flowhelp Privacy Policy
Version 1.1 of 2 October 2026. Effective from the day it is published on the Website.
This is a translation of the Polish "Polityka prywatności flowhelp". The Polish version is binding; in case of any discrepancy, the Polish version prevails.
This policy explains what personal data we process in connection with the flowhelp service, for what purposes, on what legal basis, to whom we entrust it, how long we keep it and what rights you have. We have tried to write it plainly. If anything is unclear, write to us (contact details are in § 2).
§ 1. Definitions
1.1. Controller, we, us: DOLLABROS sp. z o.o., registered office in Poznań, Poland (details in § 2).
1.2. flowhelp or the Service: our AI assistant (chat) service for businesses, available through the website https://flowhelp.ai, the panel https://app.flowhelp.ai and the widget file server https://cdn.flowhelp.ai. The website https://flowhelp.ai is also referred to as the Website.
1.3. Customer: a business that has entered into an agreement with us to use the Service (including during the trial period).
1.4. Panel User: a person with an account in the panel (owner, administrator, editor or a person with view-only access in a Customer's workspace).
1.5. Workspace: a Customer's separate working area in the panel, with its knowledge, settings, conversations and team.
1.6. Widget: the chat window that a Customer embeds on its website with a single <script> tag.
1.7. Assistant: the AI language model that answers in the Widget on the basis of the materials indicated by the Customer.
1.8. Eric: our own Assistant on the flowhelp.ai website, which answers questions about flowhelp.
1.9. Visitor: a person using a website on which the Widget runs (a Customer's website or flowhelp.ai).
1.10. Lead: data that a Visitor submits through the contact form or a request to talk to a human in the chat window.
1.11. GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
1.12. Data Processing Agreement or DPA: the agreement on the processing of personal data (Article 28 GDPR) that forms part of the flowhelp Terms of Service.
1.13. EEA: the European Economic Area (the Member States of the European Union and Iceland, Liechtenstein and Norway).
§ 2. Controller and contact
2.1. The controller of the personal data described in § 4-6, section 7.5 and § 8 is:
| Item | Details |
|---|---|
| Company name | DOLLABROS spółka z ograniczoną odpowiedzialnością (limited liability company) |
| Registered office and address | ul. Stanisława Wyspiańskiego 26B/238, 60-751 Poznań, Poland |
| KRS (National Court Register) | 0000918078 (District Court Poznań - Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register) |
| NIP (tax identification number) | 7831841993 |
| REGON (statistical number) | 389772190 |
2.2. You can contact us about any matter concerning personal data:
- by e-mail: hello@flowhelp.ai,
- by post: at the registered office address above,
- through the contact form in the chat window on https://flowhelp.ai.
2.3. We have not appointed a data protection officer (DPO), because the law does not require one in our case (Article 37 GDPR). Personal data matters are handled directly by the company's management board at the addresses in section 2.2.
§ 3. Who this policy applies to
3.1. This policy applies to four groups of people. In the first three we are the controller, which means we decide on the purposes and means of processing ourselves. In the fourth we generally act on behalf of the Customer as a processor; the exception is server logs and limit counters used for the security of the Service, for which we are the controller (section 7.5).
| Group | Who they are | Our role | Details |
|---|---|---|---|
| a) Customers and Panel Users | businesses using flowhelp and people with a panel account | controller | § 4 |
| b) Visitors to flowhelp.ai | people visiting our website, including those who write to the assistant Eric or leave their details in its contact form | controller | § 5 |
| c) Recipients of e-mails from flowhelp | e.g. a developer to whom a Panel User sent the installation code, a person invited to a team, or a person to whose address Lead notifications are sent | controller | § 6 |
| d) Visitors to our Customers' websites | people talking to a Customer's Assistant in the Widget on the Customer's website or visiting a page on which the Widget is installed | processor (the Customer is the controller); controller for server logs and limit counters (section 7.5) | § 7 |
3.2. Rules common to all groups (recipients, transfers outside the EEA, retention periods, rights, AI, cookies, security) are described in § 9-18.
