← Back to FlowBity

Privacy Policy

Last updated: May 21, 2026

This Policy describes what personal data we collect via https://flowbity.com, for what purpose and on what legal basis we process it, and what rights you have under Regulation (EU) 2016/679 (GDPR).

1. Data Controller

The controller of your personal data is:

  • FLOWBITY Spółka z ograniczoną odpowiedzialnością (FLOWBITY Limited Liability Company)
  • Registered address: Os. Jana III Sobieskiego 40/2N, 60-688 Poznań, Polska
  • Tax ID (NIP): 9721376119 (EU VAT: PL9721376119)
  • REGON: 544047871
  • National Court Register (KRS): 0001225616, registered at the District Court Poznań – Nowe Miasto i Wilda, 8th Commercial Division
  • Contact: admin@flowbity.com

We have not appointed a Data Protection Officer. For any matters concerning your personal data, please contact us at the email address above.

2. Data We Collect

Contact form. Full name, company name, email address, selected service, approximate budget, planned timeline, message content. Your IP address is logged for abuse prevention.

Booking a call. If you use booking.flowbity.com, you provide the data submitted in the booking form (name, email, meeting time, optional note).

Technical data. IP address, browser type, operating system, pages visited within the site, referrer. This data is processed mostly in aggregated form and does not usually allow identification of a specific person.

3. Purposes and Legal Bases

  • Replying to your inquiry and handling business relationships – Art. 6(1)(b) GDPR (pre-contractual steps) and (f) (legitimate interest in conducting business and contacting potential B2B clients).
  • Abuse and spam prevention (IP logging, Cloudflare Turnstile) – Art. 6(1)(f) GDPR (legitimate interest in securing the service).
  • Analytics and marketing – exclusively based on your consent (Art. 6(1)(a) GDPR). Consent is voluntary and may be withdrawn at any time via the cookie banner or by clearing your browser data.
  • B2B visitor company identification (Leadfeeder / Albacross) – Art. 6(1)(f) GDPR (legitimate B2B interest). We process company-level metadata, not individual persons.
  • Legal obligations (accounting, GDPR) – Art. 6(1)(c) GDPR.

4. Data Recipients (Processors)

We entrust processing of your data to the following trusted providers:

  • Resend, Inc. (USA) – email delivery. Transfer outside the EEA under EU-US Data Privacy Framework and Standard Contractual Clauses (SCC).
  • Cal.com (self-hosted on Netcup infrastructure in Germany) – meeting booking system.
  • Netcup GmbH (Germany, EEA) – server hosting for this site and Cal.com.
  • Cloudflare, Inc. (USA, global infrastructure) – Turnstile (bot protection). Transfer based on SCC and DPF.
  • Functional Software, Inc. (Sentry) – application error monitoring. EU region (Frankfurt), no transfer outside the EEA.
  • Google LLC (USA) – Google Tag Manager, Google Analytics 4 (with anonymized IP, no ad identifiers). Transfer based on DPF and SCC. Loaded only after consent.
  • Microsoft Corporation (USA) – Microsoft Clarity (heatmaps, session recordings). Loaded only after consent.
  • Meta Platforms, Inc., TikTok, LinkedIn (USA) – marketing pixels, loaded only after consent.
  • Umami Software Inc. (self-hosted, EEA) – privacy-friendly analytics without cookies.
  • RudderStack, Inc. (self-hosted, EEA) – CDP platform, loaded only after consent for analytics or marketing.
  • Accounting service – to the extent required by tax law (client invoices).

Each processor handles data under a data processing agreement (Art. 28 GDPR).

5. Transfers Outside the EEA

Some of the above processors are based in the United States. Transfers are made on the basis of the European Commission's adequacy decision under the EU-US Data Privacy Framework (where applicable) and Standard Contractual Clauses (SCC)adopted by the European Commission.

6. Retention Period

  • Contact form submissions – up to 24 months from the last contact (unless a contract is signed, in which case under accounting law).
  • Data of contracted clients – for the duration of cooperation plus 5 years from the end of the tax year of the last invoice (Polish Tax Ordinance).
  • Server logs and IP addresses – up to 12 months.
  • Analytics data (GA4, Clarity, Umami) – per each tool's default retention period (typically 14 to 26 months), if you have consented.

7. Your Rights

Under GDPR you have the right to:

  • access your data (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR, "right to be forgotten"),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing (Art. 21 GDPR),
  • not be subject to automated decisions including profiling (Art. 22 GDPR),
  • withdraw consent at any time (without affecting lawfulness of processing prior to withdrawal).

To exercise these rights, email admin@flowbity.com. We will reply within 30 days.

8. Complaint to the Supervisory Authority

You have the right to lodge a complaint with the supervisory authority, which in Poland is:

President of the Personal Data Protection Office (PUODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl

9. Automated Decisions and Profiling

We do not make decisions producing legal effects or similarly significantly affecting you, based solely on automated processing, including profiling.

10. Cookies and Similar Technologies

We use cookies and similar technologies to operate the site and, with your consent, to measure performance and run advertising campaigns. Categories:

  • Necessary (always on): language preference flowbity-lang (1 year, no personal data); Cloudflare Turnstile (bot protection) when active.
  • Analytics (only with consent): Google Analytics 4, Microsoft Clarity (anonymized heatmaps and session recordings). Umami (no cookies, no identification) runs regardless of consent as aggregated statistics.
  • Marketing (only with consent): Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, Google Ads, Microsoft Advertising UET, RudderStack CDP.
  • Functional (only with consent): Crisp chat widget.

You can manage consent any time via the cookie banner. Your choice is saved locally and applied on future visits.

11. Requirement to Provide Data

Submitting data via the contact form is voluntary but necessary for us to respond to your inquiry. Without that data we cannot contact you.

12. Changes to This Policy

We may update this Policy. The date of last update is at the top of the document. Material changes will be communicated by email if we have your address in active correspondence.

13. Contact

For privacy questions: admin@flowbity.com