Privacy Information
for the website flino.com and the web-based application flino.io · Last updated: June 2026
This English text is a convenience translation. Only the German version at flino.com/datenschutz is legally binding; in the event of any discrepancy, the German wording prevails.
We are pleased that you are visiting our website and thank you for your interest in what we offer. Protecting your personal data is important to us. We want you to know when we collect which data, how we use it and what rights you have with regard to your data. In doing so, we naturally observe all applicable data protection laws, in particular the General Data Protection Regulation (GDPR).
This privacy information tells you which data we process when you use our website and our application, for which purposes this happens, and what options you have to object to the processing or to withdraw your consent.
The following information applies to visits to and use of our website. For processing beyond this (for example within a contractual relationship), you may receive separate information.
Controller and data protection contact
If you have questions about the processing of your personal data or would like to exercise your rights as a data subject, you can contact us at any time.
Controller for data processing within the meaning of the General Data Protection Regulation (GDPR):
Flino GmbH
Kolonnenstraße 8
10827 Berlin
Germany
Contact:
Phone: +49 30 826 831 87
Email: [email protected]
Purpose and legal bases of data processing
We process your personal data in order to enable you to use our website securely, conveniently and functionally, and to offer our services in line with your needs. Depending on how you use our online offerings, processing may be necessary for:
- the technical provision of the website (including IT security),
- responding to contact enquiries,
- the performance of contractual or pre-contractual measures,
- analysing usage behaviour for statistical purposes,
- optimising our content or our offering.
Processing only takes place if there is a corresponding legal basis – in particular:
- Art. 6(1)(a) GDPR (consent),
- Art. 6(1)(b) GDPR (contract or pre-contractual measures),
- Art. 6(1)(f) GDPR (legitimate interest, e.g. security, functionality or optimisation).
Where consent is required, we obtain it transparently via a cookie or consent management tool. You have the right to withdraw your consent at any time with effect for the future.
Note on consent as a legal basis
Where we obtain your consent for the processing of personal data, this is done on the basis of Art. 6(1)(1)(a) GDPR. You can withdraw consent you have given at any time with effect for the future. The withdrawal can be made informally, for example by email or post. You will find our contact details above under “Controller”.
To document your consent, we also process the following information:
- First and last name
- Email address
- IP address of the requesting device
- Date and time of consent
- Status and scope of the consent given
The legal basis for this processing is Art. 6(1)(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
The documentation data is stored for a period of three years. The period begins on the day your consent is given.
Protection of minors
Persons under the age of 16 may not transmit personal data to us without the prior consent of their parents or legal guardians. We do not request personal data from children and adolescents, do not knowingly store it and do not pass it on to third parties. If we become aware that personal data of minors has been collected without the consent of their legal guardians, it will be deleted immediately.
Categories of recipients of personal data
Within the framework of the statutory requirements, your personal data may be transmitted to the following categories of recipients:
Disclosure to external service providers
In certain cases we use external service providers who process personal data on our behalf. This takes place on the basis of the following legal bases:
- to fulfil statutory notification obligations under Art. 6(1)(c) GDPR, in particular towards authorities such as social insurance institutions, tax authorities or law enforcement agencies
- to carry out pre-contractual measures or to perform a contract under Art. 6(1)(b) GDPR, for example in payment processing
- to safeguard legitimate interests under Art. 6(1)(f) GDPR, e.g. through commissioned service providers such as hosting providers, data centres, credit institutions, print service providers or courier services
- on the basis of your express consent pursuant to Art. 6(1)(a) GDPR
If you take part in campaigns, prize draws or other services that we run together with partner companies, data may be passed on to these partners. In such cases we will inform you in advance and directly in connection with the respective service.
All external service providers are carefully selected, obliged to comply with the applicable data protection provisions and monitored regularly.
Where we commission third parties as processors, this is done exclusively on the basis of a contract pursuant to Art. 28 GDPR.
Data transfers to third countries
If we use functions or services from providers based outside the European Union (EU) or the European Economic Area (EEA), your personal data may be transferred to so-called third countries.
Such a transfer only takes place if the specific requirements of Art. 44 et seq. GDPR are met, in particular if
- an adequacy decision of the European Commission pursuant to Art. 45 GDPR exists,
- appropriate safeguards within the meaning of Art. 46 GDPR (e.g. EU standard contractual clauses) have been agreed,
- binding corporate rules are in place, or
- you have expressly consented to the transfer.
Note on data transfers to the USA
For certain US providers, an adequacy decision of the EU Commission pursuant to Art. 45 GDPR has been in place since July 2023 (EU-U.S. Data Privacy Framework).
US companies certified under the Data Privacy Framework thereby ensure an adequate level of data protection.
For transfers to other US service providers that are not certified, the data transfer takes place on the basis of appropriate safeguards, in particular the European Commission's standard contractual clauses or your express consent.
Where possible, we give preference to providers with server locations within the EU or the EEA.
A specific transfer to a third country only takes place if this is expressly stated in the context of individual processing operations.
Data erasure and storage period
We process and store personal data only for as long as is necessary to fulfil the respective purposes. As soon as the purpose of storage ceases to apply, the data is erased or blocked.
Storage beyond this may take place where it is required by law – for example due to retention obligations under commercial, tax or anti-money-laundering law (e.g. under the German Commercial Code (HGB), the Fiscal Code (AO) or the Money Laundering Act (GwG)).
In these cases, erasure takes place after the statutory retention periods have expired, provided there is no further legal basis for the processing.
Personal data may also be stored for the duration of statutory limitation periods where this is necessary for the establishment, exercise or defence of legal claims.
The standard limitation period is generally three years but may, in individual cases, be up to 30 years.
