KORTHEXkorthex.io

Privacy Policy for Korthex

This product-specific Privacy Policy supplements the general Privacy Policy of Flowence Infrastructure, available at https://flowencehq.com/privacy. It explains how personal data is processed in connection with the Korthex software and the website korthex.io.

1. Controller and Data Protection Officer

The controller responsible for the processing of personal data within the meaning of Article 4(7) of the General Data Protection Regulation (“GDPR”) is:

  • Flowence Infrastructure
  • Owner: Hendrik Schneider
  • Address: Berghäuserstr. 105, 45663 Recklinghausen
  • Email: contact@flowencehq.com
  • Web: flowencehq.com / korthex.io

You may contact us at any time using the contact details above if you have questions about the processing of your personal data, wish to exercise your data subject rights, or have other privacy-related concerns.

Korthex is available under several domains. This Privacy Policy applies uniformly to all domains listed below; the controller is in all cases the entity named above. Responsibility is not divided by domain.

The domains korthex.io and korthex.io designate the same offering in different language versions. Links within this Privacy Policy lead to the domain through which you accessed this page. The domain flowencehq.com is the corporate website of Flowence Infrastructure; it contains company information and a general privacy policy that applies in addition. Technical subdomains, in particular api.korthex.flowence.cc for programming interfaces and license services and cl.korthex.flowence.cc for the delivery of program versions, are addressed exclusively by the software and not by a page request in a browser.

A Data Protection Officer has not currently been appointed. A legal obligation to appoint a Data Protection Officer exists only where the requirements of Article 37(1) GDPR or Section 38 of the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG) are met. Under Article 37(1) GDPR, these are processing by a public authority or body (point (a)), large-scale regular and systematic monitoring of data subjects as a core activity (point (b)), and large-scale processing of special categories of personal data or of data relating to criminal convictions and offences as a core activity (point (c)). Section 38 BDSG adds certain processing activities and the regular employment of at least 20 persons engaged in the automated processing of personal data.

Based on our assessment, these requirements are not currently met. In particular, the processing of device references for license enforcement and of connection data of the Mesh Networking feature is limited in scope and purpose to the performance of the contract and the prevention of misuse, and does not constitute monitoring of data subjects as a core activity.

We review this assessment at least once a year and on an ad hoc basis, in particular where the device binding, the Mesh Networking feature, telemetry, or user numbers are materially extended. If an obligation to appoint a Data Protection Officer arises in the future, or if a Data Protection Officer is appointed voluntarily, their contact details will be published here.

2. Subject Matter, Scope and Principles of Processing

Korthex is a desktop application with an offline-first architecture. The core purpose of the software is the local analysis of source code. Source code, binary files, local analysis results, and comparable content are generally processed on the User’s device and are not automatically transmitted to us.

Personal data may be transmitted to us, in particular, when you use the website, create or manage a user account, activate a license, request support, obtain updates, expressly activate an optional online, telemetry, error-reporting, support, or integration feature, or otherwise communicate with us. The data processed in each case depends on the service used and the processing purposes described in this Privacy Policy.

Optional features within the meaning of the preceding paragraph are disabled in their delivered state and take effect only after you have expressly activated them. Activating such a feature constitutes consent to the processing associated with it. This is to be distinguished from sending individual information on a case-by-case basis, such as attaching a log file to a support request; such a transmission is made for a specific occasion and does not constitute a permanent activation. The available consent levels and the data covered by each are described in detail in Section 5.

Not every processing activity is based on consent. Processing that is necessary to provide the service you have requested is based on Article 6(1)(b) GDPR; no separate consent is required for this and none is obtained. This applies in particular to license activation and recurring license validation, including the device reference generated for that purpose.

The device reference is derived from several hardware characteristics during activation and periodic license validation and is processed exclusively in the form of one-way hash values. It serves license administration, device binding, and the detection of impermissible multiple activations. The purpose, legal basis, characteristics processed, times of processing, and retention period are described in detail in Sections 3, 5, and 8. The procedures governed by the Terms of Use for Korthex apply to deactivating a device, changing devices, and deleting the device reference.

We process personal data exclusively in accordance with applicable data protection law, in particular the GDPR and the German Federal Data Protection Act. In doing so, we observe the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality under Article 5(1) GDPR.

We collect and process only personal data necessary for the relevant purpose. Where consent is required for processing, we obtain it before processing begins. You may withdraw your consent at any time with effect for the future; this does not affect the lawfulness of processing carried out before withdrawal. Withdrawal is possible through the relevant setting in the software or using the contact details stated above and is not subject to any particular form.

Whether providing data is required and what follows from not providing it: You are generally under no statutory obligation to provide us with personal data. For individual services, however, the provision of certain data is required by contract or necessary in order to enter into a contract; without that data we cannot provide the service concerned.

The following are required in particular: an email address and a password, or a third-party login, in order to set up and use a user account; the license key and the device reference derived from hardware characteristics in order to activate and recurrently validate paid licenses; billing, tax, and payment data in order to conclude and perform paid contracts and to comply with tax retention obligations. If that data is not provided, a user account, a license activation, or a paid contract cannot be created or continued.

