Effective: September 2026
This framework supplements the agreements with the operating business where FLIRIVO FLOW processes personal data on its behalf. Individual agreements and mandatory law prevail.
1. Parties and roles
The controller is the business using FLOW for its customer and operational workflows. The processor is the provider of the FLIRIVO FLOW platform identified in the central legal notice, to the extent data is processed solely on the business's instructions.
2. Subject matter and duration
The subject matter is the provision and operation of FLOW for the functions enabled within the purchased plan. Processing generally lasts for the relevant use and contractually required storage period and ends, subject to legal retention duties, with return or deletion of data processed on behalf of the business.
3. Nature and purpose
Depending on configuration, processing may cover appointments, requests, reservations, waitlists, queues, pickups, customer status, notifications, capacity planning, customer links, analytics and support. FLOW processes this data to provide the workflow determined by the business, maintain security and deliver the contracted service.
4. Data subjects and data categories
Data subjects may include customers, prospects, contacts and staff of the business. Data may include names, contact details, appointment and reservation information, wait and pickup information, status information, configurable fields, team and permission data and necessary security and usage records.
5. Instructions
The business determines purposes, permitted data fields, retention, recipients and allowed workflows. Instructions are given through agreed features, settings and documented communications. Instructions that are clearly unlawful may be suspended pending clarification.
6. Confidentiality and access
Persons with access to data processed on behalf of the business are bound to confidentiality and receive only the access required for their tasks. The business is responsible for appropriate assignment of team roles and individual permissions.
7. Protective measures
Appropriate organisational and technical measures are used to protect data, including access restrictions, secure transmission, separate user accounts, role-based permissions, records of important operations, backups, availability measures, ongoing security updates and procedures for handling security events.
8. Further service providers
Where further providers are used for hosting, email, infrastructure, support or comparable services as subprocessors, this is done under applicable data-protection requirements. Material changes are communicated under the agreed contractual rules. Payment providers may act under their own data-protection responsibility depending on the processing.
9. Assistance to the business
Within available features and information, FLOW assists the business with data-subject requests, correction, deletion, restriction, portability, security events, impact assessments and authority enquiries where required and appropriate for the relevant processing.
10. Security incidents
Known personal-data breaches affecting data processed on behalf of a business are communicated to that business without undue delay with the information available where a corresponding legal or contractual duty applies.
11. Return and deletion
After processing on behalf of the business ends, data is deleted or returned in accordance with agreed and legal requirements. Statutory retention duties and evidence strictly required for legal defence remain unaffected.
12. Information and audits
The provider supplies information reasonably required to demonstrate compliance with applicable processor obligations. Necessary audits are coordinated so that security, confidentiality and the rights of other customers remain protected.
13. Transfers outside the EEA
Where processing takes place outside the European Economic Area, the required legal conditions and safeguards are applied.
14. Responsibility of the business
The business remains responsible for lawfulness, transparency, data minimisation, its privacy information, permitted data fields, retention periods and the applicable legal basis. FLOW should not be used as uncontrolled storage for special categories of personal data.