Privacy Notice.
Flowdesk and its subsidiaries and affiliates (collectively, "Flowdesk" "we", "us" or any similar descriptor refers to the Flowdesk entity described in section 2 below) attach great importance to the protection of your Personal Data.
This Privacy Notice ("Privacy Notice") is provided by Flowdesk and explains what data we collect about you in connection with the Flowdesk website at flowdesk.co and any of our services ("Services"), the purposes for which we collect it, how such data is used and stored, with whom such data may be shared by us, what rights you may have, and how you can contact us about our privacy practices.
This site and our Services are made available by Flowdesk SAS and / or its affiliates. Flowdesk acts as a controller of your Personal Data and we determine how and why Personal Data is used. This Privacy Notice does not apply where we act as a processor or service provider to another controller.
If you have any questions about our handling of your Personal Data, or about this policy, or if you wish to access your personal information or make a complaint about the way we have collected, used, held or disclosed your personal information, please contact us at dpo@flowdesk.co. If you are not satisfied with the response from us, you may escalate concerns to the applicable privacy regulator in your jurisdiction (details can be provided upon request to us).
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union, Member State, or any applicable law;
Personal Data means any information relating to an identified natural person, or one who can be identified directly or indirectly by way of linking data, using identifiers such as name, voice, picture, identification number, online identifier, geographic location, or one or more special features that express the physical, economic, cultural or social identity of such person. It does not include data where the identity has been removed (anonymous data). This includes Sensitive Information.
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Special Category Data means any data that directly or indirectly reveals a natural person's family, racial origin, political or philosophical opinions, religious beliefs, criminal records, biometric data, or any data related to the health of such person, such as his/her physical, psychological, mental, genetic or sexual condition, including information related to health care services provided thereto that reveals his/her health status.
Flowdesk collects, processes, and stores Personal Data via your use of the Services or where you have given your consent.
We collect Personal Data and other information you provide through any means, to comply with our legal and regulatory obligation under applicable anti-money laundering and counter-terrorist financing laws and to fulfill our obligation in connection with including during the Flowdesk Know Your Customer on-boarding process, which may be a completed, incomplete, or abandoned process. We also collect Personal Data when you communicate with us through our representatives, subscribe to marketing communications, correspond with us by phone, email, instant messenger or any other communication channels, or when you conduct a transaction with or through us. We may actively or automatically collect, use, store, or transfer your data, which may include, without limitation, the following:
• Personal identification information such as name, email, phone number, nationality, place and date of birth, address, and government identification information, photograph, marital status, education and employment information;
• Government identification number, proof of identity and legal existence, address, business description, and beneficial owner information;
• Commercial information such as data related to transactions conducted with or through us or to your use of our Services;
• Financial information such as bank account information, wallet information, credit/debit card numbers;
• Correspondence Information such as email, address, telephone number, instant messaging contact details, or information related to communications with us and responses to surveys (including information received or recorded during calls, meetings, chats, emails, interviews, conversations);
• Information required by regulatory agencies such as state and federal licensing authorities and consumer protection agencies;
• Other technological information or identifiers such as device fingerprint data, Internet Protocol ("IP") address, Media Access Control ("MAC") address geolocation information, unique device identifiers and browsing and session information for the devices used to access our Services.
• Certain optional information which you may choose to submit or share, such as an avatar, nickname, or "handle".
We also collect Personal Data about you from third parties, such as electronic verification Services, referrers, marketing agencies, publications, databases, website or social media pages or exchanges. We may also use third parties to manage access to and traffic on our website, which may involve the use of cookies (additional information on Cookie Usage is set out below). Information collected through such analysis may not be anonymous.
We also collect information about persons with whom we have no direct relationship, for example when we receive information by a user of our Services and you are a representative, employee or shareholder of a legal entity related to the user of our Services.
We will not collect Special Category Data about you without your consent, unless an exemption or exception applies. These exemptions or exceptions include if the collection is required or authorized by law, or if it is necessary to take appropriate action in relation to suspected unlawful activity or serious misconduct.
