Name, email address, login information, workspace role, account preferences and authentication records.
How FlowOps handles personal information.
This Privacy Policy explains how Web Creators UK Ltd collects, uses, shares, protects and retains personal information when you visit FlowOps, create an account, use a workspace or communicate with us.
Web Creators UK Ltd operates FlowOps.
Web Creators UK Ltd is a company registered in England and Wales. We are the controller for personal information used for the FlowOps website, account administration, billing records, security, support, product administration and our own business communications.
Our data protection role depends on the information involved.
For account, website, billing, security and support information, Web Creators UK Ltd normally decides why and how the information is used and acts as controller.
When a service business uses FlowOps to manage its own customers, bookings, jobs, schedules, team activity and messages, that business normally decides why the information is used. In that situation the business is normally the controller and Web Creators UK Ltd acts as its processor when providing FlowOps.
Contact that business first about the record or service relationship. We will support the business with data protection requests where our processor obligations require us to do so.
We collect information needed to provide, secure and support FlowOps.
Bookings, customer details, service information, locations, schedules, assignments, messages, notes, status history and other content entered by authorised users.
Information contained in support requests, demo requests, contact messages, account conversations and other communications with us.
If you choose to start a website chat, we collect the name and email address you provide, your messages, the page where the conversation started, consent and message timestamps, and the replies sent by our team. The chat starts only after you submit the form.
IP address, browser and device information, timestamps, login activity, security events, error information and service activity needed to operate and protect the platform.
Plan, billing status, invoices and transaction records. If payment processing is enabled, payment card information is handled by the payment provider shown at checkout rather than stored by FlowOps unless clearly stated otherwise.
Addressing, delivery and technical information needed to send security codes, account notices and other transactional messages through our email provider.
We do not sell personal information. FlowOps is not designed to require special category information or criminal offence information. Customers should only enter that type of information where it is necessary, lawful and appropriate for their use of the service.
Information can come from you, your organisation, the service and our providers.
- Directly from you when you register, use website live chat, communicate with us, request a demo, use the service or change account settings.
- From the organisation that invites you to a FlowOps workspace or enters information about customers, team members or service activity.
- Automatically from browsers, devices, logs, security systems and strictly necessary storage technologies when you use FlowOps.
- From service providers that help with email delivery, payment status, hosting, security, support and related platform operations.
We use personal information only where we have a lawful reason.
Where we rely on legitimate interests, those interests include securing and improving FlowOps, supporting customers, preventing misuse, managing our business and establishing or defending legal claims. We consider whether those interests are outweighed by the rights and interests of the people affected.
When we act as processor, we use workspace information to provide FlowOps for the customer organisation.
We process customer controlled workspace information on documented instructions contained in the customer agreement, the way authorised users configure and use FlowOps, and any lawful support instructions. Our Terms include data processing commitments for this processor activity.
A customer organisation is responsible for the lawfulness of the information it collects and places in FlowOps, the notices it gives to individuals, the permissions of its authorised users and the instructions it gives to us.
Some providers may process information outside the United Kingdom.
Where a transfer is restricted under United Kingdom data protection law, we use an available lawful transfer mechanism. Depending on the destination and provider, this may include United Kingdom adequacy regulations, the International Data Transfer Agreement, the United Kingdom Addendum to approved European contractual clauses, or another permitted safeguard.
Where required, we also assess the protection available for the transfer and apply additional contractual, technical or organisational measures that are appropriate to the risk.
We keep personal information only for as long as there is a valid reason to keep it.
Retention depends on the type of information, the purpose for which it was collected, customer instructions, security needs, backup cycles and any legal, accounting, tax, regulatory or dispute requirements that apply.
Normally kept while an account or subscription is active and afterward only for as long as needed for legal, financial, security or dispute purposes.
Kept while needed to provide the customer workspace, then deleted or returned in accordance with the customer agreement, subject to lawful retention and normal backup expiry.
Kept for a period proportionate to security, troubleshooting, fraud prevention and service reliability needs.
Kept for as long as reasonably needed to respond, maintain the relationship, resolve disputes and meet legal obligations.
Closed website chat conversations are normally kept for up to 180 days so we can continue support, understand the conversation and resolve follow up questions. We may keep a specific record for longer where a legal, security or dispute reason requires it.
We use technical and organisational measures designed to protect information.
Measures are selected according to the nature of the service and the risks involved. They may include controlled access, authentication, encrypted network connections, security logging, backups, infrastructure protections and processes for responding to security incidents.
No internet service can promise absolute security. Customers and authorised users must also protect credentials, devices and access permissions and must tell us promptly if they suspect unauthorised access.
AI assistance is designed to support authorised users, not make significant decisions about people on its own.
FlowOps AI may help structure request information or assist a user using context available in the workspace. Authorised users remain responsible for reviewing output before using it in operational or customer decisions.
FlowOps is not intended to make decisions based solely on automated processing that produce legal or similarly significant effects on an individual. If we introduce such processing in the future, we will update our information and apply the safeguards required by applicable law.
United Kingdom data protection law gives individuals rights over their personal information.
- Ask for access to personal information and information about how it is used.
- Ask for inaccurate or incomplete information to be corrected.
- Ask for deletion or restriction where the legal conditions are met.
- Object to certain processing based on legitimate interests and object to direct marketing.
- Ask for data portability where the legal conditions apply.
- Withdraw consent at any time where consent is the lawful basis, without affecting earlier lawful processing.
We may need information to verify identity or understand a request. Where the law permits, the response period may pause while we reasonably wait for information needed to deal with a request.
You can raise a data protection complaint with us electronically at hello@flowopsone.com. We will consider the complaint and provide an outcome in accordance with applicable law. You also have the right to complain to the Information Commissioner’s Office if you are unhappy with how personal information has been handled.
FlowOps is designed for business use.
FlowOps is not directed to children and is not intended for individuals under 18 to create business accounts independently. If a customer organisation processes information about children through its legitimate service activities, that organisation is responsible for the lawful basis, notices and safeguards required for that processing.
The platform is not designed to require special category information or criminal offence information. If a customer chooses to process such information, the customer is responsible for identifying the additional legal condition and safeguards that apply.
Contact us about privacy or changes to this policy.
We may update this Privacy Policy when FlowOps, our providers or applicable law changes. We will keep this notice current and provide additional notice where a change is material and the law requires it.
For privacy questions, rights requests or complaints, contact Web Creators UK Ltd at hello@flowopsone.com.
Email FlowOps privacy