HAVI HAVI
Impressum ← Back

Legal

Privacy Policy

Last updated: 2026-07-17 — Version 1.1

This Privacy Policy describes how Handgemacht AI FlexCo ("HAVI", "we", "us") collects, uses, and protects personal data in connection with the HAVI annotation platform and related services. It applies to all users of the HAVI web application, browser extension, embeddable widget, and API (including the MCP endpoint).

HAVI is a hosted service offered on free and paid plans. Our core application data and screenshots are hosted in the European Union (Frankfurt). Certain processors are based in the United States, including payment processing (Stripe), error monitoring (Sentry), content delivery (Cloudflare), screenshot storage (Tigris), and, only if you use it, Google sign-in. Sections 5 and 6 describe those transfers and the safeguards that apply. We do not sell personal data, use advertising trackers, or profile users for marketing.

1. Controller Identity and Contact Details

The data controller responsible for processing your personal data is:

Legal name
Handgemacht AI FlexCo
Legal form
Flexible Kapitalgesellschaft (FlexKapG / FlexCo) under Austrian law
Registered address
Prof.-Franz-Spath-Ring 7/8, 8042 Graz, Austria
Commercial register
FN 671551 a, Landesgericht für Zivilrechtssachen Graz
EUID
ATBRA.671551-000
VAT ID
ATU83128269
Chamber membership
Wirtschaftskammer Steiermark (WKO)
Business object
Entwicklung und Vertrieb von Softwareprodukten
Applicable trade regulation
Gewerbeordnung (GewO 1994), available at www.ris.bka.gv.at
Managing director
Marco Livio Rotili

A direct electronic point of contact, as required under §5(1)(3) ECG, is available at [email protected]. To exercise data-subject rights or raise a privacy concern, contact us at this address. We will respond within one month of receipt (GDPR Art. 12(3)).

No Data Protection Officer (DPO) has been appointed. HAVI does not engage in large-scale systematic monitoring or process special-category data as a core activity (GDPR Art. 37(1)), so appointment is not currently mandatory. If a DPO is voluntarily appointed in future, their contact details will be published here.

1a. HAVI's role: controller and processor

For your account data, billing data, server logs, and error-monitoring data, HAVI acts as the data controller. For the annotation content you capture — screenshots and technical context from applications you are testing, which may contain other people's personal data — a business customer that uses HAVI to store that content typically acts as the controller and HAVI as the processor acting on that customer's instructions. Business (controller) customers may request a data processing agreement under GDPR Art. 28 (Auftragsverarbeitungsvertrag / AVV) covering that content; contact us at the address above. Consistent with this allocation, HAVI's position is that the customer who captures such content bears controller responsibility for it and HAVI acts solely as processor on that customer's documented instructions; where HAVI acts as a processor, data-subject requests relating to that content are directed to and handled by the controlling customer.

2. Categories of Personal Data Processed

2a. Account data (provided by you)

  • Email address (used for passwordless magic-link sign-in, or the email address of your Google account if you choose Google sign-in)
  • Display name (entered by you, or imported from your Google profile if you sign in with Google)
  • Workspace membership records, and workspace invitations (invitee email address, single-use invite token, 7-day expiry)

2b. Captured annotation data (collected on your instruction)

When you capture an annotation via the HAVI browser extension or the embeddable widget, the following data is sent to and stored by HAVI:

  • Screenshot of the visible browser tab (PNG image; the image bytes are held in object storage and referenced by a storage key)
  • Annotation text you enter
  • CSS selector and DOM coordinates of the targeted element
  • URL of the annotated page
  • Browser console errors logged at the time of capture
  • Failed network request details (URL, HTTP status code, method)
  • Web performance metrics (web vitals)
  • Viewport dimensions

The extension and widget capture content from whichever page is active at the time you trigger a capture. HAVI does not knowingly process special-category data (GDPR Art. 9), and you must not capture screens containing such data (for example health, financial, or other sensitive information visible in an application you are testing). If your screen incidentally contains personal data, that data will appear in the screenshot; please take care to capture no more than you need. This notice does not relieve HAVI of its own responsibilities as a controller (or, where applicable, processor) for the data captured, but it does ask you to meet any obligations you have to the people whose data may appear on your screen.

