Logo

COOKIE POLICY

Version 1.0 – 2025-07-14


1 Scope and controller

This Cookie Policy explains how Jaden Data GmbH (trading as 'FlowhiveAI', 'we', 'our'), Goethestraße 67 a, 10625 Berlin, Germany (HRB 236369 B – Amtsgericht Charlottenburg, VAT DE 349 098 543, e‑mail info@jadendata.com), uses cookies and comparable technologies on https://www.flowhiveai.io (the "Service").

Unless stated otherwise, Jaden Data GmbH is the controller within the meaning of Art 4 No 7 GDPR.


2 Cookies and similar technologies

"Cookies" are small text files that a website stores on a visitor’s device and that the browser returns on subsequent visits. Technologies such as localStorage, sessionStorage, tracking pixels, web beacons and tags serve comparable purposes. In this notice, "cookie" is shorthand for all such technologies.

Legal framework. Reading or writing information on end‑user devices is governed by Art 5 (3) ePrivacy Directive, transposed in Germany via § 25 TTDSG. Where a cookie involves processing of personal data, the GDPR applies in parallel.


3 Why we use cookies

CategoryPurposeLegal basis (GDPR)Default state
Strictly necessaryProvide the Service and keep it secure (authentication, CSRF‑protection, load balancing)Art 6 (1)(b) contract or Art 6 (1)(f) legitimate interestAlways active – § 25 (2) TTDSG
AnalyticsUnderstand and improve how visitors interact with the Service (PostHog, Google Analytics 4)Art 6 (1)(a) consentDisabled until opt‑in
Session RecordingMay record certain user interactions to improve website usability and identify potential issues (PostHog session recording)Art 6 (1)(a) consentDisabled until opt‑in
Marketing / AdvertisingMeasure campaign performance, build audiences and serve relevant ads (LinkedIn Insight Tag, X Pixel, Google Ads Tag)Art 6 (1)(a) consentDisabled until opt‑in

Non‑essential cookies are never set before you give consent. 'Accept all' and 'Reject all' are equally prominent. The banner is implemented with vanilla‑cookieconsent.


4 Detailed cookie list

Audit date: 2025‑07‑14 – we re‑scan quarterly and update this table as required.

4.1 Strictly necessary

NameProvider / DomainPurposeExpiryHttpOnlySecureSameSite
_cfuvidCloudflare – *.flowhiveai.ioDistinguishes visitors behind a shared IP so Cloudflare’s WAF rules do not over‑block trafficSession✔︎None
appSession.0FlowhiveAI – www.flowhiveai.ioKeeps the user logged‑in (encrypted Auth0 token)24 h✔︎✔︎Lax
appSession.1FlowhiveAI – www.flowhiveai.ioSilent token refresh paired with appSession.024 h✔︎✔︎Lax
flowhive_sessionFlowhiveAI – www.flowhiveai.ioMaintains session state & CSRF tokenSession✔︎✔︎Lax
cookie_consentFlowhiveAI – www.flowhiveai.ioStores your banner choice12 mo✔︎Strict
docs_current_tenantAuth0 – .auth0.comSelects the correct Auth0 tenant for docsSession✔︎Lax
wclangAuth0 – .auth0.comStores interface languageSession✔︎Lax

docs_current_tenant and wclang only appear after you log in to the dashboard.

4.2 Analytics – loaded only after consent

NameProviderPurposeDefault expiry
ph_<project_api_key>_posthogPostHogDistinct ID, session ID, feature‑flag state12 mo
_gaGoogle Analytics 4Distinguishes users24 mo
_ga_<container-id>Google Analytics 4Persists session state24 mo
_gidGoogle Analytics 4Distinguishes users per day24 h

PostHog also writes to localStorage for feature‑flags. LocalStorage is cleared when you withdraw consent.

4.3 Session Recording – loaded only after consent

TechnologyProviderPurposeData collected
Session RecordingPostHogMay record user interactions to improve website usability and identify potential issuesMouse movements, clicks, scrolling patterns (text input is masked)
HeatmapsPostHogMay generate heatmaps showing popular areas of the websiteAggregated click and scroll data

Session recording data is stored for up to 12 months and may be used solely for website improvement purposes. Text input fields are automatically masked to protect your privacy.

4.4 Marketing / Advertising – loaded only after consent

NameProviderPurposeDefault expiry
personalization_idX (Twitter)Ad personalisation & analytics24 mo
guest_id_adsX (Twitter)Identifies devices for ads when logged‑out24 mo
bcookieLinkedIn Insight TagBrowser ID for fraud detection & ads12 mo
lidcLinkedIn Insight TagDatacentre selection & load balancing24 h
li_gcLinkedIn Insight TagStores guest consent for non‑essential cookies6 mo
li_fat_idLinkedIn Insight TagMember indirect identifier for conversions30 d
IDEGoogle Ads (doubleclick.net)Stores ad preferences & user ID13 mo
__gadsGoogle AdsMeasures interactions with ads & prevents duplicate displays13 mo
_gcl_auGoogle Ads / Tag ManagerStores Google Click ID (GCLID) for conversion tracking90 d
test_cookieGoogle Ads (doubleclick.net)Tests if the browser supports cookies15 min

5 Consent mechanism & withdrawal

Our banner:

  • Loads only strictly necessary cookies by default.
  • Shows “Accept all” and “Reject all” with equal prominence, plus category toggles and a “Save preferences” button.
  • Stays visible until you make a choice.
  • Stores decisions in the cookie_consent cookie for 12 months.
  • Can be reopened at any time via Cookie Settings in the footer.

Withdrawing consent deletes analytics/marketing cookies and blocks the associated scripts.


6 International data transfers

  • PostHog EU Cluster is hosted in Frankfurt/Stockholm – no data leaves the EEA.
  • Google LLC, X Corp. and LinkedIn Corp. may process data in the United States. Transfers rely on:
    • certification under the EU–US Data Privacy Framework (DPF),
    • Standard Contractual Clauses (SCCs), and
    • documented Transfer Impact Assessments.

Copies of the SCCs are available on request.


7 Storage duration & deletion

We keep personal data derived from cookies no longer than necessary. Analytics events are truncated or aggregated after 25 months at the latest. Marketing identifiers are deleted once a campaign ends or after 30 days of inactivity, whichever comes first.


8 Your rights

You may exercise the rights in Art 15–22 GDPR (access, rectification, erasure, restriction, portability, objection, automated decision‑making) at any time. See our Privacy Policy for details.


9 Changes to this policy

We review this notice at least quarterly. Material changes (e.g. adding a new marketing pixel) trigger a renewed consent request.

Last update: 2025‑07‑14


10 Contact

Data Protection Officer
Jaden Data GmbH
Goethestraße 67 a
10625 Berlin, Germany
privacy@jadendata.com

You may also lodge a complaint with the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).