Privacy Policy
Last updated: September 2026
1. Introduction
Kho’n Sul’t SRL, a private limited liability company incorporated under Belgian law, registered office Rue Victor Rauter 147, 1070 Anderlecht, Belgium, enterprise number 0846.631.440, VAT BE0846631440, contactable at contact@getflowr.app, is responsible for the personal data described here ("we", "us"). Full company details are in the Legal Notice.
This covers both the website and the Flowr application. Where your organisation uses Flowr to manage its own projects, your organisation decides what goes into it and is the controller of that data; we process it on its behalf under the Data Processing Agreement.
We have not appointed a data protection officer; data protection questions go to the address above.
2. If you only contact us
When you request early access or use the contact form, we collect:
- Your email address
- Your name, where you give it
- Your role, the number of projects you run and the tools you use today, where you give them
- The message you write and the plan a link carried, if any
3. If your organisation uses Flowr
A workspace holds the data your organisation puts into it. This includes personal data about the people who use it and the people it refers to:
- Account and sign-in identifiers, name and email address
- Which organisation you belong to, your access role, and the project responsibilities assigned to you
- Projects, plans, tasks, milestones, dependencies and stages
- Status reports and the narrative written in them, risks, issues, business cases, lessons and closure records
- Budgets, approved amounts and their approval history, rates, forecasts and calculated costs
- Timesheets, hours recorded against tasks, leave, and who submitted and approved them
- Resource assignments and capacity
- An audit history recording who changed what, and when
- Notification preferences, and billing identifiers held against your organisation
4. How we use it
- To operate the service your organisation subscribes to
- To authenticate you and enforce the access your organisation grants
- To bill your organisation and keep the records that requires
- To answer your questions and manage early access
- To diagnose faults, using error reports
5. Our legal bases
We rely on the following legal bases under Article 6 GDPR:
- Performance of a contract — to provide the service your organisation subscribes to, to administer accounts and to bill.
- Legitimate interests — to secure and diagnose the service, to prevent abuse, and to respond to enquiries. We have considered these against your interests and rights.
- Legal obligation — to keep the accounting and tax records the law requires.
- Where we act as processor for your organisation's workspace data, your organisation determines the legal basis for that processing.
6. Where it is processed
The Flowr application and its database run in Microsoft Azure, West Europe. Backups are point-in-time backups held in the same region.
Some processing necessarily happens with other providers, and not all of them are inside that boundary. We name them on the subprocessor page rather than implying everything stays in one place.
Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with an assessment of the transfer. Development, maintenance and exceptional technical support are performed from Morocco, which is not covered by an adequacy decision; there is no routine access to production customer data, and exceptional access is authorised, limited, attributable and audited.
7. Who else processes it
We use these providers. The full list, with processing regions and data categories, is on the subprocessor page.
- Microsoft Azure — hosting of the application, database and backups (West Europe)
- Vercel — hosting of the website and application front end, and the contact and early-access forms
- Clerk — sign-in and account identity
- Stripe — payments; card details are never seen or stored by us
- Crisp — in-application support chat (France)
- Airtable — early-access and contact form submissions from this website
- Sentry — application error reports (Germany)
- Anthropic — AI assistance only, where a plan includes it and an administrator has enabled it
- Jilyss Advisory SARL (Morocco) — development, maintenance and exceptional technical support
8. Artificial intelligence
Flowr Assist is disabled by default, and an organisation administrator can enable or disable it for the whole organisation. It is included only on plans that list it, and nothing is generated unless somebody asks for it. Supplying your own provider key changes who pays for the call and which provider account it runs under; it does not change what is sent, does not unlock AI on a plan without it, and does not exempt it from the organisation setting.
When a draft or a review is requested, Flowr sends the model the project information behind it: the project and portfolio name, the current stage, RAG statuses and the written commentary for this period and the previous one, milestone names and dates, and open risks and issues with their impact, status and named owner. Budget figures for the period are included where the request concerns them.
That means project narrative and the names of people who own risks and issues leave the Azure boundary when AI is used. If that is not acceptable to your organisation, an administrator can disable Flowr Assist: while it is off the service refuses these requests and no project or organisation data is sent, whether the call would have run on Flowr's model access or on your own provider key. Enabling and disabling are recorded in the audit log. One exception, stated so the rest can be relied on: when an administrator saves their own provider key, Flowr checks it against that provider with a fixed test message containing no project or organisation data.
Flowr records the number of calls and the tokens they consumed, in order to apply the monthly allowance. Flowr does not store the prompt or the model's reply; a suggestion is stored only if somebody accepts it into a report, at which point it is part of that report like any other text.
What the provider does with a request under its own terms is governed by our agreement with that provider and is not something this page can assert on their behalf.
9. How long we keep it
Workspace data is kept for as long as your organisation has a workspace. Point-in-time database backups cover a rolling 7-day window; nothing older is recoverable from them.
You can export your organisation's data as JSON at any time.
We do not currently operate an automatic deletion schedule after a subscription ends: data is retained until deletion is requested, or until we publish and implement a retention schedule, of which we will give notice. To have your organisation's data deleted, contact us at contact@getflowr.app.
10. Your rights
Under the GDPR you can:
- Request access to your personal data
- Request correction or deletion
- Object to or restrict processing
- Request a copy in a portable form
- Withdraw consent where processing relies on it
Where your employer runs the workspace, ask them first — they decide what it contains. To exercise these rights with us directly, contact: contact@getflowr.app. You also have the right to lodge a complaint with a supervisory authority, in Belgium the Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), or with the authority in your country of residence.
11. Security and breaches
We implement appropriate technical and organisational measures to protect personal data; the principal measures are listed in the Data Processing Agreement.
If a personal data breach occurs affecting data we process on behalf of an organisation, we notify that organisation without undue delay so that it can meet its own obligations. Where we are controller and the breach is likely to result in a risk to individuals, we notify the competent supervisory authority as the GDPR requires.
12. Changes
We may update this policy. Changes are reflected on this page with the date above.
13. Contact
If you have any questions, contact us at: contact@getflowr.app
Read the Terms of Service and the Data Processing Agreement alongside this.