On this page
1. Overview and Who We Are
2. Information We Collect
3. How We Use Information
4. Legal Bases for Processing
5. How We Share Information
6. Data Retention
7. Your Privacy Rights
8. California Privacy Rights
9. Security
10. Children's Privacy
11. International Transfers
12. Changes
13. Contact Us
LEGAL

Privacy Policy

Last updated August 4, 2026
At FlowSmartly, your privacy is important to us. This Privacy Policy explains how we collect, use, share, and protect your information when you use our website, platform, and services.
1

Overview and Who We Are

The controller of the personal data described in this policy is General Computing Solutions, the company that provides FlowSmartly, with its principal place of business at 132 Lincoln St, Pittsfield, MA 01201, USA. This policy covers FlowSmartly (“FlowSmartly”, “we”, “us”, “our”), and describes how we handle information when you visit our website, use our platform, attend our events, or communicate with us.
We are the controller for the data we collect in our own right: website visitors, prospects, event attendees, and the account, billing and support records of the people who administer a FlowSmartly workspace. Where a customer uploads their own contacts, leads or message recipients into the platform, that customer is the controller and we act as their processor — our GDPR & Data Protection page explains how those requests are handled.
Privacy questions and requests: privacy@flowsmartly.com, or write to us at the address above. There is one privacy team and it answers both.
2

Information We Collect

We collect information in three ways:
Information you provide: name, email address, company, job title, billing information, content of messages, and other information you choose to provide.
Automatically collected information: device and browser information, IP address, pages viewed, referral URLs, usage data, and cookies or similar technologies.
Information from third parties: information from integrations, partners, and public sources.
3

How We Use Information

We use the information we collect to:
Provide, operate, and improve our platform and services.
Communicate with you about your account, services, and support.
Personalize your experience and deliver relevant content.
Analyze usage and trends to enhance performance and security.
Comply with legal obligations and enforce our agreements.
4

Legal Bases for Processing

If you are in the European Economic Area, the United Kingdom or Switzerland, we must have a legal basis for every purpose we process your data for. These are ours, purpose by purpose:
Providing the platform and your account — performance of our contract with you (Article 6(1)(b)). Without this data there is no account to operate.
Billing, tax records and anti-fraud checks — compliance with a legal obligation (Article 6(1)(c)), and performance of the contract for the payment itself.
Keeping the service secure and improving it — our legitimate interests in a safe, working, improving product (Article 6(1)(f)). We weigh those interests against your rights, and you can object at any time.
Analytics and marketing storage on this website — your consent (Article 6(1)(a)), taken through the cookie notice and withdrawable at any time from Cookie settings, with no loss of access.
Marketing email to people who are not yet customers — consent, or our legitimate interest in business-to-business outreach where local law allows it. Every message carries a one-click unsubscribe.
Establishing, exercising or defending legal claims — our legitimate interests, and a legal obligation where a law requires the record to be kept.
Where we rely on consent, you can withdraw it at any time and it is no harder to withdraw than it was to give. Withdrawing consent does not affect processing that already happened while the consent was valid.
5

How We Share Information

We do not sell personal information for money, and we have never done so. We share information in these limited circumstances:
Service providers who help us operate our business, under confidentiality obligations and our documented instructions.
Partners and integrations that enable features you use.
Legal requirements, to protect rights, safety, and security, or in connection with a business transfer.
With your consent or at your direction.
One case deserves naming plainly: if you allow the Marketing category on this website, limited online identifiers reach advertising partners so that we can tell which campaign earned a signup. California law calls that “sharing”. It is off until you turn it on, and section 8 explains how to turn it back off.
6

Data Retention

We keep personal information only as long as it is needed for the purpose it was collected for. In practice that means:
Account and profile data — for as long as the account is open, then deleted or anonymized within 90 days of closure.
Content and files you upload — until you delete them, or within 90 days of account closure.
Billing, invoicing and tax records — seven years, because tax law requires it.
Support conversations — 24 months from the last message in the thread.
Marketing contact details — until you unsubscribe. We then keep a minimal suppression record indefinitely, so that we do not contact you again by mistake.
Security, access and audit logs — 12 months.
Website analytics and attribution — up to 24 months in our systems. The first-touch record held on your own device has no expiry date, and is erased the moment you withdraw consent or clear site data.
Backups — overwritten on a rolling 35-day cycle, so anything deleted from the live service leaves our backups within 35 days.
Where a legal hold, an investigation or an active dispute requires it, we keep the specific records involved until the matter closes. When a period ends, the data is securely deleted or irreversibly anonymized.
7

