Legal / Privacy Policy
Privacy Policy
Last Updated: 26 September 2026
§1. Introduction
We operate Clientflow, a field service management platform designed for service businesses. This privacy policy describes how the legal entity identified in the company information above ("we", "us" or "our") collects, uses, stores, shares and protects information when you use our platform, website, mobile applications, APIs and related services (collectively, the "Service"). The policy applies to the Clientflow application at app.clientflow.nu, the marketing website at clientflow.nu and related subdomains, as well as future features and updates to the Service. It has been prepared in accordance with the EU General Data Protection Regulation (GDPR), the Danish Data Protection Act and the ePrivacy rules as implemented in Danish law. The policy is an information notice — not a contract: it describes what we do with your information and which rights you have. The terms governing your use of the Service itself are set out in our Terms of Service, and the processing of your customers' data is governed by our Data Processing Agreement (DPA), which takes precedence over this policy in the event of any inconsistency.
This policy also applies to the Clientflow mobile application, available via the Apple App Store and Google Play Store. By downloading or using the mobile application, you accept this privacy policy. A link to this policy is available in the app's settings as well as in the App Store listing.
Our use of information received from third-party platforms, including Meta (Facebook/Instagram), adheres to applicable platform terms and data use requirements. Meta Platform Terms
Company Information
- Legal Entity:
- Flow Solutions ApS
- Address:
- Søborg Hovedgade 94B, 2860 Søborg, Denmark
- VAT/CVR:
- DK46469178
- Contact Email:
- support@clientflow.nu
§2. Information We Collect
We collect information in the following categories:
A. Account Information
When you create an account, we collect the information needed to establish and administer your customer relationship: company name, CVR (business registration) number, organization type, industry, business address, contact details for contact persons (name, phone number, email address and role), login credentials (email address and password, stored hashed, plus any two-factor configuration), billing and payment details (card details are stored in tokenized form with our payment provider Stripe — we never see or store your full card number), preferred language and notification preferences, technical registration data (IP address, browser type and timestamp at account creation) and referral source (e.g. UTM parameters and landing page if you found us via a campaign). We also process information you choose to provide during onboarding or later account updates.
B. Business Operations Data
To provide our service, we process:
- Customer records: Names, addresses, contact information, service preferences.
- Orders and subscriptions: Service details, scheduling, pricing, history.
- Worker information: Employee names, contact details, schedules, assigned routes.
- Financial data: Invoices, payment records, pricing information.
- Lead data from integrations: Contact information and form responses from e.g. Meta Lead Ads.
We do not sell your personal data or your customers' data to third parties. For personal data about your own customers, leads and employees that you process through the Service, you are the data controller and we are the data processor — see the role allocation in Section 8. This means it is your responsibility to have a lawful basis for your processing and to fulfil your obligations towards the data subjects. The framework for our processing on your behalf is set out in the Data Processing Agreement (DPA), and your responsibilities as controller are described further in Section 12 of the Terms of Service.
C. Technical Information
We automatically collect certain technical information when you use the Service: browser type and version, operating system and device type, IP address, language and time zone settings, pages visited and features used, clicks on buttons and links, form submissions (the event itself — not the field contents), session duration, error logs with associated technical context (via our error monitoring tool), and performance measurements such as load times. We do not collect battery status, installed fonts or device fingerprints. We use session replay for troubleshooting: nothing is recorded continuously, but if an error occurs, a recording of approximately the preceding 60 seconds is sent to our error monitoring tool, and the remainder of that session is then recorded. The recordings are not masked and may therefore include customer data shown on screen. On the marketing website we use consent-based analytics and ad measurement (Google Analytics, Meta Pixel and Google Ads with Consent Mode v2) — non-essential cookies are only set once you have given consent via the cookie banner, and you can change or withdraw your consent at any time. We also measure website visits with our own statistics tool. If you accept analytics, we derive your approximate location (country, region and city) from your IP address when the visit starts. The lookup is made with the ipapi.co service in the USA, and the IP address itself is not stored in the statistics.