We may also receive unsolicited Personal Data about you. We may retain additional information we receive about you if it is combined with or related to other information we are required or entitled to collect, and we may process such Personal Data in accordance with the purposes stated in this Privacy Notice. If we do this, we will retain the information in the same way we hold your other Personal Data.
The Personal Data we process includes Personal Data about users, potential users, service providers or suppliers of our Services, prospective employees, employees and contractors and other third parties with whom we come into contact.
If the Personal Data we request is not provided by you, we may not be able to provide you with the benefit of our Services or meet your needs appropriately. Accordingly, we do not give you the option of dealing with us anonymously or under a pseudonym.
Furthermore, we conduct business in and collect Personal Data from individuals and entities located in various jurisdictions in accordance with data protection laws. Where applicable, we are required to protect Personal Data processed in such jurisdictions in accordance with the applicable data protection laws.
Flowdesk does not knowingly offer Services to or collect the Personal Data of anyone under the age of 18. If we learn that we have collected Personal Data of anyone under the age of 18, we will promptly delete it from our systems. If you are aware of anyone under the age of 18 using our Services, please notify us at the email addresses referred to in Section 2 above, so that we can take prompt action to prevent access to our Services.
Flowdesk uses Personal Data to administer, deliver, improve, personalize or terminate the Services for you and to comply with our legal and regulatory obligations. We also may use such data to communicate with you in relation to other products or Services offered by Flowdesk or to consider any concerns or complaints you may have.
We may use and disclose your Personal Data for any of these purposes. We may also use and disclose Personal Data for secondary purposes which are related to the primary purposes set out in this section, or in other circumstances authorized by the law.
Sensitive Information will be used and disclosed for the purpose for which it was provided (or a directly related secondary purpose), unless you explicitly consent otherwise, or an exemption applies.
Below are the ways in which we may process your Personal Data:
• Provide you with our Services. We use your Personal Data to provide you with our Services or to assess whether we can offer you with such Services. For example, we need to know certain financial information to conduct transfers into and out of your account or wallet or conduct transactions with or through us or to check credit risk ratings and your ability to repay.
• Detect and prevent fraud. Your Personal Data is used to detect and prevent fraud.
• Comply with our legal obligations. Your data is used when we are legally obliged to process data, for example to comply with AML regulations, or tax authorities.
• Protect the security of our Services. We process your Personal Data to maintain the security of your account and our services.
• User/customer support. We process your Personal Data when you contact our representatives to help us address your question.
• Enhance our Services. We process your Personal Data to understand how our Services are being used to improve our Services and develop new Services.
• Product marketing. We process your Personal Data to identify our Services that we believe may be of interest to you. We may contact you about them.
• Social interactions. Through our Services, we use your Personal Data to improve social interactions, or to offer features that make your experience better.
• Other business purposes. We may use your Personal Data for other reasonably expected business purposes, as permitted by law or when required to comply with our legal obligations.
• Third-party payment processors. Such processors may be used by us to process payments to, receive payments from, initiate a sale or purchase, or carry out other transactions with or for you. Your information will be received and stored by the payment processors. To safeguard your financial information, we may be provided with a unique token and/or partial payment information for reference. Additionally, these payment processors may collect information about how you use their services for analytics purposes; this is controlled by their privacy notices.
Lawful Basis for Processing
Our lawful basis for processing your Personal Data is set out below:
• Public interest. We will process your Personal Data without your consent where it is necessary to protect the public interest.
• Legal Proceedings. We will process your Personal Data without your consent where it is necessary to initiate or defend legal proceedings or in relation to judicial procedures.
• Legitimate interests. We will process your Personal Data without your consent where it is necessary for us to realize a justified and legitimate interest considering your privacy and other fundamental rights and interest, such as running an effective operation of Services and administering related activities, protecting the security of our systems, preventing fraud, and internal administrative purposes.
• Performance of a contract. We will process your Personal Data without your consent where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
• Compliance with a legal or regulatory obligation. We will process your Personal Data without your consent where we need to comply with a legal or regulatory obligation we are subject to.
