Privacy Policy
FLOWBRICKS LTD
Last updated: 7 August 2026
1. Controller
The controller responsible for data processing on this website (flowbricks.ltd) within the meaning of the EU General Data Protection Regulation (GDPR) is:
FLOWBRICKS LTD
Registered office: 95 E. Venizelou, Office 102, 8026 Anavargos, Paphos, Republic of Cyprus
Registration number: HE 496317 (Registrar of Companies, Republic of Cyprus)
VAT registration pending
Email: hello@flowbricks.ltd
(hereinafter "FLOWBRICKS", "we", "us", or "our").
2. Data Protection Officer
We have not appointed a Data Protection Officer (DPO). As a small limited company, we are not required to do so under Art. 37 GDPR: our core activities do not consist of regular and systematic large-scale monitoring of data subjects or large-scale processing of special categories of data. For all data protection matters, please contact us at hello@flowbricks.ltd.
3. Overview of Processing Activities
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Website hosting (server logs) | IP address, browser/OS data, requested pages, timestamp | Art. 6(1)(f) GDPR (legitimate interest: secure, stable operation of the website) | Short-term log retention on our EU server; deleted or anonymized thereafter |
| Website analytics (Rybbit, self-hosted) | Aggregated, anonymized usage statistics; cookieless, no personal-data tracking | Art. 6(1)(f) GDPR (legitimate interest, see Section 6) | Aggregated statistics only; no individual profiles |
| Quote request via chat funnel or email | Name, email address, project goals, scope, budget | Art. 6(1)(b) GDPR (pre-contractual measures / contract) | 12 months if no contract results, then deletion; contract data retained per Cyprus statutory/tax retention obligations |
| Newsletter / marketing emails | Name (optional), email address, subscription status | Art. 6(1)(a) GDPR (consent, double opt-in) | Until consent is withdrawn / unsubscribe |
| Client contracts & invoicing | Contact, contract, and billing data | Art. 6(1)(b) and (c) GDPR | Per Cyprus statutory/tax retention obligations |
4. Hosting and Server Location
4.1 The Website is hosted in a data center within the European Union / European Economic Area (EU/EEA). Technical infrastructure and application data, including analytics and chat-funnel data, are stored on our own server infrastructure in the EU.
4.2 When you visit the Website, the hosting server automatically processes connection data (IP address, date and time of access, requested page, browser type and version, operating system) in server log files. This processing is technically necessary to deliver and secure the Website and is based on our legitimate interest in the secure and stable operation of our online presence (Art. 6(1)(f) GDPR).
5. Email Communication
5.1 If you contact us by email, we process the data you provide (email address, name, content of the message) to handle your inquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract) or, for other inquiries, Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
5.2 Our email is operated on our own server / via an EU-based email provider. Emails and their content are not routed through or stored on servers in the United States or other third countries.
6. Website Analytics — Rybbit (Self-Hosted, Cookieless)
6.1 We use Rybbit, a privacy-friendly, open-source web analytics solution, which we operate self-hosted on our own server infrastructure in the EU.
6.2 Rybbit is configured and operated in a cookieless manner: it does not set cookies, does not use fingerprinting, and does not track personal data or create individual user profiles. It produces only aggregated, anonymized usage statistics (e.g., page views, referrer, approximate geography).
6.3 Because the data is processed exclusively on our own EU servers:
- no data is transferred to third countries;
- no third party has access to the analytics data;
- no data is shared with, sold to, or combined with data from advertising networks.
6.4 Legal basis and balancing of interests: processing is based on our legitimate interest under Art. 6(1)(f) GDPR — namely, our interest in understanding aggregate website usage in order to improve our content and offering. We have balanced this interest against your rights and freedoms: because analytics is cookieless, anonymized, aggregated, hosted on our own EU infrastructure, and involves no profiling, tracking across sites, or third-party access, your interests and fundamental rights are not overridden. Due to this privacy-by-design, cookieless setup, no consent (cookie banner) is required for this analytics processing.
