Legal

Privacy policy

What personal data we collect, why, and the rights you hold over it.

Last updated 5 September 2026

In short

FlowFinds Solutions Kft. is the controller for personal data about your FlowFinds account. We collect an email address, what you do in the product, what you pay, and the technical logs a service needs to stay up. We do not sell personal data, we do not run advertising trackers on this site, and we do not use your storefront content or your buyers’ data to train models.

Where FlowFinds handles data about your buyers — orders, satisfaction samples, support email — you are the controller and we are your processor under the data processing addendum. Your rights, and how to use them, are in clauses 8 and 9.

The summary is not the agreement. Where it and a numbered clause differ, the clause governs.

Contents

  1. Who we are
  2. What we collect, why, and on what basis
  3. What we do not do
  4. Where the data comes from
  5. Who receives it
  6. International transfers
  7. Security
  8. Your rights
  9. How to exercise them
  10. Children
  11. Changes to this policy

1. Who we are

1.1 The controller is FlowFinds Solutions Kft., registered in Hungary, company registration number 13-09-242910.

1.2 Privacy enquiries go to [email protected]. We have not appointed a Data Protection Officer, because our processing does not meet the criteria in Article 37 GDPR that make one mandatory. The address above reaches the people who are accountable for this policy.

1.3 This policy covers our company surfaces, the FlowFinds application, its API and its documentation. Storefronts generated for customers are operated by those customers and carry their own privacy notices.

2. What we collect, why, and on what basis

Every category of personal data we hold about you is in this table, with the purpose it serves, the lawful basis for it, and how long it is kept.

CategoryWhat it containsPurposeLawful basisRetention
Account identityEmail address, the time the account was created, the plan it is on, the time the address was verified, and how the account arrived.To create and operate the account, sign you in, and contact you about the service.Performance of a contract (Art. 6(1)(b) GDPR).For the life of the account, then 30 days.
Sign-in recordsSingle-use sign-in tokens sent by email, session identifiers, and the session cookie bound to your account.Passwordless authentication and keeping you signed in.Performance of a contract; legitimate interests in account security (Art. 6(1)(f)).Tokens expire within minutes of issue; sessions until sign-out or expiry.
Product and store workProducts claimed or held, passed products, offer and pricing figures, storefront settings and generated pages, domains chosen, section order and the reasons recorded for it.To deliver the product research, offer and storefront the service exists to produce.Performance of a contract.For the life of the account, then 30 days.
Usage and meteringCounts of agent actions per tool per rolling window, entitlement checks, and dashboard verdict state.To enforce plan limits fairly, to bill correctly, and to detect abuse.Performance of a contract; legitimate interests in preventing abuse.13 months.
Payment recordsAmount, currency, status, time, plan, and the payment provider's transaction reference. We never receive your card number.To take payment, credit an advertising balance, and issue receipts and invoices.Performance of a contract; legal obligation for accounting records (Art. 6(1)(c)).8 years, as Hungarian accounting law requires.
Advertising ledgerEach movement of your advertising balance, its amount, its reason and its idempotency reference.To hold money you added separately from usage allowance, and to make every movement auditable.Performance of a contract; legal obligation.8 years, as Hungarian accounting law requires.
Referral recordsYour referral code, the sessions that opened it, and which milestone each reached. Not the identity of the invited person.To operate the referral programme and to detect manipulation of it.Performance of a contract; legitimate interests in programme integrity.24 months from the last milestone.
Storefront orders and supportOrders recorded against a generated store, satisfaction samples, and email your buyers send to the support address the product issues you.To run the after-sale tools: order tracking, satisfaction sampling and the support agent. Here you are the controller and we act on your instructions.Processed on your behalf under the data processing addendum.For the life of the account, then 30 days, unless you delete sooner.
Supplier and payout detailsSupplier connection settings, and the payout destination you configure for store revenue.To connect sourcing and to route money you earn.Performance of a contract; legal obligation where anti-money-laundering rules apply.For the life of the account, then as accounting law requires.
Technical and security logsIP address, user agent, request path, timestamps, error traces and rate-limit events.To keep the service available, to investigate faults and to detect attacks.Legitimate interests in security and service continuity.90 days, longer only for a specific incident under investigation.
CorrespondenceEmails you send us, and our replies.To answer you and to keep a record of what was agreed.Legitimate interests in handling enquiries; performance of a contract.24 months from the last message, longer where a dispute is live.

