Privacy Policy
Controller
The controller is FLOWMATIC S.R.L., tax id (CUI) 52891900, trade registry J2025087179005, Str. Vasile Alecsandri, bl. 66A, sc. A, parter, ap. 1, Pitești, Argeș 110377, Romania. Contact for privacy matters: office@flowmatic.ro.
What we collect
- Account data: your email address, a hash of your password (never the password itself) or, if you sign in with Google, your Google subject id and the email Google gives us.
- Product data: the websites you add, keywords, generated articles and images, service pages, and the site structure we import when you connect a site.
- Platform credentials: the API keys, application passwords or authorisations you give us to publish. They are encrypted at rest with AES-256-GCM.
- If you connect a Shopify store through our Shopify app, we store the store's myshopify.com address and an access token, encrypted at rest, to publish your articles and to read and update the search titles and descriptions of your blog posts and pages. The app only asks for access to online store content (blog posts, blogs and pages); it does not access your customers, orders, products or payments. When you uninstall the app, Shopify revokes the token and we delete the stored connection during our daily maintenance.
- Billing identity from Stripe: name, postal address, country and VAT id, as collected at checkout, plus the id and link of your latest invoice.
- Technical and usage logs: IP address, browser type, timestamps, the actions you take in the app, provider errors and an audit trail of sign-ins and admin actions.
- Support: the messages and tickets you send us, including any screenshots you attach.
- Security and contract declarations: multi-factor authentication configuration and recovery-code hashes; for withdrawal or cancellation, name/company, contact and account email, contract reference, requested date, receipt time, correspondence and handling outcome. An extraordinary cancellation may include its reason. Temporary hashed identifiers help prevent form abuse.
Why we use it and on what basis
- To provide the service you signed up for: contract (GDPR art. 6(1)(b)).
- To issue invoices and keep accounting records: legal obligation (art. 6(1)(c)).
- To keep the service secure, detect abuse and rate-limit attacks: legitimate interest (art. 6(1)(f)).
- To send you product news: your consent (art. 6(1)(a)), which you can withdraw at any time.
- To measure whether Meta ads lead to page visits, signups, checkout starts or trials: your consent (GDPR art. 6(1)(a)), which you can withdraw at any time.
We do not sell personal data or train AI models on your account data. Advertising measurement with Meta is used only after the consent described above.
Account contact details and the information needed to deliver and bill the chosen service are required to enter and perform the contract; without them we cannot provide those features. Website and content data may also come from the public sites or platforms you ask us to connect. Automated quota and abuse checks can pause an action; contact support to ask for a human review. Withdrawal and cancellation declarations are used to fulfil contract and legal duties and to document requests.
Service providers and recipients
The recipients below receive data needed for the feature you use. Their roles differ: some process content for us, while others determine their own purposes for part of the processing. Hosting, mail and support are operated by FLOWMATIC S.R.L..
| Recipient | Service and data | Role and locations |
|---|---|---|
| Anthropic Ireland, Limited | AI writing and content analysis: website text and URLs, keywords, business context and generation instructions. | Processor for submitted content; processing in the US and other regions. |
| kie.ai (NEXUSAI SERVICES LLC / INNOLEAP AI LLC) | AI images from fixed generic scene prompts. Our service account and server network information. | Image-service supplier. NEXUSAI is based in the US; API processing countries are not specified in the reviewed terms. |
| DataForSEO (entity specified in the account agreement) | Search, Maps, backlinks and AI visibility: keywords, questions, domains, business name/city and language/country. | Processor for Service Data under the applicable DPA. Published terms identify Dataforseo OÜ in Estonia; a US contracting option is also offered. International suppliers. |
| Stripe Payments Europe, Limited / Stripe, LLC | Checkout, subscriptions, invoices and tax: customer/billing identifiers, payment and transaction information. | Processor for service provision; controller for its own fraud, regulatory and other stated purposes. Ireland, US and other service locations. |
| Google LLC / Google Ireland Limited | Google sign-in, Search Console reports and Blogger: authorization data, account/site/blog identifiers, selected reports and content to publish. | Independent controller for its services under the applicable API terms; international processing. |
| Meta Platforms | Advertising measurement: PageView, CompleteRegistration, InitiateCheckout and StartTrial; a restricted source URL, event identifiers and time, a hashed internal account identifier, optional _fbp/_fbc, and browser/network information for browser events. | Advertising measurement provider and recipient. Meta's published terms and privacy policy describe its own purposes and international processing. |
| Shopify | Subscription billing when you install our app from the Shopify App Store: your store's domain and plan/subscription status. | Independent controller for the App Store subscription and payment; shares your store's plan status with us. International processing. |
| FLOWMATIC S.R.L. | Own hosting, transactional email and support: account/product data, recipients, messages and support requests. | Flowmatic operations in Romania. |
Image generation uses prewritten industry scenes and styles selected within our application. We do not send your raw keywords, niche, brand tone, article text, names or account identifiers to kie.ai. Generated images are downloaded by our server and stored before use; a storage failure leaves the article available without that image and records an operational error. This does not make the provider interaction anonymous: our service account and server network information still reach the provider.
