VANIV Studio
Privacy

Privacy Policy

Last updated: 27 July 2026

This policy explains how data is processed when you visit the VANIV website, join Early Access or contact us.

1. Controller

Manfred Flecker
Kolonieweg 7
8580 Köflach
Austria
Email: info@vaniv.studio

2. Scope

This policy applies to the VANIV Studio website, the Early Access sign-up process and contact requests. Additional information will be provided where required for processing within future VANIV software.

3. Hosting, delivery and security

The website is delivered through Cloudflare Pages and related Cloudflare services. Processing may include the IP address, request time and destination, referrer, browser, device and operating-system information, and technical security or diagnostic data.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the website and the prevention of attacks and abuse.

4. Cloudflare Web Analytics

We use Cloudflare Web Analytics for aggregated information about reach, page views and technical performance. According to Cloudflare, this service does not use cookies or LocalStorage to recognise individual visitors and does not create individual user profiles or browser fingerprints.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is improving the technical quality, stability and clarity of the website.

5. VANIV first-party reach measurement on Early Access pages

On the Early Access pages, we use a deliberately limited first-party measurement system. It answers only which VANIV page or allowlisted campaign source led to an Early Access visit, how many successful sign-ups resulted and how many Double Opt-in confirmations were completed.

The browser sends at most one deferred page-view event. A successful sign-up is counted only after the email provider accepts the Double Opt-in request. A confirmation is counted only after a signed token has been verified and at most once.

The analytics database contains hourly aggregate counters only, including language, normalised page path, reduced source category, sanitised source page or allowlisted source code, CTA category, technical version and, where applicable, an allowlisted campaign code. It does not store email addresses, names, raw IP addresses, User-Agent strings, visitor or session identifiers, browser fingerprints, full referrer URLs, query strings, individual page sequences, Brevo contact identifiers or sign-up IDs.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are evaluating and improving the Early Access pages and obtaining reliable, data-minimised conversion figures. You may object at any time through the Privacy settings. Global Privacy Control and “Do Not Track: 1” are also treated as objections. After an objection, no further VANIV measurement events are sent and attribution fields are neutralised during sign-up.

6. Privacy settings and storage of your choices

On your first visit, we ask only for your consent to Google Analytics 4. VANIV reach measurement is separate and can later be disabled or enabled again in the Privacy settings.

The GA4 choice is stored in LocalStorage under vaniv_cookie_consent_v3 and contains the choice, timestamp and technical version. An objection to VANIV measurement is stored only as the boolean setting vaniv_measurement_optout_v1=1. These values are used solely to respect your privacy choices and are not used as visitor identifiers.

You can change your choices at any time through “Privacy settings” or delete the website data in your browser.

7. Google Analytics 4

Google Analytics 4 is loaded only after you actively consent. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Processing may include pages visited, interactions, approximate region, referrer, browser, device and operating-system information, technical identifiers and the IP address during transmission. Google Analytics may set analytics cookies such as _ga.

We do not enable Google Signals or personalised-advertising features. The legal basis is Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future through the Privacy settings.

8. Early Access, email updates and Brevo Double Opt-in

When you join VANIV Early Access, we process your email address, selected page language and the consent-text version used at the time of sign-up. Brevo does not receive source-page, CTA or campaign data from our website measurement.

We use Brevo, a service of Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany, for email delivery and Double Opt-in. Brevo first sends a confirmation email. Only after you click the confirmation link is the address included for Early Access information, suitable testing waves, important development updates and the product launch. After confirmation, you may voluntarily provide product and tester interests.

The legal basis for email delivery is your consent under Article 6(1)(a) GDPR. You can withdraw it at any time through an unsubscribe link or by emailing info@vaniv.studio.

Before Double Opt-in is completed, the email address is stored only in AES-GCM-encrypted form in a separate operational Cloudflare D1 database. A random sign-up ID, language, consent version, status and timestamps and—unless you have objected to VANIV measurement—reduced attribution fields are also stored. These operational data are used to secure the process and count confirmation once; they are not copied into the analytics table.

9. Cloudflare Turnstile and abuse prevention

The Early Access form loads Cloudflare Turnstile only after you interact with the email field or submit the form. Turnstile helps determine whether a request is likely to be made by a human. Cloudflare may process the IP address, browser and device information, security signals and the verification result.

We also use a honeypot and short-lived rate-limit values. The IP address is not stored for rate limiting; instead, it is transformed with a secret key into a daily rotating HMAC value. The legal basis is Article 6(1)(f) GDPR, and our legitimate interest is protecting the form against spam, automated sign-ups and abuse.

10. Contact requests

If you contact us, we process in particular your name, email address, message and any technical information you voluntarily provide. Contract-related or pre-contractual requests are processed under Article 6(1)(b) GDPR; general enquiries and abuse-prevention measures under Article 6(1)(f) GDPR.

11. Affiliate links and external websites

When you click an affiliate or other external link, you are redirected to the relevant third party and its privacy policy applies. With ordinary links, data is generally transferred only after you click.

12. Recipients and international transfers

Recipients may include Cloudflare, Brevo and—only after your consent—Google. Where providers act on our behalf, the required data-processing agreements are used.

Where processing takes place outside the European Economic Area, transfers are based, where required, on an adequacy decision, the EU-U.S. Data Privacy Framework, Standard Contractual Clauses or another lawful safeguard. We do not sell personal data.

13. Retention

  • hourly aggregate VANIV counters: currently intended for up to 18 months;
  • rate-limit pseudonyms: approximately 25 hours;
  • unconfirmed, failed or expired operational Early Access records: after the confirmation token expires, generally no later than 30 days;
  • confirmed operational Early Access records: generally 45 days after confirmation;
  • Brevo contact data: until withdrawal, unsubscribe or the email purpose ends, subject to required evidence and statutory duties;
  • contact correspondence: generally no later than twelve months after closure, unless legal duties or legitimate reasons require longer storage.

14. Your rights

Subject to the legal requirements, you may have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time with effect for the future. Under Article 21 GDPR, you may object on grounds relating to your particular situation to processing based on Article 6(1)(f) GDPR.

Send requests to info@vaniv.studio. You may also lodge a complaint with a data protection authority. The authority responsible for the controller is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, email: dsb@dsb.gv.at.

15. Data security, children, automated decisions and changes

We use appropriate technical and organisational measures to protect personal data. The website is not specifically directed at children. We do not make solely automated decisions through the website that produce legal or similarly significant effects.

We update this policy when the services used, legal requirements or processing activities change. The applicable version is the one published on this page with its update date.

info@vaniv.studio