Privacy policy | Flowstead
Privacy

Privacy policy

We handle personal data with care, and we think you should be able to read exactly what we do. This policy explains what we process when you visit our website, contact us or apply for a job with us.

1. Who we are

Flowstead, established in Utrecht. hello@flowstead.ai

Flowstead is the controller for the processing described in this policy. We have no data protection officer, because we are not required to appoint one. For privacy questions, use the address above.

2. What this policy covers

This policy covers the data we collect ourselves: through our website, through contact with us, and through job applications.

It does not cover the data our customers have processed through the Flowstead platform. When a company uses a digital colleague and that colleague processes orders, invoices or contracts, the company decides what happens with that data. That company is the controller and Flowstead is the processor. What we may and may not do in that role is set out in a data processing agreement per customer.

If you are an employee or a contact of one of our customers and you have a question about your data, please contact that company. We are happy to help them answer it.

3. What data we process

If you contact us

Through the form on our website, by email, on WhatsApp or by phone we process your name, your email address, the name of your organisation, your phone number if you provide it, and the content of your message.

If you book an introduction

We process your name, email address and the time slot you pick. We use the appointment feature of Google Calendar for this.

If you visit our website

Our web server automatically records your IP address, the browser and device you use, the page requested, the time and the status code. That is needed to run the site and to spot abuse.

If you apply for a job

We process your name, contact details, CV, motivation and the notes we take during interviews. We do not ask for data we do not need for the role.

We do not ask for special categories of personal data through our website, and we do not process them there.

4. Why we do it

What we doWhyLegal basis under the GDPR
Answering your message, booking a meeting, preparing a proposalTo answer your question and see whether we can help youPerformance of a contract or steps prior to it, article 6(1)(b)
Keeping our website available and secure and spotting abuseTo protect our serviceLegitimate interest, article 6(1)(f)
Handling your job applicationTo assess whether we want to continue togetherSteps prior to entering into a contract, article 6(1)(b)
Keeping our records and invoicesBecause the law requires itLegal obligation, article 6(1)(c)

We do not use your data for purposes other than those listed above. We do not sell your data and we do not rent it out.

5. How long we keep data

Type of dataRetention period
Contact and demo requests that do not lead to a customer relationshipUp to 24 months after our last contact
Data of customers and their contactsFor as long as we work together, and after that for as long as we need it for our records
Server logsUp to 30 days
Job applicationsUp to four weeks after the procedure ends. If we want to keep your data longer we ask for your consent separately and keep it for at most a year
Invoices and bookkeepingSeven years, under article 52 of the Dutch General Tax Act

6. Cookies

Our website places no cookies. We use no analytics cookies, no advertising cookies and no tracking pixels from social networks or ad platforms. That is why you never see a cookie banner.

We do load the typeface for our pages through Google Fonts. In doing so your IP address becomes visible to Google. No cookies are placed and you are not tracked across other websites.

7. Who we share data with

We use other parties to do our work, for example for hosting, email, calendar and the forms on our website. With each of them we have a data processing agreement stating that they may only process your data for us and not for their own purposes.

Which parties those are right now, where they are established and where the data is stored, we keep up to date on our trust page.

Beyond that we only share data when we are legally required to, for example at the request of a regulator. We always check the lawfulness of such a request first.

8. Data processed through the Flowstead platform

When a customer uses a digital colleague, that customer decides what data is processed and for what purpose. Flowstead acts solely on the customer's instructions and does not use customer data for its own purposes. What we may and may not do in that role is set out in the data processing agreement we sign with each customer.

How we secure that data, where the platform runs and which parties are involved is set out on our trust page. You can request the data processing agreement at hello@flowstead.ai.

9. How we secure data

We take appropriate technical and organisational measures to protect your data:

  • Traffic to our website and our platform is encrypted with TLS.
  • Data in our platform is stored encrypted.
  • Access to systems is limited to the people who need it and runs through personal accounts with two-factor authentication.
  • We keep a record of who has had access to systems holding customer data.
  • We have a responsible disclosure policy, so security researchers can report vulnerabilities to us.

If you suspect something has gone wrong with your data, tell us straight away at hello@flowstead.ai.

10. Your rights

You can ask us for:

  • Access to the data we process about you.
  • Rectification if data is incorrect or incomplete.
  • Erasure of your data.
  • Restriction of processing, for example while we assess a request from you.
  • Portability of your data in a common file format.
  • Objection to processing we base on a legitimate interest.

If you have given us consent for something, you can withdraw it at any time. That does not affect what we did before you withdrew it.

Send your request to hello@flowstead.ai. We respond within one month. If your request is complex we may extend that by two months, and we will tell you within the first month. To avoid handing data to the wrong person, we may ask you to prove your identity.

On our website we take no decisions about you based solely on automated processing that have legal effects for you.

11. Complaints

If you are unhappy with how we handle your data, tell us first. We would rather solve it together. If we cannot, you have the right to lodge a complaint with the Dutch Data Protection Authority.

autoriteitpersoonsgegevens.nl

12. Changes

We update this policy when our service or the rules give us reason to. The current version is always on this page, with the date of the last change below it. For significant changes we notify our customers directly.

Version 1.0. Last changed on 1 September 2026.

Want to know more about how we handle data?

Our trust page lists our security measures and the parties we work with. If you find a vulnerability, use our responsible disclosure policy.