In short: we only collect the personal data you give us when you book a call, use our chatbot, or email us, things like your name, company, email, phone, and what you'd like help with. We use it to reply to you and deliver our services. We don't sell your data. You can ask us to delete it at any time.
Who we are
FlowNest ("we", "us", "our") is a workflow automation studio based in the United Kingdom.
- Trading name
- FlowNest
- Legal entity
- FlowNest Ltd
- Company number
- 17210422
- Registered in
- England and Wales
- Contact email
- hello@flownest.xyz
- Telephone
- +44 113 519 4131
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, FlowNest is the data controller for the personal data collected via this website.
This Privacy Policy covers personal data FlowNest collects for its own website, enquiries, bookings, chatbot, AI voice agent (if enabled) and direct communications. Where FlowNest processes personal data on behalf of a client as part of a signed Services Agreement, the relevant Data Processing Agreement or client contract will also apply.
What personal data we collect
Data you give us directly
- When you book a call: first name, last name, company name, email address, phone number, and a short description of what you need help with.
- When you use our website chatbot: first name, email, and (optionally) company name, captured once per session before chatting, plus the content of the messages you send to the bot.
- When you email us directly: your email address and whatever you include in the email.
- When you message us on Telegram: your Telegram handle (or display name) and the content of your messages.
- When you call our AI voice agent (if enabled): your name, phone number, the content of the conversation, and a recording of the call. You will be notified at the start of the call.
Where calls are recorded, callers are informed at the start of the call. The recording and transcript may be used to create enquiry summaries, internal handovers, follow-up actions and service records.
Data collected automatically
- Technical data: IP address, browser type and version, device type, operating system, referring URL, pages visited, date and time of visit. This is collected via our hosting provider (Cloudflare) for security and abuse-prevention purposes.
- Session storage: we store a session ID in your browser's local session memory so the chatbot remembers your conversation within the same tab. This is cleared when you close the tab.
What we do not collect
- We do not use tracking cookies, advertising pixels or similar without your consent. With your consent we use Google Analytics 4 to understand which pages are useful, and Microsoft Clarity for heatmaps and session replay. Google and Microsoft act as our processors for that data, which may involve transfers outside the UK under their standard contractual clauses. Form and chat input is masked and never recorded. Withdraw consent at any time from the cookie policy page.
- We do not knowingly collect personal data from children under 16.
- We do not collect special-category data (health, ethnicity, biometrics, religion, political views, sexual orientation, trade union membership, genetic or biometric data) unless you volunteer it as part of a client engagement and have explicit lawful basis to share.
Why we collect it, and our lawful basis
Under UK GDPR Article 6, we process your data on the following lawful bases:
- Legitimate interest (Art. 6(1)(f))
- To respond to enquiries you initiate, to provide a chatbot that answers questions about our services, and to protect our website from abuse and spam. We believe this is a reasonable expectation when you proactively contact us, and we balance it against your rights.
- Contract (Art. 6(1)(b))
- To deliver services you've engaged us for, e.g. scheduling a call, sending a proposal, delivering an automation project, invoicing.
- Consent (Art. 6(1)(a))
- For any non-essential cookies or marketing messages. We will always ask first and you can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c))
- To meet tax, accounting, and regulatory requirements (e.g. HMRC record-keeping for invoices).
How long we keep your data
- Enquiries that don't lead to a project: up to 12 months, then deleted.
- Active client data: for the duration of our engagement plus 6 years afterwards (to comply with HMRC record-keeping rules).
- Chatbot conversation logs: 90 days, then deleted.
- Phone call recordings (if applicable): 30 days, then deleted, unless needed for a live dispute or client project.
- Technical / server logs: up to 30 days.
- Email correspondence: up to 3 years, unless part of an ongoing client relationship.
- Records required by law: retained for the period required by the relevant law (e.g. tax records, 6 years).
Who we share your data with
We use trusted third-party technology and infrastructure providers to operate our website, communicate with enquiries, manage bookings, protect our systems, and deliver our services. We only share personal data where it is necessary for those purposes.
These providers may support areas such as website hosting, security protection, email, calendar management, data storage, enquiry routing, customer communication, automation, artificial intelligence features, and voice or messaging services where enabled.
We do not allow our service providers to use your personal data for their own marketing. They are only permitted to process data for the service they provide to us, under appropriate contractual, security, and confidentiality obligations.
Some providers may process data outside the United Kingdom. Where this happens, we rely on recognised transfer safeguards such as adequacy regulations, the UK-US Data Bridge, Standard Contractual Clauses, International Data Transfer Agreements, or other safeguards approved under UK data protection law.
We do not sell your data to any third party. We do not share your personal data for third-party advertising purposes.
We may disclose personal data if required by law, regulation, court order, legal process, or where disclosure is necessary to protect our rights, users, systems, or the safety of others.
How we protect your data
We take the security of your personal data seriously and apply industry-standard safeguards appropriate to the sensitivity of the data we hold and the expectations of clients operating in regulated environments:
- Encryption in transit: all data sent to or from our website is encrypted using TLS 1.2+ (HTTPS). Our hosting provider uses modern cipher suites.
- Encryption at rest: personal data stored in our systems is encrypted at rest using provider-managed keys or industry-standard disk encryption.
- Access control: only authorised personnel can access personal data. Multi-factor authentication (MFA) is enforced on all administrative accounts.
- Credential hygiene: API keys and credentials are stored in an encrypted secrets vault, never in source code, and rotated when staff change.
- Principle of least privilege: our automation workflows only access the data needed to perform their function.
- Network protection: our public endpoints sit behind Cloudflare, providing DDoS protection, rate limiting and Web Application Firewall features.
- Logging and monitoring: we log access to our systems and monitor for anomalous activity.
- Audit trail: every workflow run is logged with timestamp, input, output and status, available for compliance and audit review.
- Data minimisation: we only ask for the data we genuinely need.
No online system is 100% secure. But we take reasonable, proportionate steps to protect your data and we continuously improve our security practices.
Your rights under UK GDPR
As a UK resident (or anyone whose data we hold), you have the right to:
- Be informed about how your data is used, that's what this page is for.
- Access the personal data we hold about you (Subject Access Request).
- Rectification, correct inaccurate or incomplete data we hold about you.
- Erasure, ask us to delete your data (the "right to be forgotten"), subject to legal exceptions.
- Restrict processing, limit how we use your data in certain circumstances.
- Data portability, receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to automated decision-making that produces significant legal effects without human review.
To exercise any of these rights, email us at hello@flownest.xyz. We'll respond within one calendar month as required by UK GDPR.
Complaints
If you're unhappy with how we've handled your data, we'd rather you told us first so we can try to put it right, email hello@flownest.xyz.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters. Website: ico.org.uk/make-a-complaint. Telephone: 0303 123 1113.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in how we operate or in the law. The "Last updated" date at the top of the page will always reflect the most recent revision. For material changes we'll make reasonable efforts to notify you, e.g. via email if we have a live engagement with you.
Contact
Questions about this policy or how we handle your data? Email hello@flownest.xyz or call +44 113 519 4131 and we'll get back to you within two working days.