Privacy Policy & Data Protection (GDPR)
Last updated: September 28, 2026
Web Site / Application: flexynook.app / hub.flexynook.app
Contact / DPO Email: dpo@tandemcode.studio
1. Overview and Roles of the Parties
In the context of using the FlexyNook application and web platform, this Privacy Policy outlines how we process and protect personal data regarding natural persons using the application (hereinafter referred to as “Users”) and natural persons associated with reservations, workspaces, or schedules. Depending on the nature of the processing, we operate as:
- Data Processor on behalf of the Customer (organization or company providing the application to Users) for managing and hosting business data entered by the Customer.
- Data Controller for contract execution, Customer account management, billing, platform security monitoring, and ethical, cookie-less audience measurement.
2. Types of Data Collected
The personal data processed are exclusively the data entered by the Customer or Users into the FlexyNook platform, specifically:
- User Account and Profile Data: Last name, first name, professional email address, phone numbers, department, role, login timestamps, and system logs.
- SSO & User Profile Pictures: Profile images imported via Single Sign-On (SSO) authentication connections (e.g., Google Workspace, Microsoft Entra ID / Azure AD) or directly uploaded by the User.
- Office, Site, and Organization Photos: Photographs of offices, buildings, meeting rooms, workstations, and organization assets uploaded by the Customer to illustrate workspaces. All office, site, and organization images are stored exclusively in JPG format.
- Booking and Schedule Data: Desk and meeting room reservations, presence status (office, teleworking, leave), working hours, and scheduling preferences.
- Anonymized Technical Analytics Data: Anonymous performance and traffic metrics collected via our self-hosted, cookie-less analytics platform (Umami). This includes aggregated page views, referrer source, browser type, and country. No IP addresses are stored in an identifiable format, and no cross-site tracking is conducted.
- No GPS Tracking: FlexyNook does not collect, track, or process GPS signals or real-time location data.
3. Storage, Security, and Database Architecture
To ensure maximum security and strict confidentiality of all processed data:
- Data Residency & Cloud Deployment Options: By default, our public SaaS infrastructure, databases, and analytics components (including self-hosted Umami) are strictly hosted within the European Union on European sovereign infrastructure, ensuring full GDPR compliance with zero unauthorized third-party transfers. For Enterprise customers requiring specific data residency (including US-based cloud deployment, dedicated tenant instances, or local compliance requirements), dedicated deployments can be arranged upon request.
- Single Centralized Database: All data entered by the Customer and Users (including profile data, bookings, schedules, and photo metadata) are stored within a single, unified database per tenant environment.
- Deployment Server Access Restricted: Databases are strictly isolated and accessible solely from the application’s deployment server. Direct external access to the database from the Internet is prohibited.
- Security & File Storage Measures: Access controls, SSL/TLS encrypted communications, network firewalls, and secure storage for uploaded images (JPG assets and avatar files).
4. Data Retention and Automatic Deletion (12-Month Inactivity Rule)
We enforce strict data minimization and retention policies to ensure data is not kept indefinitely:
4.1. Automatic Purge for Inactive Organizations (12-Month Threshold)
Any organization (Customer) that shows no activity for a continuous period exceeding twelve (12) months will have all of its data automatically and permanently deleted.
- Scope of Erasure: Automatic deletion is absolute and irretrievably destroys all data associated with the organization. This includes all User account data, SSO metadata, uploaded profile/office JPG photos, workspace configurations, bookings, and historical logs.
- Re-registration Requirement: Once the 12-month inactivity purge has occurred, the account is permanently closed. To use FlexyNook again, the organization and its Users will be required to complete a new registration process.
4.2. Operational Retention during Active Contract
As long as the organization remains active, entered data is retained for the duration necessary to provide the FlexyNook service and comply with applicable legal, accounting, and tax obligations (e.g., billing records retention).
5. Processing Operations as Data Controller
- Owner & Data Controller: TandemCode (Publisher of FlexyNook)
- Website: tandemcode.studio
- Contact / DPO Email:
dpo@tandemcode.studio - Purposes: Contract management, customer relationship management, invoicing, customer support, platform performance monitoring, and privacy-friendly analytics via self-hosted Umami.
- Legal Bases: Performance of a contract, compliance with legal obligations (accounting), and legitimate interest (securing, monitoring performance, and improving the SaaS platform without compromising user privacy).
6. Processing Operations as Data Processor
When the Customer uses FlexyNook to manage workspace bookings and employee schedules, the Customer acts as the Data Controller. As a Data Processor, TandemCode commits to:
- Process personal data solely on documented instructions from the Customer and for providing the SaaS services (desk booking, schedule management, SSO sync).
- Maintain strict confidentiality and technical security on the application deployment server.
- Automatically execute the 12-month inactivity data purge as detailed in Section 4.
7. Rights of Data Subjects
In accordance with the General Data Protection Regulation (GDPR – Regulation EU 2016/679) and applicable data protection laws, Users have the following rights:
- Right of Access & Rectification: Access personal data and update profile information or uploaded photos.
- Right to Erasure (“Right to be Forgotten”): Request the deletion of personal data (subject to legal retention requirements).
- Right to Restriction & Objection: Restrict processing or object to data processing activities.
- Right to Data Portability: Receive personal data in a structured, commonly used format.
Exercising Rights: Users can exercise their rights by contacting the Customer (Data Controller) or by reaching out to our Data Protection Officer at dpo@tandemcode.studio.
8. Photo Uploads and SSO Integrations
- User Profile Pictures: Users may import their profile photo via SSO identity providers (e.g., Google Workspace, Microsoft Entra ID) or upload a picture directly. Profile pictures can be modified or removed at any time in account settings.
- Office & Organization Media: Photos of offices, buildings, sites, and workstations uploaded by administrators to illustrate booking spots are stored exclusively in JPG format on secure server storage.