Flowella Privacy Policy
Last updated: August 21, 2025
Introduction
Flowella (the “Service”, operated by Discover Digital Solutions Limited) is committed to protecting your privacy and handling personal data in a transparent, secure manner. This Privacy Policy explains what information we collect when you use Flowella’s no-code WhatsApp integration platform, how we use and store that information, and your rights regarding your data. We maintain this Privacy Policy in accordance with WhatsApp’s requirements that businesses provide clear notices and obtain necessary permissions for data use business.whatsapp.com, and in compliance with applicable data protection laws (including GDPR). By using Flowella, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Service.
Information We Collect and Process
Data from WhatsApp Interactions
When you or your customers interact with your WhatsApp flows via Flowella, we collect minimal personal data necessary to provide the Service, in line with GDPR’s data minimization principle heydata.eu. Specifically:
-
WhatsApp Phone Numbers: We store the WhatsApp phone number of the user initiating or participating in a Flow. This is used to identify the conversation and deliver messages.
-
WhatsApp Profile Name: We may store the profile name associated with the WhatsApp account (the name the user has set on WhatsApp) to help identify the user in the interface.
No Message Content or Form Responses: Flowella does not store the content of your WhatsApp conversations or any form inputs provided through the WhatsApp Flows. Message text, attachments (like photos/documents), and responses to flow questions are not saved on our servers. Instead, all such customer data is transmitted and stored directly in your connected systems (e.g. your HubSpot CRM) as configured. This means the substantive information collected via a flow (survey answers, form data, documents, etc.) resides in your own HubSpot instance or other integrated application, not in Flowella’s database. We limit our data collection solely to what is necessary to facilitate the conversation (phone number and name), honouring the purpose limitation principle (data is used only for the intended conversational flow and integration ), heydata.eu.
Account and Contact Information
If you are a Flowella customer (for example, you sign up for a free trial, create an account, or contact us for support), we will collect information you provide directly to us, such as:
-
Contact details: Your name, business name, email address, and phone number (for account registration, inquiries, or onboarding).
-
Account credentials: If an account is created, we collect necessary login information (such as email and password).
-
Communication content: If you correspond with us (e.g. via email or our contact form), we collect the information in those messages (for example, questions or feedback you submit).
We use this information to create and manage your Flowella account, provide customer support, and communicate about our services. This data is kept separate from WhatsApp end-user data. We do not access or collect personal data from your HubSpot CRM or other integrated apps beyond what is required to send the data you direct us to send.
Automatically Collected Data
When you use our website or dashboard, certain technical information may be collected automatically to ensure the Service functions properly and securely. This can include:
-
Usage and log data: such as IP address, browser type, device type, and timestamps of access. We primarily use this data for security logging, fraud prevention, and to improve platform performance.
-
Cookies or similar technologies: Our website may use cookies to remember your preferences or session state. Any non-essential cookies will be used only with your consent, where required. (Please refer to our Cookie Policy if available for more details on how we use cookies.)
We do not use any of this technical data to identify individual users, and we do not track users across third-party sites.
How We Use Your Information
We only use personal information for the following purposes:
-
To Provide and Operate the Service: Phone numbers and profile names from WhatsApp are used to deliver messages and run the interactive flows (e.g. ensuring the right user receives the right form questions). We use the data you input (such as responses in a flow) strictly to route it into your chosen integrated system (like updating a record in your HubSpot CRM). We do not use this data for any secondary purposes. In fact, WhatsApp requires that data obtained through its platform be used only as necessary to support the messaging interaction business.whatsapp.com, and we adhere to this rule.
-
Integration with Your Systems: We process the collected WhatsApp interaction data and immediately forward it to the platforms you’ve connected (for example, sending a survey response to your HubSpot CRM or another database as configured). This allows you to collect and manage customer information in your own systems in real time. Flowella acts as a conduit in this process and does not retain the content of the data.
-
Account Management and Customer Support: For Flowella customers, we use your account and contact information to manage your account, provide support, send important service updates, and respond to inquiries. For instance, we might email you about important changes to the Service, security notifications, or to offer help with onboarding if you requested it.
-
Service Improvement and Analytics: We may use aggregated or anonymized usage data (that does not identify any individual) to understand how the Service is used and to improve features and performance. For example, we might track the number of flows executed or messages sent in a given period. These analytics do not include any personal conversation content or personal identifiers—they are purely operational metrics.