D. Mobile-Specific Information
When you use the Clientflow mobile application, we may additionally collect:
- Location data (GPS): We collect precise location data from your device to enable route optimization, navigation, and recording of completed work at customer locations. Location data is only collected when the app is in use and you have granted permission via your device settings. You can revoke this permission at any time in your device settings.
- Microphone access: If you enable call transcription, the app accesses your device's microphone to record conversations for transcription and AI analysis. Microphone access requires your explicit consent and can be disabled at any time.
- Push notifications: We may send push notifications about task updates, customer messages, and system alerts. You can manage notification preferences in your device settings.
- Device identifiers: We collect anonymized device identifiers for troubleshooting, crash reporting, and platform security. We do not use device identifiers to track you across third-party apps or services.
- Camera access: If you use features such as photo documentation of completed work, the app accesses your camera. Camera access requires your explicit consent.
E. AI-Processed Information
Clientflow uses artificial intelligence (AI) and machine learning to deliver several core features. The following data is processed by AI systems:
- Route optimization: Customer addresses, order details, and time window constraints are sent to our route optimization engine to calculate optimal driving routes. This processing takes place on our own servers within the EU.
- Call transcription and analysis: Audio recordings of customer conversations are processed by third-party AI services for speech-to-text conversion, summarization, satisfaction scoring, and communication feedback. The specific third parties performing this processing are listed below in section 5.
- Lead management: AI may be used to categorize and prioritize incoming leads based on form responses and contact information.
We only send the data to third-party AI services that is necessary for the specific feature. AI features involving third-party AI processing are enabled by default and can be turned off at any time under Settings → Company. When AI is turned off, disclosure to third-party AI providers ceases; this does not affect the lawfulness of processing carried out beforehand. Transfers to AI providers outside the EU/EEA are made on the basis of the European Commission's Standard Contractual Clauses, as described in Section 10. AI-generated output — transcriptions, summaries, lead scores, route suggestions and the like — consists of indicative suggestions, not professional advice. It may contain errors, and you are responsible for verifying it before acting on it; our liability is governed by Section 7 of the Terms of Service. We may update or replace the underlying AI models and providers on an ongoing basis; changes of sub-processors are notified as described in Section 5.
§3. How We Use Your Information
We process your personal data on one of the following legal bases under Article 6(1) GDPR: (a) consent (point (a)) — e.g. for AI features, location-based features, microphone and camera access, and marketing; consent can always be withdrawn, cf. Article 7(3); (b) performance of a contract (point (b)) — delivery, operation and support of the Service, and billing; (c) legitimate interest (point (f)) — product development, usage analytics, security, abuse and fraud prevention, and enforcement of our terms; you may object to this processing, cf. Article 21; and (d) legal obligation (point (c)) — e.g. bookkeeping, tax and anti-money-laundering legislation. The specific legal basis for each processing activity is stated in the list below. We use collected information to:
- Provide the Service: Operate your dashboard, manage customers, optimize routes, process orders, and facilitate communications. Legal basis: contractual necessity, GDPR Article 6(1)(b).
- Improve the Platform: Analyze usage patterns, fix issues, and develop new features. Legal basis: legitimate interests, GDPR Article 6(1)(f) (product development and service optimization).
- Communicate with You: Send service notifications, respond to inquiries, and provide support. Legal basis: contractual necessity, GDPR Article 6(1)(b), for service-related communications; legitimate interests, Article 6(1)(f), for non-contractual operational communications; consent, Article 6(1)(a), for marketing where required.
- Ensure Security: Detect fraud, protect against abuse, and maintain platform integrity. Legal basis: legitimate interests, GDPR Article 6(1)(f) (network and information security and fraud prevention).
- Meet Legal Obligations: Comply with applicable laws and respond to lawful requests. Legal basis: legal obligation, GDPR Article 6(1)(c) (including the Danish Bookkeeping Act, tax legislation, and anti-money-laundering regulations).
Collection Methods
We collect information in the following ways:
- Directly from you: Information you enter during account creation, service configuration, and use of platform features.
- Automatically via the app: Technical data, location data, and device information are collected automatically when you use the platform, based on the permissions you have granted.
- From third-party integrations: Data synchronized from services you have connected, such as Meta Lead Ads, Dinero, or Billy.