By contrast, no data is required in connection with optional features, in particular telemetry, crash reports, Mesh Networking, and ticket integrations. Not providing such data, or withdrawing consent, has no effect on the existence of the contract or on the usability of the remaining features; you will suffer no disadvantage as a result.

We process personal data only where a legal basis applies. Depending on the processing activity, we rely in particular on Article 6(1)(b) GDPR for the performance of a contract or pre-contractual measures, Article 6(1)(c) GDPR for compliance with a legal obligation, Article 6(1)(f) GDPR for the purposes of legitimate interests, or Article 6(1)(a) GDPR where you have given consent.

Where we process data on the basis of legitimate interests, these interests include the secure, efficient, and needs-based provision of Korthex, the prevention of misuse and attacks, the enforcement of our legal claims, and the improvement of our services. You have the right to object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR.

For every processing activity we base on Article 6(1)(f) GDPR, we carry out a documented balancing of our legitimate interests against your interests, fundamental rights, and freedoms, and record the outcome in writing as part of our accountability obligation under Article 5(2) GDPR. Upon request, we will provide you with a summary of the considerations relevant to you. We will submit the documentation to the competent supervisory authority upon request.

The following sections provide further information on the specific purposes, categories of data typically processed, and applicable legal bases.

  • Providing, operating, and technically securing the Korthex software and the website korthex.io, in particular under Article 6(1)(b) and (f) GDPR
  • Creating and managing user accounts, in particular under Article 6(1)(b) GDPR
  • License activation, recurring license validation, and device binding, including the generation and matching of a device reference derived from hardware characteristics in the form of one-way hash values, in particular under Article 6(1)(b) GDPR; details of the characteristics processed and the times of processing are set out in Section 5
  • Detecting impermissible multiple activations and enforcing the contractually agreed license scope on the basis of the device reference, the activation history, and associated technical metadata, in particular under Article 6(1)(f) GDPR
  • Processing orders, payments, invoices, refunds, and contractual communications, in particular under Article 6(1)(b) and (c) GDPR
  • Providing technical support, handling enquiries, and communicating with Users, in particular under Article 6(1)(b) or (f) GDPR
  • Providing software updates, security patches, model updates, and important product-related information, in particular under Article 6(1)(b) and (f) GDPR
  • Detecting, investigating, and preventing misuse, fraud, security incidents, and license violations, in particular under Article 6(1)(f) GDPR and, where necessary, Article 6(1)(c) GDPR
  • Operating the Mesh Networking feature after express activation, in particular under Article 6(1)(b) GDPR for providing the feature and Article 6(1)(f) GDPR for the security of the transmission path
  • Improving the detection logic, functionality, security, and usability of our software and website, based on Article 6(1)(a) GDPR for consent-based telemetry and otherwise, where necessary, on Article 6(1)(f) GDPR
  • Complying with statutory retention, documentation, and tax obligations, in particular under Article 6(1)(c) GDPR
  • Establishing, exercising, or defending legal claims and enforcing our Terms of Service, in particular under Article 6(1)(f) GDPR

In the course of detecting and investigating misuse, fraud, security incidents, and license violations, we process in particular IP addresses, the device reference derived from hardware characteristics, license and activation metadata, timestamps, operating system type, software version, and a flag for detecting virtualised environments. We do not derive fine-grained location data from IP addresses for these purposes; any evaluation takes place at country level at most. We do not create movement, location, or behavioural profiles.

No decision based solely on automated processing producing legal effects or similarly significant effects is taken in the course of this processing; see Section 10 on this and on your right to object. See Section 6 regarding the handling of special categories of personal data within the meaning of Article 9 GDPR.

To improve the detection logic, we use exclusively data from consent-based telemetry and from error reports, and only where you have activated the relevant feature. Only categorical values from a fixed, predefined vocabulary and technical metrics are processed, such as the type of a detected cryptographic category, coarsely banded quantity indications, and runtime and error metrics.

Source code, file names, file paths, project designations, specific algorithm strings from your code, and the content of individual analysis results are not used to improve the detection logic and are not transmitted to us. Analysis results, inventories, reports, and migration plans are not used for training or adapting models. Detection patterns derived from a particular customer project are not passed on to other Users.

The telemetry data processed in accordance with the preceding paragraphs therefore does not contain confidential information within the meaning of the confidentiality provisions of the Terms of Use for Korthex. In addition to this assurance, you may disable telemetry at any time; the individual consent levels, the events recorded in each case, and the data expressly not recorded are described exhaustively in Section 5.

Personal data is processed on the basis of the following legal bases under the GDPR:

Article 6(1)(a) GDPR (consent): Where you have given us consent to process personal data for specific purposes, processing is carried out on the basis of that consent. You may withdraw your consent at any time with effect for the future.

Article 6(1)(b) GDPR (performance of a contract): Processing is necessary for the performance of the agreement governing the use of Korthex or for taking steps prior to entering into a contract at your request.

