Document ID: O-03
Version and date: 2026-08-21.1 - 21 August 2026
Data controller: FlowDule ApS, CVR 46273397, Syrenvænget 8, 8362 Hørning, Denmark
Contact: privacy@flowdule.com
Are you a client of a practitioner? Your practitioner or clinic is normally the data controller for your bookings, records and other client data. Please therefore contact the practitioner about access, rectification, erasure or other rights. FlowDule processes this data on the practitioner’s behalf and assists on their instructions.
1. Who this policy applies to
This policy applies where FlowDule itself determines the purpose of the processing, in particular for visitors to flowdule.com, enquirers, prospective and current business customers, customers’ contact persons and users, test participants, and individuals involved in support, security or data subject rights cases.
FlowDule is not the data controller for the customer’s professional services or client records. The fact that data is technically held in FlowDule does not change the allocation of roles. Each individual customer must provide their own clients with their own privacy information.
2. Our processing as data controller
| Purpose and persons | Data and sources | Basis and legitimate interest | Period/criterion |
|---|---|---|---|
| Sales, demos, events and enquiries | Name, work contact details, company, role, message and event choices from you, your organisation or a public business register. | Art. 6(1)(b) prior to a contract; Art. 6(1)(f) for relevant B2B enquiries. Interest: answering and documenting the dialogue. | 12 months after the most recent relevant contact, unless an agreement or a specific legal claim requires longer. |
| Customer, agreement and account | Legal/contact name, address, country, CVR/registration number where one exists, role, e-mail, telephone, agreement, proof of acceptance, subscription, modules and account activity from you, the customer and the platform. | Art. 6(1)(b) for the agreement/pre-contractual steps; Art. 6(1)(f) for B2B administration and evidence. Interest: delivering and documenting the customer relationship. | The customer relationship plus normally 5 years for agreement and claims documentation; access is closed immediately upon termination. |
| Invoicing, payment and bookkeeping | Customer, invoice, amount, payment status and transaction reference from the customer, FlowDule, Stripe and the bank. We do not receive full card details. | Art. 6(1)(b) and (c); Art. 6(1)(f) for reconciliation and legal claims. | Accounting records 5 years from the end of the financial year; other data is deleted when the purpose and the limitation period for claims expire. |
| Support and service | Contact details, case, correspondence and necessary account/technical data from you, the customer and the system. Please do not submit unnecessary health or record data. | Art. 6(1)(b) for agreed support; Art. 6(1)(f). Interest: resolving and documenting the specific case. | Normally 24 months after closure; record content follows the customer’s instructions and not this period. |
| Operations, security and misuse | IP address, device/browser, login, role, time, request/incident ID, activity and security logs from the platform, the cloud and authorised investigations. | Art. 6(1)(f), and (c) where an obligation applies. Interest: protecting individuals, customers, the service and legal claims. | Security/operations logs normally 12 months; significant incident cases normally 5 years after closure. |
| Testing, feedback and product quality | Test identity, role, account activity, bug report, redacted screenshot and technical metadata from the participant and the test environment. | Art. 6(1)(b) for agreed participation; Art. 6(1)(f). Interest: bug fixing and quality. Production record data must not be reused. | Raw test material no later than 3 months after the test period; data-minimised bug/improvement history normally 24 months. |
| News and direct marketing | Name, work e-mail address, preferences, consent and proof of opt-out from you and our distribution system. | Art. 6(1)(a) where consent is required; otherwise only a documented lawful B2B rule and Art. 6(1)(f). The function is not active in this version. | Until opt-out/withdrawal or normally 24 months of inactivity; minimal proof of opt-out is retained. |
| Data subject rights, compliance and legal claims | Identity, contact details, case, correspondence, decision and necessary evidence references from you, the customer, advisers, authorities and internal records. | Art. 6(1)(c), (f) and possibly (b). Interest: documenting compliance and establishing/defending claims. | Ordinary data subject rights cases 3 years after closure; disputes according to the specific need for claims and documentation, with an annual review. |
3. Which data is necessary
For an ordinary business registration we typically require name, work e-mail address, telephone number, company/practice, country, password and a declaration of business purchase. A CVR or registration number is required only if the customer has one; a lawful sole trader without a number can be documented by legal name and business address.
If necessary information is missing, we cannot create or secure the account, enter into the agreement or comply with a specific legal obligation. Date of birth, gender and nationality are not collected by default for FlowDule’s own account purposes.
4. Where the data comes from
We normally obtain data directly from you. We may also receive work contact details and role from your employer/customer, payment status from Stripe or a bank, technical data from your use of the service, and company data from a public business register.
Where data comes from sources other than you, we provide the required information no later than within the time limits in Article 14 GDPR, unless a lawful exemption applies. We do not use public registers of individuals for general profiling or marketing.