§ 4. Customers and Panel Users
4.1. What data we process:
- account data: e-mail address, first name (optional; if you do not provide it, we use the part of your e-mail address before the @ sign), password in the form of a cryptographic hash (we do not know your password), selected language and interface settings, information on whether the e-mail address has been confirmed, dates of creation and changes;
- data on acceptance of documents: the date of acceptance and the version identifier of the Terms of Service (including the DPA) and the Privacy Policy in force when the account was created (for version 1.0: "2026-10-01"); the registration form states: "By creating an account, you accept the terms of service and the privacy policy.";
- login session data: IP address, information about the browser and device (User-Agent), session validity, active workspace;
- web server log data when you use the panel: IP address, time, request, Referer and User-Agent (kept for 14 days, see § 11);
- workspace and membership data: the workspace name and the Customer's website address, plan, trial period, use of limits, settings (including e-mail addresses for notifications, see § 6), team members' roles, invitations;
- workspace event log: who (account identifier) performed a significant action in the panel and when (e.g. a role change, deletion of data), without conversation content; e-mail addresses are stored in it in masked form (e.g. ab***@domain.com);
- the content of correspondence with us (see § 8);
- once payments are launched: data necessary for billing (see section 4.4).
4.2. Purposes and legal bases:
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and maintaining the account, providing the Service, operating the workspace and the team | Article 6(1)(b) (contract), where you yourself are the party to the contract (e.g. as a sole trader); Article 6(1)(f) where you create or use the account on behalf of a Customer that is another person (e.g. a company), including as its employee or associate (legitimate interest: ours and the Customer's in enabling its team to use the Service it ordered) |
| E-mails necessary for the account to work: address confirmation, password reset, invitations, information about changes to the Terms of Service and the Service | Article 6(1)(b) or (f) (as above) |
| Security of the account and the Service: sessions with IP address and User-Agent, server logs, login attempt limits, event log, abuse detection | Article 6(1)(f) (legitimate interest: protection of accounts, Customers' data and infrastructure) |
| Demonstrating that the account was created after acceptance of a specific version of the documents | Article 6(1)(f) (legitimate interest: ability to prove the content and conclusion of the contract) |
| Billing and compliance with accounting and tax obligations (once payments are launched) | Article 6(1)(c) in conjunction with accounting and tax laws |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) (legitimate interest: protection of our rights) |
4.3. Where we get data from, if not from you: if another Panel User invited you, we received your e-mail address and assigned role from that person. Your IP address and browser data come from your device when you log in.
4.4. Payments. Payments have not been launched yet, and the Service is free of charge during the trial period. Once they are launched, payments may be handled by an external operator acting as the seller (Merchant of Record). In that case the operator, as a separate controller, processes payment data under its own privacy policy, and we receive from it the information needed to maintain the account (e.g. the plan and subscription status). Before payments are launched, we will update this policy and name the operator.
4.5. Members of a team in the same workspace can see each other's first names, e-mail addresses and roles.
§ 5. Visitors to flowhelp.ai, including conversations with the assistant Eric
5.1. Visiting the website. The flowhelp.ai website does not use analytics tools, advertising pixels or third-party scripts, and its fonts are served from our server. Our server records technical data of each request in its logs: IP address, time, the address of the requested page (with parameters), response code, the referring page (Referer) and browser data (User-Agent). If you enter an address in the "your website address" field on flowhelp.ai and continue, it is passed to the panel as an address parameter (and into the panel server's logs).
5.2. Conversation with the assistant Eric. When you write to Eric, we process:
- the content of your messages and the Assistant's answers, message times, language, your rating of answers (thumbs up or down), cited sources;
- a random Visitor identifier stored in your browser's storage with no expiry (see § 16), which links subsequent conversations from that browser;
- questions Eric could not answer (stored separately, not linked to the conversation, in order to improve the Assistant's knowledge);
- for a few minutes (up to 2 hours for the contact-form limit): a cryptographic hash of your IP address, used only in the limit counter (the IP address itself is not stored in the conversation database).
Message content is processed by the AI providers described in § 9 and § 15. Do not enter sensitive data, or data you do not want to share with us, in the conversation.