Article 6(1)(c) GDPR (legal obligation): Processing is necessary for compliance with a legal obligation to which Flowence Infrastructure is subject, in particular tax-related retention obligations under Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code.

Article 6(1)(f) GDPR (legitimate interests): Processing is necessary for the purposes of the legitimate interests pursued by Flowence Infrastructure or a third party, except where the interests or fundamental rights and freedoms of the data subject which require protection of personal data override those interests. Legitimate interests include in particular protection against misuse, ensuring IT security, and improving our services.

Each individual processing activity is based on exactly one legal basis. Where several legal bases are stated for one purpose, each reference relates to a different part of the processing and not to the same processing on an alternative basis. For example, the provision of software updates is based on Article 6(1)(b) GDPR in so far as it concerns the contractually owed updating of your installation, and on Article 6(1)(f) GDPR in so far as it concerns the distribution of security-related fixes and the secure operation of the delivery infrastructure.

We do not rely on several legal bases in the alternative for the same part of a processing activity. In particular, where we have obtained your consent for a processing activity, we do not rely on legitimate interests in the alternative if you do not give that consent or withdraw it. If you withdraw consent, the processing concerned is discontinued.

The rights available to you depend on the applicable legal basis. Where processing is based on Article 6(1)(a) GDPR, you have the right to withdraw consent under Article 7(3) GDPR. Where processing is based on Article 6(1)(f) GDPR, you have the right to object under Article 21 GDPR. Where processing is based on Article 6(1)(b) or (c) GDPR, there is neither a right of withdrawal nor a right to object; the rights under Articles 15 to 20 GDPR remain unaffected in all cases. Details are set out in Section 10.

The legal basis applicable to a specific processing activity is stated where that processing is described: Section 5 for the software’s network activities, Section 6 for the individual categories of data, and Section 8 for retention periods. Where the information in Section 5 or Section 6 differs from the general information in Section 3 or in this Section, the information given there, which relates to the specific processing activity, prevails.

5. Data Processed When Using the Software

Korthex is designed as an offline-first desktop application. Source code, binary files, project files, local analysis results, and other content analysed by the User are generally processed locally on the User’s device and are not automatically transmitted to Flowence Infrastructure.

Certain features may transmit personal data or technical information over a network. This applies in particular to license management, optional updates, voluntarily activated telemetry, voluntarily activated mesh networking features, voluntary crash reports, and third-party integrations expressly configured by the User.

The following overview explains the individual network activities, the respective categories of processed data, the time of transmission, and the available deactivation options. Where processing is required to provide a paid plan or an expressly requested feature, it is carried out on the basis of Article 6(1)(b) GDPR. Where we process data to ensure security, prevent misuse, or maintain stability, processing is based on Article 6(1)(f) GDPR. We process voluntary telemetry data exclusively on the basis of your consent pursuant to Article 6(1)(a) GDPR.

ActivityDataWhenCan be disabled
License activation and validationLicense key, email address, a device reference derived from multiple hardware characteristics in the form of SHA-256 one-way hashes, virtual-machine detection flag, IP address, operating system type, and software version. The device reference is used for license management, device binding, and the detection of misuse and multiple activations.During initial activation, when changing devices, and during periodic license validation. Paid plans may be used offline for up to seven days.No, insofar as processing is required for activation, validation, and management of paid licenses. Without license validation, paid features may be unavailable or only available on a limited basis.
Mesh networkingEncrypted relay data, technical connection data, IP addresses of participating nodes, and connection metadata. Analysis metadata may contain personal data where it can be linked to an identified or identifiable natural person. Source code content is not transmitted under the intended functionality.Exclusively during a mesh-networking session activated by the User.Yes. The feature is disabled by default and requires explicit activation.
Model updates and update checksCurrent model version, software version, operating system type, and technical information concerning the success or failure of an update check. No source code content or local analysis results are required for update checks.During a manual update check or an automatic check, where automatic updates are enabled.Yes. Automatic update checks and automatic updates can be disabled in the settings. Manual update checks remain available upon the User’s express request.
Crash reportsStack traces, software and operating system versions, error context, log excerpts cleansed of detected secrets, and, where applicable, a memory dump (minidump). In rare cases, a minidump may contain personal data. Any possible User or device reference is transmitted only in hashed form. Under the intended configuration, neither source code nor analysis results are transmitted.Only when the software crashes and only where the User has enabled crash reports.Yes. Crash reports can be disabled under `privacy.crashReportsEnabled` and are disabled by default.
Desktop telemetry and usage analyticsData-minimised event data relating to the use, performance, and stability of the application. Numerical values are grouped into fixed ranges, such as scan duration or number of processed files. No source code content, file names, file paths, project or solution names, license keys, email addresses, stack traces, or specific algorithm strings from analysed code are transmitted. IP addresses are not stored for telemetry purposes under the intended architecture; however, short-term technical processing may be necessary when establishing a network connection.Only when telemetry is enabled during use of the desktop application. Events are bundled and transmitted hourly by default to `api.global.korthex.io`.Yes. Telemetry is disabled by default and is enabled only following express consent under Settings > General > Analytics. Consent may be withdrawn at any time through the same setting.
Support and ticket system in the user accountKorthex provides its own support and ticket system within the user account, operated by Flowence Infrastructure. We process the information you enter, in particular the subject, category, priority, message texts, file attachments, status history, timestamps, and an optional satisfaction rating once the matter has been closed. No transmission to a third-party system takes place in this context.When you create, reply to, or open a ticket in the user account.Using the ticket system is voluntary. If you do use it, processing the information you enter is necessary in order to handle your request. You may alternatively contact us using the contact details stated in Section 1.
Ticket integrations with third-party systems (InterfaceEngine)When an integration is enabled, analysis results may be transmitted to a third-party system configured by the User. This may include severity, algorithm, file path, line number, code excerpt, recommendation, and, where applicable, CVE or CVSS information. Depending on the content, this data may include personal data, trade secrets, or confidential information.Exclusively after the User activates the integration and grants additional project-specific approval.Yes. Integrations are disabled by default and may be disabled globally or for individual projects.
Known data-breach checkNeither a password, nor a password hash, nor any part thereof leaves the device. The software merely downloads a verification dataset in the form of a Bloom filter from the Korthex backend and performs the comparison entirely locally on the device. Technical connection data, in particular IP address and timestamps, may be processed when retrieving the dataset; it does not permit any inference about a checked input, because the retrieval takes place independently of any specific check. By design, a Bloom filter can produce false positives; a hit therefore only means that the input may be contained in the breach collection. Even in the event of a hit, no follow-up query, confirmation request, or other online check is sent to our servers or to third parties. The result is determined exclusively locally.Only when using the optional feature to compare inputs against known data breaches.Yes. This feature is optional and may be disabled.