2c. Payment and billing data (via Stripe)

  • Stripe customer and subscription identifiers, subscription status, plan tier, and current billing-period end

Full payment card numbers are never processed or stored by HAVI. Card data passes directly to Stripe and is subject to Stripe's own privacy policy. Your billing email, card details (brand, last four digits), and invoices are held by Stripe under its own privacy policy, not by HAVI.

2d. Technical and operational data

  • Session authentication tokens (stored in browser cookies)
  • OAuth authorization codes, consents, and access/refresh tokens issued by HAVI's OAuth server for API, MCP, and extension access
  • IP address and HTTP request metadata (server access logs, Fly.io infrastructure)
  • Error traces, stack traces, and performance spans (Sentry / OpenTelemetry)

2e. Connected-client / agent activity data

When you connect a coding agent, MCP client, or the browser extension to HAVI using a credential issued to you, we record the last successful call made with that credential, together with the client display name and the repository, worktree, and branch names your client reports. This lets you see which of your clients are connected and helps us secure the service.

2f. Guest / demo data

If you try HAVI without an account via /try, we create an anonymous guest workspace and issue a short 6-character connect code (single-use, valid for 8 minutes, and rate-limited by IP address) so you can link a coding-agent session. Annotations you create as a guest belong to that anonymous workspace and can later be claimed into a registered account.

2g. Feedback (optional feature)

If the in-app feedback feature is enabled (off by default) and you submit feedback, we store the free-text comment plus optional context your client sends — the page URL, the extension version, your browser's user-agent string, and your workspace name. Feedback is submitted through an unauthenticated endpoint and is not linked to your user account.

2h. Email-suppression records

We keep a permanent list of email addresses that must not receive email (for example, after an unsubscribe request or a hard bounce), so that we can honour those requests. This record is limited to the email address and the suppression reason.

2i. Communications data

  • Magic-link authentication emails (sent via our transactional email provider)
  • Transactional email content and delivery status

2j. Signup source (campaign attribution)

If you arrive at HAVI via a link that carries campaign parameters (utm_source, utm_medium, utm_campaign — for example from a launch announcement) and then request a magic sign-in link, we record those parameters together with the email address you submit, so we can measure which channel brought a signup. This happens entirely server-side: the parameters travel only in the page URL, no cookie or browser storage is used for it, and no third-party service is involved. The information is not used to profile you and is not shared with anyone. Attribution records are automatically deleted after 12 months at the latest.

2k. Whether you must provide data, and data we receive from others

Providing your account and billing data is necessary to create an account and to use paid features; without it we cannot provide the service. Captured annotation data is provided entirely at your discretion. Where a workspace member invites you, we receive your email address from the inviting user; the invitation email itself serves as the notice required under GDPR Art. 14 and links you to this policy.