5.3. Contact form in the chat window. If you leave us your details (e.g. e-mail address, name, company, message), we store them in the database, linked to the conversation, and send a notification containing those fields and up to the 10 latest messages of the conversation to our mailbox hosted in the Gmail service (Google, see section 9.2). We keep this data until the matter is handled, for no longer than 12 months; after that we delete it manually in the panel and delete the notification from our mailbox.
5.4. Purposes and legal bases:
| Purpose | Legal basis (GDPR) |
|---|---|
| Displaying the website, server logs, protection against attacks and abuse | Article 6(1)(f) (legitimate interest: security and continuity of the website) |
| Answering your questions in the conversation with Eric | Article 6(1)(f) (legitimate interest: informing about our offer and answering enquiries); Article 6(1)(b) where you ask about entering into a contract (steps taken at your request prior to entering into it) |
| Reviewing conversations and unanswered questions to improve Eric's knowledge | Article 6(1)(f) (legitimate interest: accuracy of information about our Service) |
| Getting back to you after you fill in the form | Article 6(1)(b) where the matter concerns entering into a contract; otherwise Article 6(1)(f) (legitimate interest: responding to your message) |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) (legitimate interest: protection of our rights) |
5.5. We do not send newsletters or marketing communications to addresses left in the form. We reply only regarding the matter you contacted us about.
§ 6. Recipients of e-mails from flowhelp
6.1. This applies to people whose e-mail address was entered in the panel by a Panel User, in particular:
- a developer to whom a Panel User sent the Widget installation code (the "Send to a developer" feature): we process the e-mail address and a short note added by the sender (up to 500 characters), and information on who sent the message and from which workspace; replies to that message go to the sender's e-mail address;
- a person invited to a team: we process the e-mail address, the assigned role, the status and expiry date of the invitation (7 days) and information on who is inviting;
- a person to whose address notifications are sent about a new Lead or a request to talk to a human: we process that person's e-mail address set in the action or workspace settings (or, if none is set, the e-mail address of the workspace owner). We process the address itself as controller under this policy. The content of such a notification (the Visitor's form data and an excerpt of the conversation) is the Customer's data, which we process as a processor under the Data Processing Agreement (§ 7).
6.2. Source of data: your address was provided to us by the Panel User who sent the message or invitation or set the notification address. Every e-mail sent by flowhelp carries a short footer with our company name and a link to this policy.
6.3. Purpose and legal basis: sending the message requested by the Panel User and handling the invitation or notifications, under Article 6(1)(f) GDPR (legitimate interest: ours and the Customer's in enabling the Customer to use the Service, including working with its team and installing the Widget).
6.4. We do not store the developer's full e-mail address from the "Send to a developer" feature in the database; only its masked form (e.g. ab***@domain.com) remains in the workspace event log. We pass the full address to the e-mail operator (Resend) solely for sending. An invitation (valid for 7 days) is deleted automatically 30 days after it expires, whether or not it was accepted; if the workspace is deleted, the invitation is removed at the latest when the workspace's data is permanently deleted, that is 30 days after the workspace is deleted. If you do not want to receive such messages, write to us or to the person who provided your address.
§ 7. Visitors to our Customers' websites
7.1. Who is the controller. If you talk to an Assistant on another company's website (our Customer's), the controller of your data is that company. It decides whether and how it uses the Widget, what knowledge the Assistant uses, which fields the contact form has, how long conversations are kept and to whom Leads are passed. We process this data on behalf of the Customer and on its instructions, as a processor, under the Data Processing Agreement. We do not use it for our own purposes.
7.2. Information about the processing can be found in the Customer's privacy policy. The Customer can enter the address of its privacy policy in the panel; the Widget then shows a "Privacy policy" link with the request for consent to the conversation and below the contact form and the form for requesting contact with a human.
7.3. What we process on the Customer's behalf:
- the content of the conversation (your messages and the Assistant's answers), time, language, your rating of answers, cited sources;
- a random Visitor identifier stored in your browser's storage with no expiry (see § 16), which links subsequent conversations from that browser, and its cryptographic hash;
- if the Customer has configured the Widget this way: the identifier of your account in the Customer's service (e.g. a customer number), passed on by the Customer's website; the Customer decides which identifier it passes on;
- questions the Assistant could not answer (stored separately, not linked to the conversation);
- data from the contact form or a request to talk to a human (the fields are defined by the Customer, e.g. e-mail, name, telephone, message); the Customer receives them by e-mail, together with up to the 10 latest messages of the conversation, at the notification address it has chosen;
- content that the Customer adds as the Assistant's knowledge (websites, notes, question-and-answer pairs); it may contain personal data for which the Customer is responsible.