The User’s source code is not transmitted to Flowence Infrastructure servers or third parties unless the User activates a feature whose purpose specifically requires the transmission of certain content. This may apply in particular to ticket integrations with third-party systems. Before activating such an integration, Korthex indicates which data categories may be transmitted to the configured third-party system.

The support and ticket system provided within the user account is to be distinguished from this. It is operated by Flowence Infrastructure itself; we are the controller within the meaning of Article 4(7) GDPR for that purpose. No transmission to a third-party system takes place in that context.

In the case of ticket integrations with third-party systems, you determine which target system is connected, which projects are released, and which content is transmitted. You or the operator of the target system are responsible for the processing within the target system; we have no influence over it and receive no data from it. For the transmission itself, we act on your instructions and exclusively within the scope of your configuration; the content, format, recipient, and timing of the transmission follow from your settings and your project-specific approval.

Should we, in an individual case, jointly determine the purpose or means of such a transmission, for example because we determine the content or timing beyond your configuration, the allocation of roles is governed by Article 26 or Article 28 GDPR. In that case we will conclude the required agreement with you before the relevant processing begins and make its essential content available to you. Section 7 of the Terms of Use applies in addition.

Analysis results leave the User’s device through the mesh-networking functionality only where the User has expressly enabled that feature. The transmission is encrypted. The User remains responsible for ensuring that they are authorised to transmit the relevant data and to include the respective network participants.

Where data is transferred to recipients outside the European Economic Area, we provide information in the relevant sections of this Privacy Policy concerning the third country, the recipient, and appropriate safeguards for the transfer under Articles 44 et seq. GDPR.

We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised disclosure, alteration, and destruction. The specific measures are regularly reviewed and adjusted, taking into account the state of the art, the nature, scope, context, and purposes of processing, as well as the respective risks.

6. Categories of Data

In connection with the use of Korthex and the website korthex.io, we process the categories of personal data described below. The data processed in each case depends on the features you use, the plan you have subscribed to, and whether you activate optional features, including telemetry, crash reports, mesh networking, or third-party integrations.

We process personal data only where this is necessary for the relevant purpose and a legal basis pursuant to Article 6 GDPR applies. The following overview identifies the categories of data typically processed and the legal bases that regularly apply. Multiple legal bases may apply concurrently in individual cases.

