Privacy policy

This privacy policy explains how personal data is processed in the Fangzone application (spec chapter 9, GDPR and Austrian DSG). Fangzone is a business-to-business tool for invited users; there is no public self-registration.

Controller

  • Controller: Asterize e.U., owner Amelie Clement, Vienna, Austria
  • Postal address: see the imprint
  • Email for privacy requests: info@asterize.at

What data we process

  • Account data: email address, password hash, sign-in metadata. Processed to authenticate you and operate your account (Art. 6(1)(b) GDPR).
  • Business contact data you enter: leads, persons, companies, activities, notes, documents and files that you or your team store in your tenant. Processed on behalf of the tenant's business purpose — typically the initiation of business relationships (legitimate interest, Art. 6(1)(f) GDPR) or consent, as recorded per person in the "legal basis/source" field.
  • Technical logs: server logs limited to what is technically necessary (troubleshooting, security), rotated and kept short-term.

Multi-tenancy and access

Data is strictly separated per tenant: every record carries a tenant ID and database row-level security enforces that only members of a tenant can access its data. Files are stored under tenant-scoped paths and served via short-lived signed URLs.

Processors and data location

Your records and files are stored exclusively in the EU. The web application itself is delivered by a US provider, which means that data passes through the USA while a request is being processed:

  • Supabase (database, authentication, file storage) — EU project (Frankfurt, Germany), bound by a data processing agreement. This is the only place where your data is stored persistently.
  • Netlify (web hosting, content delivery and server functions for the app) — Netlify, Inc., USA. The server-side part of the app — the code that renders pages and processes your requests (Netlify Serverless Functions and Edge Functions) — runs in Netlify's US region (Ohio, us-east-2), and the content delivery network serves the app from locations worldwide. The data of a request (what you enter and what is shown to you, plus technical request logs such as IP address, requested URL and time) is therefore processed in the USA in transit; it is not stored there beyond the technical logs. Transfer mechanism: data processing agreement with the EU standard contractual clauses (Art. 46(2)(c) GDPR). Netlify's data processing agreement and GDPR information: https://www.netlify.com/gdpr-ccpa/.
  • IONOS SE (Germany) — sends the app's authentication e-mails (invitations, password reset) from noreply@fangzone.com via the operator's mailbox; mail servers in Germany, bound by a data processing agreement (IONOS data processing agreement: https://www.ionos.de/terms-gtc/avv/, in German; explanation: https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/vereinbarung-zur-auftragsverarbeitung-avv-mit-ionos-abschliessen/).

No data is transferred to third countries without a valid transfer mechanism.

Cookies & storage

Fangzone uses only technically necessary cookies and storage — for the session and your preferences. There is no third-party tracking, no analytics cookies and no advertising, which is why no consent banner is shown. What is stored, exactly:

Name Kind Purpose Lifetime
sb-*-auth-token (one or more) Cookie Supabase authentication session — keeps you signed in For the duration of the session (refreshable)
NEXT_LOCALE Cookie Remembers your language choice (English/German) Browser session
fz-active-tenant Cookie Remembers which tenant you last worked in 1 year

The browser's local storage is not used for tracking; if you install Fangzone as an app (PWA), the browser caches static assets for offline startup only.

Introducing any non-essential cookie or tracker would require an explicit decision by the operator and a consent banner — see the project conventions.

Retention and deletion

Deleted records move to a trash bin (default 30 days) and are then permanently removed, including stored files. Backups rotate out automatically after their retention period. Erasure requests are executed immediately in the production system and the fact of the deletion is logged.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Contact the controller at the address above. You may also lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).

AI features

Fangzone currently contains no AI features. Planned AI features are assistive only, will be clearly labeled, require an explicit user action and human confirmation, and can be disabled per tenant; the provider and model used will be disclosed in the settings. Details: the AI Act readiness notes in the project documentation (docs/ai-act.md).

Changes

This policy is updated when the application's data processing changes. The current version is always available on this page.

Last updated: 18 September 2026.