7.4. What we do not store. We do not store your IP address or browser data in the conversation database.
7.5. Server logs and limit counters: here we are the controller. When a Customer's website loads the Widget from our servers (the Widget scripts, its configuration) and when the Widget sends requests to our API, our servers record in their logs the IP address, time, request, referring page (Referer, usually the address of the Customer's page) and browser data (User-Agent). This happens when the page loads, even before you start a conversation. In addition, for a few minutes (up to 2 hours for the contact-form limit), we use a cryptographic hash of your IP address in limit counters. We process this data as controller, not on the Customer's behalf:
- purpose: ensuring the security of the Service, detecting attacks and preventing abuse;
- legal basis: Article 6(1)(f) GDPR (legitimate interest: security and continuity of a Service provided to many Customers); you may object (section 12.1 point 6);
- retention: logs 14 days, IP address hash from 5 minutes to 2 hours;
- recipients: our hosting provider (OVH) and, to the extent necessary for a specific maintenance task, the provider of AI tools supporting server administration (section 9.1); we do not pass this data to the Customer.
For matters concerning this data, contact us (§ 2), not the Customer.
7.6. Assistant image. If the Customer has set an image (avatar) for the Assistant from its own address, your browser downloads it directly from that address, and its operator may see your IP address.
7.7. How to exercise your rights. Please address any request for access, erasure, rectification or other request concerning a conversation, a Lead or questions to the Customer, i.e. the owner of the website where you had the conversation (for the server logs in section 7.5, contact us). In the panel, the Customer can delete individual conversations, any Lead and the unanswered questions shown in the panel, and export conversations; we delete other questions on its instruction. If you write to us, we will forward your request to the Customer without undue delay and help it fulfil the request. To make it easier to find the data, please give the address of the website where you had the conversation and the approximate time of the conversation.
§ 8. Contacting us, complaints and notices
8.1. When you write to us (by e-mail, by post or through the form in the chat window), file a complaint or report content that you consider illegal, we process your contact details, the content of the message and the data needed to handle the matter.
8.2. Legal bases:
- replying to a message: Article 6(1)(f) GDPR (legitimate interest: conducting correspondence);
- complaints concerning the Service: Article 6(1)(b) GDPR (performance of the contract);
- notices of illegal content and information about decisions: Article 6(1)(c) GDPR in conjunction with Articles 16 and 17 of Regulation (EU) 2022/2065 (Digital Services Act);
- establishment, exercise or defence of legal claims: Article 6(1)(f) GDPR.
§ 9. Who we share data with
9.1. Processors (subcontractors). We use the providers listed below, only to the extent needed to provide their services. The entities in items 1, 2, 4, 5 and 6 process data on our behalf on the basis of agreements concluded with those entities, including standard contractual clauses where data leaves the EEA. The entities in item 3 process data as sub-processors of OpenRouter, under agreements concluded by OpenRouter. The same entities process data entrusted to us by Customers, as the sub-processors listed in Annex A to the Data Processing Agreement.
