Legal
Privacy Policy
Last updated: August 2026
In plain language
Your workspace content belongs to your organization; we hold it to run the service. We do not sell personal data, do not use workspace content for advertising, and do not send it to third-party AI providers or use it to train models. Analytics is off until you accept it, and it never carries names, emails, or record ids.
1. Who we are
FlowX ("we", "us") provides an operations platform for teams, delivered as a web application and as iOS and Android apps. This policy explains what personal data we collect when you use our website, product, and apps, why we collect it, and the rights you have over it. For privacy questions, contact support@flowx.ninja.
Two roles apply. For the content inside a workspace, the customer organization decides what is stored and why — it is the controller, and we process that content on its instructions. For account, website, billing, and security data, we decide the purposes ourselves and act as controller. If you are a member of someone else's workspace, address requests about workspace content to your workspace administrator first.
2. Data we collect
- Account data — name, work email, password (stored only as a bcrypt hash), workspace name, job title, avatar, role and permissions, language and timezone preferences.
- Workspace content — tasks, requests, approvals, projects, routines, comments, documents, attachments, and voice notes with their transcripts. Your organization controls this content.
- Usage and security data — sign-in times, IP addresses, browser and device details, and the actions recorded in your workspace's audit trail (a core product feature).
- Device data — push tokens for the browsers and mobile devices you enable notifications on, and the per-device notification settings that go with them.
- Communications — emails we send you (verification codes, invitations, notifications, invoices), messages sent to your workspace's email-intake address together with their attachments and sender details, and support tickets you submit — including the optional screenshot, the page you were on, and your browser's user agent.
- Billing data — the billing contact, company and address details, tax registration number, plan, seat and usage counters, and the invoices generated from them.
- Diagnostics — crash reports and performance traces from the mobile apps (device model, operating system, app version, and the technical stack of the error), and consent-based analytics described in section 9.
We never receive or store your full card details. Card data goes directly to the payment provider handling your purchase, under its own PCI-DSS compliance — see section 6.
3. Why we process it
- To provide the service: authentication, workspace functionality, approvals and SLA timers, notifications, and audit trails.
- To secure the service: abuse prevention, rate limiting, account-lockout protection, and security logging.
- To communicate: verification codes, invitations, service and billing notices, and support replies.
- To bill: calculating seats, storage, and usage, issuing invoices, collecting payment, and meeting tax and e-invoicing obligations.
- To improve the service: aggregate usage measurement, and diagnostics from crashes and slow requests.
- To comply with legal obligations applicable to us.
We do not sell personal data and we do not use your workspace content for advertising. We do not use workspace content to train AI models, and we do not send it to third-party AI providers — see section 7.
4. Legal bases (GDPR) and PDPL alignment
Where the EU GDPR applies, we rely on contract performance (providing the service you signed up for), legitimate interests (service security, diagnostics, and improvement), legal obligation (tax and accounting records), and consent where required — analytics being the clearest case. Where the Saudi Personal Data Protection Law (PDPL) applies, we process personal data with your knowledge for the purposes described here, and honor the rights it grants you. You can withdraw consent at any time without affecting processing already carried out.
5. Where your data lives and how it is protected
- Workspace data is hosted on Amazon Web Services in the EU (Frankfurt) region, unless your order form states another region.
- Each workspace's data is isolated from other customers at the database level (row-level security), enforced on every query rather than by application code alone.
- Data is encrypted in transit (TLS). Files and attachments are encrypted at rest in object storage with AWS-managed keys, or with a customer-managed KMS key where one is configured.
- Access to production data is restricted to the operators who need it, is authenticated separately from customer accounts, and is recorded in an operator audit log.
- Backups are taken on a rotating schedule and are protected to the same standard as the live system.
6. Sharing and sub-processors
We share personal data only with the processors needed to run the service:
- Amazon Web Services — hosting, database, file storage, and backups.
- Microsoft — delivery of transactional email, and Microsoft sign-in where your workspace uses it.
- Google (Firebase) — push notifications on Android and the web, mobile crash reporting, performance reporting on mobile and the web, consent-based analytics, and Google sign-in where your workspace uses it.
- Apple — push notification delivery to iOS devices.
- Payment providers — depending on your billing country, either our payment gateway (with FlowX as the seller) or a merchant of record that is the seller for that transaction and processes the payment under its own privacy policy.
Where your workspace connects single sign-on or a mailbox for email intake, data also flows to and from the provider you chose, under your own agreement with it.
We may disclose data where a competent authority legally requires it. We do not give any provider the right to use your data for its own purposes.
7. Automated processing inside the product
- Voice notes may be transcribed to text automatically. The transcription service runs on our own infrastructure — audio is not sent to any third-party AI provider, and nothing from it is used to train models.
- The product moves work forward automatically: status changes, approval routing, SLA timers, escalations, and reminders. These follow rules your workspace configures, not profiling of individuals.
- We do not make automated decisions about you that produce legal effects or similarly significant effects.
8. Retention
- Workspace data is retained while your workspace is active. Audit history is kept for the window your plan provides (30 to 365 days).
- If a workspace is closed, data is retained so the closure can be reversed; it is not deleted automatically. An administrator can ask us to erase it, and we do so on request. Backups age out on their own rotation.
- Invoices and the billing records behind them are kept for as long as tax and accounting law requires, even after a workspace closes.
- You can export your workspace data at any time from Settings → System.
9. Cookies, analytics, and local storage
- Strictly necessary: an authentication session cookie (httpOnly, SameSite=Lax, sent only over HTTPS in production) and your interface preferences (theme, language), stored in your browser.
- Analytics: we use Google Analytics to count visits and see which pages and screens are used. Nothing loads and no analytics cookie is written until you accept the banner, a decline is remembered, and analytics is disabled entirely outside production.
- Inside the product and the mobile apps the rules are stricter: we never send your name, email, user id, or workspace identifiers; record ids in URLs are replaced with a placeholder before anything is sent; and query strings — which can contain search terms — are dropped entirely.
- Crash reporting is active in released mobile app versions, and performance reporting on the mobile apps and the web, so we can fix defects and slow pages. Both carry technical diagnostics, never your workspace content.
- We use no advertising or cross-site tracking cookies anywhere.
10. Security of your account
Passwords are stored only as bcrypt hashes and are never recoverable in plain text. You can protect your account with two-factor authentication, a passkey, or your organization's single sign-on, and administrators can require two-factor authentication for the workspace. Sessions are held in an httpOnly cookie that JavaScript cannot read, and changing a password or revoking a session invalidates the tokens issued before it. Tell us at once if you suspect unauthorized access; where a personal-data breach is likely to affect you, we notify the affected customers and the relevant authority within the deadlines the law sets.
11. International transfers
Workspace data is hosted in the EU, and some of our processors — notably push notification and analytics providers — operate outside it. Where personal data is transferred across borders we rely on the safeguards the applicable law provides, including standard contractual clauses and the transfer conditions of the Saudi PDPL. Details for your contract are available on request.
12. Your rights
Subject to applicable law (PDPL / GDPR), you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing. Workspace members should direct requests to their workspace administrator first, since the customer organization controls workspace content; where we act as processor we assist that organization in answering you. You can also contact us directly, and we respond within the period the applicable law allows. If you are not satisfied, you may complain to your supervisory authority — in Saudi Arabia, SDAIA.
13. Children
FlowX is a workplace tool sold to organizations. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.
14. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be announced to workspace administrators by email before they take effect.
15. Contact
Privacy questions, or a request about your data: support@flowx.ninja. The terms that govern use of the service are in the Terms of Service.