Favel

Privacy Notice

Last updated: 20 September 2026

This privacy notice applies to viewing and using the marketing website at favel.io. Favel is a brand of AMCing UG (haftungsbeschränkt).

The Favel application, where signed-in users work, has its own privacy notice. This notice describes the marketing website only.

1. Controller

The controller for the processing of personal data on this website is:

AMCing UG (haftungsbeschränkt)
Richard-Wagner-Weg 4
52385 Nideggen
Germany

Represented by the managing director: Christoph Attemeier

Email: info@favel.io

No data protection officer has been appointed. Data protection enquiries reach us at the email address above. Further details are in the Imprint.

2. Visiting the website and server logs

The website is delivered through infrastructure operated by Vercel Inc. (USA). When you open a page, your browser sends technical connection data that is required to establish the connection and deliver the page. This includes your IP address, the date and time of access, the address you requested, and information about your browser and operating system.

We do not keep an access log of our own. The delivery infrastructure retains runtime logs for a short period according to its own documentation; on the plan we use, that period is currently one day. We set no cookies and no comparable storage for the purpose of logging this access.

The purpose is to provide the website and to keep it secure. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in running the site securely and reliably.

3. Waitlist

The website offers a waitlist. If you join, we process the details you enter: name, email address, company, company size, and two optional free-text entries (a line about your team's current AI use and an open message).

The purpose is to tell you when Favel launches and to understand who is on the list. To join, you tick a checkbox that is not preselected. The legal basis for processing your waitlist details and for sending you launch information is your consent under Art. 6(1)(a) GDPR.

We do not use double opt-in. When you submit the form, your entry is stored immediately as a lead in the Google lead sheet. There is no confirmation click and no confirmation state, and your entry is not pending. We then send you a one-off welcome email in plain text that acknowledges your signup without requiring you to click anything. The email is sent by our email service provider, Resend (Plus Five Five, Inc., San Francisco, USA), with which we have a data processing agreement. Resend is established in the USA, so your data is transferred to a third country; we state the basis in Section 5.

We store evidence of your consent, with the timestamp, the page you signed up on, and the exact wording of the consent text shown to you at that moment, on your own row in the Google lead sheet (Art. 7(1) GDPR).

You can withdraw your consent at any time with effect for the future. A message to the address in Section 1 is enough, and you can reply directly to the welcome email to do it. After withdrawal we delete your entry unless a statutory retention obligation applies. The record of the consent you gave remains under Art. 7(1) GDPR, and then serves only as evidence.

Providing your details is voluntary. Without an email address we cannot add you to the waitlist.

4. Analytics and consent management

We measure how this website is used only if you agree. Before you agree, the site loads no analytics software, sets no non-essential cookies, and does not measure your usage. Independently of that, the site transmits your banner decision to the analytics service as a separate record; that record serves only as accountability for your choice (Art. 7(1) GDPR) and is not analytics measurement.

You give your decision through a banner on the site. Rejecting is as easy as accepting, and rejection is not a setting you have to find. You can withdraw or change your decision at any time; the footer of every page offers access. We record the decision with its timestamp, the categories chosen, the version of the wording shown, and the page where you decided. These records are stored together with the service's measurement data and are subject to the same retention period as that data (Section 6).

4.1 PostHog

For analytics we use PostHog, operated in the EU region of PostHog EU (Amazon Web Services, Frankfurt am Main). The contracting entity is PostHog, Inc., based in the USA.

After you consent, we process the pages you view, the referring source you arrived from, information about your browser and device, the approximate geographic region, the time of the event, and performance measurements for the page (load time, responsiveness to input, and visual stability, known as Web Vitals). We use this to understand which content is read and where the page needs work. Session recording is not part of the current configuration.

For the measurement, the service stores an identifier in your browser (local storage or cookie) after you consent, so visits can be attributed to a browser and visitors counted correctly. The identifier contains no plain-text data and is deleted when you withdraw your consent. No session recording, no autocapture, and no surveys are part of the current configuration.

The legal bases are your consent under Art. 6(1)(a) GDPR and, for storing and reading information on your device, Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.

5. Recipients and transfers to third countries

Personal data reaches only the parties we use for the purposes above. These are currently:

RecipientPurposeLocation
Vercel Inc.Hosting and delivery of this websiteUSA
Resend (Plus Five Five, Inc.)Sending the welcome emailUSA
Google (AMCing's Workspace account)Holding the lead sheet: one row per lead with the consent record. Data at rest is assigned to the Europe regionEU; the contracting entity is Google LLC, USA, certified under the EU-US Data Privacy Framework
PostHog, Inc. (PostHog EU)Analytics, only after your consent; storing the consent recordsUSA, processed in the EU region

These providers process data on our behalf where an agreement to that effect exists. They may use further sub-processors, according to their own agreements and public sub-processor lists.

For transfers to the USA we rely on the instruments the providers commit to: certification of the recipient under the EU-US Data Privacy Framework where it exists, and standard contractual clauses in the respective data processing and privacy agreements. For Resend these are the EU Standard Contractual Clauses (Module Two) and its EU-US Data Privacy Framework certification. We provide a copy of the relevant safeguards on request, where we have received them.

With PostHog EU the processing takes place in Frankfurt. The contracting entity is nonetheless established in the USA, and the provider uses its own sub-processors. We draw no conclusion from this that no third-country transfer occurs for that service. The consent records described in Section 4 are also processed at that provider in the USA.

6. Retention and deletion

The hosting provider retains technical connection data in its runtime logs for its own periods, which are short on our plan. We keep no access log of our own.

We keep your waitlist entry until you have it deleted, until you withdraw your consent, or until the waitlist has served its purpose and closes. We keep the consent record for three years after the business relationship ends, and delete it afterwards unless a statutory retention obligation applies. That short period serves only as evidence (Art. 7(1) GDPR).

Analytics data is deleted according to the periods PostHog specifies; the period depends on the configuration and on our plan. This notice does not state a fixed number of days. The consent records described in Section 4 sit with the same service and are deleted on the same schedule.

Deleting data with us does not automatically delete copies held by a provider at once. Providers may retain data for a limited time under their terms, for backup and security purposes.

7. Your rights

Where the statutory conditions are met, you have the following rights:

  • Access to the data we process (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing we base on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

For any of these rights, a message to the email address in Section 1 is enough. We may ask for evidence where it is unclear whether a request comes from you.

8. Right to complain to a supervisory authority

You may lodge a complaint with a data protection supervisory authority. This is normally the authority at your habitual residence, your place of work, or the place of the alleged infringement. For our registered office it is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

9. No automated decision-making

This website carries out no automated decision-making within the meaning of Art. 22 GDPR. People decide who joins the waitlist.

10. Changes to this notice

We update this notice when the processing, the legal position, or the offering changes. The version published on the website with the date above applies.

This is a translation of the German Datenschutzerklärung at Datenschutz. In case of doubt, the German version is authoritative.