CategoryData
Master data and account dataName, email address, company or organisation, where provided, user identifier, account status, subscribed license or plan type, language settings, and dates of account creation and account administration.
Billing and transaction dataBilling address, invoice number, ordered products or plans, payment status, payment references, tax information, and VAT identification number, where provided or legally required. Complete payment data, such as card numbers, is processed directly by the payment service provider under the intended payment process and is not stored by Flowence Infrastructure.
License and activation dataLicense key, license status, license plan, activation date, software version, a device reference derived from multiple hardware characteristics in the form of separate SHA-256 one-way hashes, virtual-machine detection flag, and technical information for device binding and license validation. Depending on the technical configuration, input values may include SMBIOS or mainboard identifiers, CPU identifiers, storage-device serial numbers, MAC addresses, and the computer name.
Technical connection and security dataIP address, time and duration of a connection, operating system type and version, software version, technical log data, HTTP status codes, requested endpoints, error codes, information relating to update or license checks, and security and misuse signals.
Communication and support dataContents of email correspondence, contact enquiries, support tickets, feedback, communicated contact details, information relating to the license or account, and voluntarily submitted attachments, logs, or screenshots.
Website and API server log dataTechnically required server log data, in particular IP address or truncated IP address, date and time of access, requested resource or API endpoint, HTTP method, HTTP status code, transmitted data volume, referrer URL where transmitted, and browser or client information where technically available. Under the intended configuration, the website does not use external tracking or audience measurement services.
Crash report dataStack traces, software version, operating system version, error context, cleansed log excerpts, and, where applicable, a memory dump (minidump). In rare cases, a minidump may contain personal data. Under the intended configuration, source code and analysis results are not transmitted.
Telemetry and usage dataData-minimised event data relating to application usage, scan performance, stability, feature use, and configuration. Numerical values are grouped into fixed ranges. A weekly rotating installation token, session IDs, and event IDs may be processed. No source code content, file names, file paths, IP addresses for telemetry purposes, stack traces, license keys, email addresses, or specific algorithm strings from analysed code are transmitted. The detailed schema is documented at https://schemas.korthex.io/telemetry/event/v1.1.0.json.
Mesh networking and relay dataEncrypted relay data, IP addresses of participating nodes, connection times, connection status, and technical connection metadata. Analysis metadata may contain personal data where it can be linked to identified or identifiable persons. Source code content is not transmitted under the intended functionality.
Data from ticket integrationsWhere ticket integrations are activated, analysis results may be transmitted to a third-party system configured by the User. This may include severity, algorithm, file path, line number, code excerpt, recommendation, and, where applicable, CVE or CVSS information. Such data may contain personal data, trade secrets, or other confidential information.
Third-party login dataWhen optionally signing in through Google or GitHub, we may process profile data released by the respective provider for authentication purposes, including a unique provider identifier, display name, email address, and information about the authentication time. The exact scope depends on the permissions granted to the provider.

Where you voluntarily provide special categories of personal data within the meaning of Article 9(1) GDPR, for example in a support ticket or attachment, we process such data only where necessary to handle your request and where legally permitted. Please provide such data only where strictly necessary.

We use telemetry and crash report data exclusively for the purposes set out in Section 3, in particular to improve the detection logic, stability, and usability, and only where you have activated the relevant feature. Only categorical values from a fixed vocabulary and technical metrics are used to improve the detection logic, and not content from analysed source code or from analysis results. We do not use telemetry or crash report data to build user profiles, for advertising purposes, or to evaluate individual persons.

We do not process data from source code, analysis results, or ticket integrations for our own training, profiling, or advertising purposes. Processing takes place exclusively to the extent required by the feature activated by the User.

The telemetry installation token is generated locally on the device and is not linked to any user account, license key, or email address. We do not maintain a server-side mapping table between the installation token and account, license, or billing data. Within a rotation period of one week, telemetry events from the same installation can be related to one another; beyond the point of rotation, no such attribution is possible. See Section 8 regarding retention.

The use of a hash value or rotating identifier does not necessarily mean that data can no longer be linked to a person. We therefore treat such identifiers as privacy-relevant technical data where association with a person or device cannot be excluded with sufficient certainty.

7. Recipients, Service Providers and Processors

We transfer personal data only where this is necessary for the purposes described in this Privacy Policy, where a legal basis exists, and where the transfer is permissible under data protection law. Recipients may be processors, independent controllers, joint controllers, or other third parties.

Where service providers process personal data exclusively on our behalf and in accordance with our documented instructions, we engage them as processors pursuant to Article 28 GDPR. Where service providers independently determine the purposes and means of processing, in particular due to their own legal obligations, they act as independent controllers. The precise data protection role may vary depending on the service used.

  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]

Where service providers process personal data on our behalf, we enter into data processing agreements pursuant to Article 28 GDPR where legally required. These agreements require service providers, in particular, to process data in accordance with documented instructions, maintain confidentiality, implement appropriate security measures, and assist with the exercise of data subject rights.

The preceding paragraphs concern our role as controller vis-à-vis our own service providers. This is to be distinguished from the reverse constellation, in which we process personal data on behalf of a User.

Where you use Korthex to process personal data of third parties, such as data of your employees, customers, or project participants, and you determine the purposes and means of that processing, you are the controller and we are the processor under Article 28 GDPR in that respect. This may concern in particular analysis results, support content, and content transmitted through activated online features, in so far as such content contains personal data.

Whether such processing on your behalf exists depends exclusively on the specific processing activity and not on the plan you have subscribed to. The entitlement to conclude a data processing agreement applies irrespective of the plan; we will provide you with a template free of charge upon request. Details, including the applicable periods, are governed by Section 7 of the Terms of Use for Korthex.

