LAST UPDATED: JANUARY 5th, 2023

Privacy Policy

Flowdesk attaches great importance to the protection of your personal data. That is why Flowdesk has adopted, in addition to this Notice, the main principles regarding the protection of your data, which you can find in our Privacy Policy available on the flowdesk.co website.
The purpose of this Notice is to provide you with detailed information about how Flowdesk ("we" or "us") protect your Personal Data.
The purpose of this Notice is to inform you about the personal data we collect about you, why we use it, with whom we share it, how long we keep it, what your rights are and how to exercise them.
Additional information may be provided to you if any when you subscribe to a particular product or service.

1. What personal data do we use about you?

We collect and use the personal data that we need for our activities, in particular, to offer you personalized and quality products or services. 

We may collect various types of personal data about you, including 

  • Identifying information (e.g. name, ID card and passport number, nationality, place, and date of birth, gender, photograph, IP address); 
  • Contact information (e.g., mailing address and email address, telephone number); 
  • Family status (e.g., marital status, number of children); 
  • Education and employment information (e.g., level of education, employment, name of employer); 
  • Banking, financial and transactional data (e.g. bank details, transfers); 
  • Customer or prospect status 
  • Information related to your digital activities (e.g. IP address, browsing activity, geolocation) 
  • Data about your habits and preferences:
  • Data related to your use of our subscribed products and services (banking, financial and transactional data); 
  • Data collected in the context of our exchanges with you in our agencies (appointment report), our websites, our applications, our pages on social networks, during meetings, calls, chats, emails, interviews, telephone conversations ; 
  • Information about your hobbies and interests 

We never ask you to provide us with personal data relating to your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, or sexual orientation, unless required to comply with a legal obligation. 

The data we use about you may be provided directly by you. To verify or enrich our databases, this data may come from the following sources 

  • Publications/databases made available by official authorities (e.g. Official Journal); 
  • Our corporate clients or our service providers; 
  • Websites/social media pages containing information that you have made public (e.g., your website or social media); 
  • Databases made publicly accessible by third parties. 

2. Special cases of personal data collection, including indirect collection

In certain circumstances, we may collect and use personal data about individuals with whom we have or may have a relationship, such as: 

  • Non-clients 

We may also collect information from non-customers with whom we have no direct relationship. This may be the case, for example, when your employer provides us with information about you, or when your contact information is provided to us by one of our customers, because you are, for example: 

  • Family member; 
  • Co-borrower(s)/Guarantor(s) ; 
  • Legal representative (mandates/delegations of authority) ; 
  • Shareholder(s) of companies ;
  • Representative(s) of a legal entity (which may be a client or a provider) ; 
  • A staff member of our service providers and business partners; 
  • Journalist(s); 
  • Personal contact(s).

3. Why and on what legal grounds do we use your personal data?

1. To comply with our legal or regulatory obligations

We use your personal data to comply with various legal and regulatory obligations to which we are subject, including 

The financial regulations under which we might : 

  • Put in place security measures to prevent abuse and fraud and detect abnormal transactions; 
  • Define your credit risk rating and your ability to repay; 
  • Monitor and report on the risks we may face, and 
  • Record phone calls, discussions, emails, etc. when necessary. 
  • Responses to official requests from duly authorized public or judicial authorities; 
  • The fight against money laundering and terrorist financing ;

2. To enter into a contract with you or to contact you, at your request, to enter into a contract

We use your personal data to enter into and perform our contracts, including to: 

  • Provide you with information about our products and services; 
  • Assist you and answer your questions; 
  • Assess whether we can offer you a product or service and if so, under what conditions; and
  • Provide products or services to our corporate customers of which you are an employee or customer (e.g. in the field of cash management).

3. To pursue our legitimate interests

We use your personal data to implement and develop our products or services, to optimize our risk management, to defend our rights, and also to : 

  • Keeping proof of operations or transactions; 
  • Manage information technology, including infrastructure management (e.g. shared platforms), service continuity, and IT security; 
  • Establish anonymized statistical models, tests, for research and development, to optimize Flowdesk's risk management or to improve our offer of new or existing products and services; 
  • To personalize the products or services we offer you or that Flowdesk entities may offer you: 
  • By improving the quality of our technological or financial products or services; 
  • by offering you products or services that correspond to your situation and profile as we define it. 