The operational detail behind the retention column — where each store lives and how deletion actually runs — is on data handling and retention.

3. What we do not do

3.1 We do not sell personal data, and we do not share it for cross-context behavioural advertising.

3.2 We do not use advertising or analytics trackers on this site. The only cookies we set are the ones listed in the cookie policy, and they are strictly functional.

3.3 We do not use your storefront content, your buyers’ orders or your support email to train models.

3.4 We do not make decisions producing legal or similarly significant effects about you by automated means. The agent’s verdicts are recommendations shown to a person, and no account is suspended without human review.

4. Where the data comes from

4.1 Mostly from you: what you type, upload, configure and buy.

4.2 Some from your use of the service: usage counters, verdict state, and technical logs generated as requests are served.

4.3 Some from our payment provider: the confirmed status and reference of a transaction, which we read back rather than trusting a returning browser.

4.4 Some from a person who referred you: the fact that a link was opened, recorded against a session rather than against your identity.

5. Who receives it

5.1 Sub-processors. A small number of vendors process data on our instructions — payments, transactional and inbound email, network delivery, and the model provider behind the agent. Each is named with its role and location on sub-processors, and each is bound by the sub-processor terms.

5.2 Professional advisers. Accountants and lawyers, where they need it and under a duty of confidence.

5.3 Authorities. Where the law compels disclosure. We check that a request is valid and proportionate, disclose the minimum, and tell you unless we are prohibited from doing so.

5.4 A successor. If the business is sold or reorganised, under equivalent protection and with notice to you.

6. International transfers

6.1 Personal data is stored on infrastructure we operate in the European Union.

6.2 Some sub-processors are established outside the EEA. Where a transfer occurs, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision covering the recipient, and we assess whether additional safeguards are needed for that destination.

6.3 The country of establishment of each sub-processor, and the transfer mechanism relied on, are stated on sub-processors. Ask us at [email protected] for a copy of the clauses relied on for a particular transfer.

7. Security

7.1 Data is encrypted in transit, access is restricted to the people who need it, and payment credentials are held outside the application and never written into a generated store.

7.2 The measures we actually apply — and the certifications we do not hold — are set out plainly on security. We do not claim an audit we have not had.

7.3 Where a breach is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectify data that is inaccurate or incomplete;
  • erase data where it is no longer needed, where you withdraw consent that was the basis for it, or where you successfully object;
  • restrict processing while a dispute about accuracy or lawfulness is resolved;
  • port the data you gave us, in a structured, machine-readable format;
  • object to processing based on legitimate interests, on grounds relating to your situation;
  • withdraw consent at any time, where consent was the basis, without affecting processing already carried out.

8.1 Erasure does not extend to records we are legally required to keep, principally accounting records of payments.

8.2 Where you are a buyer of a FlowFinds customer’s shop, your rights are exercised against that shop as controller. Contact them; if they cannot be reached, write to us and we will pass the request on.

9. How to exercise them

9.1 Email [email protected] from the address on the account, saying which right you are exercising. There is no form to complete.

9.2 We respond within one month. Where a request is complex we may extend by two further months and will tell you why within the first month.

9.3 Requests are free. We ask for proof of identity only where we genuinely cannot otherwise confirm it, and we ask for the minimum that settles the question.

9.4 If you are unhappy with how we handled a request, you may complain to the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), or to the supervisory authority of the EU member state where you live or work. We would rather you told us first.

10. Children

10.1 FlowFinds is not offered to people under 18, and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will delete it.

11. Changes to this policy

11.1 The date at the top of this page is the date of the last substantive revision.

11.2 Where a change materially affects how we use your data, we give at least 30 days’ notice by email before it takes effect. A previous version is available on request.

Questions about this document

Write to [email protected]. For a privacy request specifically, use [email protected], which reaches the same people faster. Every other document in this set is listed on the legal index, and the plain-English explanations of how we operate are under trust.