Because of the offline-first architecture of Korthex, we do not process source code or complete analysis results in regular operation. Processing on your behalf therefore only comes into consideration for the processing activities you trigger by using the user account, support, or expressly activated online features.

Where we transfer personal data to recipients who act as separate controllers in that respect, the transfer itself requires a legal basis. We base such transfers on Article 6(1)(b) GDPR in so far as they are necessary to provide the service you have requested, and otherwise on Article 6(1)(f) GDPR. We do not transfer data for the purpose of the recipient using it for its own purposes going beyond the provision of the relevant service. Where a recipient nevertheless processes the data for its own purposes, it is solely responsible for doing so; that further processing is governed by the recipient’s own privacy policy and is not covered by our basis for the transfer.

Where personal data is transferred to the United Kingdom, the transfer may be based on an adequacy decision of the European Commission. For other transfers to countries outside the European Economic Area, we ensure appropriate safeguards under Articles 44 et seq. GDPR where required, including an adequacy decision, the European Commission’s Standard Contractual Clauses, or supplementary measures.

Adequacy decisions may be amended, suspended, or repealed by the European Commission and declared invalid by the Court of Justice of the European Union. We continuously monitor the continued existence of the adequacy decisions we rely on, in particular the EU-US Data Privacy Framework, as well as the certification status of the respective recipients.

If an adequacy decision ceases to apply or is suspended, or if a recipient loses its certification, we will without undue delay base the affected transfer on another permissible mechanism, in particular the European Commission’s Standard Contractual Clauses under Implementing Decision (EU) 2021/914, together with a transfer impact assessment and any necessary supplementary measures. Where no such mechanism is available or sufficient, we will discontinue the affected transfer and replace the service in so far as this is necessary to provide our services. We will update this Privacy Policy without undue delay in such a case.

The United Kingdom currently benefits from a renewed European Commission adequacy decision for transfers under the GDPR. According to the current status, this decision applies until 27 December 2031, subject to earlier amendment or revocation. [Source: European Commission / ICO]

Where the User activates an optional ticket integration with a third-party system, data is transmitted directly to the third-party system selected by the User. These systems are outside the control of Flowence Infrastructure. The User is responsible, in particular, for reviewing the privacy information, contractual terms, storage locations, access controls, and permissions of the respective third-party provider. See Section 5 regarding the allocation of responsibilities for the transmission itself.

The confidentiality provisions of the Terms of Use for Korthex operate between the contracting parties and protect each party’s information against the other. Where the User passes on their own analysis results, inventories, or reports to a third-party system of their choosing through an integration they have activated, this does not constitute a breach of those confidentiality provisions. Our own confidentiality obligation towards the User remains unaffected.

Personal data is disclosed to authorities only where we are legally required to do so or where disclosure is necessary for the establishment, exercise, or defence of legal claims.

8. Data Retention Periods

We retain personal data only for as long as necessary for the relevant processing purpose. Beyond this period, we retain data only where and for as long as statutory retention, evidentiary, or documentation obligations apply, or where the data is required for the establishment, exercise, or defence of legal claims.

Once the relevant processing purpose no longer applies and applicable retention periods have expired, the data will be deleted or, where technically and legally permissible, anonymised. Anonymisation takes place only where a connection to an individual can be permanently excluded with sufficient certainty.

DataRetention
Master and account data, in particular name, email address, company, user identifier, and planFor the duration of the contractual relationship and, as a rule, until the expiry of three years after the end of the calendar year in which the contractual relationship ended
Billing data, invoices, and accounting recordsEight years after the end of the calendar year in which they were created for invoices and other accounting records; longer statutory retention periods remain unaffected
Books, inventories, annual financial statements, opening balance sheets, and comparable accounting documentsTen years after the end of the calendar year in which the relevant document was created or the last relevant entry was made
License, activation, and license-validation dataFor the duration of the contractual relationship and, as a rule, until the expiry of three years after the end of the calendar year in which the contractual relationship ended
Device binding data and device fingerprintsFor the duration of the active license and for no more than 30 days after effective deactivation or expiry of the license, unless longer retention is necessary to prevent specific misuse or enforce legal claims
Technical connection and security data, in particular IP addresses and API log dataGenerally seven days; in the event of specific security incidents, suspected misuse, or error analysis, until the relevant matter has been conclusively resolved
Support communications and support ticketsThree years after completion of the relevant matter; for contract- or billing-related content, potentially longer in accordance with the applicable retention periods
Crash report dataTwelve months after receipt of the relevant report or until prior withdrawal of consent, unless retention is necessary to investigate a specific security incident
Raw telemetry events, including envelope data90 days after receipt of the relevant event
Daily aggregates from telemetry data36 months, provided that the data no longer contains personal or re-identifiable identifiers
Monthly aggregates from telemetry dataIndefinitely, but only where the data has been effectively anonymised and no longer relates to an identifiable person
Local telemetry queue on the User’s deviceA maximum of seven days before transmission, or until telemetry is disabled or consent is withdrawn, whichever occurs first
Data from activated ticket integrationsOn Flowence Infrastructure systems, generally only for the technically necessary duration of the transmission; on the third-party system selected by the User, in accordance with that provider’s settings, agreements, and privacy notices

Withdrawal of consent generally takes effect only for the future. Data lawfully processed before consent was withdrawn may be retained only where another legal basis or a statutory retention obligation applies.