These commercial proposals can be made through: 

  • Segmentation of our prospects and customers; 
  • Analysis of your habits and preferences on our various channels of communication with you (visits to our agencies, emails or messages, visits to our websites, etc.); 
  • The communication of your data to another Flowdesk entity, in particular, if you are a customer of this other entity or are likely to become one; 
  • A match made between the products or services you already have and the data we hold about you (for example, we may identify your need for a family protection insurance product because you have indicated that you have children); 
  • The management of games, sweepstakes, giveaways, contests, or other similar marketing campaigns or the offering of promotional games or the organization of events; 
  • Communications about our products, services, offers, news, and what we do at Flowdesk or other Flowdesk managed brands; 
  • Customer service management, including answering your questions; Improving and personalizing your experiences on our sites and applications; 

We can also use your personal data to manage your accounts, including administering any loyalty or reward programs that may be linked to your account.

Your personal data may be aggregated into anonymized statistics to be offered to our corporate clients to help them develop their business. In this case, our corporate customers will not be able to identify you, and your personal data will never be disclosed to them.

4. To respect your choice when we have asked for your consent for a specific treatment

In some cases, your consent is required for us to process your data, including: 

  • Where the purposes described above result in an automated decision that has legal effects on you or significantly affects you, we will inform you separately of the underlying logic of that decision and the significance and consequences of that processing; (If we are processing for purposes other than those described in section 3, we will inform you and, if necessary, seek your consent) 
  • For certain interactions on social networks, to administer communication or other such marketing operations

4. With whom do we share your personal data?

To accomplish the above purposes, we disclose your personal data only to: 

  • Flowdesk entities for example to make you benefit from our full range of products and services); 
  • Providers performing services on our behalf; 
  • Independent agents, intermediaries or brokers, banking or commercial partners with whom we are in contact; 
  • Judicial or financial authorities, state agencies or public bodies, upon their request and to the extent authorized by regulation; 
  • Regulated professions such as lawyers, notaries, or auditors

5. Transfers of personal data outside the european economic area (EEA)

In the event of transfers of your data outside the EEA, this will be done on the basis of a decision by the European Commission, where the Commission has recognized that the country to which your data will be transferred provides a level of protection equivalent to that existing in the EEA. 

If we transfer your data to a country whose level of data protection has not been recognized as adequate by the European Commission, we will put in place one of the following safeguards to ensure the protection of your personal data: 

  • Standard contractual clauses approved by the European Commission ; 
  • Binding corporate rules. 

We may also, in specific situations, transfer your personal data on the basis of an exemption (for example, in the case of international payments or when the transfer is necessary for the performance of a contract). 

If you wish to know what safeguards are in place to protect your data, or how you can find out about them, you can send us a written request as set out in Section 9 below.

6. How long do we keep your personal data?

We keep your personal data for the period necessary to comply with applicable regulations, or for a period defined by our operational requirements, such as proper account maintenance, efficient management of customer relations, and to respond to legal requests or requests from authorities and regulators. 

At Flowdesk most personal data relating to our customers is kept for the duration of the contractual relationship and two years after the end of the contractual relationship. In the case of prospects, data is kept for two years.

7. What are your rights and how can you exercise them?

Depending on the legislation applicable to your situation, you can exercise the following rights:

  • Right of access: you can obtain information about the processing of your data and a copy of these data; 
  • Right of rectification: if you believe that your personal data are inaccurate or incomplete, you may request that they be amended accordingly; 
  • Right to erasure: you may request the deletion of your personal data, to the extent permitted by law; 
  • Right to limit processing: you can request the limitation of the processing of your personal data; 
  • Right to withdraw your consent: if you have given your consent to the processing of your personal data, you may withdraw that consent at any time; 
  • Right to the portability of your data: when this right is applicable, you can request the communication of the personal data you have provided to us, or, when technically possible, the transfer of these to a third party 

You also have the right to object to the processing of your personal data for reasons relating to your particular situation. You have the absolute right to object at any time to your data being used for commercial prospecting purposes, or for profiling purposes if this profiling is linked to commercial prospecting. In the event of your death and in the absence of instructions from you, we undertake to destroy your data, unless its retention is necessary for evidential purposes or to meet a legal obligation.

These rights can be exercised by post: FLOWDESK DPO, 26 rue de Montholon 75009 Paris, by email to dpo@flowdesk.co,by proving your identity by any means.

To find out more about your rights, you can also consult the website of the French Data Protection Authority (CNIL) at the following address: http://cnil.fr.

8. How to be informed of changes to this data protection notice?

In a world where technologies are constantly evolving, we will regularly update this Notice. We invite you to review the latest version of this document on our sites, and we will inform you of any significant changes through our website or our usual communication channels.

9. How to contact us?

If you have any questions regarding the processing of your personal data, here are the different ways to contact us: dpo@flowdesk.co