- From device sensors: GPS, microphone, and camera, only when you have actively granted permission and are using relevant features.
§4. Data Storage and Security
We implement technical and organizational security measures in accordance with Article 32 GDPR, taking into account the state of the art and the risks of the processing. Platform data is hosted with Supabase on Amazon Web Services in the EU region Frankfurt (eu-central-1); the data centers are certified under, among others, ISO 27001 and SOC 2 Type II. Our security work includes network security (firewalls and monitoring), secure development practices and vulnerability scanning, encryption of data in transit (TLS/HTTPS) and at rest, role-based access control under the principle of least privilege, multi-factor authentication on internal systems, centralized logging, and documented incident response procedures. Our security work further includes the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident, and a process for regularly testing and evaluating the effectiveness of the measures, cf. Article 32(1)(c) and (d) GDPR. No internet service can be guaranteed 100% secure, however. You are responsible for protecting your own login credentials and for contacting us immediately if you suspect unauthorized use of your account. In the event of a personal data breach, we notify the competent supervisory authority and affected data subjects in accordance with Articles 33-34 GDPR. Our liability is governed by Section 7 of the Terms of Service.
- Encrypted data transmission: All communication runs over TLS 1.2 or newer.
- Encryption at rest: AES-256 with every provider we host with.
- Data isolation: Separation between customers is enforced in the database layer through Row Level Security on every table in production, and the application accesses the database with a role that cannot bypass those policies. Isolation therefore does not depend on the application code.
- Access controls: Role-based access under the principle of least privilege. Access to production data is limited to a named group, granted through short-lived access tokens that renew automatically, and removed when someone leaves. Critical database events are audit-logged.
- Support access: Access to the Controller's data for setup or troubleshooting occurs only with consent. Every lookup is logged and documented with a reason per incident, and support access can be declined at any time.
- Backup in two independent layers: Point-in-time recovery in the database, plus an encrypted daily copy with a provider independent of the database provider, in object storage under EU jurisdiction and under separate access keys. Backups are encrypted separately before they leave our infrastructure.
- Recovery times: Maximum data loss (RPO) is seconds on the first layer and up to 24 hours on the second. Maximum recovery time (RTO) is approximately one hour on the first layer and hours on the second.
- Testing and monitoring: Restores are tested quarterly, comparing row counts and security policies against production. A missing or truncated backup raises an alarm. Monthly copies are write-protected for the retention period, and backups are copies — not synchronization — so deletions in production do not propagate to the backups.
§5. Data Sharing
We share data only in the following circumstances:
Service Providers
We engage a number of trusted sub-processors to deliver the Service, including cloud hosting, database and storage, transactional email, SMS and voice, payment processing, AI processing, mapping, error monitoring, and invoicing. An overview of these categories — with purpose, processing location, and legal basis for any transfers to third countries (GDPR Article 28(2)-(4)) — is available at:
- Overview: clientflow.nu/underdatabehandlere — categories of sub-processors with purpose, location, and transfer mechanism. The complete list of named sub-processors is available on request from support@clientflow.nu.
All sub-processors are contractually bound through written data processing agreements in accordance with Article 28 GDPR, and we only share the data necessary for the service in question. When adding or replacing sub-processors in a way that changes the processing location or transfer mechanism, we notify you at least 30 days in advance via the platform and email. During the notice period you may object by writing to support@clientflow.nu; if we cannot accommodate the objection through reasonable measures, you may terminate the Service with no obligations beyond payment for use already delivered. Changes that relate solely to the internal organization of an existing sub-processor without affecting the level of data protection may be implemented without notice. For providers established outside the EU/EEA we rely on valid transfer mechanisms under Chapter V GDPR — primarily the European Commission's Standard Contractual Clauses (SCCs) and, where the provider is certified, the EU-U.S. Data Privacy Framework (DPF). The complete list of named sub-processors is available on request from support@clientflow.nu.
