Data Handling
Practical controls for approved client workflows
This page describes the current operating approach. Exact data sources, roles, providers, locations, retention and deletion instructions must be recorded for each live engagement in the Order Form and, where required, a data processing addendum.
Purpose and minimisation
Client workflow data is used only to provide, secure, monitor and support the agreed service or to meet documented legal and business-administration duties. The workflow should use only the data reasonably required for its stated purpose.
Roles and documented instructions
Roles depend on the processing activity. A client may act as controller and FlowOps as processor when FlowOps handles personal data on documented client instructions. FlowOps may act as an independent controller for its own billing, security, sales, legal and business administration. The relationship must be assessed before live processing; it is not assumed from this page alone.
Client separation and access
Live clients use separated configuration and approved destination resources. Access is limited according to role and operational need. Tokens and provider credentials should be handled through approved secure channels and kept server-side where the architecture supports it. The client remains responsible for its authorised users and source-system access.
Providers and locations
Only providers needed for an approved workflow should receive necessary data. The applicable provider, purpose, data categories, processing or storage location and any transfer safeguard should be recorded in the Order Form, DPA or approved subprocessor register. Not every provider is used for every client.
AI processing and Human Review
AI-assisted processing may produce drafts, summaries or classifications. Business-critical or external actions require the Human Review points defined in the workflow. Client data is not authorised for an unrelated purpose merely because an AI provider is part of the approved workflow.
Retention, export and deletion
Retention is set according to the workflow purpose, documented instructions, legal duties, security and technical constraints. The Order Form or DPA should state the active retention period, an available export format and window, and the deletion approach. Deletion from backups may follow the relevant backup cycle rather than occur immediately.
Logging and incidents
Operational and security events may be logged to investigate errors, protect the service and provide an audit trail. Logs should avoid unnecessary credentials and personal data. Relevant incidents are assessed and communicated without undue delay according to the parties' roles, facts and applicable obligations; no universal notification deadline is promised by this overview.
End of service
When a service ends, access may cease and data is returned, exported, retained or deleted as agreed and subject to legal and technical constraints. FlowOps does not guarantee every data type in every format or immediate deletion from every backup.
Operational template text. Owner and counsel review is required before Production. This is not a licensed attorney opinion. No company registration number or address is stated here.
Related documents: Privacy Policy, Security Overview, Service Scope and Terms.