3. Purposes of Processing and Legal Bases

Processing activity Purpose Legal basis (GDPR Art. 6(1))
Account creation and management Provide access to the HAVI service Art. 6(1)(b) — performance of contract
Magic-link sign-in email delivery Authenticate the user without a password Art. 6(1)(b) — performance of contract
Google sign-in (OAuth), where you choose it Authenticate you via your Google account as an alternative to magic-link Art. 6(1)(b) — performance of contract
Storing and serving annotations (text, screenshots, selectors, URLs, console errors, network failures, web vitals, viewport) Core product functionality: capturing and retrieving development observations Art. 6(1)(b) — performance of contract
Serving annotations via MCP to connected agent sessions on request Core product functionality: making annotations available to the developer's agent session when it requests them via MCP Art. 6(1)(b) — performance of contract
Subscription billing via Stripe Processing payment for the paid SaaS subscription Art. 6(1)(b) — performance of contract
Guest / demo workspaces and connect codes Providing the no-account trial you requested via /try Art. 6(1)(b) — performance of contract (including pre-contractual steps)
Recording connected-client / agent activity (last call, repo / worktree / branch names) Showing you your connected clients; service security and abuse prevention Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8.
Recording the campaign link (UTM parameters) a signup request arrived with (Section 2j) Measuring which of our own marketing channels bring signups Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8.
Error tracking and performance monitoring via Sentry / OpenTelemetry Detecting and fixing bugs; ensuring service reliability and security Art. 6(1)(f) — legitimate interest (HAVI's interest in maintaining a stable, secure service). You have the right to object: see Section 8.
Server access logs (IP address, request metadata) Security, abuse prevention, and infrastructure operation Art. 6(1)(f) — legitimate interest. You have the right to object: see Section 8.
Processing feedback you submit (where the feature is enabled) Understanding user needs and improving the product Art. 6(1)(a) — consent. You may withdraw consent at any time: see Section 8.
Maintaining the email-suppression list Honouring unsubscribe requests and not emailing addresses that must be suppressed Art. 6(1)(c) — legal obligation, and Art. 6(1)(f) — legitimate interest
Retention of billing records Tax and accounting obligations under Austrian UGB §212 and §132 BAO Art. 6(1)(c) — legal obligation

4. Data Retention

Account data
Retained for the duration of your account. On request, we delete your account data within 30 days of your account-closure request, except where a legal retention obligation (for example billing records) requires longer retention. There is no self-service account-deletion control in the app today; closure and erasure are actioned by contacting us (see Section 8).
Annotation data (screenshots, text, selectors, URLs, console errors, web vitals, etc.)
Retained until you delete it. You can delete any individual annotation at any time in the HAVI app; deleting an annotation also removes its screenshot from object storage. If your workspace is downgraded to the Free plan (for example after a subscription ends), your existing annotations are retained and remain accessible under the current Free-plan limits — they are not deleted on downgrade. See Section 9 for export options.
Guest / demo data
Connect codes are single-use and expire 8 minutes after issue. Annotations created in an anonymous guest workspace are retained so that you can later claim them into a registered account; unclaimed guest data is removed on request.
Signup source (campaign attribution) records
Deleted automatically after 12 months at the latest; expired records are purged whenever a new record is written.
Connected-client activity records
Retained for the lifetime of the client credential. They are removed when you revoke the credential or when your account is closed.
Feedback submissions
Retained for as long as needed to review and act on the feedback, then deleted on request.
Email-suppression list
Retained indefinitely. The suppression record (email address and reason) is necessary to keep honouring the request and to meet our obligations, so it is not deleted on account closure.
Billing and payment records
Retained for 7 years from the end of the relevant financial year, in compliance with Austrian UGB §212 and §132 BAO (tax and accounting records).
Server / access logs
Retained for a maximum of 90 days for security and operational purposes.
Error traces (Sentry)
Retained per our Sentry plan configuration. We minimise the personal data sent to Sentry: error reports carry only a pseudonymous user identifier (not your email address, authentication tokens, or annotation content), and the Sentry SDK's default scrubbing removes sensitive request fields.
Magic-link tokens
Single-use and short-lived; expire shortly after issue. No further retention after use or expiry.
Authentication session cookie
The _havi_key session cookie is cleared when you close your browser. The authentication token it references remains valid for up to 14 days from sign-in or until you sign out.

5. Processors, Sub-Processors, and Third-Party Recipients

We share data only with the processors listed below. We do not sell personal data or share it with advertising networks, analytics platforms, or marketing services.

5a. Fly.io Inc. — Infrastructure and hosting

Role
Processor
Service
Cloud infrastructure and Postgres database hosting. HAVI uses the Frankfurt (fra) EU region — data at rest is stored in the European Union.
DPA
Available at fly.io/documents (pre-signed by Fly.io; HAVI executes as customer).
Transfer mechanism
See Section 6. Fly.io Inc. is a US entity (Delaware). EU-US Data Privacy Framework certification confirmed. SCCs (EU Commission Decision 2021/914) apply as fallback.

