FlowMindLabs AI acts as a Data Processor for the personal data processed through your workflows, and as a Data Controller for the limited personal data we collect to operate our business (such as your account information and usage analytics). This page describes both roles and the rights you have under the EU General Data Protection Regulation (GDPR).
We process personal data only where we have a lawful basis: (a) performance of a contract (providing the Service you signed up for); (b) compliance with legal obligations; (c) our legitimate interests in operating and securing the Service; and (d) your consent, where applicable. You can withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Under GDPR, you have the right to: (a) access your personal data; (b) rectify inaccurate data; (c) erase your personal data ("right to be forgotten"); (d) restrict processing; (e) data portability; (f) object to processing; and (g) lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at privacy@flowmindlabs.ai. We respond to verified requests within 30 days.
As a Controller, we process your name, email address, company name, billing information (processed by Stripe), and usage data. As a Processor, we process the data you submit to your workflows, including any personal data in connected integrations. We do not use your workflow data to train AI models. Zero-retention modes are available on Enterprise plans.
FlowMindLabs AI operates globally and may process personal data in countries outside the EEA and UK. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by transfer impact assessments where required. Enterprise customers can select data residency in the EU to keep their workflow data within the EEA.
We retain personal data only as long as necessary to provide the Service and comply with legal obligations. Workflow run logs are retained based on your plan: 7 days on Free, 90 days on Pro, and unlimited on Enterprise. Account data is deleted or anonymized within 30 days of account closure. You can request earlier deletion at any time.
We use a limited set of sub-processors to deliver the Service, including cloud hosting, AI providers (OpenRouter, Google Gemini, HuggingFace), payment processing (Stripe), and email delivery. We require all sub-processors to sign GDPR-compliant agreements. A current list of sub-processors is available on request and is updated with 30 days notice before adding new sub-processors.
We offer a GDPR-compliant Data Processing Agreement to all Enterprise customers and to any customer whose use of the Service requires one under Article 28 of the GDPR. To request a DPA, contact us at privacy@flowmindlabs.ai and we will provide a countersigned agreement within 5 business days.
Our Data Protection Officer (DPO) is responsible for overseeing our GDPR compliance and can be reached at dpo@flowmindlabs.ai. The DPO is independent and reports directly to senior management. You can contact the DPO with any questions about how we handle your personal data or to raise a concern about our data practices.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and notify affected individuals without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
You have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data violates the GDPR. We encourage you to contact us first so we can address your concern, but you are not required to do so.
For any GDPR-related questions or to exercise your rights, contact us at privacy@flowmindlabs.ai or dpo@flowmindlabs.ai. You can also write to us at: FlowMindLabs AI, Attn: Data Protection Officer, [Company Address].