GDPR Compliant

Privacy Policy

Last updated: March 19, 2026  ·  Hopson & Cie Srl  ·  Brussels, Belgium

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis (GDPR)
  5. Google Calendar & Third-Party Integrations
  6. Data Sharing & Sub-processors
  7. Data Retention
  8. Your Rights (GDPR)
  9. Security
  10. Cookies & Local Storage
  11. Children's Privacy
  12. International Transfers
  13. Changes to This Policy
  14. Contact & DPO
Our commitment: We collect only what is strictly necessary to operate Flowo. We never sell your personal data. You can request deletion at any time.

1. Who We Are

Flowo is operated by Hopson & Cie Srl, a company incorporated under Belgian law:

Hopson & Cie Srl

149 avenue du Domaine, 1190 Bruxelles, Belgium

VAT: BE 0450.443.155

Email: privacy@getflowo.com

Website: https://getflowo.com

Hopson & Cie Srl acts as the data controller within the meaning of the EU General Data Protection Regulation (GDPR — Regulation 2016/679) for all personal data processed through the Flowo platform.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

2.2 Subscription & Payment Data

Payments are processed exclusively by Polar.sh (our payment processor). We do not store your credit card number or bank details. We receive and store:

2.3 Usage & App Data

To provide the service, we store:

2.4 Google Calendar Integration Data (Optional)

If you choose to connect Google Calendar:

2.5 Technical Data

CategoryExamplesStored inRetention
AccountEmail, username, password hashCloudflare D1 (SQLite)Until account deletion
SubscriptionPlan, status, datesCloudflare D1Until account deletion
Tasks & EventsTitles, dates, notesCloudflare D1Until account deletion
GCal TokensAccess + refresh tokenCloudflare D1 (encrypted)Until disconnection
Local preferencesLanguage, sidebar stateBrowser localStorageUntil browser clear

3. How We Use Your Data

We never use your data for advertising, never sell it to third parties, and never build marketing profiles based on your usage.

4. Legal Basis (GDPR Art. 6)

Processing activityLegal basis
Creating and managing your accountContract performance (Art. 6.1.b)
Processing subscription paymentsContract performance (Art. 6.1.b)
Sending transactional emailsContract performance (Art. 6.1.b)
Google Calendar integrationConsent (Art. 6.1.a) — you explicitly authorise via OAuth
AI task suggestionsLegitimate interest (Art. 6.1.f) — core product feature
Security monitoring & fraud preventionLegitimate interest (Art. 6.1.f)
Legal obligations (tax records)Legal obligation (Art. 6.1.c)

5. Google Calendar & Third-Party Integrations

5.1 Google Calendar (Optional)

When you connect Google Calendar, Flowo requests the following OAuth scopes:

We use these permissions exclusively to:

Your OAuth refresh token is stored encrypted in our database and is used solely to maintain the sync. You can revoke access at any time from your Google Account settings (myaccount.google.com/permissions) or from within the Flowo settings page.

Flowo's use of Google Calendar data complies with the Google API Services User Data Policy, including the Limited Use requirements.

5.2 Other Integrations

6. Data Sharing & Sub-processors

We share personal data only with the following categories of recipients:

Sub-processorPurposeLocation
Cloudflare, Inc.CDN, edge hosting, D1 database, DDoS protectionUSA (SCCs)
OpenAI, LLCAI task suggestions (task content only, no account data)USA (SCCs)
Polar.shPayment processing and subscription managementUSA (SCCs)
Resend, Inc.Transactional email deliveryUSA (SCCs)
Google LLCOAuth authentication, Calendar API (only if you connect)USA (SCCs)

SCCs = Standard Contractual Clauses (EU Commission Decision 2021/914) for GDPR-compliant international transfers.

We do not share data with advertisers, data brokers, analytics companies, or any other parties beyond the above.

7. Data Retention

8. Your Rights (GDPR)

As a data subject under the GDPR, you have the following rights:

To exercise any of these rights, email us at privacy@getflowo.com. We will respond within 30 days as required by GDPR.

9. Security

We implement appropriate technical and organisational measures to protect your personal data:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33, and affected individuals without undue delay as required by Art. 34.

10. Cookies & Local Storage

10.1 What we use

Flowo uses no third-party tracking cookies and no advertising cookies. We use only:

NameTypePurposeDuration
flowo_session / sa_user_*localStorageKeeping you logged in between visitsUntil logout or browser clear
sa_langlocalStorageRemembering your language preferencePersistent until changed
sa_sidebar_*localStorageSidebar width and mini/expanded statePersistent until changed
g_stateHTTP Cookie (HttpOnly)CSRF protection during Google OAuth flow10 minutes (auto-expires)
gcal_stateHTTP Cookie (HttpOnly)CSRF protection during Google Calendar OAuth10 minutes (auto-expires)
No analytics trackers (no Google Analytics, no Facebook Pixel, no Hotjar). No advertising networks. No cross-site tracking.

10.2 Cloudflare

Cloudflare may set a cookie (__cf_bm) for bot detection and security purposes. This is a strictly necessary cookie. See Cloudflare's privacy policy.

11. Children's Privacy

Flowo is not directed at children under the age of 16. We do not knowingly collect personal data from individuals under 16. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at privacy@getflowo.com and we will delete the data promptly.

12. International Data Transfers

Our primary sub-processors (Cloudflare, OpenAI, Polar, Resend) are based in the United States. These transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914, providing adequate safeguards for your personal data as required by GDPR Chapter V.

Data processed by Cloudflare is subject to their Data Processing Addendum and their binding corporate rules. Cloudflare Workers and D1 can be configured to process data exclusively within the EU — we are actively evaluating this option for future compliance improvements.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

Continued use of Flowo after the effective date of changes constitutes acceptance of the updated policy.

Previous versions of this Privacy Policy are available upon request at privacy@getflowo.com.

14. Contact & Data Protection

For any questions, requests, or complaints regarding this Privacy Policy or the processing of your personal data:

Data Controller & Privacy Contact

Hopson & Cie Srl

149 avenue du Domaine, 1190 Bruxelles, Belgium

Email: privacy@getflowo.com

VAT: BE 0450.443.155

If you are not satisfied with our response, you have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA):

Autorité de protection des données (APD)

Rue de la Presse 35, 1000 Bruxelles

Website: www.dataprotectionauthority.be

Email: contact@apd-gba.be

Phone: +32 2 274 48 00

For cross-border disputes, you may also use the EU Online Dispute Resolution platform: ec.europa.eu/consumers/odr