| No. | Entity | Role | What data | Location | Safeguard for transfers outside the EEA |
|---|---|---|---|---|---|
| 1 | OVH SAS, 2 rue Kellermann, 59100 Roubaix, France | hosting of the whole Service (server, database, backups) | all Service data | data centre in Germany (EU) | not applicable (EU) |
| 2 | OpenRouter, Inc., USA | gateway to AI language models (writing chat answers, the "Suggest an answer" feature in the panel, welcome-message suggestion during account setup) | Visitors' questions, the latest messages of the conversation, matching excerpts of the Customer's knowledge, public text of the Customer's website (during account setup) | USA | standard contractual clauses (SCC) |
| 3 | AI model providers selected by OpenRouter for a given request (default model: Google Gemini; depending on the model chosen by the Customer, also OpenAI, Anthropic or other providers available in OpenRouter); routing is restricted to providers that do not collect data from requests (OpenRouter setting data_collection: deny) | generating the answer by the model | as in item 2 | USA and other countries | SCC or the provider's equivalent safeguards under Chapter V GDPR |
| 4 | CoinAxe Ltd (deAPI), Dragonara Business Centre, 5th Floor, Dragonara Road, St. Julians STJ 3141, Malta | computing embeddings (numeric vectors) used to search the knowledge base | excerpts of the Customer's content; Visitors' questions only as a fallback (see section 15.1) | EU (Malta) and a distributed network of GPU servers that may be located outside the EEA | SCC where data leaves the EEA |
| 5 | Resend, Inc., USA | sending all flowhelp e-mails (account, invitations, "Send to a developer", notifications of Leads and contact requests) | recipients' e-mail addresses, message content (in notifications: contact-form fields, up to the 10 latest messages of a conversation); Resend keeps sending logs, including message content, for the period set out in its terms | sending infrastructure in the EU (Ireland, AWS), company in the USA | SCC |
| 6 | Anthropic, PBC, San Francisco, USA | AI tools supporting technical maintenance and support of the Service (diagnostics, server administration) | access to Service data only to the extent necessary for a specific maintenance or support task | USA | SCC (the provider's data processing terms) |
9.2. Other recipients:
- the Customer and its team: we make data of Visitors to the Customer's websites (§ 7) available to the Customer, and team members' data (first name, e-mail, role) to the other members of the same workspace;
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), the provider of the Gmail service in which we keep our mailbox, acting under its own terms: it receives the messages you send us by e-mail and notifications of Leads and contact requests from conversations with Eric on flowhelp.ai (notifications of Leads from Customers' websites do not reach our mailbox; only messages you send us yourself do, including requests concerning conversations on Customers' websites, which we forward to the Customer); Google may transfer data to the USA on the basis of safeguards under Chapter V GDPR (the adequacy decision for the EU-US Data Privacy Framework or SCC);
- Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA), the provider of the Email Routing service, which forwards messages sent to addresses in the flowhelp.ai domain (e.g. hello@flowhelp.ai) to our Gmail mailbox; Cloudflare processes them as our processor under its Data Processing Addendum and may transfer data to the USA on the basis of safeguards under Chapter V GDPR (the adequacy decision for the EU-US Data Privacy Framework or SCC);
- public authorities and courts: only where an obligation to disclose data arises from the law;
- the payment operator: once payments are launched (see section 4.4).
9.3. We do not sell personal data and do not share it for advertising purposes.
§ 10. Transfers of data outside the EEA
10.1. Some of the providers described in § 9 have their registered office or infrastructure outside the EEA (mainly in the USA). In that case data is transferred on the basis of the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR) or other safeguards provided for in Chapter V GDPR, as indicated in the table in section 9.1.
10.2. In the case of deAPI, computations may take place on GPU servers in various countries, including outside the EEA. Only text is transferred in that case (excerpts of the Customer's content, and Visitors' questions only in the situation described in section 15.1), without the Visitor identifier or IP address. If such a question contains personal data, that data is transferred with it (see section 15.5).
10.3. You can obtain a copy of the safeguards applied, or information on where they have been made available, by writing to the address in § 2.
