Document ID: O-04
Version and date: 2026-08-21.1 - 21 August 2026
Service provider: FlowDule ApS, CVR 46273397, Syrenvænget 8, 8362 Hørning
Contact: privacy@flowdule.com
1. What the policy covers
The policy covers cookies and similar technologies that store or read information on your device, including localStorage, sessionStorage, IndexedDB, tokens, pixels, SDKs and equivalent identifiers. It also covers third-party content that may transmit, for example, an IP address and browser information, even when it does not set a traditional cookie.
FlowDule consists of several surfaces with different functions: flowdule.com and the help centre; customers’ booking, webshop, events, widget and client portal; and app.flowdule.com for our customers’ staff. Inventory and consent are assessed separately per surface and language version.
2. Main rule and strictly necessary technologies
Storage on, or access to, your device requires in principle a prior, freely given, specific, informed and unambiguous consent. The exemption applies only where the technology is strictly necessary to provide a function you have expressly requested, and the information is not used for other purposes.
Login and user validation, an ongoing shopping basket or registration, and an actively selected language or display may, depending on the specific implementation, be necessary. That a technology is convenient, desirable for security reasons or widespread is not in itself sufficient.
3. Our current choices
FlowDule has not approved any analytics, advertising, profiling or marketing technologies for active use. Such technologies must be technically blocked before consent and may only be released after a documented inventory, valid consent and updated privacy information.
Necessary functions must use the least possible data and lifetime. The user’s choices must not be used for recognition across customers, websites or purposes.
4. Technology inventory
Flowdule.com uses no analytics tools and uses self-hosted fonts. The table shows the technologies the surfaces use and is updated when the inventory changes.
| Name/service | Surface and type | Purpose/party | Lifetime | Status/consent |
|---|---|---|---|---|
| language-preference, theme, currency-preference | Web/help; first-party localStorage | Actively selected display; FlowDule | Until the user clears it | May be necessary following an active choice; must not be written before that choice. |
| docs-recent-searches | Help centre; sessionStorage | Local recent searches; FlowDule | Tab session | Without consent only if necessary for the selected search function and limited locally. |
| flowdule-prefs | Booking/widget; first-party cookie | Language, currency and theme; the customer/FlowDule | Up to 1 year | Only after an active choice; otherwise session defaults without storage. |
| Login/pending token | Booking/app; cookie/localStorage/keychain | Login and two-step flow; the customer/FlowDule | The token’s documented lifetime, pending approx. 5 min. | Strictly necessary for the requested login. |
| shop-cart-* | Webshop; localStorage | Shopping basket; the customer | Until purchase or clearing | Strictly necessary for the requested basket; no reuse. |
| event-reg:* | Event; sessionStorage | Retaining an ongoing registration; the customer | Tab session | Strictly necessary if used only for the active registration. |
| @flowdule/ and @flowdule/draft/ | App; localStorage | Settings and local drafts; the customer/FlowDule | Per key until logout, use or clearing | Strictly necessary for settings and drafts in progress; drafts may contain journal data, so use secure devices. |
| flowdule-comm, flowdule.video | App; IndexedDB | Communication key and the user’s selected video background | Until cleared/removed | Only a necessary or actively user-selected function. |
Stripe (__stripe_mid, __stripe_sid, m) | Payment surfaces (booking, event, checkout, gift card); third-party cookies set by Stripe.js | Payment and fraud prevention; Stripe and the customer/FlowDule | __stripe_mid about 1 year, __stripe_sid about 30 minutes, m about 2 years | May only be loaded in a user-initiated payment flow and after a specific necessity assessment. |
| Cloudflare Turnstile | Booking site; third-party technology on selected forms | Bot protection; the customer/FlowDule and Cloudflare | The supplier’s documented period | Loaded only on the booking flow’s confirmation step and on the contact form; other pages do not call the supplier. |
| CARTO | Map display; third-party call after an active click | Map tiles; external recipient | The supplier’s documented period | Maps and map tiles load only after the visitor’s active click (click-to-load), and attribution is shown. |
| Nominatim/OpenStreetMap | Geocoding via FlowDule’s own proxy | Clinic address; no direct browser calls to an external recipient | The supplier’s documented period | The browser does not call the service directly; geocoding goes through FlowDule’s own proxy with caching. |
| Postcode.nl | Administration behind login; server-proxied address lookup | Clinic, location and event address; no client data according to the code review | The supplier’s documented period | The browser does not contact the supplier directly; lookups go through FlowDule’s own proxy behind sign-in. |
5. Flowdule.com and the help centre
These surfaces use only necessary first-party technologies and locally hosted resources. FlowDule checks regularly, and whenever the site changes, all network requests, cookies, storage, service workers, pixels and external resources in a clean browser profile on every relevant page and in every language.
If the check reveals analytics, marketing or other non-necessary technology, it must not be loaded before consent, and the inventory, banner and privacy policy must be updated.
6. Booking, webshop, events and the client portal
The customer determines its booking, event and client purposes, while FlowDule supplies the technology. The visible information must make clear who uses the technology, the purpose, the lifetime and whether a third party receives data.
Stripe may only be loaded as part of a user-initiated payment flow. Turnstile may only be used on the forms where necessity and proportionality are documented. Maps and geocoding must not contact a third party before the approved proxy or click-to-load solution has been implemented.
7. The app and local storage
The app may use technologies for login, user settings, encrypted communication and the user’s own active choices. Local storage of record drafts requires particularly clear information, the shortest possible lifetime, secure clearing on save/logout and control of shared devices.
Information does not fall outside the data protection rules merely because it is held locally. The customer must instruct users on secure devices.
8. If we introduce technology requiring consent
-
No non-necessary request, script, pixel, storage or identifier is activated before a choice is made.
-
The first layer gives equal and clear options to accept all, reject all and select purposes; no pre-ticked boxes and no misleading design.
-
Consent is given per clear purpose and identifies FlowDule and the relevant third parties as well as the essential information about the technologies.
-
It must be just as easy to withdraw consent as to give it, via a permanently visible setting.
-
A rejection must not block the core service, unless the rejected technology is in fact necessary for the specific function expressly requested.
-
New consent is obtained if purposes or technologies change materially, or the old consent is no longer current.
9. Processing of personal data
Where technologies process personal data, the GDPR also applies. FlowDule’s own purposes, legal bases, recipients, transfers, storage and rights are described in the Privacy Policy. On the customer’s client-facing surfaces, the customer’s own privacy information must be shown.
A cookie consent is also a GDPR consent only if this is stated clearly and all requirements under both sets of rules are met. Strict necessity under the cookie rules does not automatically provide a legal basis for processing under the GDPR.
10. How to change or clear your choices
Once a consent solution is activated, you can open ‘Cookie settings’ at any time and change or withdraw your choice. Withdrawal does not affect lawful use before the withdrawal, but stops future consent-based storage and access.
You can also clear cookies and local storage in your browser or device settings. This may sign you out and remove your language choice, shopping basket, an ongoing registration or local drafts. The help texts must describe secure clearing for each supported browser and app.
11. Responsibility and contact
FlowDule is responsible for technologies that FlowDule chooses on its own surfaces. On customer-specific surfaces, the customer may be the data controller for the purposes it determines, but FlowDule remains responsible for its platform implementation and for giving the customer correct configuration and information options.
Questions about technologies and personal data can be sent to privacy@flowdule.com. Complaints about the cookie rules can be addressed to the Danish Agency for Digital Government, and complaints about the processing of personal data can be addressed to the Danish Data Protection Agency.