If we need to process your data and none of the above lawful basis apply, then we will use your consent. You can withdraw consent for processing at any time.
To Whom We Might Disclose Personal Data
Flowdesk may disclose Personal Data to:
• Members of our corporate group, which includes our subsidiaries, holding companies and companies under common control including their respective contractors, affiliates, employees or representatives.
• Our service providers and other entities which assist us in providing Services to you and/or as required or permitted by law, including, for example, payment processing, customer support, data processing and analytics, information technology, network infrastructure, storage and tax reporting.
• Entities in connection with corporate transactions involving Flowdesk, including any financing, acquisition or dissolution proceedings which involve disclosing a certain portion or all of our business or assets.
• Government entities or other parties to legal process, including law enforcement agencies and authorities, officers, regulators or other third parties to comply with any law, regulation, guideline, notice, court order, subpoena or government or law enforcement request.
• Professional advisors, including legal, financial, tax, accounting or other consulting services for purposes of audits or to comply with our legal obligations.
Other than as disclosed in this Privacy Notice, Flowdesk does not share your Personal Data with any other third parties unless required to do so by law or legal reporting obligations. By using our Services, you may be directed to other third-party websites or services where such websites or services' own privacy policies / notices may apply and Flowdesk is not responsible for the privacy policies / notices of such third-party websites.
If we disclose your Personal Data to service providers that perform business activities for us, they may only use your Personal Data for the specific purpose for which we supply it. We will take reasonable steps to ensure that all contractual arrangements with third parties adequately address compliance with applicable privacy laws. Additionally, we have implemented standards to prevent money laundering, terrorist financing and circumventing trade and economic sanctions. These standards require us to undertake due diligence on our users in order to be compliant with applicable laws and regulations. This may include the use of third-party data and service providers which will cross-reference your Personal Data for identity verification, fraud detection and prevention, transaction monitoring, credit verification and security threat detection.
We recognize the importance of securing the Personal Data of our users. We take steps to ensure your Personal Data is protected from misuse, interference or loss, and unauthorized access, modification or disclosure. Your Personal Data is generally stored in our or our affiliates' computer databases and/or with third party storage providers. In relation to information that is held on our computer databases, we apply data security measures to ensure that your Personal Data is managed securely.
The data that we collect from you may be transferred to, and stored at, a destination outside of the country of your residence. It may also be processed by staff operating outside of your residence who work for us, our group, or for one of our Services providers. By submitting your Personal Data, you expressly consent to this transfer, storing or processing, except as provided herein.
We retain your Personal Data for as long as is reasonably necessary to provide Services to you, for our legitimate business purposes, and to comply with our legal and regulatory obligations. If your engagement with Flowdesk has been terminated or if for any reason our Services are no longer offered to you, we will continue to retain your Personal Data as necessary to comply with our legal and regulatory obligations. For example, we are subject to certain anti-money laundering ("AML") laws which require us to retain records to comply with our client identification and due diligence obligations for an additional period after our business relationship with you has ended.
The Flowdesk group operates a global business and Personal Data may be stored and processed in any country where we are licensed, have a presence, or employees or contractors, or where we have operations and where we may engage service providers.
We may transfer Personal Data that we maintain about you to recipients in countries other than the country in which the Personal Data was originally collected or in which you reside. Those other countries may have data protection or privacy rules that are different from those of your country. However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that your Personal Data remains protected to the standards described in this Privacy Notice.
In certain circumstances, courts, government or law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Data.
We may only use Personal Data we collect from you for the purposes of direct marketing with your consent, where we provide a simple way of opting out of direct marketing, and you have not requested to opt out of receiving direct marketing from us.
If we collect Personal Data about you from a third party, we will only use that information for the purposes of direct marketing if you have consented (or it is impracticable to obtain your consent) and we will provide a simple means by which you can easily request not to receive direct marketing communications from us. We will draw your attention to the fact you may make such a request in our direct marketing communications.
We may communicate company news, promotions, and information relating to our products and Services provided by Flowdesk. We may share Personal Data with third parties to help us with our marketing and promotional projects or sending marketing communications.