-
Legal Compliance and Protection: We may process certain data as required to comply with legal obligations or to protect our rights and users’ safety. For example, maintaining logs (including phone numbers or IP addresses) may be necessary to detect misuse, fraud, or to comply with applicable laws and regulations. If we are required by law to disclose data (e.g., under a court order), we will only do so to the extent necessary and in accordance with applicable data protection laws.
We do not use personal data for marketing or advertising purposes without consent. We do not sell or rent your personal information to any third party. All usage of data is tied to providing the Flowella service that you or your organization has signed up for.
Data Sharing and Disclosure
We value your privacy and limit the sharing of personal data to what is necessary to operate our service or as required by law:
-
With Your Authorized Integrations: By design, Flowella sends the information collected through WhatsApp flows to the integrations you connect and authorize (for example, your own HubSpot CRM instance). This means that any data your end-users submit via WhatsApp (survey answers, contact info, etc.) will be shared with that third-party platform at your direction. Flowella does not independently share this data elsewhere. The data in your CRM is then governed by your agreement with that CRM provider. For instance, if you connect HubSpot, the data will be subject to HubSpot’s privacy policy and security measures. We encourage you to ensure any integrated services you use have proper data protection practices.
-
Service Providers (Sub-processors): We use trusted third-party service providers to host and run Flowella. In particular, our database is hosted on Supabase (on AWS servers in Western Europe) for storing the limited data we keep (like WhatsApp numbers and names). These providers may process personal data on our behalf, but solely for the purposes of providing the service to you. We have agreements in place with such providers to ensure they only use data for our specified purposes and protect it to high standards. For example, Supabase ensures that all customer data is encrypted at rest and in transit supabase.com. We also use standard cloud infrastructure and may, for example, rely on AWS data centers via Supabase. All such infrastructure providers are GDPR-compliant and subject to strict confidentiality and security obligations.
-
Within Our Organization: The personal data we store (e.g. account info or WhatsApp contact data) is accessible only to authorized personnel at Flowella/Discover Digital who need to access it to operate and support the Service. Our team members are bound by confidentiality and trained on data privacy. We do not share individual customer data across different client accounts. Each Flowella client’s data is isolated – we will never disclose or transmit information from one client’s WhatsApp communications to any other client or third party without permission. (This aligns with WhatsApp’s policy that information from one customer’s chat cannot be shared with another business.whatsapp.com.)
-
Legal Requirements: We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). In such cases, we will review the request carefully and only provide information if we are legally compelled to do so. Wherever possible, we will inform the affected party of such requests.
-
Business Transfers: If Flowella (or Discover Digital) is involved in a merger, acquisition, or asset sale, your personal data may be transferred to the new owner/partner as part of that transaction. If that happens, we will ensure the new entity honors the commitments we have made in this Privacy Policy, and we will notify you (for example, via email or a notice on our site) of any such change in ownership or control of your personal information.
Importantly, we do NOT sell personal data to third parties. We do not share your information for third-party marketing. Any sharing that occurs is solely to provide our service or as legally required, as outlined above.
Data Storage and Security
We understand that the security of your data is paramount. Flowella employs industry-standard security measures to protect the personal information we handle. Here are key aspects of our data storage and security practices:
-
Data Location: All personal data that Flowella stores (such as WhatsApp phone numbers and profile names, and your account information) is stored on secure servers located in Western Europe. Our primary data store is a Supabase-managed database hosted on Amazon Web Services (AWS) in a West Europe data center. Keeping data in the EU helps ensure compliance with European data protection regulations and reduces latency for our EU customers.
-
Encryption: We utilize robust encryption to safeguard data. All data in our database is encrypted at rest using AES-256 encryption, and all data in transit is protected via TLS/HTTPS supabase.com. This means that whether your data is being stored or transmitted between our servers and your device (or to your integrated systems), it is encrypted and protected from unauthorized access.
-
Access Controls: Access to personal data is strictly limited. Only a small number of authorized Flowella personnel (such as engineers or support staff who need access to troubleshoot or manage the service) can access the databases, and even then, only for legitimate operational reasons. We employ role-based access control and authentication measures to prevent unauthorized internal access. Admin access to servers and databases is logged and audited.