Longer storage only takes place where it is necessary to fulfil contractual or statutory obligations.
Rights as a data subject
As a data subject within the meaning of the GDPR, you have various rights which you can assert against us at any time:
Right of access (Art. 15 GDPR): You have the right to request information about the personal data we process, including the purposes of processing, categories of recipients, the envisaged storage period and your further rights in connection with this processing.
Right to rectification (Art. 16 GDPR): You can request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
Right to erasure (Art. 17 GDPR): You have the right to request the erasure of the personal data we hold about you, provided that no statutory retention obligations or other legal grounds preclude erasure.
Right to restriction of processing (Art. 18 GDPR): Under certain conditions you can request the restriction of the processing of your personal data.
Right to data portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit this data to another controller.
Right to object to processing (Art. 21 GDPR): You can object at any time to the processing of your personal data on grounds relating to your particular situation. This applies in particular to data processing based on Art. 6(1)(f) GDPR.
Right to withdraw consent given (Art. 7(3) GDPR): Where we process your data on the basis of your consent, you have the right to withdraw this consent at any time with effect for the future.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): If you believe that the processing of your personal data infringes the GDPR, you can lodge a complaint with a data protection supervisory authority. The competent authority is generally the supervisory authority of your place of residence or of our registered office.
Provision of the website and creation of log files
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data is collected:
- IP address of the user
- Date and time of access
- Page/file accessed
- Website from which the access was made (referrer URL)
- Browser type and version used
- User's operating system
- User's internet service provider
The data is also stored in our system's log files. This data is not stored together with other personal data of the user.
Legal basis for the processing: The legal basis for the temporary storage of the data and the log files is Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the functionality of the website, the technical optimisation of the content and presentation, and safeguarding the security of our information technology systems (e.g. to fend off attacks).
Purpose of the processing: The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this, the user's IP address must remain stored for the duration of the session. Beyond this, storage in log files takes place in order to ensure the functionality of the website. The data is not analysed for marketing purposes in this context.
Storage period: The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. Where data is collected to provide the website, this is the case when the respective session has ended. Log files are generally erased after no more than 7 days. Storage beyond this is possible provided that users' IP addresses have been anonymised.
Right to object and to seek erasure: The collection of data to provide the website and the storage of data in log files are strictly necessary for the operation of the website. There is therefore no possibility for the user to object.
Use of cookies
Our website uses cookies. These are small text files that are stored on your device when you visit a website. They enable certain functions and serve to improve the user experience.
We use technically necessary cookies to ensure the basic functionality of the website (e.g. login function, language settings, shopping cart). In addition, with your consent, we use cookies for statistics, analytics and marketing purposes in order to evaluate the use of our website and optimise our offering.
Technically necessary cookies
These cookies are required for the operation of the website and enable basic functions such as page navigation and access to secure areas. Without these cookies, the website cannot function properly. Legal basis: Art. 6(1)(f) GDPR – legitimate interest in the functionality and security of the website.
Cookies for statistics, analytics and marketing
These cookies are only set with your consent. They help us to understand visitor behaviour, improve content and display personalised advertising. Legal basis: Art. 6(1)(a) GDPR – your voluntary consent, which you can withdraw at any time via the website's cookie settings.
Cookie settings
When you first visit our website, a cookie banner appears through which you can control the use of individual cookie categories. Your selection is saved and can be adjusted or withdrawn at any time via the cookie settings.
Storage period and erasure
Cookies are stored for varying lengths of time. Session cookies are automatically deleted when the browser is closed; persistent cookies remain on your device until they expire or you delete them manually.
Objecting to and managing cookies
You can delete cookies at any time via your browser settings or prevent them from being stored. You can find out how this works on the help pages of the respective browser providers:
- Google Chrome: support.google.com/chrome/answer/95647
- Mozilla Firefox: support.mozilla.org
- Apple Safari: support.apple.com
- Microsoft Edge: support.microsoft.com
- Opera: help.opera.com
Web analytics tools
We use various web analytics tools on our website in order to evaluate visitor behaviour statistically and to optimise our online offering technically and in terms of content.
These tools help us understand how users interact with our website – for example, which pages are accessed particularly often, how long visitors stay, or which sources they use to reach our website. The insights gained serve exclusively to improve the usability and efficiency of our web presence.
Depending on the tool used, technical data such as IP address, browser information, referrer URL, device used or click behaviour may be processed. Personal data is processed on the basis of your consent pursuant to Art. 6(1)(a) GDPR or our legitimate interest pursuant to Art. 6(1)(f) GDPR in a user-friendly and optimised website.
Below we inform you in detail about the web analytics tools we use.
Google Analytics 4 (GA4)
On our website we use the web analytics service Google Analytics 4 (GA4), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics 4 serves to analyse user behaviour on our website in order to improve its performance and usability. Visitor interactions (e.g. page views, clicks, scrolling or time spent) are recorded and evaluated statistically.
Google Analytics 4 uses cookies and similar technologies. Among other things, the following data may be processed: browser and device information, operating system, referrer URL, time of access, interactions on the website and approximate location data (e.g. country). According to Google, the IP address is not stored by Google Analytics 4.
Google processes the collected data on our behalf in order to produce evaluations of the use of our website.
It cannot be ruled out that data is transmitted to servers of Google LLC in the USA. Google is certified under the EU-U.S. Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Art. 45 GDPR exists for data transfers to the USA.
The legal basis for the use of Google Analytics 4 is your consent pursuant to Art. 6(1)(a) GDPR. Consent can be withdrawn at any time via the website's cookie settings.
Further information on data processing by Google is available at: policies.google.com/privacy
PostHog
On our website we use the analytics service PostHog. The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA.
