DRAFT v1.0 — prepared for review by qualified counsel before publication. Replace bracketed placeholders.
Version: 1.0 · Effective date: [EFFECTIVE DATE] · Published at: flowagenci.com/legal/privacy
This Privacy Policy explains how [FLOWAGENCI LLC LEGAL NAME], a [STATE] limited liability company with its registered address at [REGISTERED ADDRESS] ("FlowAgenci", "we", "us" or "our"), collects, uses, shares and protects Personal Data in connection with Flow, our operating software for creative and marketing agencies, including our website at flowagenci.com, the application at app.flowagenci.com, and client portals served at <slug>.flowagenci.com or on a customer's own domain (together, the "Service").
Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Who we are and which role we play
Flow is used by agencies (each a "Customer") to run their business: boards and tasks, client and contact records (CRM), projects, time tracking, proposals, quotes and invoices, and a Client Portal where the agency's own clients review deliverables, upload assets, fill in forms, see invoices and exchange messages.
Because of how the Service works, we play two different roles under data protection law:
| Role | Data involved | Who decides how it is used |
|---|---|---|
| Processor / service provider | Customer Data: everything a Customer and its users put into their workspace — CRM contacts and leads, client records, files and deliverables, comments and annotations, messages, documents, invoices, time entries, form responses, and the data of Portal Users (the Customer's clients). | The Customer is the controller. We process Customer Data only on the Customer's instructions under our Data Processing Addendum ("DPA"). |
| Controller | Account Data: information about account owners, billing contacts, Authorized Users (team members and guests) as needed to run, secure and bill for accounts; website visitors; people who contact support or sales; recipients of our product and marketing emails. | FlowAgenci decides, as described in this policy. |
If you are a Portal User (for example, you were invited by an agency to review work in its client portal), the agency that invited you is responsible for your data inside that portal. Please read our short Portal User Notice and contact the agency first with any request. We will help the agency respond.
This policy describes our processing as a controller and, for transparency, summarizes how Customer Data is handled as a processor. It does not replace the privacy notice of the agency you work with.
2. Personal Data we collect
2.1 Information you give us
- Identity and contact data: name, email address, phone number, job title or role, profile photo, language and timezone.
- Organization data: agency name, legal name, tax identifier, address, logo, brand colours, bank details that the Customer chooses to show on invoices.
- Authentication data: password (stored only as a salted hash), passkey public keys, two-factor authentication (2FA) secrets (stored encrypted), recovery codes (stored hashed).
- Billing data: plan, billing contact, tax ID and billing address. Card details are collected and stored by Stripe, not by us; we receive only a Stripe customer identifier, plan, card brand and last four digits, and payment status.
- Support and communications: messages you send to support@, sales or other addresses, including attachments, and our replies.
- Acceptance evidence: when someone accepts a proposal or quote in the Client Portal, we record the typed full name, date and time, IP address and user agent, so that the Customer can evidence the acceptance.
2.2 Information collected automatically
- Sign-in and security data: session identifiers, IP address, user agent/device information, sign-in timestamps, failed sign-in attempts, rate-limit counters and bot-protection signals (Cloudflare Turnstile).
- Usage and telemetry: first-party product events (for example, "invoice issued" or "view opened") associated with an account, and cookieless aggregate website analytics (Cloudflare Web Analytics), which do not use cookies or build cross-site profiles.
- Error and diagnostic data: technical error reports sent to Sentry, configured to scrub Personal Data (such as emails, tokens and form contents) before transmission.
- Cookies: we use only essential cookies — for example the session cookies
fa_app(team app) andfa_portal(client portal) and the Turnstile challenge. See the Cookie Policy.
2.3 Information from third parties
- Sign in with Google (optional): if you choose it, Google shares your name, email address and profile picture with us.
- Stripe: payment status, invoice and tax information related to your subscription.
- Your organization: an administrator may invite you and provide your name, email and role.
2.4 Customer Data (processed on the Customer's behalf)
Customer Data may include identity and contact details of the Customer's clients, contacts and leads; files and deliverables (images, PDFs, video and other documents); comments with timestamps and position anchors; approvals and change requests; messages; proposals, quotes, invoices and payment reports; time entries and allocations; and form responses. We process this data only to provide the Service to the Customer, as described in the DPA.
Sensitive data. The Service is not designed to process special categories of data (such as health, biometric or financial account credentials beyond what appears on an invoice). Customers and users should not upload such data unless the Customer has a lawful basis and has assessed the risk.