5b. Stripe, Inc. — Payment processing

Role
Processor for payment facilitation; independent controller for fraud prevention and financial compliance obligations.
Service
Subscription billing, Stripe Checkout, webhook events.
DPA
stripe.com/legal/dpa
Transfer mechanism
See Section 6. DPF certification confirmed; SCCs Modules 1 and 2 per Stripe Data Transfers Addendum (stripe.com/legal/dta).
Sub-processors
Listed at stripe.com/legal/service-providers.

5c. Sentry (Functional Software, Inc.) — Error tracking and performance tracing

Role
Processor
Service
Application error tracking and performance tracing via OpenTelemetry. Sentry may process data in the US.
DPA
Sentry DPA v5.1.0 at sentry.io/legal/dpa.
Transfer mechanism
See Section 6. DPF certification confirmed; SCCs Module 2 (controller → processor) or Module 3 (processor → processor) apply as fallback.
Sub-processors
Listed at sentry.io/legal/subprocessors; 30-day advance notice of changes.

5d. Brevo (Sendinblue SAS) — Transactional email delivery

Role
Processor
Service
Delivery of magic-link sign-in and other transactional emails (sent via the Swoosh email library using the Brevo API).
Location
Brevo (Sendinblue SAS) is established in Paris, France (European Union). Transactional emails are delivered from within the EU.
DPA
A Data Processing Agreement is in place with Sendinblue SAS (brevo.com/legal).
Transfer mechanism
Email-delivery data is processed within the European Union under a Data Processing Agreement; any Brevo sub-processor transfers outside the EU are covered by Standard Contractual Clauses.

5e. Google LLC — Google sign-in (optional)

Role
Independent (separate) controller for the Google-account authentication it performs; used only if you choose "Continue with Google" to sign in. Google's own processing is governed by Google's privacy policy. HAVI receives your verified email address and name from Google.
Service
OAuth authentication. When you sign in with Google, Google confirms your identity and provides your verified email address and name to HAVI. If you never use Google sign-in, no data is shared with Google.
Transfer mechanism
See Section 6. Google LLC is a US entity; EU-US Data Privacy Framework certification applies, with SCCs (Decision (EU) 2021/914) as fallback.

5f. Cloudflare, Inc. — Content delivery network and reverse proxy

Role
Processor
Service
Content delivery network and reverse proxy in front of the production service (caching of anonymous pages, TLS termination, and DDoS / abuse protection). As traffic passes through it, Cloudflare processes request metadata, including visitor IP addresses.
DPA
Cloudflare Data Processing Addendum at cloudflare.com/cloudflare-customer-dpa.
Transfer mechanism
See Section 6 (DPF / SCCs). Cloudflare, Inc. is a US entity; EU-US Data Privacy Framework certification applies, with SCCs (Decision (EU) 2021/914) as fallback.

5g. Tigris Data, Inc. — Screenshot object storage

Role
Processor
Service
S3-compatible object storage of the screenshot image bytes captured with your annotations. Screenshots are stored in the Frankfurt (fra) EU region; the Postgres record holds only the storage key. Tigris Data, Inc. is a separate company from Fly.io and is engaged by HAVI as its own processor under its own Data Processing Addendum.
DPA
Tigris Data Processing Addendum at tigrisdata.com/docs/legal/data-processing.
Transfer mechanism
See Section 6. Tigris Data, Inc. is a US entity; screenshot data is stored in the Frankfurt (fra) EU region. Transfers are covered by the Standard Contractual Clauses (European Commission Decision (EU) 2021/914) incorporated into the Tigris DPA.

No analytics, advertising, or marketing processors are used. HAVI uses no third-party tracking scripts on any page.

6. International Data Transfers

Several processors listed in Section 5 are incorporated in the United States. Under GDPR Art. 44, transfers to third countries require an adequate safeguard. The mechanisms in place for each US processor are as follows.

