Legal Disclosure
Privacy Policy
Last Updated: 28 August 2026
This Privacy Policy describes how Flowoo Digital LTD("we", "us", or "our") collects, uses, and protects your personal information when you visit our website at flowoo.co.uk and when you book discovery calls, use our AI chat assistant ("Flowa"), contact us via WhatsApp, or submit information through our contact forms or audit tools.
This policy is issued in compliance with UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018) and the Data Protection Act 2018, and in particular with Articles 13 and 14 of UK GDPR which require us to provide you with this information at the point of data collection.
1. Who We Are (Data Controller)
Flowoo Digital LTD is a private limited company incorporated in England and Wales under Company Number 17398812. Our registered office is located at 128 City Road, London, United Kingdom, EC1V 2NX.
Flowoo Digital LTD is the Data Controller for personal data processed via this website. For any data protection enquiries, please contact us at contact@flowoo.co.uk.
We are not currently required to register with the Information Commissioner's Office (ICO) under an exemption for organisations that only process personal data for core business purposes. We keep this under review as our processing activities evolve.
2. Information We Collect
We only collect information you voluntarily provide when interacting with our website:
- Identity Data: Full name.
- Contact Data: Email address and phone number (required at account registration).
- Portal Account Data: When you create a Client Portal account, we collect your name, email address, phone number, and password (hashed). Your account is linked to our internal CRM to manage service delivery, contracts, and billing.
- Operational Data: Business type, industry, and bottlenecks described in our audit or contact forms.
- Conversation Data: Messages exchanged with our Flowa AI chat assistant, including session timestamps, the page URL where the conversation occurred, and whether you clicked a WhatsApp or booking link. Conversations may be reviewed by our team to improve service quality.
- Lead & CRM Data: Your name, email, service interest, and any message you submit — stored in our secure CRM database when you contact us via chat, contact form, or booking.
- Booking Data: Your name, email, chosen appointment time, and any notes submitted when booking a discovery call. This data is stored both in our CRM database and in Google Calendar.
- WhatsApp Data: If you choose to contact us via the WhatsApp link on this website, your WhatsApp conversation is governed by Meta's Privacy Policy. We do not automatically record WhatsApp messages in our systems unless you provide information we need to follow up.
- Technical Data: IP address (used for rate-limiting only; not stored long-term), browser type, and device type — collected automatically by analytics tools when you consent to analytics cookies.
- Usage Data: Pages visited, scroll depth, and session duration — collected automatically by analytics tools when you consent.
We do not collect any special categories of personal data (e.g. health data, political opinions, biometric data).
3. Cookies & Tracking Technologies
We use cookies and similar tracking technologies. You can manage your cookie preferences at any time via the cookie banner on this site. Our cookies fall into three categories:
- Strictly Necessary Cookies: These cookies are essential for the website to function and cannot be switched off. They include the cookie that stores your consent preference (
flowoo-cookie-consent). No personal data is transmitted to third parties via these cookies. - Analytics Cookies (conditional on your consent): We use Google Analytics 4 to understand how visitors interact with the site. Data is anonymised and aggregated; no personally identifiable information is stored in GA4. These cookies are only loaded after you explicitly accept analytics cookies.
- Marketing Cookies: We do not currently run any retargeting or advertising cookie campaigns. This category is reserved for future use and will only be activated with your explicit consent.
You can clear or block cookies at any time via your browser settings. Note that blocking strictly necessary cookies may impair site functionality.
4. Third-Party Data Processors
To deliver our services, we share limited personal data with verified third-party processors. All processors are bound by data processing agreements and adhere to UK GDPR requirements:
- Calendly LLC (US): Renders appointment schedulers and processes booking details. Safeguard: Standard Contractual Clauses (SCCs) under UK GDPR.
- OpenAI Inc. (US): Processes text messages submitted through the Flowa AI assistant to generate contextual responses. Safeguard: SCCs. Chat data is not used to train OpenAI models under our enterprise API terms.
- Vercel Inc. / AWS (US/EU): Hosts our application on servers located in the EU (Frankfurt region) and US. Safeguard: EU Standard Contractual Clauses and Vercel Data Processing Agreement.
- Google LLC (US): (a) Provides Google Analytics 4 for anonymised usage analytics, conditional on your consent; (b) Provides Google Calendar for appointment management — booking details (name, email, time) are stored as calendar events. Safeguard: SCCs.
- Resend Inc. (US): Processes transactional email notifications (booking confirmations, contact form replies). Safeguard: SCCs.
- Supabase Inc. (US): Provides our secure CRM database infrastructure where leads, booking records, and Flowa conversation logs are stored. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Servers located in EU (Frankfurt). Safeguard: SCCs.
- Meta Platforms Inc. / WhatsApp (US): If you choose to contact us via the WhatsApp button on this website, your communication is transmitted via WhatsApp's infrastructure and governed by Meta's Privacy Policy. We do not control data processed by Meta. Safeguard: SCCs.
- Make.com / Celonis SE (EU): Processes workflow automation triggers for client service delivery. GDPR-compliant EU entity.
