We take your privacy seriously. This policy explains what data we collect, why we collect it, and how we keep it safe — in plain English, not legalese.
FlowStack AI Ltd is a data controller registered in England and Wales. Our registered office is in Manchester. If you have questions about this policy, write to us at contact@flowstackai.cloud.
We collect personal data only when you actively provide it or when it is generated as a necessary part of delivering our services. We do not buy data lists or acquire personal information from third-party data brokers.
Data we collect includes:
We do not collect payment card data directly. Any transactions are handled by third-party payment processors under their own security standards.
We use your data to deliver our consultancy services and to communicate with you about your engagement. Our lawful bases under UK GDPR are:
We will never sell your personal data, use it for unrelated advertising, or share it with third parties except where required to deliver your project (e.g. integration partners you've selected) or where required by law.
We use a small number of carefully selected third-party tools to run our business. Each processor is bound by a Data Processing Agreement and GDPR-compliant terms.
Where a client engagement involves AI model APIs (e.g. OpenAI, Anthropic), any data processed is covered by the data processing agreements we put in place as part of that engagement.
We retain client data for as long as is necessary to fulfil the engagement and comply with our legal obligations. In practice:
All data is stored on servers located within the UK or EEA, or in jurisdictions with adequate protection decisions from the UK ICO.
Under UK GDPR you have the right to:
To exercise any of these rights, email contact@flowstackai.cloud. We will respond within 30 days. If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the ICO at ico.org.uk.
This website uses no advertising cookies and no cross-site tracking technologies. We use Plausible Analytics, a cookieless, privacy-first analytics tool that does not collect personal identifiers and does not require a cookie consent banner.
If you contact us via a third-party form or booking tool embedded on our site, that provider may set their own cookies. Please refer to their individual privacy policies for details.
We may update this policy from time to time as our services evolve or legal requirements change. When we make material changes, we will update the "last updated" date at the top of this page and, where appropriate, notify active clients by email.
Continued use of our website or services after a policy update constitutes acceptance of the revised terms.