Security & data

What we sign, where your data lives, how we protect it, what we never do with it, and what the EU AI Act asks of you.

A data processing agreement with every contract

Every contract includes a GDPR Article 28 DPA: you stay the controller, and we process your data only on your documented instructions.

  • Breaches notified without undue delay, within 72 hours at most.
  • At contract end, your data is deleted or returned, your choice, within 30 days unless the law requires otherwise, confirmed in writing on request.
  • Sub-processors listed in the DPA. Any addition or replacement is announced first, and you have 30 days to object.
  • Audits of our compliance with 30 days' notice, and professional indemnity insurance covering data processing errors.

Hosting in Germany, or on your own servers

Applications, databases and backups run on servers in the EU, in Germany. AI model routing, transactional email and the phone receptionist's voice and telephony use US providers under Standard Contractual Clauses. On request:

  • EU-only hosting, with AI models served from EU regions.
  • Swiss hosting on Swiss-only infrastructure under Swiss law, with providers such as Exoscale or Infomaniak.
  • On-premise, on your servers or cloud account, under your security policies: open-weight models such as Mistral and Llama run on your hardware, and we are responsible for the application layer.
  • A split: open-weight models do document search, drafting, classification and internal Q&A well, hosted models still lead on the hardest reasoning, so sensitive work stays on your infrastructure.

Compare the four ways to keep AI data in Europe

Your data does not train AI models

We never use your data to train, fine-tune or improve an AI model, ours or anyone else's.

  • The DPA extends that ban to every sub-processor and AI model provider.
  • API settings that turn such use off, training disabled at account level, and only providers that keep no request data.
  • No AI model provider processes your personal data until you approve it in writing, and you can withdraw that approval at any time.

How we protect it

The DPA commits us to measures appropriate to the risk. A security overview detailing each one is available on request.

  • TLS 1.2 or higher in transit, each client's data separate with its own credentials, minimal network exposure, key-only SSH, and secrets encrypted, never in plain text or source code.
  • Access limited to those who need it, revoked within five business days of an engagement ending or a team member leaving.
  • Daily encrypted backups in two separate off-site locations (7 daily, 4 weekly, 3 monthly), and server configuration as code, so production can be rebuilt in a reasonable time after a major incident.
  • Round-the-clock uptime checks on every client-facing service, themselves watched by an independent monitor on separate infrastructure, 30 days of metrics with alerts to the team, automatic dependency security updates, and OS security patches in regular maintenance windows.

Incidents are contained once confirmed, root-caused and documented. If one touches your personal data, you learn within 72 hours at most what happened, who is affected and what we did. Security questions are acknowledged within two business days.

The EU AI Act and your chatbot or voice agent

The AI Act gets stricter as risk rises. A customer-facing chatbot or voice agent is usually limited risk: under Article 50, applicable since 2 August 2026, it must clearly tell people they are dealing with an AI, at the latest at the first interaction.

  • In practice it says so in its first message or call greeting, and answers honestly if asked whether it is human. A line in your terms is not enough on its own.
  • On a Flowful package, that duty is ours as the provider: our web chatbot and AI phone receptionist, white-label deployments included, open every conversation with an AI disclosure in their first message or greeting, and both offer a route to a human.
  • Staff tools count too. An internal chatbot is limited risk as well, and Article 4 asks you to take measures that support your team's AI literacy, which is simpler with one approved assistant than with a dozen personal accounts.
  • Most other automation, such as email drafting or document processing, is minimal risk with no specific obligations. We build no high-risk system, such as hiring or credit scoring, without a formal compliance plan.

This is not legal advice, and we are not a law firm. Our guide covers the dates, the fines and a compliance checklist.

Read our EU AI Act guide for SMEs

FAQ

Common questions

When does the DPA take effect?

The day you sign the service agreement. We can send you the current version to review beforehand.

Must our chatbot say it is an AI even when that is obvious?

Yes. That exception is narrow, and the Commission's guidelines say it does not cover helpdesk chatbots.

Can you help us with the EU AI Act?

Yes. On request, our AI Audit adds an AI Act risk review to the opportunity analysis, in the same day.

Questions about your data?

Where your data lives is decided with you, before we build. Book a 30-minute call.

Get in touch