-
Security Practices: We follow best practices to secure our application and infrastructure. This includes regular software updates, security patching, firewalls, and network security measures to prevent unauthorized intrusion. We also utilize Multi-Factor Authentication (MFA) and other identity verification for our internal accounts. Our hosting platform Supabase is SOC 2 Type 2 certified and undergoes regular third-party penetration tests supabase.com , adding extra assurance that our infrastructure is secure.
-
Data Minimization: As noted, we intentionally minimize the personal data we store. By not storing conversation content or sensitive customer data on our servers, we significantly reduce the risk exposure. The most sensitive data (your customers’ responses, documents, etc.) bypasses our storage and goes straight to your systems, meaning we don’t hold that data at rest. This design choice (processing in real-time without storing) helps protect your users’ privacy by limiting what exists on Flowella’s platform heydata.eu.
-
Monitoring and Protection: We monitor our systems for any signs of security breaches or suspicious activity. In the unlikely event of a data breach involving personal data, we have an incident response plan that includes notifying affected users and authorities as required by law. We also utilize encryption and secure protocols in all communications with WhatsApp and with your integrated services.
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. However, we continuously update and refine our security measures to meet or exceed industry standards, and we commit to promptly addressing any security issues that arise.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law. Our retention practices are as follows:
-
WhatsApp Contact Data: WhatsApp phone numbers and profile names that we store in our database are kept as long as you continue to use Flowella and need these contacts for ongoing flows. This data is necessary to recognize returning users and maintain conversation context. If you (the Flowella client) delete a contact from the system or if you stop using our service, we will delete or anonymize those contact records during periodic clean-ups, or earlier upon your request.
-
Conversation Content: As noted, we do not store conversation content or flow responses on our servers. Any message content or data entered by users in WhatsApp is not retained by Flowella beyond the immediate processing moment. Once the data is handed off to your integrated system (e.g. logged in HubSpot or forwarded to your API endpoint), we do not keep a copy. We also do not create persistent logs of message bodies. This means there is no long-term retention of your customers’ message text, answers, or attachments within Flowella. In effect, conversation data exists only in transit through our service and is then stored on your side (e.g., your CRM) according to your own retention policies.
-
Account and Transaction Data: For our direct customers (the businesses using Flowella), we may retain certain information like your account details, billing records, and communications with us for as long as your account is active and as needed for our business operations. For example, we keep invoicing records as required for financial reporting and audits. If you cancel your Flowella account, we will delete or anonymize personal data associated with your account within a reasonable period, except for any data we are required to keep by law (for example, records of transactions for tax purposes) or for legitimate business interests (like handling any disputes).
-
Analytics Data: Any aggregated usage data or technical logs that we collect (which do not contain personal content) may be retained for internal analysis and security monitoring. Typically, web server logs and similar data are retained for a short period (e.g., a few weeks or months) unless we are investigating security incidents, in which case relevant log excerpts might be kept until the issue is resolved.
-
Deletion Requests: If we receive a verified deletion request from an individual (either an end-user or one of your customers) regarding their personal data that we control, we will delete the relevant data from our systems (see “Your Rights” below for details on how to request deletion). When we act as a data processor for data stored in your integrated systems (like HubSpot), we will assist you in fulfilling deletion requests as needed, but you as the data controller will generally be responsible for removing data from your own systems.
After the retention period has elapsed, or upon fulfilling the purpose for which the data was collected, we will securely delete or anonymize personal data. Anonymization means stripping the data of personally identifying characteristics so that it can no longer be linked to an individual.
GDPR Compliance and Legal Basis
Flowella is designed and operated with strong privacy protections to comply with the General Data Protection Regulation (GDPR) and other applicable privacy laws. If you are in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with similar laws, you have specific rights and assurances under this policy. We want to highlight how we comply with key GDPR principles and requirements:
-
Lawful Bases for Processing: We only process personal data when we have a valid legal basis. For the data of our business customers (you, the client using Flowella), we process your information (like account data) primarily on the basis of contractual necessity – i.e., to provide you the service you have requested. For personal data of end-users (your customers who interact via WhatsApp), we act as a data processor on your behalf. In GDPR terms, you as the business are the data controller determining the purpose (e.g. collecting a survey response) and Flowella processes that data per your instructions. We rely on the fact that you have obtained the user’s consent or have another lawful basis (such as legitimate interest or contract with the user) to engage with them via WhatsApp. WhatsApp’s policy itself requires that businesses using its platform secure all necessary consents from users before messaging them business.whatsapp.com business.whatsapp.com. By using Flowella, you confirm that you have the right to send messages to those users and to collect their data through the platform. We can also sign a Data Processing Agreement (DPA) with our customers upon request, to formally outline our GDPR obligations as a processor.
