Legal

Privacy Policy

Last updated: March 12, 2026

This privacy notice explains how the website for The Booking Project, operated by CutFlow Cloud Ventures UG (haftungsbeschraenkt), processes personal data for visits, enquiries, and rollout conversations.

These pages are here for policy and due diligence. The public sales path stays on the homepage and contact page.

1. Controller

Controller: CutFlow Cloud Ventures UG (haftungsbeschraenkt), Berlin, Germany.

General contact: hello@cutflowcloud.com. Privacy contact: privacy@cutflowcloud.com.

2. Data Protection Contact

For privacy rights requests, contact privacy@cutflowcloud.com.

If we appoint a dedicated Data Protection Officer or privacy representative, we publish the direct contact details here.

3. Data Categories

We process identity and business context information submitted in contact requests and rollout conversations.

We also process technical metadata needed for fraud prevention, uptime, and security monitoring.

  • Identity and contact data: name, email, business name, city, optional message
  • Operational metadata: IP address, user agent, referrer, timestamps
  • Security/anti-abuse data: challenge verification tokens and rate-limit events

4. Purposes and Legal Bases

Processing is based on Art. 6(1)(b) GDPR for pre-contractual communication and service initiation.

Processing is based on Art. 6(1)(f) GDPR for secure operation, abuse prevention, and platform integrity.

Where optional technologies are used, processing may be based on Art. 6(1)(a) GDPR consent.

5. Recipients, Processors, and DPA Controls

Data may be processed by hosting, database, email, and anti-abuse providers acting as processors.

Processor agreements under Art. 28 GDPR are maintained where legally required.

A current processor or subprocessor overview is available on request.

6. International Transfers

If personal data is transferred outside the EEA, appropriate safeguards such as SCCs or adequacy decisions apply.

Transfer impact assessments are documented whenever the law requires them.

7. Retention and Deletion

Contact-request and rollout-conversation records are retained only as long as necessary for request handling, contracting, and statutory obligations.

Security and anti-abuse records are kept only for the period needed for fraud prevention, platform integrity, and incident response.

8. Data Subject Rights

You may request access, rectification, erasure, restriction, portability, and objection under GDPR.

You may withdraw consent at any time without affecting prior lawful processing.

9. Security and Incident Handling

The Booking Project applies technical and organizational measures including access controls, logging, encrypted transport, and abuse-prevention checks.

Potential incidents are investigated and, where legally required, reported to supervisory authorities and affected persons.

10. Supervisory Authority and Complaints

You may lodge a complaint with a competent data protection authority, especially in your place of residence, place of work, or the controller location.

We update this notice when processing activities, service providers, or legal requirements materially change.