PostHog enables us to analyse user behaviour on our website and within our application. This allows us to understand how users use our offerings, which functions are used and where there is room for optimisation. In particular, information about pages accessed, interactions, click behaviour, technical information about the device used and further usage data may be processed.
According to the provider, data processing for European customers takes place via infrastructure within the European Union. However, a transfer of personal data to the USA cannot be entirely ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular through the conclusion of standard contractual clauses.
Processing takes place exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG (German Digital Services Data Protection Act). Consent can be withdrawn at any time with effect for the future.
Further information on data processing by PostHog is available at: posthog.com/privacy
Fan pages on social media websites
We maintain fan pages on social networks and process personal data in this context in order to communicate with the users active there or to provide information about us. We would like to point out that when you visit our fan pages, your data may be processed outside the European Union. The operators of the respective social networks are responsible for this. You can find a detailed description of the respective forms of processing and the options for objecting (e.g. opt-out) in the privacy policies of the operators of the respective social networks.
Please note that despite joint responsibility with the platform operators, we have no complete influence over the data processing carried out by the social networks. We recommend that you also inform yourself directly with the platforms.
We operate a Facebook fan page for our company on the social network facebook.com. When you visit and use the Facebook fan page, Facebook may evaluate your usage behaviour and provide us with information derived from it (“page insights”). This information is used for the purposes of the economic optimisation and needs-based design of our web presence and our services. The categories of data processed here are master data, contact data, content data, usage data and connection data.
The recipient of the data is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as joint controller within the meaning of Art. 26 GDPR.
The legal basis for processing the data as described here arises from our legitimate interest (Art. 6(1)(f) GDPR) in an effective external presentation and communication via social media.
Facebook is generally responsible for implementing your data subject rights in connection with the processing of personal data on our Facebook fan page. Facebook provides information on this at facebook.com/legal/terms/information_about_page_insights_data and facebook.com/about/privacy. You can also assert your rights against us. In that case, we will forward your request to Facebook without delay.
We operate an Instagram fan page for our company on the social network instagram.com. When you visit and use the Instagram fan page, Instagram may evaluate your usage behaviour and provide us with information derived from it (“page insights”). This information is used for the purposes of the economic optimisation and needs-based design of our web presence and our services. The categories of data processed here are master data, contact data, content data, usage data and connection data.
The recipient of the data is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as joint controller within the meaning of Art. 26 GDPR.
The legal basis for processing the data as described here arises from our legitimate interest (Art. 6(1)(f) GDPR) in an effective external presentation and communication via social media.
Instagram is generally responsible for implementing your data subject rights in connection with the processing of personal data on our Instagram fan page. Instagram provides information on this at: privacycenter.instagram.com/policy. You can also assert your rights against us. In that case, we will forward your request to Instagram without delay.
We operate a LinkedIn fan page for our company on the social network linkedin.com. When you visit and use our LinkedIn fan page, LinkedIn may evaluate your usage behaviour and make information derived from it available to us (“page insights”). This information is used for the purposes of the economic optimisation and needs-based design of our web presence and our services. The categories of data processed here are master data, contact data, content data, usage data and connection data.
The recipient of the data is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, as joint controller within the meaning of Art. 26 GDPR.
The legal basis for processing the data is our legitimate interest pursuant to Art. 6(1)(f) GDPR in effective communication and external presentation via social media.
LinkedIn is generally responsible for implementing your data subject rights in connection with the processing of personal data on our LinkedIn fan page. LinkedIn provides information on this at linkedin.com/legal/privacy-policy and linkedin.com/legal/l/dpa. You can also assert your rights against us. In that case, we will forward your request to LinkedIn without delay.
YouTube
We operate a YouTube channel for our company on the video portal youtube.com. When you visit and use our YouTube channel, Google may evaluate your usage behaviour and make information derived from it available to us (“YouTube Analytics” or “page insights”). This information is used for the purposes of the economic optimisation and needs-based design of our web presence and our content. The categories of data processed here are master data, contact data, content data, usage data and connection data.
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as joint controller pursuant to Art. 26 GDPR.
The legal basis for processing the data arises from our legitimate interest pursuant to Art. 6(1)(f) GDPR in an informative and targeted external presentation via social media.
Google is generally responsible for implementing your data subject rights in connection with the processing of personal data on our YouTube channel. Further information on this is available at: policies.google.com/privacy. You can also assert your rights against us. We will then forward your request to Google without delay.
Cloud services
We use various cloud services to store, manage and collaboratively edit data. These enable us to process data securely, flexibly and independently of location, and to exchange information efficiently with customers, business partners and employees.
Personal data is stored on the servers of the respective providers and may – depending on the provider – also be transferred to locations outside the European Union. Such a transfer only takes place if appropriate safeguards pursuant to Art. 46 GDPR (e.g. standard contractual clauses) are in place or an adequacy decision of the European Commission exists.
The processing of personal data in connection with the use of cloud services takes place on the basis of Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in secure and efficient data management).
We use the cloud services listed below:
Google Drive
For storing, managing and sharing documents and files we use the cloud service Google Drive provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Drive enables us to store and organise data securely and to share it with authorised persons. This may also involve personal data arising in the context of our business relationship or communication with you.
Data processing takes place for the purpose of organisation, data management and efficient collaboration pursuant to Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in secure and structured data management).
Google may also process personal data on servers outside the European Union, in particular in the USA. The transfer takes place on the basis of the European Commission's standard contractual clauses pursuant to Art. 46 GDPR in order to ensure an adequate level of data protection.
The data is erased as soon as it is no longer required for the stated purposes or statutory retention periods have expired.
