Back home

Privacy policy

This policy explains how ffdev.pro handles personal data when you visit the site, send an enquiry or use an account, order workspace or chat.

About this policy and how to contact us

This policy covers ffdev.pro and the services delivered through it. It does not govern websites or services operated independently by Telegram, Discord, Google or other third parties.

In this policy, “FFDEV”, “we” and “us” mean the team that operates ffdev.pro and provides the services described on the site. Questions about personal data and requests to exercise your rights can be sent to hello@ffdev.pro.

Where the EU General Data Protection Regulation applies, we process data under the GDPR. The German Federal Data Protection Act (BDSG) supplements it where applicable, and section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) governs storage on, or access to, your device.

Data we receive

You provide your name, contact details and project brief when you send an enquiry. Account and workspace use can add your email address, password hash, profile details, email-verification status, orders, assignments and chat messages. Staff actions and changes to an order may also become part of its history.

Our systems generate technical data needed to deliver and protect the service: IP address, request time, User-Agent, session and authentication records, rate-limit data, security events and an audit trail of sensitive actions. Consent-based public-page statistics are described separately below.

Purposes and legal bases

We use enquiry, account, order and message data to take steps at your request before a contract and to perform a contract, including responding to you, preparing an offer, managing delivery and providing the workspace (Article 6(1)(b) GDPR).

We use limited technical, session and audit data to operate, troubleshoot and secure the service, prevent abuse and establish or defend legal claims. These are our legitimate interests under Article 6(1)(f) GDPR. Where a record must be kept by law, Article 6(1)(c) GDPR applies.

Optional first-party statistics run only with your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw that consent at any time without affecting processing carried out before withdrawal.

Enquiries, accounts, orders and chat

Sending the public form creates an isolated lead record and order so the team can handle the request. If the contact is a valid email address, we may send a one-time invitation. Registration and password-recovery flows use short-lived, single-use tokens; only token hashes are stored in the database.

Fields marked as required are needed to process the request or provide the account function. Without them, we cannot accept the enquiry, create the account or provide the relevant workspace feature. Do not send special-category data or another person's data unless it is necessary and you are entitled to do so.

Security and access records

The server uses IP address and request metadata for rate limiting, session protection, incident investigation and the audit of sensitive actions. Session records contain a token hash, IP address, truncated User-Agent, last activity and expiry time; the browser holds the corresponding random secret in an HttpOnly cookie.

Access is role-based and limited to people who need the information for an enquiry, project, support case, security task or administration. Passwords are stored only as strong hashes, sensitive tokens are stored as hashes, connections are encrypted, and privileged actions are logged.

Cookies and browser storage

The essential ffdev_lang cookie stores the selected language for up to one year. ffdev_sess maintains a signed-in session for up to 30 days after the latest activity and is removed on sign-out. ffdev_cookie_consent stores your statistics choice for up to one year. Short-lived ffdev_flow_email, ffdev_flow_reset and ffdev_flow_lead cookies protect email, reset and invitation flows for up to 24 hours, 30 minutes and seven days respectively.

The workspace can store display and filter preferences in localStorage and uses a timestamp or BroadcastChannel event to keep authentication state consistent between tabs. These values contain no message or password content and remain until replaced or cleared in the browser.

Essential storage is used to provide a function you request and does not require consent under section 25(2)(2) TDDDG. Optional analytics storage is disabled until you choose Allow statistics. Privacy settings in the footer lets you withdraw or change that choice at any time.

Consent-based first-party statistics

After consent, a random visit identifier is kept in sessionStorage, rotates after 30 minutes of inactivity and is cleared when consent is withdrawn. The server stores only its one-way hash together with page path, time, language and broad device category. It does not store the IP address, full User-Agent, referrer, query string, account ID or a durable advertising identifier in analytics data.

Analytics events are deleted after three years. We use them only for aggregate traffic reports, not for advertising, cross-site tracking, profiling or decisions about an individual. Global Privacy Control and browser Do Not Track signals disable this collection.

Recipients and service providers

Data may be accessed by authorised FFDEV staff and by providers that support hosting, database and backup storage, security, and service-email delivery. They receive only the data needed for their task. Professional advisers, courts or authorities may receive data where this is required by law or necessary to protect legal rights.

We do not sell personal data, disclose it to data brokers or use it to build advertising audiences. Current processor and transfer information can be requested at hello@ffdev.pro.

Google Fonts and external channels

Public pages currently request font files from Google Fonts. Your browser therefore sends Google the technical connection data needed to deliver those files, such as IP address, request time, requested resource and browser headers. This processing supports consistent, readable presentation and is based on our legitimate interest under Article 6(1)(f) GDPR; Google handles the request under its own privacy terms.

If you choose to contact us or open a community link through email, Telegram or Discord, the selected provider processes the information under its own terms. Those channels are optional; you can always use hello@ffdev.pro.

International processing

FFDEV and technical providers may process data outside the European Economic Area, including in Russia and, for some third-party services, the United States. Privacy laws and public-authority access rules in those countries may differ from those in the EEA.

Where Chapter V GDPR applies, a transfer may take place only on the basis of an adequacy decision, appropriate safeguards such as the European Commission's standard contractual clauses, or a narrowly applicable statutory derogation. You can ask which mechanism applies to your data.

How long we keep data

Session and browser-storage periods are stated above. Expired authentication tokens and queued service emails are no longer used. Public-page analytics events are automatically removed after three years. Backup copies follow a limited rotation and disappear when the relevant backup set expires.

Enquiry, account, order, chat and audit records are kept while the enquiry, account or project is active and afterwards only as long as reasonably needed for support, security, accounting or tax duties, limitation periods and the establishment, exercise or defence of legal claims. We delete or anonymise data when those purposes and duties end.

Your rights

Subject to the legal conditions, you may request access, correction, deletion, restriction and portability of your data. You may object on grounds relating to your situation to processing based on Article 6(1)(f) GDPR. You may withdraw consent for future processing at any time.

Send a request to hello@ffdev.pro. We may verify your identity and will explain if a legal exception prevents us from fulfilling all or part of a request. You may also complain to a data-protection supervisory authority, in particular in the EU or EEA country of your habitual residence, place of work or the alleged infringement.

No automated decisions; policy changes

We do not use the data covered by this policy for automated decisions with legal or similarly significant effects, and we do not create advertising profiles. The service is not designed to collect special-category data at scale.

We revise this policy when the service, providers or legal requirements change. Material changes are presented on this page before they take effect where practicable; the revision date below identifies the current version.

Updated: September 17, 2026