Privacy Policy
Last updated: August 2026
We take the protection of personal data seriously. Neese Consulting LLC is a US company operating internationally, and a substantial part of the customers we serve — together with the applicants and leads reaching them through RecruitFlow — are based in the European Union. We therefore run our processing to the GDPR standard and describe it here in the terms the GDPR uses: what data we process, for what purpose, on what legal basis, and which rights you have. Where the GDPR does not apply to you, the same description still tells you accurately what happens to your data.
This marketing site sets no tracking cookies, loads no analytics, and serves its typefaces from our own servers.
1. Controller
Neese Consulting LLC1914 Thomes Ave, Ste 2 #5296
Cheyenne, WY 82001, USA
Represented by: Neese Consulting LLC
Email: support@neese-consulting.com
Phone (DE): +49 571 73075360 · Phone (US): +1 307-278-7246
For any matter concerning data protection, write to support@neese-consulting.com. Requests are handled by the team operating RecruitFlow.
2. Scope and the two roles we hold
This policy covers the marketing site start-recruitflow.neese-consulting.com and the RecruitFlow application at recruitflow.neese-consulting.com. Which role we hold depends on whose data is being processed, and the distinction decides whom you should contact.
Two distinct roles:
a) Visitors to this website. For data processed when you visit this site, and for enquiries that reach us through it, Neese Consulting LLC is the controller within the meaning of Art. 4(7) GDPR.
b) Applicant and lead data inside the RecruitFlow app. Where a customer uses RecruitFlow to process data about applicants or leads, that customer alone decides on the purposes and means of the processing. The customer is the controller; Neese Consulting LLC acts as processor under Art. 28 GDPR, on the basis of a data processing agreement concluded with each customer. Data subjects — applicants in particular — should therefore address their requests primarily to the company they applied to. Where such a request reaches us instead, we forward it to the responsible customer.
3. Where data is stored
Customer, applicant and lead data is held primarily on servers in the European Union. Our database and authentication run on Supabase in region eu-central-1 (Frankfurt, Germany). Individual operations — delivery through our hosting provider's content delivery network, or the sending of transactional email — may additionally involve transfers to third countries; sections 8 and 9 describe these.
4. Data processed when you visit this website
4.1 Server log files
When you open one of our pages, our hosting provider automatically processes the technical data your browser transmits: IP address, date and time of the request, the page or file requested, volume of data transferred, HTTP status code, referrer URL, and browser and operating system details (user agent).
Purpose: delivering the site, keeping it technically operational, and detecting and defending
against attacks and abuse.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the secure and stable operation of the
service. This data is retained only for as long as those purposes require.
4.2 Contacting us
If you write to us by email or through a form, we process the details you provide — for example your name, email address, company and your message — in order to answer your enquiry.
Legal basis: Art. 6(1)(b) GDPR where the enquiry concerns the conclusion or performance of a contract; otherwise Art. 6(1)(f) GDPR — our legitimate interest in responding to enquiries. Enquiries are not used for advertising.
5. No analytics or tracking cookies
This marketing site sets no analytics or tracking cookies and embeds no analytics service. There is no audience measurement and no profiling, and no data is passed to third parties for advertising purposes. A cookie banner is therefore not required for this site.
Inside the application at recruitflow.neese-consulting.com, technically necessary storage mechanisms are used — a session token for login, for instance — without which the service cannot operate.
6. Web fonts
The Geist typefaces used on this site are self-hosted and delivered from our own infrastructure. No connection to Google Fonts or any other third-party font service is established when a page loads, and no data is transmitted to a font provider.
7. Data processed when using RecruitFlow
7.1 Customer and account data (we are the controller)
To provide access to the application we process data about the users on the customer's side: name, business email address, company affiliation, access and authentication data, roles and permissions, and technical usage data of the account.
Purpose: performing the contract, providing and securing access, support and billing.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for security and abuse prevention
additionally Art. 6(1)(f) GDPR; where statutory retention obligations apply, Art. 6(1)(c) GDPR.
