RecruitFlow ← Back to site

Privacy Policy

Last updated: August 2026

We take the protection of personal data seriously. Neese Consulting LLC is a US company operating internationally, and a substantial part of the customers we serve — together with the applicants and leads reaching them through RecruitFlow — are based in the European Union. We therefore run our processing to the GDPR standard and describe it here in the terms the GDPR uses: what data we process, for what purpose, on what legal basis, and which rights you have. Where the GDPR does not apply to you, the same description still tells you accurately what happens to your data.

This marketing site sets no tracking cookies, loads no analytics, and serves its typefaces from our own servers.

1. Controller

Neese Consulting LLC
1914 Thomes Ave, Ste 2 #5296
Cheyenne, WY 82001, USA
Represented by: Neese Consulting LLC
Email: support@neese-consulting.com
Phone (DE): +49 571 73075360 · Phone (US): +1 307-278-7246

For any matter concerning data protection, write to support@neese-consulting.com. Requests are handled by the team operating RecruitFlow.

2. Scope and the two roles we hold

This policy covers the marketing site start-recruitflow.neese-consulting.com and the RecruitFlow application at recruitflow.neese-consulting.com. Which role we hold depends on whose data is being processed, and the distinction decides whom you should contact.

Two distinct roles:

a) Visitors to this website. For data processed when you visit this site, and for enquiries that reach us through it, Neese Consulting LLC is the controller within the meaning of Art. 4(7) GDPR.

b) Applicant and lead data inside the RecruitFlow app. Where a customer uses RecruitFlow to process data about applicants or leads, that customer alone decides on the purposes and means of the processing. The customer is the controller; Neese Consulting LLC acts as processor under Art. 28 GDPR, on the basis of a data processing agreement concluded with each customer. Data subjects — applicants in particular — should therefore address their requests primarily to the company they applied to. Where such a request reaches us instead, we forward it to the responsible customer.

3. Where data is stored

Customer, applicant and lead data is held primarily on servers in the European Union. Our database and authentication run on Supabase in region eu-central-1 (Frankfurt, Germany). Individual operations — delivery through our hosting provider's content delivery network, or the sending of transactional email — may additionally involve transfers to third countries; sections 8 and 9 describe these.

4. Data processed when you visit this website

4.1 Server log files

When you open one of our pages, our hosting provider automatically processes the technical data your browser transmits: IP address, date and time of the request, the page or file requested, volume of data transferred, HTTP status code, referrer URL, and browser and operating system details (user agent).

Purpose: delivering the site, keeping it technically operational, and detecting and defending against attacks and abuse.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the secure and stable operation of the service. This data is retained only for as long as those purposes require.

4.2 Contacting us

If you write to us by email or through a form, we process the details you provide — for example your name, email address, company and your message — in order to answer your enquiry.

Legal basis: Art. 6(1)(b) GDPR where the enquiry concerns the conclusion or performance of a contract; otherwise Art. 6(1)(f) GDPR — our legitimate interest in responding to enquiries. Enquiries are not used for advertising.

5. No analytics or tracking cookies

This marketing site sets no analytics or tracking cookies and embeds no analytics service. There is no audience measurement and no profiling, and no data is passed to third parties for advertising purposes. A cookie banner is therefore not required for this site.

Inside the application at recruitflow.neese-consulting.com, technically necessary storage mechanisms are used — a session token for login, for instance — without which the service cannot operate.

6. Web fonts

The Geist typefaces used on this site are self-hosted and delivered from our own infrastructure. No connection to Google Fonts or any other third-party font service is established when a page loads, and no data is transmitted to a font provider.

7. Data processed when using RecruitFlow

7.1 Customer and account data (we are the controller)

To provide access to the application we process data about the users on the customer's side: name, business email address, company affiliation, access and authentication data, roles and permissions, and technical usage data of the account.

Purpose: performing the contract, providing and securing access, support and billing.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for security and abuse prevention additionally Art. 6(1)(f) GDPR; where statutory retention obligations apply, Art. 6(1)(c) GDPR.

7.2 Applicant and lead data (the customer is the controller)

Our customers use RecruitFlow to build funnels and landing pages through which applicants and leads get in touch. The data collected there — name, contact details, the answers given in the application or enquiry form, CRM status, notes — is stored in our infrastructure but processed exclusively on the customer's documented instructions.

We do not use this data for our own purposes, do not disclose it to uninvolved third parties, and do not use it to train AI models. Requests for access, rectification or erasure of this data are handled by the respective customer; we support them in doing so under the data processing agreement.

Legal basis for our relationship with the customer: Art. 28 GDPR together with the data processing agreement. The legal basis for the processing itself — for instance Art. 6(1)(b) GDPR, or the national employment data provisions applicable to a recruitment process — has to be established by the customer as controller.

8. Processors we use

We work with carefully selected service providers and have concluded data processing agreements under Art. 28 GDPR with them:

Vercel — hosting and delivery
Hosting and content delivery for the marketing site and the application, including technical server logs. Vercel Inc., USA, with EU delivery infrastructure.
Supabase — database and authentication
Storage of account, applicant and lead data, and management of logins. Server location: region eu-central-1 (Frankfurt, Germany).
Resend — transactional email
Delivery of system email, such as login messages and notifications about new applications or leads. Processed are the recipient address, subject, content and delivery status of the respective message.

9. International data transfers

Neese Consulting LLC is based in the United States, and some of the providers listed above are US companies or process data there. Transfers to a third country within the meaning of Chapter V GDPR therefore take place.

For these transfers we rely — depending on the provider — on the EU-US Data Privacy Framework where the provider is certified under it, and on the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Primary data storage nevertheless remains in the EU (Supabase, Frankfurt). Despite these safeguards, access by authorities in a third country cannot be entirely ruled out.

10. Retention

We keep personal data only for as long as the respective purpose requires:

11. Your rights under the GDPR

You have the following rights vis-à-vis the respective controller:

An informal message to support@neese-consulting.com is enough to exercise these rights. If your request concerns data that a customer processes through RecruitFlow — your application to a company, for example — please address that company as the controller; see section 2.

12. Data security

We apply technical and organisational measures in line with the state of the art to protect data against loss, manipulation and unauthorised access. These include encryption in transit via TLS/HTTPS, separation of access at database level (row-level security), role-based permissions, and limiting access to what is necessary. Our measures are adapted continuously as technology develops.

13. No automated decision-making

We do not carry out automated decision-making within the meaning of Art. 22 GDPR — that is, a decision producing legal effects or similarly significantly affecting a person, taken solely by automated means.

14. Changes to this policy

We update this policy when our processing, the providers we use, or the legal framework change. The current version is always available at start-recruitflow.neese-consulting.com/rechtliches/datenschutz.html.

Further legal texts

Provider details are set out in the Legal Notice, the contractual terms in our Terms and Conditions.