Users can opt out from these marketing communications at any time by following the unsubscribe link within any marketing communications sent to you or by contacting us.
For Services related communications, such as policy/terms updates and operational notifications, you will not be able to opt out of receiving such information.
While you access our website (www.flowdesk.co) or use our Services, we may use the practice of placing a small amount of data that will be saved by your browser or device ("Cookies"). This information can be placed on your computer or other devices used to visit our website or use our Services. We use Cookies to enhance your experience of using our site and Services. The information is used to identify users, remember user preferences and allow users to complete tasks without having to re-enter information when browsing from one page to another or when re-visiting our site or using our Services at a later date. Session Cookies are added when a user starts to browse our site, use our Services or interacts with a specific feature and are deleted when the session has ended. Persistent Cookies are added when a user starts to browse our site, use our Services or interacts with a specific feature but may remain stored on your device until a certain termination date is reached or when deleted by you. We also use Cookies to collect and analyze site or Services usage data, related to user use and patterns. This data is used to improve our site or Services and enhance users' experience. We may also use the information collected to ensure compliance with our regulatory and AML requirements, and to ensure your account security has not been compromised by detecting irregular, suspicious, or potentially fraudulent account activities.
You can set your browser to block or alert you about these Cookies, but this may affect the functionality of the site, Services or your user experience.
Our Cookie Policy is accessible on our website here.
We endeavor to protect our site, our Services and you, from unauthorized access, alteration, disclosure, or destruction (or other similar risks) of Personal Data we collect and store. We take various measures to ensure information security, including: encryption of communications; periodic review of our Personal Data collection, storage, and processing practices; and restricted access to your Personal Data on a need-to-know basis for our employees, contractors and third parties with whom we engage, who are subject to strict contractual confidentiality obligations.
If you have any questions about information security or report any security issues, please contact us by sending an email to the address referred to in Section 2 above. We will provide such information as required by applicable laws.
If you have any questions or concerns about this Privacy Notice or the use of your Personal Data, please contact us by sending an email to the relevant email address set out in Section 2 above.
We may update this Privacy Notice at any time by posting the amended version on our site, which may have retroactive effect, so please check frequently to see if there are any updates or changes. Your continued access to or use of our Services constitutes your acknowledgment and acceptance of such changes to this Privacy Notice.
For users who are located in the UK, EEA or other locations subject to UK and EU data protection laws (collectively, "UK/EU Data Subjects"), we adhere to relevant and applicable EU data protection laws and provide UK/EU Data Subjects with the following additional information. For the purposes of this section, "Personal Data" has the meaning provided in the General Data Protection Regulation (EU) 2016/679 (GDPR).
A. Legal Bases For Processing Personal Data. We process Personal Data subject to the GDPR on one or more of the following legal bases:
• To comply with legal obligations and regulations. To comply with applicable laws, including "know your customer" obligations based on applicable AML and anti-terrorism requirements, financial crime and fraud prevention, suspicious activity reporting, responding to requests from government or law enforcement authorities, complying with economic and trade sanctions requirements, performing customer due diligence, performing audit and risk assessments, preparing tax reports, fulfilling our retention obligations and handling legal claims.
• To comply with contractual obligations. To comply with our contractual obligations to you under our terms of service, including to provide you with our Services, and to optimize and enhance our Services.
• Consent. To provide and market our Services to you based on your consent. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before and for a short time after consent is withdrawn.
• Legitimate interest. To monitor the usage of our Services, fraud prevention, network and information security, conduct automated and manual security checks of our Services, to engage in direct marketing activities and to protect your rights. When we process your Personal Data for our legitimate interests, we consider and balance any potential impact on you and your rights under data protection laws.
B. UK and European Privacy Rights. UK/EU data subjects have the following rights under the UK GDPR and EU GDPR with respect to their Personal Data, subject to certain exceptions provided under the law. In any privacy related request to us, you should include adequate information to identify yourself and other relevant information that will reasonably assist us in fulfilling your request.