-
Data Minimization & Purpose Limitation: In line with GDPR principles, we minimize the data we collect and ensure it is used only for the specific purpose intended heydata.eu. As described, we only collect WhatsApp contact identifiers and do not collect or store any unnecessary personal data or message content. We use personal data strictly to facilitate the WhatsApp conversation flows and integrate with your systems – nothing more. We do not repurpose the data for profiling, marketing, or any unrelated activities.
-
Transparency: This Privacy Policy is meant to provide transparent information about our data practices, fulfilling GDPR’s requirement for clear and plain-language privacy notices. If anything is unclear, please reach out to us (contact details are provided below) and we will be happy to explain further.
-
International Data Transfers: We understand our clients may be globally distributed. Flowella itself stores data in the EU (Western Europe). If you access Flowella from outside the EU, or if you integrate Flowella with a system that stores data outside the EU, there may be transfers of personal data across borders. When we (or our sub-processors) transfer personal data out of the EEA, we ensure appropriate safeguards are in place, such as the Standard Contractual Clauses or other lawful transfer mechanisms, to protect the data. For example, if any support or engineering work on data is done from our offices outside the UK/EU, it is done under EU-approved data transfer frameworks. We also note that WhatsApp is a global service; using WhatsApp Business API inherently involves Meta’s processing which may include transfers (Meta uses data centers in the US and globally). We advise our customers to inform their end-users of this and obtain any necessary consent.
-
Integration Partners’ Compliance: We integrate with third-party platforms like HubSpot which are themselves GDPR-compliant. HubSpot, for instance, acts as a processor under strict terms and offers DPAs to its customers legal.hubspot.com. By ensuring that data is passed into reputable systems, we help maintain end-to-end compliance. However, it is also your responsibility to configure and use such systems in a compliant way (e.g., not storing data longer than needed in HubSpot, honoring deletion requests, etc.).
-
Children’s Data: Flowella is not directed to or intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you are aware that a child’s data has been provided to us via our Service, please contact us and we will take steps to delete it. We expect our business customers to avoid using Flowella to target or collect data from children in ways that would violate applicable laws.
Overall, Flowella’s approach – using an EU-based infrastructure and enforcing strict data use limits – is aligned with recommendations for WhatsApp Business API GDPR compliance heydata.eu. We require explicit opt-in from end users via WhatsApp’s own mechanisms and your policies, we limit data collection to the necessary metadata, and we ensure data is kept within the EU or protected by adequate safeguards. These measures help you use WhatsApp for business while staying GDPR-compliant heydata.eu.
Your Rights and Choices
If you are an individual in the EEA, UK, or other regions with similar data protection laws, you have certain rights regarding your personal data. Flowella is committed to assisting our customers and end-users in exercising these rights:
-
Right of Access: You have the right to request a copy of the personal data we hold about you, as well as information on how we process it.
-
Right of Rectification: If any personal data we have is inaccurate or incomplete, you have the right to ask us to correct it. For example, if you are a Flowella account holder and your email address has changed, you can update it or ask us to update it.
-
Right to Erasure: You have the “right to be forgotten,” meaning you can request that we delete personal data we hold about you. For instance, if you are an end-user who interacted with a Flowella-powered WhatsApp conversation and you wish to have your phone number removed from our database, you can request deletion. We will comply with such requests to the extent required by applicable law. (Note: if your data resides in a third-party system like a business’s CRM, you’ll need to contact that business as well, but we will assist our clients in fulfilling such requests from their users.)
-
Right to Restrict Processing: You can ask us to limit processing of your data in certain circumstances (for example, while a question about accuracy or legality of processing is being resolved).
-
Right to Data Portability: For data you provided to us directly, you have the right to request a copy in a common format to transfer to another provider. (This mostly applies to account owners. For WhatsApp end-users, since we collect minimal data, portability requests would generally be handled by the business that collected your info through their CRM.)