Further information on data processing by Google Drive is available at: policies.google.com/privacy
Microsoft 365 / Microsoft Graph
Within our application we offer the option of connecting Microsoft 365 accounts to the application. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The parent company is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA.
The integration enables the receipt and sending of emails via a connected Microsoft 365 account as well as the processing of the communication data required for this. In particular, email metadata such as sender, recipient, subject, times of sending and receipt, and email content may be processed to the extent necessary to provide the respective functions.
Processing takes place exclusively to provide the functions requested by the user within the application, in particular to manage communication processes, to detect replies and to create and carry out follow-up processes.
The data is not used for advertising purposes. Data processed via the Microsoft interfaces is used exclusively to provide the functions requested by the user.
Processing takes place on the basis of Art. 6(1)(b) GDPR insofar as it is necessary for the performance of the usage agreement, and additionally on the basis of Art. 6(1)(f) GDPR due to our legitimate interest in providing our services efficiently and in a user-friendly manner.
A transfer of personal data to third countries, in particular to the USA, cannot be ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of standard contractual clauses, or on the basis of an adequacy decision pursuant to Art. 45 GDPR.
Further information on data processing by Microsoft is available at: privacy.microsoft.com/en-us/privacystatement
Supabase
For storing and managing data within our application we use the service Supabase. The provider is Supabase, Inc., 970 Toa Payoh North #07-04, Singapore.
Supabase serves as the database and backend infrastructure for our application. In particular, the data processed in the course of using the application is stored, managed and made available for the respective functions via the service.
In the course of use, account data, usage data, communication data, quote data and other information processed by the user within the application may be stored and processed.
According to the provider, data processing takes place via server locations within the European Union. However, a transfer of personal data to third countries cannot be entirely ruled out. Where personal data is transferred to third countries, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of the European Commission's standard contractual clauses.
Processing takes place on the basis of Art. 6(1)(b) GDPR insofar as it is necessary for the performance of the contractual relationship, and additionally on the basis of Art. 6(1)(f) GDPR due to our legitimate interest in providing our application securely and efficiently.
Further information on data processing by Supabase is available at: supabase.com/privacy
Functional services / processing of user input
On our website we use functions for processing user input in order to provide certain content and services. External service providers may also be used, processing the entered data on our behalf.
Deepgram (speech-to-text)
On our website we use a speech-to-text function provided by Deepgram. The provider is Deepgram, Inc., 665 Third Street, Suite 150, San Francisco, CA 94107, USA.
The speech-to-text function enables users to convert spoken content into text, for example to enter notes or summaries of phone calls directly into the system. This makes it easier to capture information and optimises further processing within our application.
In the course of use, the voice data entered by the user is transmitted to Deepgram and automatically converted into text there. Personal data may also be processed if it forms part of the spoken content. In addition, technical data such as IP address, device information and usage data may be processed.
According to the provider, processing generally takes place via infrastructure within the European Union. However, a transfer of personal data to the USA cannot be entirely ruled out.
Processing takes place to provide the requested function on the basis of Art. 6(1)(b) GDPR, insofar as use takes place within the framework of a contract, and additionally on the basis of our legitimate interest in a user-friendly and efficient design of our services pursuant to Art. 6(1)(f) GDPR.
A transfer of personal data to third countries, in particular to the USA, cannot be ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of standard contractual clauses.
Further information on data processing by Deepgram is available at: deepgram.com/privacy
Google Cloud Vertex AI
On our website and within our application we use Google Cloud Vertex AI. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Cloud Vertex AI enables the AI-assisted analysis and processing of content as well as the creation of copy and optimisation suggestions in connection with the use of our application. The function is used in particular to support quote processes, follow-up communication and other workflows within the application.
In the course of use, the content entered by the user and the technical data required for processing may be processed. Personal data may also be affected if it forms part of the content processed by the user.
Processing takes place to provide the requested function on the basis of Art. 6(1)(b) GDPR, insofar as use takes place within the framework of a contract, and additionally on the basis of our legitimate interest in a user-friendly and efficient design of our services pursuant to Art. 6(1)(f) GDPR.
According to the provider, processing generally takes place within regions selected by us. However, a transfer of personal data to third countries, in particular to the USA, cannot be entirely ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of standard contractual clauses, or on the basis of an adequacy decision pursuant to Art. 45 GDPR.
Further information on data processing by Google is available at: policies.google.com/privacy
Google Gemini API
On our website and within our application we use the Google Gemini API. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
The Google Gemini API enables the AI-assisted processing of user input as well as the automated creation of replies, copy suggestions and other content. The function is used in particular within our support and assistance system and to support various functions within the application.
In the course of use, the content entered by the user is transmitted to Google's systems and processed there. Personal data may also be processed if it forms part of the input. In addition, technical data such as IP address, device information and usage data may be processed.
Processing takes place to provide the requested function on the basis of Art. 6(1)(b) GDPR, insofar as use takes place within the framework of a contract, and additionally on the basis of our legitimate interest in a user-friendly and efficient design of our services pursuant to Art. 6(1)(f) GDPR.
A transfer of personal data to third countries, in particular to the USA, cannot be ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of standard contractual clauses, or on the basis of an adequacy decision pursuant to Art. 45 GDPR.
Further information on data processing by Google is available at: policies.google.com/privacy
Fonio AI
Within our application we use the service Fonio AI to provide and support AI-assisted telephony functions. The provider is Fonio AI GmbH, Germany.
Fonio AI enables the automated receipt, processing and answering of telephone calls as well as the support of communication processes through the use of artificial intelligence. In particular, call content, contact data, communication data and other information transmitted during a phone call may be processed.
Processing takes place exclusively to provide the functions requested by the user and to carry out and optimise communication processes within our application.
