Effective: 2026
This notice explains personal-data processing when using FLIRIVO FLOW. For a specific customer workflow, the privacy information of the business operating that workflow may additionally apply.
1. Provider and point of contact
The provider of the FLIRIVO FLOW platform is identified in the central legal notice. Privacy requests may be submitted using the contact details published there.
2. Roles of FLIRIVO and the operating business
The platform provider acts as controller for platform accounts, contractual administration, security, billing, support, operation and its own communications. When a business, authority, practice, workshop, restaurant or other organisation uses FLOW for its own appointments, reservations, queues, pickups or status processes, that organisation generally determines the purpose and content of its customer-data processing. Where legally required, FLIRIVO is used as a processor and the appropriate data-processing agreement must be established before productive use.
3. Privacy gate before publication
A newly created business cannot publish customer-facing FLOW functions until the required privacy setup is completed and an active product plan is available. Internal configuration and preview may remain available while public booking, reservation, queue and status entry points stay blocked.
4. Categories of data
- Account and sign-in data such as name, email, protected sign-in information, verification and two-step sign-in status.
- Business and contract data including organisation, address, contact details, plan, enabled functions and payment references.
- Staff and permission data including memberships, roles, individual rights, invitations and records of important changes.
- Appointment and reservation data including customer details, service, date, time, party size, alternatives, confirmations, rejections, cancellations and no-shows.
- Queue data including call number, position, join time, call, confirmation, requeue and service status.
- Pickup and customer-status data including reference codes, time windows and expected completion.
- Business-configured custom fields, for which the operating business must ensure necessity and legality.
- Security and usage data required to protect the service, such as IP-related information, time, browser/device information, accessed area, errors and protection events.
- Communication data including service emails and support messages.
5. Purposes
Data is processed to provide and administer the platform, operate customer processes, deliver notifications, control permissions, handle contracts and payments, support users, diagnose errors, plan capacity, produce authorised analytics and exports, and prevent abuse or unauthorised access.
6. Legal bases
Depending on the processing activity, relevant bases may include Article 6(1)(b) GDPR for contracts and pre-contractual steps, Article 6(1)(c) for legal obligations, Article 6(1)(f) for legitimate interests in secure and efficient operation, and Article 6(1)(a) for consent-based functions. The operating business determines the appropriate basis for its own customer workflows.
7. Special-category data
FLOW is not designed as a patient record, diagnostic system or general repository for sensitive information. Special-category data under Article 9 GDPR should only be processed where the operating organisation has a valid legal basis, appropriate safeguards and the necessary contractual setup. Free-text fields should not contain unnecessary sensitive information.
8. Public and private customer links
Some customer processes are accessed through personal, hard-to-guess customer links. Such links may expose status, appointment options or cancellation functions and must be treated as confidential. Public display boards default to ticket numbers without customer names; enabling names is a deliberate choice for which the operating organisation remains responsible.
9. Email notifications
FLOW can send service emails for requests, alternatives, confirmations, rejections, changes, reservations, pickups and status updates. Marketing communications are handled separately and require an appropriate legal basis.
10. Payments and Stripe
Stripe is used for one-time payments for paid FLOW licences. FLOW licence terms do not renew automatically. Payment data is generally processed directly by the payment provider while FLOW stores only the references required for the contract, product, licence term, status, invoice and transaction record. Stripe subscriptions that existed before this model was introduced may be processed through the end of an already paid period and then discontinued. The payment provider’s privacy information applies additionally.
11. Advertising
Depending on the selected plan, labelled advertising placements may be shown. Consent-dependent advertising or measurement technologies may only be activated where valid consent or another appropriate basis exists. Higher FLOW plans may be ad-free.
12. Cookies and browser storage
Required cookies or browser storage may be used for login, security, language, sessions and consent choices. Non-essential services are controlled through the configured consent mechanism.
13. Security and blocking logs
Erroneous or suspicious access attempts may be recorded and temporary access restrictions may be applied. Relevant information can include IP-related data, time, browser/device information, the accessed area and the reason for a restriction. Ordinary service errors are not treated as misuse by customers.
14. Recipients and service providers
Access is limited to parties that need the data for the relevant purpose, which may include hosting, email, payment, support and security providers. Staff access within each customer organisation is governed by FLOW’s role and permission model.
15. International transfers
Where providers outside the EEA are used or can access data from third countries, the required transfer mechanisms are considered, such as adequacy decisions or appropriate safeguards.
16. Retention and deletion
Data is retained only as long as necessary for the purpose, legal retention duties, contractual administration, evidence or security. FLOW supports process-specific retention periods and deletion of completed records. Backups may retain data for a limited additional recovery period.
17. Analytics and exports
Analytics and Excel/PDF exports are available only within the relevant business workspace and according to assigned permissions. Once exported, files become the responsibility of the exporting organisation and must be protected and deleted appropriately.
18. Data-subject rights
Where statutory conditions are met, individuals may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent for the future. For data belonging to a specific business process, the operating business will generally be the first point of contact.
19. Supervisory authority
Individuals have the right to lodge a complaint with a competent data-protection supervisory authority.
20. Automated process rules
FLOW can execute process rules such as automatic confirmations, requeueing or timed status changes. These automations are not intended as legally significant solely automated decisions under Article 22 GDPR. The operating organisation is responsible for configuring its rules appropriately.
21. Locations, maps and floor plans
A business can store locations, addresses, coordinates, counters, tables, rooms, entrances, pickup points, parking areas, calling screens and its own schematic floor plans and assign them to individual records. These details are shown publicly only where the business has enabled public visibility for the relevant place and record. Floor plans should contain operational information only and must not be used for unnecessary personal or sensitive data. FLOW can generate a privacy-conscious external Google Maps link; data is transferred to Google only when the user opens that link. Direct map embedding is optional. FLOW loads the embedded Google Maps view only where the user either explicitly allows Google Maps for that map view or has accepted all optional categories in the shared cookie dialog. The separate map permission is stored as a required consent choice and can be revoked again in the map view. Without such consent, only the privacy-conscious route link or a map/cookie-settings notice is displayed.
22. Changes
This notice may be updated when functions, legal requirements or service providers change. The published version applies.