Where data must continue to be retained due to statutory retention obligations or for the establishment, exercise, or defence of legal claims, processing will be restricted to those purposes. The data will be deleted once the relevant period has expired.

For data stored in local files, local databases, or local queues of the Korthex software, the User may delete such data within the application or by uninstalling the application in accordance with the relevant operating system functions. This does not affect data already transmitted to Flowence Infrastructure or to a third party activated by the User.

Retaining monthly aggregates indefinitely presupposes that they are genuinely anonymous. We ensure this through fixed thresholds: an aggregate value is only formed and retained where it is based on at least twenty (20) distinct installations. Where that threshold is not met, the value concerned is either merged into a higher-level category or suppressed and not included in the monthly aggregate.

In addition, monthly aggregates contain no installation tokens, session IDs, event IDs, timestamps below monthly granularity, or other characteristics that would make an individual installation distinguishable. Monthly aggregates are not combined with account, license, or billing data. We review the effectiveness of these measures whenever the telemetry schema changes and at least once a year, and document the outcome.

For as long as, and to the extent that, anonymisation is not ensured in accordance with the preceding paragraphs, we treat the aggregates concerned as personal data and delete them in accordance with the period applicable to daily aggregates.

The deletion obligations under the Terms of Use for Korthex and the retention periods in this Privacy Policy concern different subject matter and apply independently of one another. The Terms of Use require the User to delete or uninstall the copies of the proprietary components present on their devices once the license ends. The table above, by contrast, concerns the data stored by us.

Uninstalling the software and terminating the contract therefore do not result in the immediate deletion of the account, license, and billing data stored by us. We retain that data in accordance with the table above, in particular to comply with statutory retention obligations and for the duration of the limitation periods applicable to potential claims.

If you additionally wish to have the data stored by us deleted, you may submit a request for erasure under Article 17 GDPR. We will delete the data concerned unless a statutory retention obligation or another ground listed in Article 17(3) GDPR prevents this; otherwise we will restrict processing. Details of this and your other rights are set out in Section 10.

9. International Data Transfers

Flowence Infrastructure is based in Germany. We generally process personal data within the European Economic Area. Where we engage service providers whose processing or access may take place outside the European Economic Area, data transfers are carried out only in compliance with the requirements of Articles 44 et seq. GDPR.

Under the currently intended infrastructure, database and storage infrastructure is operated through Supabase in the London, United Kingdom region. The United Kingdom is covered by an adequacy decision of the European Commission pursuant to Article 45 GDPR. Transfers of data to the United Kingdom may therefore be based on that adequacy decision.

The technical provision of the website and API through Vercel, as well as the use of Google, Stripe, GitHub, and their respective subprocessors, may – depending on the specific service configuration, support services, security measures, and corporate structures used – also require access to or transfers of data to countries outside the European Economic Area, in particular the United States of America.

Where personal data is transferred to the United States of America or another third country, we rely – where applicable – on an adequacy decision of the European Commission, in particular the EU-US Data Privacy Framework adequacy decision, provided that the respective recipient is certified under that framework. The recipient’s certification is reviewed before relying on this transfer mechanism.

Where no applicable adequacy decision exists or the relevant recipient is not covered by such a decision, we use appropriate safeguards pursuant to Article 46 GDPR. These may include, in particular, the Standard Contractual Clauses adopted by the European Commission and, where required, supplementary technical, organisational, or contractual measures.

You may request current information about the specific recipients engaged, their processing locations, and the transfer mechanism used in each case by contacting us using the contact details set out in Section 1. Where we materially change our service providers, data regions, or transfer mechanisms, we will update this Privacy Policy accordingly.

Where the User activates optional ticket integrations, data may be transmitted directly to the selected third-party system. In this case, possible processing locations, third-country transfers, and safeguards are additionally determined by the relevant provider and the configuration selected by the User.

10. Data Subject Rights

As a data subject, you have the rights described below under the General Data Protection Regulation. To exercise your rights, you may contact us at any time using the contact details set out in Section 1.

When submitting a request, please indicate, where possible, which processing activity, account, or service your request concerns. Where there are reasonable doubts about your identity, we may request additional information to verify your identity and prevent unauthorised access to personal data (Article 12(6) GDPR).

We will make any such request without undue delay, and at the latest within five (5) business days of receiving your request, and will limit it to the information actually required for identification. We do not use identity verification to delay handling your request. Where we can already identify you from the information available or through your signed-in user account, we will not make a separate request.

In that case, the period for responding to your request begins upon receipt of the information required for identification. If we do not receive that information, we will inform you that we are unable to process your request for that reason.

Independently of individual requests, we maintain a record of processing activities pursuant to Article 30 GDPR and submit it to the competent supervisory authority upon request.