-
Right to Object: You have the right to object to our processing of your personal data if you believe it is being done on grounds (like legitimate interests) that are not compelling or if it’s for direct marketing. We do not send marketing to end-users, and any marketing to our customers is consent-based, so this is unlikely to be an issue. But if you ever receive such communications, you can opt out at any time.
-
Right not to be subject to Automated Decision-Making: Flowella does not make any legally significant decisions about individuals solely by automated means. There is no profiling or automated decision in our service that affects your rights.
To exercise any of these rights, or to inquire about your personal data, please contact us at info@flowella.io. We may need to verify your identity before fulfilling certain requests (to ensure that we don’t disclose or delete data to the wrong person). We will respond to requests within the timeframe required by law (generally within one month for GDPR-related requests, with an extension if necessary and permitted). For end-users of our customers: if you contact us directly, we might forward your request to the relevant business (our customer) when appropriate, since they may be the data controller of your information in their CRM. We will guide and assist in this process.
Additionally, if you are in the EEA or UK and believe we have not handled your personal data properly according to the law, you have the right to lodge a complaint with your country’s Data Protection Authority (DPA). For example, in the UK, this would be the Information Commissioner’s Office (ICO). We encourage you to contact us first so that we can address your concerns directly. However, you also have the option to reach out to the authorities.
Deletion and Account Cancellation
If you wish to delete your data or cancel your Flowella account, please submit a request to our support team at info@flowella.io. For security, please write to us from the email associated with your account (or otherwise provide proof of ownership). Upon such a request:
-
We will delete personal data that we hold about you (as an account holder) that we are not required to retain. This includes removing your profile information from our user database, and any WhatsApp contact data associated solely with your account’s use of the Service.
-
For any end-user data that might remain in our logs or databases (like a WhatsApp number), we will remove it or anonymize it so it can no longer be linked to that individual.
-
Note that deletion in our system does not automatically remove data that was already delivered to your integrated systems (for example, if a contact was created in your HubSpot, that record remains in HubSpot until you remove it). You should separately delete data from those systems if required. We can assist by clarifying what data was transmitted.
-
We will confirm once the deletion process is completed. Some residual data (backups or cached data) might persist for a short period in our secure backups, but if so, it will be protected and eventually purged in the normal backup rotation cycle. We ensure that such data is not readily accessible and is only retained temporarily for disaster recovery purposes.
Keep in mind that if you are an end-user of one of our business clients and you want your WhatsApp conversations or data removed, it’s best to reach out to the business you interacted with (the data controller). They can then instruct us if any action is needed on our end. We have a dedicated email for privacy inquiries (info@flowella.io) and will treat deletion requests with priority.
Third-Party Links and Services
Our website or communications may occasionally contain links to third-party websites (for example, a link to our blog, documentation, or an external article). If you follow a link to any external site, please note that these sites have their own privacy policies and we do not accept responsibility or liability for their content or practices. This Privacy Policy applies solely to data processed by Flowella. We encourage you to review the privacy policies of any third-party services you interact with. The same goes for the external services you integrate with Flowella (like HubSpot, WhatsApp itself, etc.) – those services have their own privacy commitments. For instance, WhatsApp’s privacy policy and terms will govern what WhatsApp (Meta) does with any metadata or info they collect when you use their platform.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Service, legal requirements, or other aspects of our operations. If we make material changes, we will notify our users by email (if you have an account) or by posting a prominent notice on our website or within the dashboard. The “Last updated” date at the top will always indicate when the last changes were made. We encourage you to periodically review this page for the latest information on our privacy practices. Continuing to use Flowella after a change to this Privacy Policy means you acknowledge and accept the revised terms (to the extent permitted by law). If you disagree with any update, you should discontinue using the Service and can request that your data be deleted as described above.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please do not hesitate to contact us:
Flowella (Discover Digital)
Email: info@flowella.io
You may also reach out to us by mail at our operating office:
Discover Digital – Flowella Team
Arlington Business Park
Theale, Reading, RG7 4TY
United Kingdom
(This address is provided for official correspondence. Please use email for the fastest response.)
We are here to help and will gladly answer any questions you may have about your privacy. Your trust is extremely important to us, and we want to ensure you feel secure using Flowella.
Thank you for choosing Flowella. We’re dedicated to enabling powerful WhatsApp interactions with respect for privacy and data security at every step heydata.eu business.whatsapp.com.