Insofar as voice data is processed in the course of use, it may be analysed automatically and processed to provide the respective function. Personal data may also be affected if it forms part of the transmitted content.
Processing takes place on the basis of Art. 6(1)(b) GDPR insofar as it is necessary for the performance of the contractual relationship, and additionally on the basis of Art. 6(1)(f) GDPR due to our legitimate interest in providing our services efficiently and in a user-friendly manner.
Personal data is only transferred to third parties insofar as this is necessary to provide the respective function or there is a legal obligation to do so.
Further information on data processing by Fonio AI is available at: fonio.ai/privacy
Ways to contact us
We offer various ways to get in touch with us via our website. Below we inform you about the respective communication channels and the data processing that takes place.
If you contact us by email, the personal data you transmit is used exclusively to process your enquiry. Providing a valid email address is necessary so that we can assign and answer your enquiry. Any further information is provided voluntarily.
Data processing takes place on the basis of Art. 6(1)(b) GDPR insofar as the enquiry relates to the performance of a contract or serves to carry out pre-contractual measures. In all other cases, processing takes place on the basis of Art. 6(1)(f) GDPR, as we have a legitimate interest in handling enquiries appropriately.
The data you transmit remains with us until the purpose of storage ceases to apply or you ask us to erase it, provided there are no statutory retention obligations.
Contact form
If you send us a message via the contact form provided on our website, the data you enter is used exclusively to process your enquiry. As a rule, a valid email address is required so that we can assign and answer your enquiry. Further information can be provided voluntarily.
The data transmitted via the form is transferred using SSL encryption. It is not passed on to third parties.
The legal basis for the processing is Art. 6(1)(b) GDPR insofar as the enquiry relates to the performance of a contract or serves to carry out pre-contractual measures. In all other cases, processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate handling of enquiries received via the contact form.
Telephone
If you contact us by telephone, the personal data you transmit is used exclusively to deal with your request. Which data is collected depends on the content of your call and the information you provide.
The data is processed on the basis of Art. 6(1)(b) GDPR insofar as the contact relates to the performance of a contract or pre-contractual measures. In all other cases, processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the efficient and appropriate handling of incoming enquiries.
The data you transmit during the phone call is stored only for as long as is necessary to deal with your request, provided there are no statutory retention obligations.
Newsletter
You can subscribe to our newsletter via our website in order to receive regular information about current topics, offers or news. Below we inform you about the data processing that takes place.
Resend
For sending system and transactional messages and, where applicable, newsletters in future, we use the service Resend. The provider is Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
If you sign up for our newsletter or receive emails from us, the personal data required for this – in particular your email address and, where applicable, further information you provide – is processed via Resend's systems.
Processing takes place in order to send newsletters and information about our services and for the technical delivery and management of email dispatch.
A transfer of personal data to the USA cannot be ruled out. The transfer takes place on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular through the conclusion of standard contractual clauses.
Where our newsletter is sent, processing is based on your consent pursuant to Art. 6(1)(a) GDPR. Where system or transactional messages are sent in connection with an existing contractual relationship, processing is based on Art. 6(1)(b) GDPR.
Further information on data processing by Resend is available at: resend.com/legal
Customer account and order processing
Customers can create a personal customer account and place orders on our website. Below we inform you about the data collected and the purposes of processing.
General registration function
On our website we offer users the option of registering in order to use certain functions or content. The personal data requested in the registration form, such as name, email address and, where applicable, further voluntary information, is collected and stored.
Registration serves to give you access to protected areas or personalised content. The data entered during registration is used exclusively for the purpose for which you registered.
The legal basis for the processing is Art. 6(1)(b) GDPR insofar as registration is necessary for the performance of a contract or to carry out pre-contractual measures. In all other cases, processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a user-friendly and secure online platform.
You can have your registration deleted at any time, provided there are no statutory retention obligations.
Order processing
To book and use our services, we process the personal data you provide during registration or when concluding the contract, in particular name, billing address, email address, telephone number and payment information.
This data is processed to initiate, perform and administer the contractual relationship, to provide the booked services, to process payments and to communicate in connection with your user account and the services you use. Your data is only passed on to third parties insofar as this is necessary to perform the contract, for example to payment service providers or technical service providers.
The legal basis for the processing is Art. 6(1)(b) GDPR. The data is erased as soon as it is no longer required to perform the contractual relationship and there are no statutory retention obligations.
Opening a customer account
If you create a customer account within our application, we collect and store the personal data you provide, in particular name, email address, company data and other information required to use the application or to perform the contractual relationship.
The customer account enables you in particular to use the application, manage your account settings, access your stored data and make use of the functions and services we offer.
The data is processed on the basis of Art. 6(1)(b) GDPR, as it is necessary to carry out pre-contractual measures and to perform the contractual relationship. Your data is only passed on to third parties insofar as this is necessary to perform the contract.
You can request the deletion of your customer account at any time. In that case, the personal data stored in connection with your customer account will be erased, provided that no statutory retention obligations or other legal grounds preclude erasure.
Registration function for concluding a contract
On our website we offer users the option of registering in order to conclude contracts for our services. During registration, the personal data requested in the form, such as name, address, email address and, where applicable, payment information, is collected and stored.
Registration is necessary in order to handle the conclusion of the contract technically and organisationally, to provide access to the contractual content and to enable communication within the contractual relationship. The data is only passed on to third parties insofar as this is necessary to perform the contract.
The legal basis for the processing is Art. 6(1)(b) GDPR, as registration serves to prepare, perform or administer a contractual relationship.
After the contract ends or the user account is deleted, the data is erased, provided there are no statutory retention obligations.
Payment service providers
If you order services via our website, the storage and processing of personal data is necessary in order to perform the contract. In addition, we collect and store the payment method you select during the ordering process.
