GetFlowly IA
Data protection

Privacy policy

We limit collection to information required to operate and secure the service and support users.

Controller and scope

The operating entity named in your contract or commercial document controls account data. Each customer company remains responsible for its own contacts’ data and configures the purposes of its agent.

Data we process

  • Account: name, professional email, phone number and role.
  • Organization: business identity, catalog, services, opening hours and members.
  • Conversations: WhatsApp or email messages, authorized attachments and delivery events.
  • Commerce: orders, bookings, payments and receipts, without storing payment secrets in the browser.
  • Technical: security logs, correlation identifiers, Push subscriptions and usage metrics.

Purposes and legal bases

This data is used to provide the platform, fulfill contractual requests, secure access, prevent abuse, improve agent quality and meet legal obligations. Campaigns and follow-ups respect recorded consent for each channel.

Processors and transfers

Depending on enabled features, data may be processed by Supabase, Meta, the configured AI provider, Chariow, the email service and Push services. Only the data required for the requested operation is transmitted.

Retention and security

Retention periods depend on the contract, organization settings and accounting obligations. Secrets remain server-side, data access is isolated by organization using RLS, and sensitive actions are logged.

Your rights

You can request access, correction, export or deletion when permitted by law. Administrators also have controlled export and deletion tools. Use the contact page for any request.