Data Controller
FlowDule ApS, Syrenvænget 8, 8362 Hørning, CVR 46273397, is the data controller for the personal data we process about visitors to our website and users of our platform in connection with our own purposes. When a customer uses FlowDule to manage their own clients, the customer is the data controller and FlowDule is the data processor - see Data Processing Agreement.
Contact regarding data protection: privacy@flowdule.com.
What information we process
- Account information: name, email, phone number, address, date of birth, gender and nationality.
- Usage data: login events, device and log information necessary for operation.
- Content you enter: bookings, journals and notes (may include health data - see below).
Legal basis (Art. 6)
- Performance of a contract (Art. 6(1)(b)) for the provision of the platform’s features.
- Legal obligation (Art. 6(1)(c)) for, e.g., accounting.
- Consent (Art. 6(1)(a)) for marketing communication, which you may withdraw at any time.
- Legitimate interest (Art. 6(1)(f)) for security and improvement of the service.
Special categories of data (health data in the journal module) are processed only on a valid basis under Art. 9, typically explicit consent or a health-related purpose.
Retention
We retain personal data for as long as your account is active, and thereafter only for as long as necessary to fulfil legal obligations (e.g. requirements under the Danish Bookkeeping Act). When an account is deleted, we anonymise data that must be retained for legal reasons. Specific retention periods will be determined after legal review.
Your rights (Art. 12-23)
You have the right to access, rectification, erasure, restriction, data portability and objection. You can exercise access and portability directly in the app under Profile → Privacy. Requests are generally answered within one month. You may lodge a complaint with the Danish Data Protection Agency (datatilsynet.dk).
Transfers to third countries (Chapter V)
We use sub-processors that may process data outside the EEA (e.g. in the USA). Such transfers take place on a valid basis - the European Commission’s Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework. See Sub-processors.
Security (Art. 32)
Data is encrypted in transit and at rest. Access follows the principle of least privilege, and authentication is handled via AWS Cognito.
Changes
We update this policy in the event of significant changes and state the date of the most recent update at the top.