GDPR Rights & Data Protection
Last Updated: February 2, 2026
1. Overview
FlowDrafts is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). This page explains your rights under GDPR and how to exercise them.
2. Your Rights Under GDPR
If you are a resident of the European Economic Area (EEA), you have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you.
You can request correction of any inaccurate or incomplete data.
You can request deletion of your personal data ("right to be forgotten").
You can request your data in a machine-readable format.
Additional rights include:
- Right to Restrict Processing: Limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File a complaint with a supervisory authority
3. Data Controller Information
For the purposes of GDPR, FlowDrafts acts as the data controller for your personal data. Our contact details are:
FlowDrafts
1 Pan Peninsula Square
London, E14 9HD, UK
Email: support@flowdrafts.com
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: Processing necessary to fulfill our service agreement
- Consent: Where you have given explicit consent (e.g., marketing emails)
- Legitimate Interests: For product improvement and security
- Legal Obligations: To comply with applicable laws
5. International Data Transfers
Your data may be transferred to and processed in countries outside the EEA. When this occurs, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with our service providers
- Technical and organizational security measures
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Specific retention periods:
- Account data: Duration of account plus 30 days after deletion
- Transaction records: 7 years (legal requirement)
- Usage analytics: 26 months (anonymized thereafter)
- Support communications: 2 years
7. Submit a Data Request
Use the form below to exercise your GDPR rights. We will respond to your request within 30 days.
8. Contact Our DPO
For any questions about this page or our data practices, please contact our Data Protection Officer:
Email: support@flowdrafts.com
Response time: Within 48 hours