The legal basis for the processing of personal data is Art. 6(1)(f) GDPR.
If you select a payment service provider as the payment method, you will be redirected directly to the website of the respective payment service provider during the payment process. The data you enter on the website of the respective payment service provider is not collected, processed or stored by us. The privacy provisions of the respective payment service provider apply.
Stripe
On our website we offer payment processing via the service Stripe, provided by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. The parent company is Stripe Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA.
Stripe enables the processing of online payments by credit card, debit card or other payment methods. If you select payment via Stripe, the personal data required for payment processing is transmitted to Stripe. This includes name, address, email address, payment information (e.g. credit card number, expiry date, CVC), IP address, transaction amount and, where applicable, further technical metadata.
The data is processed for the purposes of payment processing, fraud prevention and the fulfilment of contractual obligations. Stripe may pass the data on to external service providers or banks for identity and credit checks.
A transfer of personal data to third countries, in particular to the USA, may take place. The transfer takes place on the basis of the EU Commission's standard contractual clauses pursuant to Art. 46 GDPR, which are intended to ensure an adequate level of data protection.
The legal basis for the processing of the data is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in secure and efficient payment processing).
Further information on data processing by Stripe is available at: stripe.com/privacy
Chat widgets for customer interaction
On our website we use chat widgets in order to enable users to communicate with us directly and quickly. The data entered in the course of use may be processed to handle enquiries and to improve our service.
Support chatbot (in-house development)
On our website we provide an integrated support chatbot which serves to communicate with users and answer enquiries. The chatbot is embedded directly in our application and operated by us.
Via the chatbot, users can enter messages in order to receive support in using our services or to clarify questions. In the course of use, the content entered by the user and technical data such as IP address, timestamp and device information are processed. If users voluntarily provide personal data in the chat, this is also processed.
Processing takes place exclusively for the purpose of providing and improving our support offering and handling user enquiries efficiently.
The data is generally not passed on to third parties unless this is necessary to handle the enquiry or there is a legal obligation to do so.
Processing takes place on the basis of Art. 6(1)(b) GDPR insofar as use takes place in connection with the performance of a contract, and additionally on the basis of our legitimate interest in efficient and user-friendly communication pursuant to Art. 6(1)(f) GDPR.
The data is stored only for as long as is necessary to handle the respective enquiry or as statutory retention obligations exist.
Videos, audio and images
We embed multimedia content such as videos, audio files and images on our website in order to make our online offerings more illustrative and informative. External services or platforms that provide or play this content may be used.
When a page with embedded media is accessed, technical data such as IP address, browser information, referrer URL, operating system, device information and timestamp may be transmitted, depending on the provider. This is necessary so that the corresponding content can be transmitted to and displayed on your device.
Where third-party services are used for this, data processing may also take place on servers outside the European Union, in particular in the USA. In such cases, the transfer takes place on the basis of the standard contractual clauses pursuant to Art. 46 GDPR in order to ensure an adequate level of data protection.
The legal basis for embedding videos, audio and image content is your consent pursuant to Art. 6(1)(a) GDPR, insofar as the content is loaded via external providers, or Art. 6(1)(f) GDPR in the case of our legitimate interest in an appealing and user-friendly presentation of our website.
Below we inform you about the services and platforms used on our website in the area of videos, audio and images.
Adobe Stock
On our website we use image material from the service Adobe Stock, provided by Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. The parent company is Adobe Inc., 345 Park Avenue, San Jose, CA 95110-2704, USA.
Adobe Stock serves to provide and license photos, illustrations, videos and graphics used for the visual design of our website. When pages containing embedded Adobe Stock content are accessed, a connection to Adobe's servers may be established in order to provide the media files. Technical data such as IP address, browser information, operating system, referrer URL and timestamp may be processed in this context.
Adobe may process the data on servers in third countries, in particular in the USA. The transfer takes place on the basis of the EU Commission's standard contractual clauses pursuant to Art. 46 GDPR, which are intended to ensure an adequate level of data protection.
The legal basis for the use of Adobe Stock is Art. 6(1)(f) GDPR. Our legitimate interest lies in the appealing and professional presentation of our website through lawfully licensed media content.
Further information on data processing by Adobe is available at: adobe.com/privacy.html
Flaticon
On our website we use graphics and icons from the service Flaticon, provided by Freepik Company S.L., Calle Malaga 3, 29015 Málaga, Spain.
The service serves the appealing and consistent visual design of our website through the integration of licensed icons and illustrations.
When you access our website, your browser may establish a connection to Flaticon's servers in order to display the graphics. Technical data such as browser type, operating system, language settings, date and time of the page view and your IP address may be transmitted in this context. This data is necessary in order to display the icons correctly. We do not store any personal data.
Processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the visually appealing and consistent presentation of our website. If the integration takes place via a cookie or consent tool, the legal basis is Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future.
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected.
Further information on the provider's data protection is available at: flaticon.com/privacy-policy
YouTube (extended data protection mode)
We embed videos from the YouTube platform, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, on our website.
The videos are embedded in what is known as extended data protection mode. As a result, information about visitors to our website is only transmitted to YouTube once the video is actively played.
When a video is played, a connection to YouTube's servers is established and it is transmitted which page you have visited. If you are logged into your Google account at the same time, YouTube can assign your browsing behaviour directly to your personal profile. You can prevent this by logging out of your Google account before visiting our website.
YouTube may use cookies or similar technologies to collect information about user behaviour. This data is generally transmitted to servers of Google LLC in the USA and stored there. The transfer takes place on the basis of the standard contractual clauses pursuant to Art. 46 GDPR; in addition, Google is certified under the EU-U.S. Data Privacy Framework.
