Future Market Navigator Canvas
Privacy — how this tool handles data
What this tool is
The Future Market Navigator Canvas is a workshop tool. Participants fill out a canvas on their own device — Haves, Core Markets, Future Markets, a readiness assessment, and a strategic gap — save it, and optionally get an access link by email and a PDF export. A second device can show a live board that combines every participant's canvas for the workshop discussion.
What data is collected
- Canvas content: whatever a participant types into the three layers, the readiness scores, and the strategic gap. Every field is optional.
- Contact details (optional): company name, contact name, and contact email — only if a participant chooses to enter them.
- Consent flags: whether a participant agreed to (a) receive the access link by email, and (b) be contacted about the Future Market Navigator afterwards. These are two separate, independent choices — agreeing to one does not imply the other.
Why this data is collected
The contact fields exist so a participant can get their access link by email and, only if they separately agree, be followed up with afterwards. The canvas content is the actual output of the workshop exercise — collecting it is the point of the tool.
Where it is stored
In a Supabase Postgres database hosted in the Frankfurt (EU) region. When a participant asks for their access link by email, that one message is sent through Resend; Resend's own documentation states that the sending region for a domain (e.g. Ireland / eu-west-1) is chosen when that domain is set up in the Resend dashboard, and that account-level metadata (such as delivery logs) is kept in the US regardless of the sending region.
[PLACEHOLDER — Which sub-processors (Supabase, Resend, Vercel, and any others involved in hosting or email delivery) are formally covered by a data processing agreement — confirm and list here.]
Who can see it
Workshop facilitators can see every canvas for a session on the live board and through the admin export. The live board is built to never receive contact details — company, name, or email never leave the database for that view. The admin export and the raw database are reachable only with the admin password and the database credentials.
How long it is kept
Contact name, contact email, and both consent flags are cleared automatically, permanently, 90 days after a canvas is created — this runs on a schedule, not on request. Company name and all canvas content (entries, scores, gap) are kept beyond that point, deliberately: the plan is for that data to remain usable, in anonymized form, for a later benchmark.
How to delete your data before then
Open your canvas link and use the Delete my data button. It removes your submission and everything in it immediately and permanently — there is no way to undo it, and no way for anyone, including the workshop organizers, to recover it afterwards.
Legal basis and your rights
[PLACEHOLDER — The legal basis for processing this data (e.g. consent under GDPR Art. 6(1)(a)) and a description of data subject rights (access, rectification, erasure, objection, complaint to a supervisory authority) must be added here after legal review.]
Who is responsible for this data
Controller: Ecosystemizer GmbH, Altestadt 6-8, 40213 Düsseldorf.
Named contact person: Prof. Dr. Julian Kawohl.
[PLACEHOLDER — A contact address for data subject requests, and whether a data protection officer has been formally appointed, must still be added here.]