On this page
1. Our Role
2. Lawful Bases
3. Data Subject Rights
4. Data Processing Agreement
5. Subprocessors
6. International Transfers
7. Security Measures
8. Breach Response
9. Retention and Deletion
10. Complaints and Supervisory Authorities
11. Contact the Data Protection Team
Your privacy, built in
We design our platform and processes to protect personal data and earn your trust every day.
LEGAL

GDPR & Data Protection

Last updated August 3, 2026
FlowSmartly is committed to protecting personal data and helping our customers comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and other applicable data protection laws.
1

Our Role

Our role depends on whose data it is, and the difference decides who answers a request.
For the personal data you bring to FlowSmartly — your contacts, leads, message recipients and the people your campaigns reach — you are the controller and we are your processor. We process it only on your documented instructions, under the Data Processing Agreement in section 4.
For the data we collect in our own right — website visitors, prospects, event attendees, and the account, billing and support records of the people who administer a FlowSmartly workspace — we are the controller ourselves. That processing is described in our Privacy Policy, and we answer those requests directly.
The controller in that second case is General Computing Solutions, 132 Lincoln St, Pittsfield, MA 01201, USA. Data protection questions and requests go to privacy@flowsmartly.com.
2

Lawful Bases

Every purpose needs its own lawful basis, so here they are purpose by purpose rather than as a list of bases in the abstract:
Providing and operating the platform — performance of our contract with you (Article 6(1)(b)).
Billing, tax records and anti-fraud checks — compliance with a legal obligation (Article 6(1)(c)).
Security, abuse prevention and product improvement — our legitimate interests (Article 6(1)(f)), weighed against your rights and open to objection at any time.
Analytics and marketing storage on our website — your consent (Article 6(1)(a)), withdrawable at any time from Cookie settings.
Processing carried out for a customer — the customer’s own lawful basis. We act on their documented instructions and never for purposes of our own.
We only process special categories of personal data or data about criminal convictions when strictly necessary and permitted by law, and with appropriate safeguards in place.
3

Data Subject Rights

Data subjects whose personal data is processed through FlowSmartly have the following rights under GDPR:
Right of access
Right to rectification
Right to erasure
Right to restriction
Right to data portability
Right to object
Where we are the controller — you visited our site, wrote to us, attended an event, or hold a FlowSmartly account — send your request to privacy@flowsmartly.com and we handle it ourselves. We acknowledge it, confirm who you are, and answer within one month. If the request is genuinely complex we may extend by up to two further months, and we will tell you why before the first month is up.
Where your data reached us because one of our customers uploaded it, that customer is the controller and only they can decide the request. Send it to us anyway: we identify the customer, forward it to them within five business days, tell you who they are, and support them in answering it as required by the DPA. We never leave a request unanswered on the grounds that it arrived at the wrong party.
You can also withdraw consent at any time where we rely on it, which is no harder than giving it and does not affect processing that already happened. And whatever we decide, you keep the right to complain to a supervisory authority — see section 10.
4

Data Processing Agreement

We maintain a Data Processing Agreement (DPA) with our customers governing the processing of personal data in accordance with GDPR. It sets out our responsibilities as a processor, your obligations as a controller, data security requirements, the use of subprocessors, and international transfer mechanisms.
5

Subprocessors

We use a small number of carefully selected subprocessors to deliver our services. Each one is contractually bound to protect personal data and to process it only on our behalf and on our documented instructions.
6

International Transfers

FlowSmartly is established in the United States and some subprocessors operate elsewhere, so personal data does leave the European Economic Area. For those transfers we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), on the UK International Data Transfer Addendum for transfers from the United Kingdom, and on the Swiss addendum recognized by the Federal Data Protection and Information Commissioner.
We carry out a transfer impact assessment where the destination country calls for one, and we apply supplementary measures — encryption in transit and at rest, strict access control, and a commitment to challenge overbroad government requests for data — where they are needed to keep the protection essentially equivalent. A copy of the clauses we use is available on request from privacy@flowsmartly.com.
7

Security Measures

We protect personal data with encryption in transit and at rest, role-based access controls, regular security testing, and continuous monitoring of our infrastructure and applications.
8

Breach Response

If a personal data breach occurs, we notify affected customers without undue delay and, where required, the relevant supervisory authority within 72 hours of becoming aware of the breach.
9

Retention and Deletion

Where we are the controller, we keep personal data on the schedule published in our Privacy Policy: account data for the life of the account and then up to 90 days, billing and tax records for seven years, support conversations for 24 months, security logs for 12 months, and website analytics for up to 24 months.
Where we process for a customer, we keep the data for as long as their agreement runs. On termination we delete or return it within 30 days of their request, and it leaves our backups within a further 35 days as the rolling backup cycle overwrites them — unless a law requires us to keep a specific record for longer. When a period ends, data is securely deleted or irreversibly anonymized.
10

Complaints and Supervisory Authorities

If you think we have handled personal data badly, tell us first if you are willing — privacy@flowsmartly.com reaches the people who can actually investigate it. That is an invitation, not a condition: nothing about it limits your right to go straight to a regulator.
You may lodge a complaint with the supervisory authority in the EEA country where you live, where you work, or where the alleged infringement took place. In the United Kingdom that is the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. Where one of our customers is the controller, the complaint is normally made against them, and we will help both sides establish the facts.
11

Contact the Data Protection Team

For questions about this policy, our processing activities, or to raise a data protection concern, contact us:
Data Protection Team
privacy@flowsmartly.com
General Computing Solutions, 132 Lincoln St, Pittsfield, MA 01201, USA — we acknowledge within 2 business days and answer within one month.