Your Privacy Matters
Your privacy is fundamental to how we operate. We are committed to protecting your personal data and being transparent about how we collect, use, and safeguard your information.
Flowwixa Inc. ("we," "us," or "our") operates the Flowwixa automation service platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our white-glove automation services.
Information We Collect
We collect information in two primary contexts:
1. Account & Service Data (We are the Data Controller)
- Account Information: Name, email, company name, billing address
- Payment Information: Credit card details (processed by Stripe), billing history
- Usage Data: Workflow execution logs, task counts, feature usage analytics
- Technical Data: IP address, browser type, device information, cookies
- Communications: Support tickets, feedback, email correspondence
2. Automation-Processed Data (We are the Data Processor)
Data processed through your automations (e.g., CRM contacts, lead information, customer records). You remain the Data Controller of this data; we process it solely on your behalf according to your instructions.
Important: We do not access, use, or sell automation-processed data for our own purposes.
How We Use Your Information
- Service Delivery: Create and manage your account, build and execute automations, provide customer support
- Billing & Payments: Process subscription fees, send invoices, manage payment methods
- Platform Improvement: Analyze usage patterns to improve features, fix bugs, and optimize performance
- Communications: Send transactional emails (e.g., password resets), service updates, and (with consent) marketing newsletters
- Security: Detect fraud, prevent abuse, protect against security threats
- Legal Compliance: Comply with tax laws, GDPR, CCPA, and other regulatory requirements
Legal Basis for Processing (GDPR)
For EU/EEA residents, we process your data based on:
- Contractual Necessity: Processing required to provide our automation services
- Legitimate Interests: Improving our platform, fraud prevention, analytics
- Legal Obligation: Tax compliance, financial regulations, legal requests
- Consent: Marketing communications, optional analytics, third-party integrations
Data Sharing & Disclosure
We share data only in the following circumstances:
Service Providers (Sub-processors)
AWS (hosting), Stripe (payments), Make.com (automation platform), Google (workspace tools), Datadog (monitoring). All sub-processors are bound by strict data protection agreements.
Legal Requirements
When required by law (e.g., court orders, subpoenas, tax authorities). We will notify you unless prohibited.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred (you'll be notified).
With Your Consent
When you authorize third-party integrations (e.g., connecting your CRM or email platform).
International Data Transfers
Flowwixa is headquartered in the United States. If you use our services from outside the US, your data may be transferred to and processed in the US. We protect international transfers using Standard Contractual Clauses (SCCs) approved by the EU Commission. Enterprise customers can request data residency in EU or APAC regions.
Data Security
We implement enterprise-grade security measures:
- AES-256 encryption at rest, TLS 1.3 for data in transit
- Role-based access controls (RBAC), Multi-Factor Authentication (MFA)
- Regular penetration testing and security audits
- SOC 2 Type II certified infrastructure
- 24/7 security monitoring and automated threat detection
Your Privacy Rights
Depending on your location, you may have the following rights:
✅ Access
Request a copy of your personal data
✏️ Rectification
Correct inaccurate or incomplete data
🗑️ Deletion
Request erasure of your data ("Right to be Forgotten")
📦 Portability
Receive your data in a machine-readable format
⛔ Restriction
Limit how we process your data
🚫 Objection
Object to processing for direct marketing
🔄 Withdraw Consent
Withdraw consent at any time
🏛️ Lodge Complaint
File a complaint with your Data Protection Authority
To exercise your rights: Email privacy@flowwixa.com or gdpr@flowwixa.com. We respond within 30 days.
Data Retention
We retain your data only as long as necessary:
- Active Accounts: While your account is active and for service delivery
- Billing Records: 7 years (tax and financial compliance)
- Usage Logs: 90 days for operational purposes
- Marketing Data: Until you unsubscribe or withdraw consent
- Closed Accounts: 30 days after account deletion (backups retained for 90 days)
Cookies & Tracking
We use cookies and similar technologies:
- Essential Cookies: Required for authentication and platform functionality
- Analytics Cookies: Google Analytics to understand usage patterns (anonymized)
- Preference Cookies: Remember your settings and preferences
You can control cookies through your browser settings. However, disabling essential cookies may limit platform functionality.
Children's Privacy
Flowwixa is not intended for children under 16. We do not knowingly collect personal information from children. If we discover that a child's data has been collected, we will delete it immediately.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email or through a prominent notice on our platform at least 30 days before they take effect. Continued use after changes constitutes acceptance.
Contact Us
For privacy-related questions or requests:
Privacy Team: privacy@flowwixa.com
GDPR Requests: gdpr@flowwixa.com
Data Protection Officer: dpo@flowwixa.com
Postal Address: Flowwixa Inc., 123 Automation Ave, Suite 500, San Francisco, CA 94105, USA