Purposes of processing
Flowz is a processor for customers and their user’s data processed in Flowz and Work Flowz software.
Flowz is a controller for personal data it processes in the course of business activities, these include:
- Customers, potential customers and past customers for sales, marketing and financial recordkeeping purposes as appropriate to the relationship.
- We largely rely on our legitimate interests for these purposes, but also have a legal duty to process and retain financial records for up to 7 years.
- Where we hold data for marketing purposes, we periodically cleanse the data, although opt-out is offered in every communication and we delete the data of opted-out potential customers.
- We do not share customer data with anybody outside the company except as required by law, courts and law enforcement.
- Suppliers, potential suppliers and past suppliers for procurement, contract management and financial recordkeeping purposes as appropriate to the data subject type.
- We rely on our legitimate interests for these purposes described, but may also have a legal duty to process and retain financial records for up to 7 years.
- We do not share supplier data with anybody outside the company except as required by law, courts and law enforcement.
- Staff, potential staff and past staff for recruitment, training, payroll, taxation, pension, disciplinary and financial recordkeeping purposes as appropriate to the data subject type.
- We rely on our contract with staff members past and present, or legitimate interests to process for business management for past, present and potential staff. We also have a legal duty to process and retain financial records for up to 7 years.
- We will hold pension records for up to 50 years
- The data we hold is deleted over time as it loses its usefulness and is cleansed out.
- We do not share this data with anybody outside the company except as required by law, courts and law enforcement.
- Website visitors to the extent that any data processed is personal data in our hands.
- We try not to process personal data for this purpose but do analyse website visitors without knowing who they are as appropriate to the data subject type. What we cannot delete immediately is held for less than 12 months.
- We do not share this data with anybody outside the company except as required by law, courts and law enforcement.
All data is processed in the United Kingdom and Flowz Limited is exempt from the requirement to register with the Information Commissioner’s Office.
If you have a question or complaint about the ways in which we process personal data, please contact us in the first instance. If we are not able to satisfy your questions, you should contact the Information Commissioner’s Office. There are multiple contact channels. Please see www.ico.org.uk for details.
All of the end user created data we process is held encrypted in Microsoft 365 suite of products, similar software providers, or on our own hosted servers (customer data). Data access is controlled by username, password and multifactor authentication.
Data subjects may have the following rights in respect of the personal data we process about them:
- The right of access
- The right to request rectification of errors
- The right to restrain further processing
- The right to erasure
- The right to object to the processing
- The right to not be subject to decision making without human input (we don’t do this)
These rights are not all absolute rights, but if you are a data subject of data we process as a controller and would like to access any of these rights, please contact us in the first instance.