• Right of access: You can request access to a copy of the personal data which we hold about you, as well as details about why and how we use it;
• Right to rectification: You can ask us to change or complete any personal data we hold about you which is inaccurate or incomplete;
• Right to be forgotten/erasure: You have a right, under certain circumstances, to ask us to delete any personal data we hold about you. Please note that there may be situations where we must retain your personal data after a request for erasure where we have a lawful basis for doing so;
• Right of restriction: You can ask us to restrict (i.e. prevent) the processing of your personal data where you have objected to our use of it and we have no lawful basis to continue processing your personal data;
• Right of data portability: In certain circumstances, you can ask us to transfer the data we hold about you to another party. This would be sent in a structured, commonly used, electronic form;
• Right to object: You can object to us using your personal data for particular purposes; and
• Automated decision making: You have a right not to be subjected to automated decision making and profiling in certain circumstances
• Right to complain: You may lodge a complaint with a data protection supervisory authority.
C. Auto decision-making. We may engage in automated decision-making for purposes of providing our Services, risk and fraud detection. When we do, we implement suitable measures to safeguard your rights, freedoms and legitimate interests, including the right to obtain human intervention, to express your point of view and to contest the decision.
D. Transfers of Personal Data out of the UK and EEA. We may transfer Personal Data from the UK or EEA to countries outside of the UK or EEA where the transfers are necessary to satisfy our obligations to you, to provide our Services (including optimizing and enhancing our Services). When we transfer data outside of the UK/EEA we take appropriate safeguards to ensure that your information remains protected in accordance with the law. These measures may include:
• Ensuring the country has been recognised as providing an adequate level of protection;
• Implementing EU Standard Contractual Clauses/UK International Data Transfer Agreement or other approved transfer mechanisms, with a transfer impact assessment in place; and/or
• Obtaining your explicit consent where required by law.
For users who are located in Singapore, we adhere to the Personal Data Protection Act ("PDPA") and provide Singapore residents with the following additional information. For the purposes of this section, "Personal Data" has the meaning provided in section 2 of the PDPA.
A. Transfers of Personal Data out of Singapore. If your Personal Data has been processed in Singapore, prior to transferring such Personal Data from Singapore to a jurisdiction or territory outside Singapore, Flowdesk will generally take appropriate steps to ensure that the recipient of the Personal Data is bound by legally enforceable obligations to provide to the transferred Personal Data a standard of protection that is at least comparable to the protection under the PDPA ("Comparable Standard"). To this end, Flowdesk will ensure that at least one of the following measures is implemented:
• you consented to such transfer after you have been given a reasonable summary in writing of the extent to which your Personal Data to be transferred will be protected to a Comparable Standard (including but not limited to through this Privacy Notice);
• the overseas recipient of such Personal Data is bound by law, contract, binding corporate rules or any other legally binding instrument to protect the transferred Personal Data to a Comparable Standard; and/or
• The overseas recipient of such Personal Data holds a valid certification under the Asia Pacific Economic Cooperation Cross Border Privacy Rules System or the Asia Pacific Economic Cooperation Privacy Recognition for Processors System.
Where the above measures are not feasible, Flowdesk may still proceed with the transfer of your Personal Data from Singapore to a recipient outside of Singapore if:
• the transfer is necessary for a use or disclosure that is in your vital interests or in the national interest and Flowdesk has taken reasonable steps to ensure that the Personal Data will not be used or disclosed by the recipient for any other purpose; and/or
• the transfer is reasonably necessary for the conclusion or performance of a contractual obligation between you and Flowdesk.
B. Security of your Personal Data. If we have credible grounds to believe that a data breach has occurred, we will take steps to assess whether the data breach is notifiable under the PDPA. Once we assess that a data breach is a notifiable data breach, we will notify the Personal Data Protection Commission of Singapore or other applicable regulators and you as soon as it is reasonably practicable. If we share your Personal Data with our third-party service providers, we will require them to process it strictly in accordance with our instructions or as otherwise required by the PDPA.
A. Identity Verification and Biometric Data Privacy Notice
To comply with applicable laws, regulations, and other legal obligations in the United States and in other countries, including "know your customer" obligations, we require all users to verify their identity before using our Services.