Fly.io Inc. (US)

Primary mechanism: EU-US Data Privacy Framework (DPF) — Fly.io holds a current DPF certification. The DPF is based on the European Commission adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795). The DPF survived its first judicial challenge before the EU General Court (Latombe v. Commission, Case T-553/23, 3 September 2025, action dismissed); the adequacy of the DPF remains subject to ongoing legal review. Fallback: Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914 of 4 June 2021, incorporated into the executed Fly.io DPA. Although Fly.io stores and processes HAVI data in its Frankfurt (fra) EU region, Fly.io Inc. as a US entity may be subject to US law (including the CLOUD Act). We have conducted a Transfer Impact Assessment (TIA) documenting our assessment of the adequacy of these safeguards.

Tigris Data, Inc. (US)

Tigris Data, Inc. stores HAVI's screenshot image bytes in its Frankfurt (fra) EU region, but as a US entity it may be subject to US law. We could not confirm a current EU-US Data Privacy Framework certification for Tigris, so we rely on the Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914, incorporated into the Tigris Data Processing Addendum (Module 2, controller → processor, and, where applicable, Module 3, processor → processor).

Stripe, Inc. (US)

Primary mechanism: DPF certification confirmed. Fallback: SCCs Modules 1 and 2 per the Stripe Data Transfers Addendum (stripe.com/legal/dta).

Sentry / Functional Software, Inc. (US)

Primary mechanism: DPF certification confirmed. Fallback: SCCs Module 2 (controller → processor) or Module 3 (processor → processor) as set out in the Sentry DPA.

Cloudflare, Inc. (US)

Primary mechanism: EU-US Data Privacy Framework — Cloudflare holds a current DPF certification. Fallback: Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914, incorporated into the Cloudflare Data Processing Addendum.

Google LLC (US) — only if you use Google sign-in

Google acts as a separate controller for the authentication it performs; where you choose to sign in with Google, your verified email address and name are disclosed to Google in the United States. Primary mechanism: EU-US Data Privacy Framework — Google LLC holds a current DPF certification. Fallback: Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914.

Copies of the applicable Standard Contractual Clauses (the appropriate safeguards) are available on request (GDPR Art. 46(1), and Art. 13(1)(f)). Contact us using the details in Section 1.

7. Cookies and Browser Storage

HAVI uses only technically necessary cookies and equivalent browser storage. No advertising cookies, cross-site tracking cookies, or third-party analytics trackers are used on any HAVI page or in the extension.

Under §165(3) of the Austrian Telekommunikationsgesetz 2021 (TKG 2021), which implements the ePrivacy Directive (2002/58/EC), prior consent is not required for cookies that are strictly technically necessary to provide a service explicitly requested by the user. All cookies HAVI uses fall into this category. No cookie consent banner is legally required.

Cookie / storage item Purpose Type Duration
_havi_key (SameSite=Lax) Carries your sign-in session and CSRF token Session cookie Cleared when you close your browser. The authentication token it references remains valid for up to 14 days from sign-in or until you sign out.

You can clear cookies at any time via your browser settings. Clearing the _havi_key cookie will sign you out of HAVI.

8. Your Rights

Under GDPR Arts. 15–22 and the Austrian Datenschutzgesetz (DSG), you have the following rights regarding your personal data. To exercise any of these rights, contact us at the address in Section 1. We will respond within one month of receipt. For complex or numerous requests we may extend the response period by up to two further months, and will inform you of any extension within the first month (GDPR Art. 12(3)). Exercising your rights is free of charge. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive (Art. 12(5)).

Right of access (Art. 15)
You may request confirmation of whether we process your personal data and, if so, receive a copy of that data along with information about how it is used.
Right to rectification (Art. 16)
You may request correction of inaccurate personal data we hold about you (for example, your display name).
Right to erasure (Art. 17)
You can delete individual annotations yourself at any time in the HAVI app; deleting an annotation also removes its screenshot from object storage. Account-level erasure — deleting your account and the personal data associated with it — is handled on request: contact us at the address in Section 1 and we will action it within the GDPR deadlines, unless we are required to retain specific data by a legal obligation (for example, billing records subject to Austrian UGB / BAO retention periods).
Right to restriction of processing (Art. 18)
You may request that we restrict processing of your data in specified circumstances, for example while a rectification request is being resolved.
Right to data portability (Art. 20)
Where processing is based on contract performance or consent and is carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format. HAVI exposes all annotation data in W3C Web Annotation format (JSON-LD, open standard) through its authenticated REST API — see Section 9. On request, we also provide your account and profile data (such as your email address and display name) in a structured, machine-readable format, so portability is not limited to annotations.
Right to object (Art. 21)
Where processing is based on our legitimate interest (Art. 6(1)(f)) — namely error tracking and performance monitoring, server access logs, and connected-client activity records — you may object at any time. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to withdraw consent (Art. 7(3))
Where processing is based on your consent — namely the optional in-app feedback feature, where enabled — you may withdraw it at any time and simply stop submitting feedback. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right not to be subject to automated decisions (Art. 22)
HAVI does not conduct automated decision-making or profiling that produces legal or similarly significant effects on you.

