Last updated: 4 August 2026. Items in square brackets are publishing placeholders and require review by the person responsible for legal and privacy matters.
Who is responsible
The data controller is [LEGAL COMPANY NAME], with registered address at [REGISTERED ADDRESS]. Privacy enquiries can be sent to [PRIVACY CONTACT EMAIL].
Data we process
When you request a demo, we process the details you enter: name, email address, company, optional role and engineering-team size, use case, target hardware, referral source, and any project information you choose to add.
The website and API also process limited technical information needed to deliver and secure the service, such as request timestamps and network addresses in transient infrastructure logs. For demo-form rate limiting, the application stores keyed, non-reversible identifiers derived from the visitor address and email address; it does not store the raw address in the rate-limit table.
If you sign in, Auth0 handles authentication and Flash receives the account information required to maintain your session. Your identity-provider avatar is loaded only when you allow preference technologies.
How we use the data
- to review and respond to your demo request;
- to arrange a technical evaluation related to the project you described;
- to prevent duplicate, abusive, or automated submissions; and
- to operate and secure authenticated areas of the product.
A demo request is not treated as consent to receive unrelated marketing. The current form does not subscribe you to a mailing list.
The legal basis is [CONFIRM APPLICABLE LEGAL BASIS]. Depending on the final operating entity and context, this may include taking steps at your request before entering a contract and legitimate interests in responding to business enquiries. This wording must be confirmed before publication.
Service providers and transfers
The current deployment uses Vercel to host the website, Fly.io to host the API, Auth0 for authentication, and an SMTP email provider to deliver demo-request notifications. During initial setup, the notification recipient and sender are configured as v.r.adrian96@gmail.com, so Google may process the notification email. Replace this personal address with the approved company mailbox before production use.
[CONFIRM PROVIDER ENTITIES, PROCESSING LOCATIONS, CONTRACTS, AND TRANSFER SAFEGUARDS].
Retention
Demo requests remain in the application database until they are deleted under the organisation's approved retention process. Set and publish the final period: [DEMO REQUEST RETENTION PERIOD]. Hosting, authentication, and email providers may keep operational logs under their own configured retention periods: [CONFIRM LOG RETENTION PERIODS].
Your choices and rights
Subject to the law that applies to you, you may ask to access, correct, delete, restrict, or obtain a copy of your personal data, or object to certain uses. You may also complain to your competent data-protection authority. Send requests to [PRIVACY CONTACT EMAIL]. We may need to verify your identity before acting on a request.
You can change optional website preferences at any time using “Cookie settings” in the footer. See the Cookie Policy.
Required legal review
- [LEGAL COMPANY NAME], registration details, and postal address
- [PRIVACY CONTACT EMAIL] and any data-protection representative
- the lawful basis that applies to demo-request processing
- the final retention period for demo requests and server logs
- the countries and safeguards used by the selected hosting and email providers