Legal Requirements
We may disclose information where required by law, court order or binding governmental request. We may also disclose information where necessary, in good faith, to protect our or third parties' rights, property or safety, to enforce our terms, or to prevent and investigate fraud, abuse or other unlawful activity. Where the law permits, we aim to notify you of disclosures concerning your data; in some cases legislation or a court order may prohibit us from notifying you.
Business Transfers
In connection with a merger, acquisition, sale of assets, reconstruction, insolvency proceedings or other business transfer, your information may be transferred as part of the transaction. During any due diligence process, information is shared only under confidentiality agreements. An acquiring entity will be required to process your information under data protection obligations materially equivalent to this policy, unless you are notified of a new privacy policy. We will notify you of a completed transfer to the extent required by applicable law.
We never sell, trade, or rent your personal data or your customers' data to third parties. We do not use your data to train AI models.
§6. Data Retention
We retain your data for as long as necessary to provide the Service and fulfil the purposes described in this policy, in line with the storage limitation principle in Article 5(1)(e) GDPR. When setting retention periods we consider the nature and sensitivity of the information, the purpose of the processing, statutory retention requirements (e.g. the Danish Bookkeeping Act's requirement to retain accounting records for five years from the end of the financial year) and limitation periods for legal claims. Deleted data may remain in encrypted backups for up to 90 days before being permanently removed from all backup media. Data that has been anonymized or aggregated so that it can no longer be linked to a person may be retained without time limitation for statistics and product development.
- Active Accounts: Data is retained while your account is active.
- Deleted Data: When you delete specific records, they are removed from our active systems promptly.
- Account Closure: After account termination, data is retained for 30 days to allow for reactivation, then permanently deleted.
- Legal Requirements: Some data may be retained longer if required by law (e.g., financial records, tax documentation).
§7. Your Rights
Under Chapter III of the GDPR you have a number of rights regarding our processing of your personal data: (a) access (Article 15) — the right to confirmation and a copy of the data we process about you; (b) rectification (Article 16) — the right to have inaccurate data corrected; (c) erasure (Article 17) — the right, in certain circumstances, to have your data deleted; (d) restriction of processing (Article 18); (e) data portability (Article 20) — the right to receive the data you have provided in a structured, machine-readable format; (f) objection (Article 21) — including, at any time, to direct marketing; (g) withdrawal of consent (Article 7(3)); and (h) the right not to be subject to purely automated decisions with legal effect (Article 22). These rights apply subject to the exceptions provided by law — for example, information we are legally required to retain (bookkeeping and tax records) cannot be deleted before the statutory period expires. Write to support@clientflow.nu to exercise your rights. For security reasons we ask for reasonable proof of identity before disclosing or deleting information. We respond to requests within one month of receipt; for particularly complex requests the deadline may be extended by up to two further months, in which case we will inform you within the first month, cf. Article 12(3) GDPR. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse the request, cf. Article 12(5) — this is the exception, not the rule. You may lodge a complaint at any time with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, phone +45 33 19 32 00, www.datatilsynet.dk, or with the supervisory authority in the EU country where you live or work, cf. Article 77.
How to Exercise Your Rights:
- In-App Controls: You can view, edit, and delete most data directly within Clientflow.
- Account Deletion: You can initiate deletion of your account and all associated data at any time directly in the Clientflow app via your user profile under Personal Information. Account deletion permanently removes your account and all associated data from our active systems after a 30-day reactivation period, in accordance with our data retention policy in section 6. Data we are legally required to retain (e.g., financial records under the Danish Bookkeeping Act) is retained for the legally mandated period and then deleted. You can also contact us at support@clientflow.nu for assistance with account deletion.
- Third-Party Integrations: If you disconnect a third-party integration (e.g., Meta), new data will stop syncing. To delete previously synced data, use the in-app delete functions or contact us.
Consent Withdrawal
You can withdraw consent for specific data processing activities at any time:
- Location data: Disable location permission in your device settings (iOS: Settings > Clientflow > Location).
- Microphone access: Disable microphone permission in your device settings (iOS: Settings > Clientflow > Microphone).
- Push notifications: Disable notifications in your device settings (iOS: Settings > Clientflow > Notifications).
- AI features: Turn off AI processing under Settings → Company to stop all third-party AI processing.
