Legal

GDPR Compliance

Last updated: July 5, 2026

1. Our Role Under GDPR

FlowMindLabs AI acts as a Data Processor for the personal data processed through your workflows, and as a Data Controller for the limited personal data we collect to operate our business (such as your account information and usage analytics). This page describes both roles and the rights you have under the EU General Data Protection Regulation (GDPR).

2. Lawful Basis for Processing

We process personal data only where we have a lawful basis: (a) performance of a contract (providing the Service you signed up for); (b) compliance with legal obligations; (c) our legitimate interests in operating and securing the Service; and (d) your consent, where applicable. You can withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

3. Data Subject Rights

Under GDPR, you have the right to: (a) access your personal data; (b) rectify inaccurate data; (c) erase your personal data ("right to be forgotten"); (d) restrict processing; (e) data portability; (f) object to processing; and (g) lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at privacy@flowmindlabs.ai. We respond to verified requests within 30 days.

4. Data We Process

As a Controller, we process your name, email address, company name, billing information (processed by Stripe), and usage data. As a Processor, we process the data you submit to your workflows, including any personal data in connected integrations. We do not use your workflow data to train AI models. Zero-retention modes are available on Enterprise plans.

5. International Transfers

FlowMindLabs AI operates globally and may process personal data in countries outside the EEA and UK. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by transfer impact assessments where required. Enterprise customers can select data residency in the EU to keep their workflow data within the EEA.

6. Data Retention

We retain personal data only as long as necessary to provide the Service and comply with legal obligations. Workflow run logs are retained based on your plan: 7 days on Free, 90 days on Pro, and unlimited on Enterprise. Account data is deleted or anonymized within 30 days of account closure. You can request earlier deletion at any time.

7. Sub-Processors

We use a limited set of sub-processors to deliver the Service, including cloud hosting, AI providers (OpenRouter, Google Gemini, HuggingFace), payment processing (Stripe), and email delivery. We require all sub-processors to sign GDPR-compliant agreements. A current list of sub-processors is available on request and is updated with 30 days notice before adding new sub-processors.

8. Data Processing Agreement (DPA)

We offer a GDPR-compliant Data Processing Agreement to all Enterprise customers and to any customer whose use of the Service requires one under Article 28 of the GDPR. To request a DPA, contact us at privacy@flowmindlabs.ai and we will provide a countersigned agreement within 5 business days.

9. Data Protection Officer

Our Data Protection Officer (DPO) is responsible for overseeing our GDPR compliance and can be reached at dpo@flowmindlabs.ai. The DPO is independent and reports directly to senior management. You can contact the DPO with any questions about how we handle your personal data or to raise a concern about our data practices.

10. Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and notify affected individuals without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

11. Supervisory Authority

You have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data violates the GDPR. We encourage you to contact us first so we can address your concern, but you are not required to do so.

12. Contact Us

For any GDPR-related questions or to exercise your rights, contact us at privacy@flowmindlabs.ai or dpo@flowmindlabs.ai. You can also write to us at: FlowMindLabs AI, Attn: Data Protection Officer, [Company Address].