9. Data Export — No Lock-In

You can export all your annotations at any time through HAVI's authenticated REST API, at no charge. The API returns your data in an open standard, so you are never locked in.

  • Export format: W3C Web Annotation (JSON-LD, open standard — www.w3.org/TR/annotation-model)
  • The API returns your annotations as W3C JSON-LD, which references each screenshot by URL; the PNG image bytes are downloaded per annotation from the image endpoint (GET /api/annotations/:id/image). The JSON-LD includes annotation text, CSS selectors, page URLs, console errors, network failure details, web vitals, viewport metadata, and all captured technical context
  • Structured, commonly used, machine-readable, and interoperable
  • No proprietary format lock-in; no export fee

You can delete individual annotations yourself at any time in the HAVI app, which also removes the associated screenshot. Full account deletion and other erasure requests are handled on request at [email protected] within the GDPR deadlines (see Section 8). Providing your annotation data via the API, together with the account and profile data we supply on request, satisfies your right to data portability under GDPR Art. 20; if you need help exporting your data, contact us at the same address.

10. Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with the competent data protection supervisory authority at any time (GDPR Art. 77). The lead supervisory authority responsible for Austria is:

Österreichische Datenschutzbehörde (DSB)
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: [email protected]
Website: data-protection-authority.gv.at

As HAVI is an Austrian company, the DSB is the lead supervisory authority. If you are habitually resident or employed in another EU member state, you may also lodge a complaint with the supervisory authority of that member state (Art. 77(1)).

11. Security Measures

We implement appropriate technical and organisational measures (TOMs) to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with GDPR Art. 32. Our measures include:

  • Encryption in transit: All connections between clients and HAVI services use HTTPS / TLS.
  • Encryption at rest: Fly.io managed disk encryption in the Frankfurt (fra) EU region.
  • Access controls: Workspace-scoped data endpoints require bearer-token authentication and are scoped to the authenticated user's workspace membership; health checks and the optional feedback endpoint are exceptions.
  • Error monitoring data minimisation: Error reports sent to Sentry carry only a pseudonymous user identifier — not email addresses, session tokens, or annotation content — and the Sentry SDK's default scrubbing removes sensitive request fields from payloads and stack traces.
  • Sub-processor security review: We review sub-processor security and compliance posture via their published compliance reports and audit certificates on a regular basis.
  • Confidentiality obligations: All staff and contractors with access to user data are contractually bound to confidentiality, including after contract end (DSG §6).

12. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available at havi.handgemacht.ai/privacy.

  • Minor changes (for example, adding a new sub-processor or updating a retention period): we will update the "Last updated" date at the top of this page.
  • Material changes (for example, a new purpose of processing or a change of legal basis): we will notify you by email before the change takes effect, giving you the opportunity to exercise your rights before processing changes.

13. Policy Version and Effective Date

Version
1.1
Last revised
2026-07-17
Effective date
2026-07-17

Version history:

  • Version 1.1 — effective 2026-07-17 (this version). The v1.1 changes are clarifications and corrections that more accurately describe existing processing; they do not introduce new processing purposes and are non-material, so no separate advance-notice period applies.
  • Version 1.0 — effective 2026-06-08

Questions about this policy? Contact us at the address in Section 1.

HAVI
Home Impressum Privacy Terms Cancellation