Google sign-in, Search Console and Blogger data is used only for the features you request, under the Google API Services User Data Policy, including Limited Use. We do not sell this data or use it for advertising. Human access is limited to the permitted security, legal or support purposes. Publishing sends content to the platform you connect, under your instructions and that platform's terms.
International processing and safeguards
Our main database is hosted by Flowmatic in Romania. External services may process data outside the EEA. Their contracting address is not a promise that all processing stays in that country.
The Anthropic API Commercial Terms incorporate its DPA, including applicable standard contractual clauses. DataForSEO's Terms incorporate its DPA when GDPR applies; its Privacy Policy describes onward suppliers and transfer safeguards. These processing terms form part of the applicable online service agreement.
Stripe's DPA incorporates its Data Transfers Addendum, which provides the Data Privacy Framework for covered US transfers and standard contractual clauses as applicable fallback. The Google APIs Terms refer to controller-to-controller terms, with provisions for European recipients and onward transfers. These are service-specific arrangements, not a claim that every recipient is our processor.
kie.ai's published Terms and Privacy Policy do not establish an API data-processing agreement or transfer safeguards for personal data in customer prompts. Our image workflow therefore sends only the fixed scene/style prompts described above. Its API documentation states that generated media is retained for 14 days and text/metadata logs for two months. For the recipient, countries and applicable safeguards for a particular use, or a copy of available documentation, contact office@flowmatic.ro.
Retention
- Account and product data remain while your account is active. Account deletion removes the active account and its product content; justified accounting records, payment reconciliation and abuse-prevention evidence are assessed separately.
- Account and subscription confirmations are queued for delivery and retries with your email, account reference, subscription details and a copy of the accepted documents where available. The queue is configured to retain pending records for 30 days and completed records for 90 days after completion. Necessary evidence may be preserved separately under a documented legal hold.
- Administrative audit trail: 730 days, with a configured floor of 180 days. Login successes and failures, lockouts and password-reset security events, including their IP information: 90 days.
- Provider error logs: 90 days. Inactive authentication-throttle records are reviewed for removal after 90 days; expired password-reset records after seven days. This maintenance is reviewed monthly.
- Invoices and accounting supporting records are retained for five years from 1 July following the financial year in which they were prepared, including after account closure. A documented tax, legal or dispute obligation may require longer retention.
- Financial usage, payment, quota and trial-abuse records can remain identifiable or pseudonymous after account closure. We review their necessity quarterly and on closure, and review unnecessary IP information or other technical metadata monthly. Accounting periods do not automatically justify retaining every associated field. These records are not subject to an automatic blanket deletion period.
- Local database backups have a 14-day rotation after a successful new copy. Encrypted off-server and maintenance backups have a 35-day retention target, checked monthly. Older copies are retained only for a documented legal hold or where no newer verified recovery copy is available, with a next review date. These separate copies are not automatically overwritten. Account deletion does not immediately remove historical backups; restoration includes replaying recorded deletions before normal service resumes.
- Withdrawal and cancellation declarations remain while being handled. Closed declarations are deleted three years after resolution once all notifications have been sent, unless a legal hold applies. Short-lived abuse-prevention hashes are removed after 48 hours.
- We keep a minimal deletion record to prevent deleted accounts from returning after a backup restore. It is reviewed after three years and kept longer only while a retained recovery copy or a specific legal hold requires it. Contact us for an erasure assessment covering separately retained records and backups.
Your rights
You may request access, correction, erasure, restriction, data portability where applicable, and object to processing based on legitimate interests. You can withdraw consent at any time without affecting earlier lawful processing. Write to office@flowmatic.ro. We respond within one month; where the GDPR allows an extension for a complex or numerous request, we explain it within that first month. We may ask for proportionate identity verification.
Account settings offer an export of product content and account deletion. That export is not a complete copy of every personal-data record. Contact us for a complete access or portability request, including logs and data retained separately after account closure.
If you think we handle your data unlawfully, you can complain to the Romanian supervisory authority, ANSPDCP (www.dataprotection.ro), or to the authority in your own EU country.
Security
Traffic is encrypted with TLS. Passwords are stored hashed. Platform credentials are encrypted at rest. Access to production systems is limited to the people who run the service and is logged. Each customer's data is isolated at the database layer.
Children
SEO Conquest is for businesses and adults. You must be at least 18 to open an account.
Changes
If this policy changes, the date at the top changes with it. For meaningful changes we notify you by email or in the app.
Contact
Privacy questions go to office@flowmatic.ro. Postal address: FLOWMATIC S.R.L., Str. Vasile Alecsandri, bl. 66A, sc. A, parter, ap. 1, Pitești, Argeș 110377, Romania.