- n8n GmbH (EU): Processes workflow data for custom automation builds. GDPR-compliant EU entity.
5. How We Use Your Information
We process your personal data for the following purposes:
- To respond to discovery call bookings and provide the requested consultation.
- To send booking confirmation and follow-up communications via email.
- To store and manage leads and booking records in our internal CRM for business development and client follow-up purposes.
- To review Flowa AI chat conversation logs internally for the purposes of improving service quality, identifying common queries, and following up with prospective clients.
- To analyse operational bottlenecks and provide custom automation recommendations.
- To improve our website and services using anonymised analytics data.
- To comply with regulatory or legal obligations under the laws of England and Wales.
6. Legal Basis for Processing (UK GDPR Art. 6)
We rely on the following legal bases for processing your personal data:
- Contract (Art. 6(1)(b)): Processing your name, email, and contact details is necessary to perform pre-contractual steps and to fulfil service agreements you enter into with us (e.g. responding to your enquiry, processing your booking).
- Legitimate Interests (Art. 6(1)(f)): We process the following data on the basis of our legitimate interests: (a) basic technical data (IP address, browser type) for website security and operation; (b) Flowa AI chat conversation logs for the purpose of service quality improvement and lead follow-up — we have conducted a Legitimate Interests Assessment (LIA) and determined our interests in improving service quality and following up with prospective clients are not overridden by your rights, given the limited sensitivity of the data and your reasonable expectation of contact when initiating a chat on a business website; (c) lead and booking records stored in our CRM, on the basis of our legitimate interest in managing our sales pipeline and delivering contracted services.
- Consent (Art. 6(1)(a)): Analytics cookies (Google Analytics 4) and marketing cookies are only placed and processed on the basis of your freely given, informed, and unambiguous consent, obtained via our cookie banner. You may withdraw this consent at any time by clearing your cookies or changing your preferences via the cookie banner.
- Legal Obligation (Art. 6(1)(c)): We may process personal data where required to comply with legal obligations under the laws of England and Wales.
7. International Data Transfers
Some of our third-party processors are located outside the UK (primarily in the United States). Where personal data is transferred to countries not deemed adequate by the UK Secretary of State, we ensure appropriate safeguards are in place, specifically:
- UK International Data Transfer Agreements (IDTAs) or equivalent Standard Contractual Clauses (SCCs) approved by the ICO.
- Processor-specific adequacy certifications where applicable.
Affected processors include: Calendly LLC, OpenAI Inc., Vercel Inc., Google LLC, Resend Inc., and Supabase Inc. Details of applicable transfer mechanisms are available upon request.
8. Data Retention Period
We retain different categories of data for different periods:
- Lead & CRM records (name, email, service interest, contact messages): retained for 2 years from your last interaction, or until you request deletion.
- Booking records: retained for 2 years from the date of the appointment for legitimate business and legal purposes.
- Flowa conversation logs: retained for 12 months from the date of the conversation, then permanently deleted or anonymised.
- Cookie consent records: retained for 12 months from the date of consent.
- Technical/IP data: used for rate-limiting in real time only; not stored beyond the request lifecycle.
After any applicable retention period, personal data is permanently and securely deleted from all our systems.
9. Data Storage & Security
We implement the following technical and organisational measures to protect your personal data:
- Encryption at rest: All data stored in our Supabase CRM database is encrypted using AES-256.
- Encryption in transit: TLS 1.2+ is enforced on all API connections and web traffic.
- Access control: Our internal admin dashboard (where conversation logs and leads are reviewed) is protected by password authentication. Access is restricted to authorised personnel only.
- Row-Level Security: Our database enforces row-level access policies so that only our authenticated server-side application can read or write personal data.
- HTTP security headers: We implement Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and other security headers on all responses.
- No data selling: We do not sell, rent, or distribute your personal data to third-party marketing brokers under any circumstances.
- EU hosting: Our CRM database (Supabase) is hosted on servers in the EU (Frankfurt, Germany). Our web application is hosted in the Vercel EU region.
10. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights:
- Right of Access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): You may request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): You may request deletion of your personal data ("the right to be forgotten"), subject to any overriding legal obligations we may have.
- Right to Restrict Processing (Art. 18): You may request that we limit how we use your data in certain circumstances.
- Right to Data Portability (Art. 20): Where processing is based on consent or contract, you may request a machine-readable copy of the personal data you provided to us.
- Right to Object (Art. 21): You may object at any time to processing based on our legitimate interests, including profiling. You also have the absolute right to object to processing for direct marketing purposes.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: If you believe we have mishandled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
To exercise any of the above rights, please email us at contact@flowoo.co.uk. We will respond to all valid requests within 30 calendar days as required by UK GDPR Art. 12. In complex cases, this period may be extended by a further two months, in which case we will notify you within the initial 30-day period.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last Updated" date at the top of this page will always reflect the most recent version. We encourage you to review this page periodically. Where changes are material, we will notify users via a prominent notice on the website.