3. How and why we use Personal Data (as controller)
| Purpose | Examples | Legal basis (GDPR / UK GDPR and similar laws) |
|---|---|---|
| Provide and operate the Service | Create accounts and organizations, authenticate users, deliver emails you request (magic links, invitations, notifications), render PDFs, store files | Performance of a contract; legitimate interests in running the Service for Customers who contract with us |
| Billing and account administration | Trials, subscriptions, seats, invoices, taxes, dunning | Performance of a contract; legal obligation (tax and accounting) |
| Security and abuse prevention | Rate limiting, bot protection, fraud detection, malware scanning of uploads, audit logs, investigating incidents | Legitimate interests in keeping the Service and its users safe; legal obligation where applicable |
| Support | Answering requests, troubleshooting (including audited, time-limited staff access to a workspace when you ask for help) | Performance of a contract; legitimate interests |
| Product improvement | Understanding feature usage in aggregate, fixing errors, measuring performance | Legitimate interests (using aggregated or de-identified data where possible) |
| Communications | Service announcements, policy changes, security notices; product news and marketing (you can opt out at any time) | Performance of a contract / legitimate interests for service notices; consent where required by law for marketing |
| Legal compliance | Responding to lawful requests, enforcing our Terms, keeping accounting records | Legal obligation; legitimate interests in defending legal claims |
What we do not do:
- We do not sell Personal Data and we do not share it for cross-context behavioural advertising.
- We do not use Customer Data to train third-party artificial intelligence models, and we do not allow our subprocessors to do so.
- We do not use Customer Data for our own marketing or to build profiles of Portal Users or the Customer's contacts.
- We do not make decisions that produce legal or similarly significant effects based solely on automated processing.
4. How we share Personal Data
We share Personal Data only as follows:
- Subprocessors and service providers who host, store or process data for us under written contracts that require confidentiality and appropriate security: Cloudflare, Inc. (hosting, database, storage, email delivery, PDF rendering, bot protection and cookieless analytics), Stripe, Inc. (billing, payments and tax calculation), Functional Software, Inc. d/b/a Sentry (error monitoring) and Google LLC (optional sign-in). The current list, with locations and purposes, is at /legal/subprocessors.
- Within a Customer's workspace. Information you add is visible to other users of the same organization according to their roles and permissions. Content marked as visible to the client is shown to Portal Users of that client; internal notes are not.
- At the Customer's direction. For example, when a Customer sends an invoice or proposal by email, or connects a custom domain.
- Legal reasons. To comply with applicable law, regulation, legal process or enforceable governmental request; to enforce our Terms; or to protect the rights, property or safety of FlowAgenci, our users or the public. Where legally permitted, we will notify the affected Customer before disclosing Customer Data.
- Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this policy and to notice where required.
5. International transfers
FlowAgenci is based in the United States. Our infrastructure runs on Cloudflare's global network, and our primary database region is in North America. Personal Data may therefore be processed in the United States and other countries where our subprocessors operate.
When we transfer Personal Data from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and on the EU–U.S. Data Privacy Framework where a recipient is certified, together with supplementary measures such as encryption in transit and at rest and access controls.
For transfers of Personal Data originating in Chile, we apply the safeguards required by Law 19.628 and, from 1 December 2026, Law 21.719, including contractual clauses that provide an adequate level of protection. For other Latin American jurisdictions (including Brazil, Mexico, Argentina and Colombia) we rely on contractual safeguards and the mechanisms recognized by local law.
6. How long we keep Personal Data
| Data | Retention |
|---|---|
| Account Data (account owners, billing contacts, Authorized User accounts) | For the life of the account, then deleted or anonymized, except records we must keep |
| Billing, tax and accounting records | Up to 7 years after the transaction, as required by tax and accounting law |
| Security logs (sign-ins, rate limits, staff access) | 12 months |
| In-app notifications | 180 days |
| Activity and audit events | 24 months |
| Magic links, one-time codes and email verification tokens | Expire after 15 minutes; purged daily |
| Customer Data | Until the Customer deletes it, or, on termination, the workspace becomes read-only for 90 days and is then deleted within 30 days |
| Backups | Roll off within 30 days (database point-in-time recovery and nightly object-storage copies) |
| Support communications | Up to 3 years after the request is closed |
| Marketing preferences | Until you opt out, then kept only as a suppression record |
7. How we protect Personal Data
We apply technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2 or higher) and at rest (provider-managed encryption).
- Tenant isolation by organization, enforced in our data layer and verified by automated isolation tests.