- Camera access: Disable camera permission in your device settings (iOS: Settings > Clientflow > Camera).
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
§8. Clarification of Roles under GDPR
To ensure clarity regarding the parties' roles under the General Data Protection Regulation (GDPR Articles 4(7)-(8)), the following applies:
- Customer data in the Service: When you, as a business customer, use Clientflow to process personal data relating to your own customers, leads, employees, suppliers, and other data subjects, Flow Solutions ApS acts as a data processor on your behalf pursuant to GDPR Article 28, and you remain the data controller for such data. The terms of our processing are governed by a separate Data Processing Agreement (DPA), which forms an integral part of your subscription agreement.
- Marketing website visitors: When visitors interact with clientflow.nu (the marketing website), when leads submit contact information through web forms, or when recipients subscribe to newsletters and marketing communications, Flow Solutions ApS acts as the data controller for such processing.
- Account administration and billing: For personal data relating to login, user accounts, billing and payment information, support requests, Service usage, and other account administration, Flow Solutions ApS likewise acts as an independent data controller, as such processing is carried out to deliver the subscription, perform our contract with you, and comply with our legal obligations.
- Sub-processors: Our sub-processors (see the categories at clientflow.nu/underdatabehandlere) process your customers' personal data solely on your documented instructions, conveyed through us. We have entered into data processing agreements with all sub-processors in accordance with GDPR Article 28(4), and the sub-processors are bound by data protection obligations equivalent to ours.
This role clarification does not replace the executed Data Processing Agreement (DPA) and must be read together with it. In the event of conflict between this policy and the DPA, the DPA prevails with respect to our processing of your customers' data.
§9. Children's Privacy
Clientflow is a B2B service aimed at businesses and their employees and is not intended for persons under 18. We do not knowingly collect information from children. If we become aware that we have received personal data from a minor without a valid basis, we will delete the information and close the associated account. Contact us at support@clientflow.nu if you suspect that a child has provided information to us.
§10. International Data Transfers
Your data is stored and processed primarily within the EU — in data centers in Frankfurt, Germany (eu-central-1). Certain sub-processors — including providers of hosting, AI, maps and error monitoring — have parent companies or processing activities in the United States. For transfers to third countries we rely on valid transfer mechanisms under Chapter V GDPR: the European Commission's Standard Contractual Clauses (SCCs, Implementing Decision (EU) 2021/914) in the relevant modules, combined with the provider's certification under the EU-U.S. Data Privacy Framework (DPF) where available, or an adequacy decision under Article 45 (e.g. for the United Kingdom). Transfers to the US in connection with AI features cease if AI is turned off under Settings → Company. In line with the CJEU's Schrems II judgment and the EDPB's recommendations, we carry out a documented Transfer Impact Assessment of the destination country's legislation and implement supplementary measures where necessary — including strong encryption in transit and at rest, data minimization, and contractual obligations on the recipient to challenge disproportionate government access requests. An overview of sub-processor categories, locations and transfer mechanisms is available at clientflow.nu/underdatabehandlere; the complete named list is available on request.
§11. Changes to This Policy
We may update this policy, for example following changes in legislation, our data processing or the Service's features. The current version is always available at clientflow.nu, and the "Last Updated" date at the top shows the latest revision. We give notice of material changes — e.g. new processing purposes, new categories of collected data or changes to data sharing — via email or in the app before they take effect. Where a change requires consent under applicable law, we obtain the consent before the new processing begins.
§12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at support@clientflow.nu. Company details are provided elsewhere in this policy. For complaints regarding data protection, you may contact the Danish Data Protection Agency (Datatilsynet) via https://www.datatilsynet.dk.
§13. Meta (Facebook/Instagram) Integration
When you connect your Meta accounts to Clientflow for lead management:
- Data retrieval: We retrieve lead data (contact information, form responses, campaign metadata) that you have collected through your Meta Lead Ads.
- Data usage: This data is used solely to populate your Clientflow dashboard and enable you to manage and contact your leads.
- Roles: We act as a Data Processor on your behalf; you remain the Data Controller responsible for how lead data is used.
Our use of Meta data complies with the Meta Platform Terms.