Privacy policy
This privacy policy explains how personal data is processed in the Fangzone application (spec chapter 9, GDPR and Austrian DSG). Fangzone is a business-to-business tool for invited users; there is no public self-registration.
Controller
- Controller: Asterize e.U., owner Amelie Clement, Vienna, Austria
- Postal address: see the imprint
- Email for privacy requests: info@asterize.at
What data we process
- Account data: email address, password hash, sign-in metadata. Processed to authenticate you and operate your account (Art. 6(1)(b) GDPR).
- Business contact data you enter: leads, persons, companies, activities, notes, documents and files that you or your team store in your tenant. Processed on behalf of the tenant's business purpose — typically the initiation of business relationships (legitimate interest, Art. 6(1)(f) GDPR) or consent, as recorded per person in the "legal basis/source" field.
- Technical logs: server logs limited to what is technically necessary (troubleshooting, security), rotated and kept short-term.
Multi-tenancy and access
Data is strictly separated per tenant: every record carries a tenant ID and database row-level security enforces that only members of a tenant can access its data. Files are stored under tenant-scoped paths and served via short-lived signed URLs.
Processors and data location
Your records and files are stored exclusively in the EU. The web application itself is delivered by a US provider, which means that data passes through the USA while a request is being processed:
- Supabase (database, authentication, file storage) — EU project (Frankfurt, Germany), bound by a data processing agreement. This is the only place where your data is stored persistently.
- Netlify (web hosting, content delivery and server functions for the app) — Netlify, Inc., USA. The server-side part of the app — the code that renders pages and processes your requests (Netlify Serverless Functions and Edge Functions) — runs in Netlify's US region (Ohio, us-east-2), and the content delivery network serves the app from locations worldwide. The data of a request (what you enter and what is shown to you, plus technical request logs such as IP address, requested URL and time) is therefore processed in the USA in transit; it is not stored there beyond the technical logs. Transfer mechanism: data processing agreement with the EU standard contractual clauses (Art. 46(2)(c) GDPR). Netlify's data processing agreement and GDPR information: https://www.netlify.com/gdpr-ccpa/.
- IONOS SE (Germany) — sends the app's authentication e-mails
(invitations, password reset) from
noreply@fangzone.comvia the operator's mailbox; mail servers in Germany, bound by a data processing agreement (IONOS data processing agreement: https://www.ionos.de/terms-gtc/avv/, in German; explanation: https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/vereinbarung-zur-auftragsverarbeitung-avv-mit-ionos-abschliessen/).
No data is transferred to third countries without a valid transfer mechanism.
Cookies & storage
Fangzone uses only technically necessary cookies and storage — for the session and your preferences. There is no third-party tracking, no analytics cookies and no advertising, which is why no consent banner is shown. What is stored, exactly:
| Name | Kind | Purpose | Lifetime |
|---|---|---|---|
sb-*-auth-token (one or more) |
Cookie | Supabase authentication session — keeps you signed in | For the duration of the session (refreshable) |
NEXT_LOCALE |
Cookie | Remembers your language choice (English/German) | Browser session |
fz-active-tenant |
Cookie | Remembers which tenant you last worked in | 1 year |
The browser's local storage is not used for tracking; if you install Fangzone as an app (PWA), the browser caches static assets for offline startup only.
Introducing any non-essential cookie or tracker would require an explicit decision by the operator and a consent banner — see the project conventions.
Retention and deletion
Deleted records move to a trash bin (default 30 days) and are then permanently removed, including stored files. Backups rotate out automatically after their retention period. Erasure requests are executed immediately in the production system and the fact of the deletion is logged.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Contact the controller at the address above. You may also lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).
AI features
Fangzone currently contains no AI features. Planned AI features are
assistive only, will be clearly labeled, require an explicit user action and
human confirmation, and can be disabled per tenant; the provider and model
used will be disclosed in the settings. Details: the AI Act readiness notes
in the project documentation (docs/ai-act.md).
Changes
This policy is updated when the application's data processing changes. The current version is always available on this page.
Last updated: 18 September 2026.