Your Privacy Rights

Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or port your personal information, and to withdraw consent where we rely on it. California residents have the additional rights set out in section 8.
To exercise a right, email privacy@flowsmartly.com or use the contact form on this site. We will confirm who you are — usually by asking you to reply from the address we already hold, or to confirm details of the account — and we only ask for what is needed to be sure we are not handing your data to someone else. You may also use an authorized agent, provided we can verify their permission to act for you.
We answer within one month for GDPR requests and within 45 days for California requests. Where a request is genuinely complex we may extend once — by two further months under GDPR, or by a further 45 days in California — and we will tell you why before the original deadline passes. Requests are free unless they are manifestly unfounded or excessive.
You always have the right to lodge a complaint with a supervisory authority. In the EEA that is the authority where you live, where you work, or where the issue arose; in the United Kingdom it is the Information Commissioner's Office; in Switzerland it is the Federal Data Protection and Information Commissioner; in California you may complain to the California Privacy Protection Agency or the Attorney General. Telling us first is welcome, never required, and never a condition.
8

California Privacy Rights

This section is for California residents and describes our practices under the CCPA as amended by the CPRA. In the preceding twelve months we collected the following categories of personal information, from you, from your device as you use the site, from our customers, and from the partner and public sources described in section 2:
Identifiers — name, email address, postal address, phone number, account identifier and IP address, to create and run your account and to answer you.
Commercial information — plan, credits purchased and transaction history, to bill you and support the account.
Internet and network activity — pages viewed, features used and the campaign you arrived from, to measure and improve the site and the product.
Approximate location — the region inferred from your IP address, for security, regional pricing and tax. We do not collect precise geolocation.
Professional information — company, job title and industry, to set the product up for the kind of business you run.
Audio and electronic information — recordings and transcripts of calls handled by Call Agent, which we hold on behalf of the customer who made them.
Inferences — simple segments drawn only from the categories above, such as which part of the product is likely to be useful to you.
We disclose these categories to service providers and contractors for the business purposes described in section 5, and we retain them for the periods in section 6.
Do Not Sell or Share. We do not sell personal information for money and have not in the preceding twelve months. We do share limited online identifiers for cross-context behavioral advertising, but only while you have the Marketing category switched on — it is off by default. “Cookie settings”, in the footer of every page, is our “Do Not Sell or Share My Personal Information” control, and we honor the Global Privacy Control browser signal automatically as an opt-out. We do not sell or share the personal information of anyone we know to be under 16.
Your rights, and what each one means here:
Know and access — the categories and specific pieces of personal information we hold about you.
Delete — personal information we collected from you, subject to the exceptions in the statute.
Correct — inaccurate personal information.
Opt out of sharing — cross-context behavioral advertising, at any time and without giving a reason.
Limit sensitive information — we do not use or disclose sensitive personal information for any purpose that gives rise to this right, so there is nothing to limit.
Non-discrimination — we will never deny you service, charge a different price, or give you a lower quality of service because you exercised a privacy right.
9

Security

We use administrative, technical, and physical safeguards to protect your information. While we strive to use commercially reasonable measures, no method of transmission or storage is 100% secure.
10

Children's Privacy

Our services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will delete it.
11

International Transfers

FlowSmartly is based in the United States, and some of the subprocessors that deliver parts of the service operate elsewhere. Personal data originating in the EEA, the United Kingdom or Switzerland is therefore transferred outside those regions.
For those transfers we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), on the UK International Data Transfer Addendum for transfers from the United Kingdom, and on the Swiss addendum recognized by the Federal Data Protection and Information Commissioner. We assess the destination country where the transfer calls for it, and we apply supplementary measures — encryption in transit and at rest, strict access control, and a commitment to challenge overbroad government requests — where they are needed to keep the protection equivalent.
A copy of the clauses we use is available on request from privacy@flowsmartly.com.
12

Changes

We may update this policy from time to time. We will post the updated policy and update the “Last updated” date above. Material changes will be communicated where required by law.
13

Contact Us

For questions about this Privacy Policy or our privacy practices, reach out to us:
General Computing Solutions
privacy@flowsmartly.com
132 Lincoln St, Pittsfield, MA 01201, USA — we answer privacy requests within one month.
Privacy choices
You're in control. Manage cookies and similar technologies or adjust your communication preferences.
Manage preferences