  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]

Exercising your rights is generally free of charge. We will inform you of the action taken in response to your request without undue delay and, in any event, within one month of receiving your request.

Taking into account the complexity and number of requests, this period may be extended by a further two months. In that case, we will inform you of the extension and the reasons for it within one month of receiving your request.

We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you. Should this change in the future, we will provide separate information before such processing begins in accordance with Article 22 GDPR.

11. Technical and Organisational Measures

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Flowence Infrastructure implements appropriate technical and organisational measures pursuant to Article 32 GDPR. These measures are intended to ensure a level of security appropriate to the risks associated with the personal data processed.

When selecting and further developing security measures, we consider in particular the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to personal data. The specific security measures are reviewed regularly and adjusted where necessary.

  • Encryption of data transmission using TLS for connections between the Korthex software, website, API, and servers of engaged service providers.
  • Encryption of stored data through suitable encryption mechanisms provided by the hosting, database, and storage infrastructure used, where technically intended for the relevant data category.
  • Processing of the device reference exclusively in the form of one-way hash values (SHA-256). The underlying hardware characteristics are never transmitted to us or stored by us in plain text; the procedure used does not provide for reversing the hash back to the original characteristics.
  • Access controls, authentication procedures, and an authorisation concept based on the need-to-know and least-privilege principles; access to personal data is granted only to authorised persons where necessary for their tasks.
  • Procedures for managing, reviewing, adjusting, and revoking access permissions, particularly in the event of role changes or the departure of authorised persons.
  • Regular security updates, patch management, and monitoring of security-relevant dependencies for server infrastructure, software, libraries, and services used.
  • Regular reviews of the systems used for known vulnerabilities, together with risk-based security and configuration assessments.
  • Pseudonymisation, data minimisation, and, where technically feasible and compatible with the purpose of processing, anonymisation of data.
  • Local processing of source code and analysis results as part of the offline-first architecture. Such content is transmitted only where the User activates a feature whose purpose requires the transfer of specific content, in particular a ticket integration.
  • Encrypted communication between Korthex instances when the mesh networking feature is enabled.
  • Encrypted backups of server data and procedures to restore availability and access to personal data following a technical or physical incident.
  • Logging of security-relevant events and procedures for detecting, investigating, containing, and handling security incidents.
  • Documented procedures for assessing, reporting, and handling personal data breaches pursuant to Articles 33 and 34 GDPR.
  • Regular assessment of the effectiveness of technical and organisational measures, as well as adjustment of measures where risks, security requirements, or technical conditions change.

No security measure can guarantee complete protection against every conceivable risk. However, we continuously develop our security measures and take into account new technical developments, known threats, and the results of internal and external security assessments.

If a personal data breach nevertheless occurs despite these measures, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, where the breach is likely to result in a risk to your rights and freedoms (Article 33 GDPR). Where a high risk is likely, we will additionally notify you directly without undue delay (Article 34 GDPR).

Any such notification is sent to the email address stored in your user account and, where necessary, additionally by a notice within the software or on the website. It describes the nature of the breach, its likely consequences, the countermeasures taken, and a contact point for further questions. You may direct questions about a security incident at any time to the contact details set out in Section 1.

Where we engage external service providers, we select them taking appropriate security and data protection requirements into account. Where such service providers process personal data on our behalf, we contractually require them, where legally necessary, to implement appropriate technical and organisational measures.

12. Cookies, Vercel Web Analytics and Google Search Console

The website korthex.io does not use advertising cookies, marketing pixels, Google Analytics, Google Tag Manager, session-replay services, or externally integrated analytics or advertising services that track Users across websites. Under the intended configuration, externally loaded web fonts are also not used for tracking or analytics purposes.

Technically necessary cookies or similar technologies may be used to provide the website, for example to store a session, an expressly selected language preference, or a security token. Such technologies are used only where strictly necessary to provide a digital service expressly requested by the User.

No consent is required for technically necessary cookies or similar technologies where the requirements of Section 25(2) of the German Telecommunications and Digital Services Data Protection Act (TDDDG) are met. Subsequent processing of personal data, where necessary, is based on Article 6(1)(b) GDPR to provide requested features or Article 6(1)(f) GDPR to ensure security, stability, and protection against misuse.

  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]
  • [object Object]

You may configure your browser to display, restrict, or delete cookies. Please note that individual features of the website may not be available or may be available only to a limited extent if you block technically necessary cookies.

Should we use cookies, local storage, similar technologies, or analytics methods in the future that are not strictly necessary or that require access to information on your device, we will inform you clearly and comprehensively in advance and, where legally required, obtain your express consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.

You may object at any time, pursuant to Article 21 GDPR, to the processing of personal data based on Article 6(1)(f) GDPR on grounds relating to your particular situation. To do so, simply contact us using the contact details set out in Section 1. This is not a separate right but the same right to object that is described in full in Section 10; the explanations given there, in particular on the distinction between objection and withdrawal of consent, apply accordingly.