.
11. Your rights
Subject to the legal requirements, you may request access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), or object to processing (Article 21). You may also withdraw consent at any time under Article 7(3). Contact the controller in section 1 to exercise these rights. We do not use automated decision-making or profiling that produces legal or similarly significant effects.
12. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority under Article 77 GDPR. The authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-WestphaliaKavalleriestrasse 2–4
40213 Düsseldorf
Germany
13. Changes to this policy
We update this policy when the website’s processing changes. The version and date shown above apply.