5. Collection points
The planned active collection points are the website/contact form, events, signup and invitations, checkout/payment, support and the client portal. Before submission, each point must display or link to the relevant text on role, purpose, mandatory fields, recipients and any consent.
In the client portal, the customer is normally the data controller. The customer’s own privacy text must be shown there, and this policy must not make it appear as though FlowDule determines the customer’s client purposes. Newsletters, non-essential product analytics and similar tracking are not enabled in this version.
6. Recipients and suppliers
Data may be disclosed to relevant, authorised FlowDule members and to suppliers who assist with hosting, identity/access, e-mail and communication, payment, support, security and approved web functions. AWS is used for core infrastructure, and Stripe is used for relevant payment functions.
The current public list of suppliers and sub-processors states the legal entity, role, purpose, place of processing and transfer basis. A service is listed as active only once the actual account, contract, region, support access and data chain have been verified. Advisers, banks, accountants, insurers, authorities or courts receive data only where there is a specific need and a valid basis.
7. Transfers outside the EU/EEA
A supplier may involve a transfer or remote access outside the EU/EEA, even where the primary storage is in the EU. For every such transfer we document the recipient, countries, purpose and valid basis under Chapter V GDPR.
The basis may be an adequacy decision, the EU-US Data Privacy Framework for a validly certified US recipient, or the European Commission’s standard contractual clauses with a transfer impact assessment and the necessary supplementary measures. A copy or description of the safeguards can be requested at privacy@flowdule.com; confidential security information may be redacted.
8. Retention and erasure
We apply the periods in the table and delete or anonymise data once the purpose and any legal or claims-related needs have expired. A specific dispute, security incident or lawful legal hold may temporarily extend retention for precisely delimited data. Needs and access are reassessed at least annually.
Data may reside for a limited period in isolated, rolling backups until it is overwritten in accordance with a documented rotation. It must not be used for other purposes and is not reintroduced into normal operations; after a restore, recorded erasures and legal holds are reapplied.
The customer’s client and record data follows the customer’s documented retention profile and DPA. FlowDule does not set a general record retention period for psychotherapists, and FlowDule’s own bookkeeping obligation is not a basis for retaining the customer’s record data.
9. Security
We apply risk-based technical and organisational measures, including personal access, role and need-to-know management, MFA for privileged roles, encryption in transit and, where relevant, at rest, logging, backup, incident handling and supplier control.
A control is described as verified only once it has been tested in the actual environment. Further security information may be provided under appropriate confidentiality where necessary and where it does not create a risk to other customers or to the service.
10. AI and automated decisions
We do not take decisions about you based solely on automated processing that produce legal effects or similarly significant effects. FlowDule’s AI features are documentation aids with active human oversight and must not independently diagnose, triage or decide on treatment or access to services.
The customer’s use of AI on client content takes place, as a starting point, on the customer’s instructions and is described by the customer to the client. Client and record data is not used for FlowDule’s own model training.
11. Your rights
-
access to the data we process about you, and a copy of it
-
rectification of inaccurate data
-
erasure or restriction where the conditions are met
-
objection to processing based on legitimate interest, and always to direct marketing
-
data portability for data you have provided to us, where the processing is based on consent or a contract and is carried out by automated means
-
withdrawal of consent, without affecting the lawfulness of processing carried out before the withdrawal
Write to privacy@flowdule.com. We may ask for the information necessary for secure identification. We reply without undue delay and normally no later than one month after receipt. The time limit may be extended by up to two months for complex or numerous requests; in that case we inform you, with reasons, within the first month.
The rights are not absolute. If we refuse or restrict a request, we explain the basis and the right to complain. If your enquiry concerns a practitioner’s client or record data, we forward it securely to the customer or tell you who to contact.
12. Complaints
You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk. You can also contact the supervisory authority in the EU/EEA country where you normally live or work, or where you believe an infringement has taken place.
13. DPO and privacy contact
As at 21 August 2026, FlowDule has not appointed a formal data protection officer (DPO). Kristoffer holds management responsibility for the privacy function but is not designated as an independent DPO. The DPO obligation is reassessed in the event of growth, new customer types, larger scale or changed monitoring and AI purposes. All enquiries can be sent to privacy@flowdule.com.
14. Cookies and similar technologies
Essential technologies are used only for the function and security for which they are required. Non-essential cookies, measurement or marketing are activated only after valid consent. The current cookie policy describes the technologies, providers, purposes and durations, and must match the actual scan and consent configuration.
15. Changes
We update this policy in the event of significant changes to purposes, data, recipients, transfers or rights. The date and version are stated at the top. If a change requires consent or new information directly to the individuals affected, we carry this out before the new processing begins.