The legal basis for embedding YouTube in extended data protection mode is Art. 6(1)(a) GDPR, provided you have given us your consent via the cookie or consent management tool. Without consent, no YouTube videos are loaded.
Further information on data processing by YouTube is available at: policies.google.com/privacy
Affiliate marketing
On our website we use affiliate marketing from the following providers in order to market our offering optimally:
Tapfiliate (affiliate marketing)
On our website we use the affiliate tracking tool Tapfiliate. The provider is Tapfiliate B.V., Keizersgracht 391 A, 1016 EJ Amsterdam, Netherlands.
Tapfiliate enables us to operate partner programmes and to track the success of affiliate links. If a user reaches our website via such a link, Tapfiliate can recognise this and assign it to the respective partner. Cookies or comparable technologies enabling the recognition of the user are used for this purpose.
In the course of use, the following data in particular may be processed: IP address, referrer URL, pages accessed, time of access and, where applicable, transaction data. Processing takes place for the purpose of settling commissions and analysing and optimising our affiliate marketing.
Processing takes place on the basis of Art. 6(1)(a) GDPR, where consent is obtained via the cookie banner, and additionally on the basis of our legitimate interest in the economic marketing of our services pursuant to Art. 6(1)(f) GDPR.
A transfer of data to third countries cannot be ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of standard contractual clauses.
Further information on data processing by Tapfiliate is available at: tapfiliate.com/privacy
Conversion optimisation tools
We use various conversion optimisation tools on our website. These serve to analyse user behaviour, improve usability and increase the effectiveness of our online marketing measures.
For example, click behaviour, time spent, scroll depth and interactions with individual elements of the website are evaluated in order to better adapt content and functions to visitors' needs.
Depending on the tool, cookies or similar technologies may be used to recognise returning users or to enable statistical evaluations. Personal data is generally processed on the basis of your consent pursuant to Art. 6(1)(a) GDPR, insofar as it takes place for analytics or marketing purposes, or on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR in a user-friendly and economically optimised website.
Below we inform you in detail about the conversion optimisation tools we use.
Facebook conversion pixel with Custom Audiences and Facebook marketing services
On our website we use the Facebook pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The parent company is Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA.
The Facebook pixel makes it possible to track the behaviour of visitors to our website after they have been redirected to our website by clicking on a Facebook ad. This allows us to evaluate the effectiveness of our Facebook ads for statistical and market research purposes and to optimise future advertising measures. Via the pixel, so-called Custom Audiences are formed in order to display interest-based advertising to website visitors within the Facebook network.
When the Facebook pixel is used, technical and behavioural data (e.g. IP address, browser information, referrer URL, timestamp, pages visited and actions performed) is collected and transmitted to Meta. Meta may link this information with existing Facebook or Instagram user accounts. If you have an account with Meta and are logged in there, Meta can assign the collected data to your profile and use it for its own advertising purposes.
Meta may also transfer personal data to servers in third countries, in particular to the USA. The transfer takes place on the basis of the EU Commission's standard contractual clauses pursuant to Art. 46 GDPR, which are intended to ensure an adequate level of data protection.
The legal basis for the use of the Facebook pixel is your consent pursuant to Art. 6(1)(a) GDPR. Consent can be withdrawn at any time via the website's cookie settings.
Further information on data processing by Meta is available at: facebook.com/privacy/policy
LinkedIn Insight Tag
On our website we use the LinkedIn Insight Tag. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
The LinkedIn Insight Tag enables us to evaluate the use of our website, measure conversions and display interest-based advertising within the LinkedIn network. In particular, information about page views, interactions, technical information about the device used, the IP address and further usage data may be processed.
LinkedIn may link the collected data with an existing LinkedIn user account and process it for its own purposes. We have no influence over LinkedIn's further data processing.
A transfer of personal data to third countries, in particular to the USA, cannot be ruled out. The transfer takes place on the basis of appropriate safeguards pursuant to Art. 46 GDPR. Insofar as LinkedIn is certified under the EU-U.S. Data Privacy Framework, the transfer additionally takes place on the basis of the European Commission's adequacy decision pursuant to Art. 45 GDPR.
Processing takes place exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time with effect for the future.
Further information on data processing by LinkedIn is available at: linkedin.com/legal/privacy-policy
Content delivery networks (CDN)
On our website we use a content delivery network (CDN) in order to optimise the loading speed and worldwide accessibility of our website. A CDN is a network of geographically distributed servers that deliver content to users more quickly and efficiently. The transfer of information between your browser and our website is routed via this network.
By using the CDN we can increase the performance of our website, in particular with regard to loading times and the availability of content, regardless of your location. The CDN stores copies of static content such as images, JavaScript and CSS files, which are then loaded from a server near the user.
No personal data is collected for the use of the CDN; however, IP addresses may be processed to identify and optimise data traffic. Further information on data use and the privacy policy of the CDN provider can be found in their privacy provisions.
Cloudflare
On our website we use the content delivery network (CDN) of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, in order to optimise the loading speed and worldwide accessibility of our website. Cloudflare is a global network that improves the performance and security of our website by enabling the exchange of information between your browser and our website via a distributed network of servers.
By using Cloudflare we can increase the performance of our website, in particular with regard to loading times and the availability of content, regardless of your location. Cloudflare stores copies of static content such as images, JavaScript and CSS files, which are then loaded from a server near the user.
In doing so, Cloudflare processes your IP address to identify and optimise data traffic. Further information on data use and Cloudflare's privacy policy is available at: cloudflare.com/privacypolicy
Cookie consent management tools
On our website we use so-called cookie consent management tools in order to record, manage and document our visitors' consent to the use of cookies and similar technologies in compliance with data protection law.
