Privacy Policy
Last updated: August 2, 2026
Flowipy ("we", "us", "our") respects your privacy and is committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR).
Data Controller
Flowipy is operated by Leif Peter Billekvist, Sweden, trading as Hoffstedts, which is the data controller for your account data. Contact: info@flowipy.com.
Data We Collect
- Account data: name, email address, business name, phone number, login credentials
- Order data: purchase history, plan and billing country. Card details are collected and processed by our Merchant of Record, Paddle — we never see or store card numbers
- Usage data: pages visited, features used, IP address, device and browser type
- Support data: messages you send us
- Customer data: your end-users' names, emails, and booking details (you are the data controller for this data)
How We Use Your Data
- To create your account and provide the service
- To complete orders, manage subscriptions and issue invoices
- To send transactional emails (booking confirmations, account notifications)
- To keep the platform secure and prevent fraud and abuse
- To provide customer support
- To improve our product based on aggregated usage patterns
Legal Basis for Processing (GDPR Article 6)
- Contract performance: processing necessary to provide the service you subscribed to
- Legitimate interest: analytics, product improvement, security and fraud prevention
- Legal obligation: accounting and tax records
- Consent: marketing emails and non-essential cookies (only with your explicit opt-in)
Data Processing Agreement (DPA)
When your customers book through Flowipy, you are the Data Controller and Flowipy acts as the Data Processor. We only process customer data on your behalf and according to your instructions to facilitate bookings.
Who We Share Data With
- Paddle.com — our Merchant of Record for the sale of our products, subscription management, payments, tax compliance and invoicing — paddle.com/legal/privacy
- Hosting, database and storage providers — EU data centers
- Transactional email provider — GDPR compliant
- AI providers used to generate images, video and text on your request (prompts and uploaded source material only)
- Professional advisers (legal, accounting) and authorities where required by law
Cookies
We use essential cookies to keep you signed in and secure, and — only with your consent — analytics cookies to understand how the product is used. You can change your choice at any time via the cookie banner or in your browser settings. See our Cookie Policy for details.
Security
We apply appropriate technical and organisational measures to protect your data, including encryption in transit, encryption at rest, row-level access controls in the database, and restricted administrative access.
Data Retention
We retain your account data for as long as your account is active. After account deletion, we remove or anonymise your personal data within 30 days; backups may retain data for up to 90 days. Generated videos in Flowipy Studio are automatically deleted after 7 days. Accounting records are kept for as long as Swedish law requires.
Your Rights Under GDPR
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to processing based on legitimate interest
- Withdraw consent at any time
To exercise these rights, email info@flowipy.com.
International Transfers
Your data is primarily stored in EU data centers. If any data is transferred outside the EU, we ensure appropriate safeguards (e.g., Standard Contractual Clauses).
Changes
We may update this policy. Significant changes will be communicated via email.