7.2 Applicant and lead data (the customer is the controller)
Our customers use RecruitFlow to build funnels and landing pages through which applicants and leads get in touch. The data collected there — name, contact details, the answers given in the application or enquiry form, CRM status, notes — is stored in our infrastructure but processed exclusively on the customer's documented instructions.
We do not use this data for our own purposes, do not disclose it to uninvolved third parties, and do not use it to train AI models. Requests for access, rectification or erasure of this data are handled by the respective customer; we support them in doing so under the data processing agreement.
Legal basis for our relationship with the customer: Art. 28 GDPR together with the data processing agreement. The legal basis for the processing itself — for instance Art. 6(1)(b) GDPR, or the national employment data provisions applicable to a recruitment process — has to be established by the customer as controller.
8. Processors we use
We work with carefully selected service providers and have concluded data processing agreements under Art. 28 GDPR with them:
- Vercel — hosting and delivery
- Hosting and content delivery for the marketing site and the application, including technical server logs. Vercel Inc., USA, with EU delivery infrastructure.
- Supabase — database and authentication
- Storage of account, applicant and lead data, and management of logins. Server location: region eu-central-1 (Frankfurt, Germany).
- Resend — transactional email
- Delivery of system email, such as login messages and notifications about new applications or leads. Processed are the recipient address, subject, content and delivery status of the respective message.
9. International data transfers
Neese Consulting LLC is based in the United States, and some of the providers listed above are US companies or process data there. Transfers to a third country within the meaning of Chapter V GDPR therefore take place.
For these transfers we rely — depending on the provider — on the EU-US Data Privacy Framework where the provider is certified under it, and on the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Primary data storage nevertheless remains in the EU (Supabase, Frankfurt). Despite these safeguards, access by authorities in a third country cannot be entirely ruled out.
10. Retention
We keep personal data only for as long as the respective purpose requires:
- Account and contract data: for the duration of the contractual relationship and beyond it where statutory retention obligations apply.
- Enquiries: until the matter has been fully dealt with, unless retention obligations apply.
- Technical log data: only for as long as operation and security require.
- Applicant and lead data in the app: according to the instructions of the respective customer as controller; after the contract ends, customer data is returned or deleted as set out in the data processing agreement.
11. Your rights under the GDPR
You have the following rights vis-à-vis the respective controller:
- Access (Art. 15 GDPR) — to learn whether and which personal data concerning you we process.
- Rectification (Art. 16 GDPR) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17 GDPR) — to have your data deleted, unless retention obligations or other grounds prevent it.
- Restriction of processing (Art. 18 GDPR) — to have processing restricted in the cases the law provides for.
- Data portability (Art. 20 GDPR) — to receive your data in a structured, commonly used and machine-readable format, or to have it transmitted onward.
- Objection (Art. 21 GDPR) — to object, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR.
- Withdrawal of consent (Art. 7(3) GDPR) — to withdraw a consent you have given at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.
- Complaint to a supervisory authority (Art. 77 GDPR) — independently of the above, you may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement.
An informal message to support@neese-consulting.com is enough to exercise these rights. If your request concerns data that a customer processes through RecruitFlow — your application to a company, for example — please address that company as the controller; see section 2.
12. Data security
We apply technical and organisational measures in line with the state of the art to protect data against loss, manipulation and unauthorised access. These include encryption in transit via TLS/HTTPS, separation of access at database level (row-level security), role-based permissions, and limiting access to what is necessary. Our measures are adapted continuously as technology develops.
13. No automated decision-making
We do not carry out automated decision-making within the meaning of Art. 22 GDPR — that is, a decision producing legal effects or similarly significantly affecting a person, taken solely by automated means.
14. Changes to this policy
We update this policy when our processing, the providers we use, or the legal framework change. The current version is always available at start-recruitflow.neese-consulting.com/rechtliches/datenschutz.html.
Further legal texts
Provider details are set out in the Legal Notice, the contractual terms in our Terms and Conditions.