In order to verify a user's identity for the use of certain Services, the user is asked to capture an image of their government ID (e.g., a passport or driver's license). We provide those images to our identity verification service providers, who then use a combination of machine learning tools and statistical algorithms to confirm the authenticity of the government ID and selfie image.
However, we do retain the information and images you provide in connection with the identity verification process, along with the results of the identity check, as long as necessary to provide our service to you and to comply with our legal obligations.
B. California and Other State Privacy Rights
This section is applicable to consumers whose Personal Data is collected, stored, used or disclosed by us under the California Privacy Rights Act, Connecticut Data Privacy Act, Virginia Commonwealth Data Protection Act, Utah Consumer Privacy Act, and the Colorado Privacy Act.
Individuals may have rights regarding their Personal Data that we have collected, stored, used or disclosed in the preceding 12 months, pending verification of your identity. These rights include the following (subject to certain limitations at law):
• Right to access to Personal Data or request a copy. You have the right to obtain information about the Personal Data we process about you or to obtain a copy of your Personal Data. For details on the categories of Personal Data we have collected and/or shared, refer to the above sections in this Privacy Notice. If you have provided your information to us, you may contact us to obtain an outline of the information we hold about you or a copy of the information.
• Right to change or correct your Personal Data. You have the right to update or correct your Personal Data or ask us to do so on your behalf.
• Right to delete or erase your Personal Data. You have the right to request the deletion of your Personal Data at any time. We will communicate back to you within the above stated timelines the result of your request. Although we might not be able to remove your personal information, we will notify you of the reason(s) and any other options you have.
• Right to object to the processing of your Personal Data. You have the right to object to our processing of your Personal Data for direct marketing purposes. This means that we will stop using your information for these purposes.
• Right to ask us to restrict processing of your Personal Data. You have the right to ask us to limit the way in which we use your Personal Data.
• Right to export your Personal Data. You have the right to request that we export to you in a machine-readable format all of the Personal Data held about you.
Automated Decision-making and Profiling
In the event that a decision we have made about you is solely the result of an automated process (for instance, automatic profiling) and it impacts your ability to use our products and Services or has another significant impact on you, you can request that this decision not be applied to you, unless we can demonstrate to you that this decision is required for the purpose of entering into or carrying out a contract with you or providing our Services to you. You may contest this decision and ask for human intervention. If we grant such a request, we may still not be able to offer our products or Services to you.
If you would like to exercise any of your rights, please refer to section 8, above. You may also contact us at the address stated in section 2, above.
We will verify your identity before processing your request. In order to verify your identity, we will generally require sufficient information from you so that we can match it to the information we maintain about you. If we need additional information from you to be able to identify you, we will notify you.
You may choose to designate an authorized agent to make a request on your behalf. No information will be disclosed until the authorized agent's authority has been reviewed and verified. Once an authorized agent has submitted a request, we may require additional information (i.e., written authorization from you) to confirm the authorized agent's authority. We endeavor to respond to your verified request within the required timeframes. We do not charge a fee to process or respond to a request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will let you know why and provide you with an estimate of the associated costs prior to completing your request.
Right to Appeal – California and Colorado
If we do not respond to your request within the 45 days, or 90 days if there is an applicable extension, we will inform you in writing of our reasons for not acting and an explanation of your right to appeal the decision.
Right to Appeal – Virginia and Connecticut
You have the right to appeal a refusal to take action on a request within a reasonable period of time after receiving our decision. Within 60 days of receipt of an appeal, we will inform you in writing of any action additionally taken in response to the appeal. If the appeal is denied, you will be provided with a method through which you may contact the Attorney General of Virginia if you are a Virginia resident or the Attorney General of Connecticut if you are a Connecticut resident to submit a complaint.
California and Delaware "Do Not Track"
The laws of the States of California and Delaware, require us to indicate whether we honor your browser's "Do Not Track" settings concerning targeted advertising. We adhere to the standards set out in this Privacy Notice and do not monitor or respond to Do Not Track browser requests.