These tools ensure that cookies are only set in accordance with the consent given and enable users to change or withdraw their consent at any time. Technically necessary cookies are used to store the selected consent status and to take it into account automatically on future visits.
The data arising in this context is processed pursuant to Art. 6(1)(c) GDPR to fulfil legal obligations and Art. 6(1)(f) GDPR on the basis of our legitimate interest in the transparent and legally compliant management of consent.
Below we inform you about the cookie consent management tools used on our website.
Cookiebot (consent management tool)
On our website we use the consent management tool Cookiebot. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.
Cookiebot enables us to obtain, manage and document users' consent to the storage of cookies and the use of certain technologies. When our website is accessed, a cookie is set in order to store the consent given and its withdrawal.
In the course of use, the following data in particular is processed: IP address (truncated or anonymised), date and time of consent, browser information, URL of the website, and the consent status. Processing takes place in order to fulfil statutory obligations to obtain and document consent.
Processing takes place on the basis of Art. 6(1)(c) GDPR in conjunction with Section 25(1) TDDDG, insofar as the storage of information on the device or access to it requires consent, and additionally on the basis of Art. 6(1)(f) GDPR for the legally compliant documentation of consent.
A transfer of data to third countries cannot be ruled out. In such a case, the transfer takes place on the basis of appropriate safeguards within the meaning of Art. 46 GDPR, in particular through the conclusion of standard contractual clauses.
Further information on data processing by Cookiebot is available at: cookiebot.com/en/privacy-policy
External hosting
We use external hosting and infrastructure service providers to provide our website and application.
The website flino.com is provided via the infrastructure of Cloudflare. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare serves in particular to provide the website, optimise loading times and ensure the stability and security of our online offerings.
The application flino.io is provided via the infrastructure of the provider Lovable. In the course of hosting, the personal data required to operate the application is processed. This includes in particular IP addresses, access times, technical log data and all data processed or entered in the course of using the application.
Processing takes place for the purpose of providing and securely operating our website and application.
Processing takes place on the basis of Art. 6(1)(f) GDPR due to our legitimate interest in the secure, stable and efficient provision of our online offerings, and on the basis of Art. 6(1)(b) GDPR insofar as processing is necessary to perform contractual services.
In connection with the use of the aforementioned services, processing of personal data outside the European Union, in particular in the USA, cannot be ruled out. In such cases, the transfer takes place on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular through the conclusion of standard contractual clauses, or on the basis of an adequacy decision pursuant to Art. 45 GDPR, insofar as one exists for the respective provider.
Further information on data processing by Cloudflare is available at: cloudflare.com/privacypolicy. Further information on data processing by Lovable is available at: lovable.dev/privacy.
Data processing in connection with the use of the “Flino” software
In addition to the purely informational use of our website, with “Flino” we offer a web-based software solution that users can use to manage and analyse quotes and automate communication processes. In the course of using this application, personal data going beyond the mere use of the website is processed.
If you connect your Google account or Microsoft account to our application, Flino accesses certain data from the respective services – depending on the permissions you have granted. This includes in particular email metadata such as sender, recipient and subject, email content, calendar information and files, insofar as these are actively integrated into the application by the user. Processing takes place exclusively to provide the functions you use.
In particular, the application enables the receipt and sending of emails, the detection of replies, the creation and scheduling of follow-up messages, the management of quote processes and the analysis of communication and quote data. In addition, AI-assisted functions may be used to create copy suggestions, analyse content or support the use of the application.
For this we use, among others, services from Google and Microsoft as well as AI services such as Google Gemini and Google Cloud Vertex AI. Processing takes place exclusively to provide the respective functions and not for advertising purposes.
The use of data from Google services takes place in compliance with the Google API Services User Data Policy, in particular the Limited Use requirements. Personal data is neither sold nor used for advertising purposes. The data is not used to train AI or machine learning models.
For sending system and transactional messages such as registration confirmations, verification emails, password resets or notifications, we use external email service providers. The personal data required for delivery is processed in this context.
In the course of using the application, we process in particular account data, usage data, communication data, quote data and technical information such as IP address, browser type, operating system or device used, insofar as this is necessary to provide, secure and optimise the application.
Email content is generally stored only for as long as is necessary to fulfil the respective function, but as a rule for a maximum period of 90 days. After that, the content is automatically truncated or deleted. Other personal data is stored only for as long as is necessary to fulfil the respective purposes or as statutory retention obligations exist.
To protect the data processed, we use appropriate technical and organisational measures. In particular, access credentials and authentication information are stored in encrypted form and access to personal data is limited to authorised persons.
The processing of personal data in the course of using the software takes place on the basis of Art. 6(1)(b) GDPR to perform the usage agreement, and additionally on the basis of Art. 6(1)(f) GDPR due to our legitimate interest in the secure, efficient and user-friendly provision of our services.
You can disconnect your Google or Microsoft account at any time via the settings of the respective account or within the application. In addition, you can request the erasure of your personal data at any time, provided no statutory retention obligations preclude this.
Security
We want to make your visit to our website secure.
SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the website operator, we use SSL (Secure Socket Layer) or TLS (Transport Layer Security) encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and by the padlock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Data processing agreement (DPA)
We have concluded data processing agreements pursuant to Art. 28 GDPR with our service providers who process personal data on our behalf. These agreements ensure that the service providers process the personal data of our website visitors only in accordance with our instructions and in compliance with data protection provisions.
Links to other providers
Our website may contain links to other providers, to which our privacy information does not extend. The processing of personal data by these providers is governed exclusively by their respective privacy provisions.
– End of the privacy information –
This privacy information was prepared by Kanzlei Fischer-Battermann.