1. Introduction & Deployment Boundaries
Welcome to FlowAIsys ("we," "us," or "our"). We provide AI-powered executive workflow automation software. FlowAIsys is a 100% self-hosted software application deployed directly within your own Virtual Private Server (VPS) using Docker and n8n nodes. Because all operational data (including email texts, credentials, and logs) is processed and stored strictly inside your controlled boundaries, FlowAIsys has zero access to or visibility of your data. This Privacy Policy outlines our compliance mappings and documents how our self-hosted software protects your privacy.
2. Information Processed (Client VPS Boundary)
Account Registration data: We collect your name, professional email, company name, and job title — provided during onboarding and billing, which we manage securely.
Operational workflow data: When you connect accounts (Gmail, Calendar, etc.) to your self-hosted agent, the software processes metadata and message payloads within your VPS. Raw message payloads are processed temporarily in volatile memory (RAM) and immediately purged (Zero Data Retention) locally on your system.
3. How We Use Registration Information
We use your registration and account information solely to (a) deliver and manage the software licensing and updates, (b) communicate essential service and security updates, and (c) provide calibration and technical onboarding support. We do not use your data for advertising, model training, or any commercial purpose.
4. India DPDP Act 2023 Compliance
Under the Digital Personal Data Protection (DPDP) Act 2023 of India, you act as the Data Fiduciary and FlowAIsys acts as the Data Processor via our self-hosted software tool. The client maintains complete administrative control over user consents and data erasure.
Data Principal Rights: The software includes built-in administrative tools to help you satisfy Data Principals' rights to access summaries of personal data, seek corrections/updates, request data erasure, and easily withdraw consent.
Consent & Deletion: Consent is managed on your server. If a user withdraws consent, the self-hosted software ceases processing instantly. Since all databases are local to your VPS, you can execute permanent data purges with zero dependence on us.
DPO contact: For questions about software privacy compliance or security policies, contact our Data Protection Officer (DPO) at [email protected].
5. Infrastructure Residency & Localization
Because the system is self-hosted, you establish data residency by choosing the physical location of your VPS. This allows you to comply with local data localization laws natively:
India: Deploying the container on AWS Mumbai or GCP Pune VPS guarantees all data remains inside local borders, complying with India's DPDP Act localization guidelines and safeguarding against its ₹250 crore penalty structure.
European Union & UK: Deploying on a VPS in Frankfurt ensures data stays inside the EEA for GDPR compliance.
United States: Deploying on a US-East VPS aligns with CCPA/CPRA regional requirements.
Canada: Deploying on a Toronto VPS satisfies PIPEDA's residency principles.
6. Global Privacy Mappings (GDPR, CCPA, PIPEDA)
The self-hosted software is designed to assist you in compliance with international privacy rules:
GDPR (EEA & UK): The software uses AES-256 GCM encryption, tracks transaction logs locally, and segregates client databases, fulfilling data protection by design and by default requirements (Article 25).
CCPA/CPRA (United States): We do not sell or share any information. The software assists you in satisfying user deletion and correction requests locally.
PIPEDA (Canada): Assists Canadian clients in satisfying PIPEDA's 10 Fair Information Principles by isolating all logs and datasets within client-controlled boundaries.
7. Data Sharing and Disclosure
We do not collect, sell, or trade your operational data. Because the software is self-hosted, your data is never shared with third parties by us. Your VPS infrastructure is subject to your own data sharing policies.
8. Data Retention & Erasure
We do not store or copy your operational data. You maintain 100% control over retention policies and data erasure on your VPS. We purge account registration data within 30 days of license cancellation.
9. Cookies and Tracking
Our informational website uses essential session cookies and aggregate analytics (Google Analytics, Microsoft Clarity) to understand performance. We do not use third-party advertising cookies.
10. Third-Party Integrations
The self-hosted software integrates with Google Workspace, Microsoft Outlook, and other tools via official APIs. You manage and store all OAuth access tokens locally in your encrypted environment variables.
11. Changes to This Policy
Material updates regarding software security or privacy compliance will be communicated via email 14 days prior to taking effect.
Last Updated: June 2026 · Governing Law: India · Contact: [email protected] / [email protected]