Privacy
Privacy Policy
- Human review
- Written roles
- Manual invoice
FlowOps AI builds practical AI-assisted workflows for business operations. This page explains the basic personal data we may handle when providing demos, lead summaries, alerts, dashboards and workflow support.
What data we may process
Depending on the workflow, we may process contact names, email addresses, phone numbers, property or business enquiry details, lead notes, status updates, reply drafts, support messages and operational logs.
Roles and why we process it
We process this data to capture enquiries, summarise leads, flag urgent follow-ups, prepare AI-assisted reply drafts, send daily reports, maintain dashboards and support the service agreed with each client.
Data-protection roles depend on each activity. A client may act as controller and FlowOps as processor for an approved client workflow. FlowOps may act as an independent controller for its own enquiries, sales, billing, security, legal and business administration. The contracting entity and controller identity must be confirmed before a paid service begins.
AI-assisted processing
AI output is a draft or operational suggestion only. Clients must review and approve messages before sending them to their customers, landlords, sellers, buyers or tenants. FlowOps AI is designed to support human work, not replace professional judgement.
Where data is stored and processed
The current Starter and Growth setup may use Google Sheets for lead storage, Vercel for hosting and serverless functions, OpenAI for AI summaries and Resend for email notifications. Client-specific workflows may add or remove tools during onboarding.
Payment data
Payments are currently arranged by manual invoice. If online payments are introduced later, payment details should be handled by an approved payment provider rather than stored by FlowOps. Provider records may include billing contacts, payment status and invoice references.
Who has access
Access is limited to the FlowOps AI operator, approved client contacts and the service providers needed to run the workflow. Dashboard access is protected by an access code.
Retention
Demo data should be removed when it is no longer needed. Live client data retention is agreed during onboarding and should match the client's own data retention duties.
Providers, transfers and processing agreements
Not every provider is used for every client. The providers, processing locations and any international-transfer safeguard relevant to a live workflow should be documented in the Order Form, a data processing addendum or an approved subprocessor register. Where FlowOps processes personal data on a client's behalf, a separate DPA may be required before activation.
Your rights
People whose personal data is processed may have rights under UK data protection law, including rights to access, correct, erase, restrict or object to processing. Requests should be sent to hello@flowopsai.ai.
Important note
This is an operational privacy notice for an early-stage service, not a claim of universal compliance in every jurisdiction. Each paying client should confirm its lawful basis, notices, retention and data-processing requirements before live use. See Data Handling for the operational framework.
Operational template text. Owner and counsel review is required before Production. This is not a licensed attorney opinion. No company registration number or address is stated here.