Privacy policy
We handle personal data with care, and we think you should be able to read exactly what we do. This policy explains what we process when you visit our website, contact us or apply for a job with us.
1. Who we are
Flowstead, established in Utrecht. hello@flowstead.ai
Flowstead is the controller for the processing described in this policy. We have no data protection officer, because we are not required to appoint one. For privacy questions, use the address above.
2. What this policy covers
This policy covers the data we collect ourselves: through our website, through contact with us, and through job applications.
It does not cover the data our customers have processed through the Flowstead platform. When a company uses a digital colleague and that colleague processes orders, invoices or contracts, the company decides what happens with that data. That company is the controller and Flowstead is the processor. What we may and may not do in that role is set out in a data processing agreement per customer.
If you are an employee or a contact of one of our customers and you have a question about your data, please contact that company. We are happy to help them answer it.
3. What data we process
If you contact us
Through the form on our website, by email, on WhatsApp or by phone we process your name, your email address, the name of your organisation, your phone number if you provide it, and the content of your message.
If you book an introduction
We process your name, email address and the time slot you pick. We use the appointment feature of Google Calendar for this.
If you visit our website
Our web server automatically records your IP address, the browser and device you use, the page requested, the time and the status code. That is needed to run the site and to spot abuse.
If you apply for a job
We process your name, contact details, CV, motivation and the notes we take during interviews. We do not ask for data we do not need for the role.
We do not ask for special categories of personal data through our website, and we do not process them there.
4. Why we do it
| What we do | Why | Legal basis under the GDPR |
|---|---|---|
| Answering your message, booking a meeting, preparing a proposal | To answer your question and see whether we can help you | Performance of a contract or steps prior to it, article 6(1)(b) |
| Keeping our website available and secure and spotting abuse | To protect our service | Legitimate interest, article 6(1)(f) |
| Handling your job application | To assess whether we want to continue together | Steps prior to entering into a contract, article 6(1)(b) |
| Keeping our records and invoices | Because the law requires it | Legal obligation, article 6(1)(c) |
We do not use your data for purposes other than those listed above. We do not sell your data and we do not rent it out.
5. How long we keep data
| Type of data | Retention period |
|---|---|
| Contact and demo requests that do not lead to a customer relationship | Up to 24 months after our last contact |
| Data of customers and their contacts | For as long as we work together, and after that for as long as we need it for our records |
| Server logs | Up to 30 days |
| Job applications | Up to four weeks after the procedure ends. If we want to keep your data longer we ask for your consent separately and keep it for at most a year |
| Invoices and bookkeeping | Seven years, under article 52 of the Dutch General Tax Act |
6. Cookies
Our website places no cookies. We use no analytics cookies, no advertising cookies and no tracking pixels from social networks or ad platforms. That is why you never see a cookie banner.
We do load the typeface for our pages through Google Fonts. In doing so your IP address becomes visible to Google. No cookies are placed and you are not tracked across other websites.
7. Who we share data with
We use other parties to do our work, for example for hosting, email, calendar and the forms on our website. With each of them we have a data processing agreement stating that they may only process your data for us and not for their own purposes.
Which parties those are right now, where they are established and where the data is stored, we keep up to date on our trust page.
Beyond that we only share data when we are legally required to, for example at the request of a regulator. We always check the lawfulness of such a request first.
8. Data processed through the Flowstead platform
When a customer uses a digital colleague, that customer decides what data is processed and for what purpose. Flowstead acts solely on the customer's instructions and does not use customer data for its own purposes. What we may and may not do in that role is set out in the data processing agreement we sign with each customer.
How we secure that data, where the platform runs and which parties are involved is set out on our trust page. You can request the data processing agreement at hello@flowstead.ai.
9. How we secure data
We take appropriate technical and organisational measures to protect your data:
- Traffic to our website and our platform is encrypted with TLS.
- Data in our platform is stored encrypted.
- Access to systems is limited to the people who need it and runs through personal accounts with two-factor authentication.
- We keep a record of who has had access to systems holding customer data.
- We have a responsible disclosure policy, so security researchers can report vulnerabilities to us.
If you suspect something has gone wrong with your data, tell us straight away at hello@flowstead.ai.
10. Your rights
You can ask us for:
- Access to the data we process about you.
- Rectification if data is incorrect or incomplete.
- Erasure of your data.
- Restriction of processing, for example while we assess a request from you.
- Portability of your data in a common file format.
- Objection to processing we base on a legitimate interest.
If you have given us consent for something, you can withdraw it at any time. That does not affect what we did before you withdrew it.
Send your request to hello@flowstead.ai. We respond within one month. If your request is complex we may extend that by two months, and we will tell you within the first month. To avoid handing data to the wrong person, we may ask you to prove your identity.
On our website we take no decisions about you based solely on automated processing that have legal effects for you.
11. Complaints
If you are unhappy with how we handle your data, tell us first. We would rather solve it together. If we cannot, you have the right to lodge a complaint with the Dutch Data Protection Authority.
12. Changes
We update this policy when our service or the rules give us reason to. The current version is always on this page, with the date of the last change below it. For significant changes we notify our customers directly.
Version 1.0. Last changed on 1 September 2026.
Want to know more about how we handle data?
Our trust page lists our security measures and the parties we work with. If you find a vulnerability, use our responsible disclosure policy.