7. Quote Request Chat Funnel
7.1 The quote request chat funnel on the Website is self-developed, first-party software; the data you enter is stored exclusively on our own server in the EU and is not transmitted to third parties.
7.2 Data collected: name, email address, project goals, project scope, and budget.
7.3 Legal basis: Art. 6(1)(b) GDPR (processing necessary to take steps at your request prior to entering into a contract). Based on your inquiry, we prepare a written fixed-price quote, normally sent by email within 24 hours.
7.4 Retention: if your inquiry does not result in a contract, the data is deleted after 12 months. If a contract is concluded, the data is retained for the duration of the contractual relationship and thereafter in accordance with Cyprus statutory and tax retention obligations.
8. Newsletter and Marketing Emails
8.1 We offer (or plan to offer) newsletter and marketing emails about our services. Registration takes place only with your consent using the double opt-in procedure: after signing up, you receive a confirmation email and your subscription becomes active only after you click the confirmation link.
8.2 Legal basis: your consent under Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future — for example via the unsubscribe link contained in every email or by emailing hello@flowbricks.ltd. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8.3 We operate our mailing infrastructure tool-neutrally on EU-based systems. Should we engage an external service provider for email delivery, that provider will be named here once operational, and processing will be covered by a data processing agreement under Art. 28 GDPR.
9. Recipients of Data / Third-Country Transfers
9.1 In our current setup, no personal data is transferred to third countries (outside the EU/EEA), and no personal data is disclosed to third parties except where required by law. All processing (hosting, analytics, chat funnel, email) takes place on our own EU infrastructure or with EU-based providers.
9.2 Should this change in the future — for example, if we engage a provider outside the EU/EEA — such transfer will only take place on the basis of an adequacy decision of the European Commission (Art. 45 GDPR) or appropriate safeguards such as EU Standard Contractual Clauses (Art. 46 GDPR), and this Privacy Policy will be updated accordingly.
10. Your Rights as a Data Subject
Under the GDPR, you have the following rights, which you may exercise at any time by contacting hello@flowbricks.ltd:
- Right of access (Art. 15 GDPR) — to obtain confirmation and a copy of your personal data;
- Right to rectification (Art. 16 GDPR) — to have inaccurate data corrected;
- Right to erasure (Art. 17 GDPR) — "right to be forgotten," subject to statutory retention obligations;
- Right to restriction of processing (Art. 18 GDPR);
- Right to data portability (Art. 20 GDPR);
- Right to object (Art. 21 GDPR) — in particular to processing based on Art. 6(1)(f) GDPR;
- Right to withdraw consent (Art. 7(3) GDPR) — at any time, with effect for the future;
- Right not to be subject to automated decision-making (Art. 22 GDPR).
11. No Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
12. Right to Lodge a Complaint
12.1 You have the right to lodge a complaint with a supervisory authority. The competent authority for FLOWBRICKS LTD is:
Office of the Commissioner for Personal Data Protection
1 Iasonos Street, 1082 Nicosia, Republic of Cyprus
Website: www.dataprotection.gov.cy
12.2 Visitors from Germany may alternatively contact the data protection authority (DPA) competent for their place of residence or habitual abode. With regard to cookies and similar technologies, § 25 TDDDG (Telecommunications Digital Services Data Protection Act) applies to German visitors; details are set out in our Cookie Policy.
13. Data Security
We implement appropriate technical and organizational measures under Art. 32 GDPR to protect personal data against unauthorized access, loss, alteration, or disclosure, including encrypted transmission (TLS) and access-restricted, self-hosted EU infrastructure. Given our cookieless analytics and minimal data collection, the amount of personal data at risk is kept deliberately low (data minimization, Art. 5(1)(c) GDPR).
14. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy to reflect changes in our processing activities or legal requirements. The current version, with its date of last update, is always available on this page.