signfloow Back

Last updated: 11 June 2026

Privacy Policy

1. Data controller

The controller of your personal data is FLOOOW 2026, S.L. (Tax ID / CIF: B88853429), based at Carrer Cala Bona, Nº 13 - Polígono Son Fuster, 07009 Palma, Illes Balears, Spain, owner of the trade name «signfloow». Legal representative: Joaquín Garrido Pérez. Contact email: hola@signfloow.ai.

2. Data we collect

We collect the following categories of personal data:

  • Registration data: name, surname, email address and password (stored encrypted).
  • Profile data: company name, phone number and country.
  • Usage data: projects created, platform interactions, configuration preferences.
  • Technical and browsing data: IP address, browser type, operating system and access data automatically generated through cookies and similar technologies (see Cookie Policy).
  • Analytics and marketing data: subject to your prior consent, we collect browsing data to measure website usage and display relevant advertising through Google Analytics 4, Microsoft Clarity and Meta Pixel.
  • Communications: messages sent through the AI assistant or contact forms.

3. Purposes and legal basis

Purpose Legal basis
Manage registration and access to the platformContract performance (art. 6.1.b GDPR)
Provide the contracted AI servicesContract performance (art. 6.1.b GDPR)
Send commercial communications about the serviceLegitimate interest / consent (art. 6.1.a & 6.1.f GDPR)
Web analytics (Google Analytics 4, Microsoft Clarity)Consent (art. 6.1.a GDPR)
Marketing and conversion tracking (Meta Pixel)Consent (art. 6.1.a GDPR)
Comply with legal and tax obligationsLegal obligation (art. 6.1.c GDPR)

4. Recipients of the data (processors)

Your data may be communicated to the following processors, with whom we maintain GDPR-compliant data protection agreements:

  • Amazon Web Services EMEA SARL — platform and database hosting (region eu-west-3, Paris).
  • OpenAI, L.L.C. — processing of AI assistant queries (no model training under API terms).
  • Anthropic PBC — processing of AI assistant queries (alternative to OpenAI; no use for training).
  • Stripe Payments Europe Ltd. — payment processing (only if you contract a paid plan).
  • Google LLC — web analytics (Google Analytics 4), only if you consent to analytics cookies.
  • Microsoft Corporation — heatmaps and session recordings (Microsoft Clarity), only if you consent to analytics cookies.
  • Meta Platforms, Inc. — conversion tracking and advertising (Meta Pixel), only if you consent to marketing cookies.
  • Cloudflare, Inc. — anti-bot protection (Cloudflare Turnstile), strictly necessary processing for contact form security.

We do not sell or assign your data to third parties for their own commercial purposes.

5. International transfers

Some of our providers (Google LLC, Microsoft Corporation, Meta Platforms, Inc., Cloudflare, Inc., OpenAI, L.L.C., Anthropic PBC) are located in the United States. These transfers take place under the EU-US Data Privacy Framework and/or the Standard Contractual Clauses issued by the European Commission, in accordance with Chapter V of the GDPR.

6. Data retention

We retain your data while your account is active or as necessary to provide the services. Once you request deletion or applicable legal periods expire, data will be deleted or anonymised. Data derived from analytics and marketing cookies is retained according to the periods set by each provider (see Cookie Policy).

7. Your rights

Under the GDPR and LOPDGDD, you have the right to:

  • Access your personal data.
  • Rectify inaccurate data.
  • Erase your data («right to be forgotten»).
  • Restrict processing.
  • Port your data in a structured format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time (e.g. by changing your cookie preferences), without affecting the lawfulness of prior processing.

To exercise any of these rights, contact hola@signfloow.ai. You also have the right to file a complaint with the Spanish Data Protection Agency (aepd.es).

8. Security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or destruction, including encryption in transit (TLS) and at rest, access controls and regular audits.

9. Changes to this policy

We may update this policy to reflect changes in our services or applicable law. We will notify you of any material changes by email or via a prominent notice on the platform.