Status: draft pending review by a Dutch IT/privacy lawyer. Final text takes effect on or before 2026-08-02.
1. Who we are
FlowVolt B.V. (“FlowVolt”, “we”) is a Dutch private limited company, registered with the Dutch Chamber of Commerce. We operate Warden, available at warden.flowvolt.io.
For questions about this policy, mail privacy@flowvolt.nl. For a security disclosure, security@flowvolt.nl.
2. What we collect
2.1 Account data
When you sign up we collect your email address, the tenant slug derived from it, and the company name you provide. We use this to create your account and send you the sign-in link.
2.2 Product data
Inside the Service you create records about your AI agents: slugs, names, owner emails, mandates, daily budgets, audit-log entries, intake answers. Some of these fields are personal data (e.g. the owner email). You decide what to put in. We act as the data processor for this data, not the controller. See the DPA.
2.3 Payment data
Stripe processes payments. We never see your card number. We do see the billing email, the company name, the country, the VAT number, the plan you chose, the amount paid, and the renewal date. We store these as part of your account.
2.4 Email content
We send transactional email through Resend: sign-in links, billing receipts, dossier notifications. We do not market by email without separate consent.
2.5 Web analytics
We use no third-party analytics on the marketing site or the dashboard. We keep server-side access logs (timestamp, path, status code, IP) for fourteen days to debug issues and detect abuse.
3. Why we process it
- To deliver the Service. Account data, product data, and payment data are needed to run Warden under our contract with you. Legal basis: contract performance.
- To bill you. Stripe handles the card; we keep the invoice. Legal basis: contract performance and our legitimate interest in keeping books.
- To keep the Service secure and abuse-free. Access logs and rate-limit counters. Legal basis: our legitimate interest, balanced against the minimal data retained.
- To comply with law. Tax records, AI Act audit log retention (six months minimum on Article 26 data), records required by Dutch corporate law. Legal basis: legal obligation.
4. Who else sees it
The following sub-processors process your data on our behalf:
- Supabase (Postgres + storage). Region: EU (Frankfurt). All of your account and product data is here.
- Vercel (hosting + edge cache). Region: EU (Frankfurt). Serves the website, dashboard, and API.
- Stripe (payments). Region: EU. Billing email, plan, invoices.
- Resend (transactional email). Region: EU. Sign-in and billing emails.
- Anthropic, OpenAI (AI models). Only if you have enabled the OpenAI usage import integration. We pass your API key to the vendor on your behalf. The vendor sees their own usage data and your API key; we receive a summary back. We do not send your audit-log contents to any model provider.
5. Where it lives
Your data is stored in the European Union, primarily in Frankfurt, Germany. We do not transfer personal data to countries outside the EU unless required by law. Stripe and the AI vendors listed above may process small amounts of data outside the EU under their own Standard Contractual Clauses; we maintain DPA agreements with each.
6. How long we keep it
- Account data: while your account is active, then thirty days after deletion.
- Audit-log entries: per your tier — 30 days (Free), 1 year (Team), 3 years (Company). AI Act Article 26 minimum (six months) takes precedence on high-risk-classified agents.
- Invoices: seven years (Dutch tax law).
- Access logs: fourteen days.
- Sign-in tokens: thirty minutes (link), thirty days (session).
7. Your rights
You have the right to:
- Ask what data we hold about you (access).
- Have it corrected if it is wrong (rectification).
- Have it deleted, subject to legal retention (erasure).
- Receive a copy in a portable format (portability).
- Object to processing or restrict it (objection / restriction).
- Withdraw consent at any time if processing relies on consent.
- Complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise any of these, mail privacy@flowvolt.nl. We respond within thirty days.
8. Cookies
The marketing site sets no cookies. The dashboard sets one session cookie (warden_session) after sign-in. It is HTTP-only, secure, and SameSite-Lax. We use no advertising or analytics cookies.
9. Children
Warden is a B2B service and is not directed at anyone under sixteen. We do not knowingly collect data about children.
10. Changes
Material changes to this policy are announced at least fourteen days in advance by email to all active customers.