- Least-privilege access for staff. Staff can access a Customer's workspace only through an audited, time-limited (30-minute), read-only-by-default session that requires a stated reason; 2FA is mandatory for staff.
- Optional 2FA and passkeys for all users, and an organization-wide 2FA requirement on eligible Plans.
- Rate limiting and bot protection, malware scanning of uploaded files, and short-lived signed URLs (typically 5–15 minutes) for file access.
- Secrets management with a documented rotation procedure; backups with 30-day point-in-time recovery; monitoring and alerting.
- An incident response process. If a personal data breach affects Customer Data, we notify the Customer within 48 hours of confirming it, as described in the DPA.
No system is perfectly secure. Please use a strong, unique password, enable 2FA or a passkey, and report suspected vulnerabilities to security@flowagenci.com.
8. Your rights
Depending on where you live, you may have the right to:
- Access the Personal Data we hold about you and obtain a copy;
- Rectify inaccurate or incomplete data;
- Delete your data ("right to be forgotten");
- Restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, without affecting prior processing;
- Not be subject to decisions based solely on automated processing;
- Lodge a complaint with a supervisory authority.
How to exercise them. Email privacy@flowagenci.com from the address linked to your account, or use the self-service options in the app (profile, security settings, account deletion and organization export). We will respond within the period required by applicable law (generally within 30 days; 15 business days where Chilean law requires) and may need to verify your identity.
Customer Data requests. If your request concerns data inside an agency's workspace or client portal (for example, you are a Portal User or a contact in an agency's CRM), the agency is the controller. Please contact the agency directly. If you contact us, we will forward your request to the relevant Customer without undue delay and assist them in responding.
8.1 European Economic Area, United Kingdom and Switzerland
You have the rights listed above under the GDPR, UK GDPR and Swiss FADP. You may complain to the supervisory authority where you live or work. [If required: EU representative — [EU REPRESENTATIVE NAME AND ADDRESS]; UK representative — [UK REPRESENTATIVE NAME AND ADDRESS].]
8.2 Chile
Under Law 19.628 and, from 1 December 2026, Law 21.719 on the protection of personal data, you have the rights of access, rectification, erasure (cancellation), objection, portability and blocking, and the right not to be subject to automated individual decisions. You may lodge a complaint with the Agencia de Protección de Datos Personales once it is operational.
8.3 United States (state privacy laws)
Residents of California and other states with comprehensive privacy laws may have the rights to know, access, correct, delete and port their data, and to opt out of sale, sharing for targeted advertising and certain profiling. We do not sell or share Personal Data as those terms are defined, and we do not use or disclose sensitive personal information for purposes that require an opt-out. You may use an authorized agent, and we will not discriminate against you for exercising your rights. When we process Customer Data, we act as a service provider/processor to the Customer.
8.4 Other Latin American countries
If you are in Brazil (LGPD), Mexico (LFPDPPP), Argentina (Law 25.326), Colombia (Law 1581 of 2012) or another country with a data protection law, you may exercise the rights that law grants you (such as the ARCO rights) by writing to privacy@flowagenci.com. You may also contact your local data protection authority.
9. Your choices
- Emails. Transactional emails (sign-in links, invitations, security notices, invoices) are part of the Service. You can manage notification emails in your preferences and unsubscribe from marketing at any time using the link in the email.
- Cookies. We only use essential cookies, so no cookie banner is required. Blocking them will prevent sign-in.
- Account deletion. You can delete your user account from Settings › Profile in the app, or Tu cuenta in a Client Portal, unless you are the only owner of an organization (transfer ownership or delete the organization first). We email you a link to confirm, which must be opened in the same browser. Deletion removes your memberships, portal access, sessions, passkeys and two-step verification; what you wrote in a workspace stays there as "Deleted user".
10. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect Personal Data from anyone under 16 (or the higher age required locally). If you believe a child has provided us Personal Data, contact privacy@flowagenci.com and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the new version at /legal/privacy with a new effective date and, for material changes, notify account owners by email or in-app notice at least 30 days before the change takes effect, unless a shorter period is required for legal or security reasons. Previous versions are available on request.
12. Contact us
- Privacy questions and requests: privacy@flowagenci.com
- Security reports: security@flowagenci.com
- Legal notices: legal@flowagenci.com
- Postal address: [FLOWAGENCI LLC LEGAL NAME], [REGISTERED ADDRESS]
Related documents: Terms of Service · Data Processing Addendum · Subprocessors · Cookie Policy · Acceptable Use Policy · Portal User Notice