§ 11. How long we keep data
| Data | Retention period |
|---|---|
| Panel User account data (including data on acceptance of documents: date and version identifier) | for as long as the account exists; we delete it permanently when you delete the account (Settings → Profile; possible if you are not the sole owner of an active workspace), and it disappears from backups within the following 14 days; if you no longer use the account after the contract ends, you can delete it or ask us to do so |
| Team invitations | 30 days after the invitation expires (valid for 7 days), whether or not it was accepted; if the workspace is deleted, at the latest when its data is permanently deleted (30 days after the workspace is deleted) |
| Login sessions (with IP address and User-Agent) | a session expires after 7 days without use (using the panel extends it); expired sessions are deleted automatically no later than 2 days after expiry |
| Workspace data (conversations, Leads, unanswered questions, knowledge sources, configuration, memberships, invitations, event log) | until the workspace is deleted; upon deletion the workspace is disabled immediately and the data is permanently deleted no later than after 30 days |
| Conversations in Customers' Widgets | according to the Customer's retention setting: 30, 90 or 365 days or no limit (90 days by default), and in any case until the Customer deletes the conversation or the workspace is deleted |
| Leads and unanswered questions in Customers' Widgets | until deleted by the Customer or until the workspace is deleted (the conversation retention setting does not cover them) |
| Conversations with the assistant Eric on flowhelp.ai | 90 days |
| Leads from Eric's form on flowhelp.ai (in the database and the notification in our Gmail mailbox) | until the matter is handled, no longer than 12 months, after which we delete them manually in the panel and in the mailbox; if we enter into a contract, the data becomes Customer data; if the form was used to file a complaint, a data protection request or a notice of illegal content, the period for correspondence applies |
| Unanswered questions put to Eric | we delete open questions in the panel when we review them; we delete ignored questions and questions to which we have added an answer at your request; a question that we have saved as a question-and-answer pair becomes part of Eric's knowledge material and is deleted together with that material (we delete its copy in Eric's internal quality test set at your request) |
| Database backups | 14 days; data deleted from the database disappears from backups within the following 14 days |
| Web server logs (IP, time, request, Referer, User-Agent), including requests to the Widget on Customers' websites | 14 days |
| Application logs (identifiers and counters, no conversation content, e-mail addresses masked) and database diagnostic logs (slow queries; may exceptionally contain fragments of content in query parameters) | overwritten in line with container log rotation (3 files of 10 MB per service) |
| IP address hash in limit counters | 5 minutes (contact-form counter: 2 hours) |
| Temporary technical data (indexing job queues, vector cache) | from 24 hours to 7 days |
| E-mails sent | we do not keep a separate archive of sent e-mails; Resend, as our processor, keeps sending logs, including message content, for the retention period set out in its terms, and the message remains in the recipient's mailbox |
| Correspondence with us and complaints | until the matter is handled and, if it concerns the contract, until the limitation period for related claims expires |
| Billing documents (once payments are launched) | for the period required by accounting and tax laws (as a rule 5 years from the end of the year in which the tax obligation arose) |
11.1. After these periods expire, we delete or anonymise the data. We may keep it longer only where it is needed for the establishment, exercise or defence of legal claims or where the law requires it, and only to the extent necessary.
§ 12. Your rights
12.1. To the extent that we are the controller of your data, you have the following rights:
- the right of access to the data and to obtain a copy of it (Article 15 GDPR);
- the right to rectification of inaccurate or incomplete data (Article 16 GDPR); you can change your first name, password and language yourself in Settings → Profile, and we will change your e-mail address at your request;
- the right to erasure of data (Article 17 GDPR); you can delete your account yourself in Settings → Profile;
- the right to restriction of processing (Article 18 GDPR);
- the right to data portability (Article 20 GDPR), with respect to data you have provided to us and that we process on the basis of a contract by automated means;
- the right to object to processing based on legitimate interest (Article 6(1)(f) GDPR), on grounds relating to your particular situation (Article 21 GDPR); after an objection we will stop processing the data for that purpose unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or grounds for the establishment, exercise or defence of legal claims;
- the right to lodge a complaint with a supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland (https://uodo.gov.pl), or with the data protection authority in the country where you live or work.
12.2. We do not base the processing described in this policy on consent. If a Customer asks for consent to a conversation in the Widget, this is the Customer's mechanism, and questions about it should be addressed to the Customer.
12.3. Send your request to the address in § 2. We will reply without undue delay and no later than within one month; in complex cases this period may be extended by a further two months, of which we will inform you within the first month. Exercising your rights is free of charge. If we have reasonable doubts as to your identity, we may ask for additional information (e.g. to write from the e-mail address linked to the account).
12.4. If your data comes from a conversation on our Customer's website, section 7.7 applies.
§ 13. Do you have to provide data
13.1. Providing an e-mail address and password is a condition for creating an account and using the panel. The first name is optional.
13.2. Talking to Eric and filling in the contact form are voluntary. Without your contact details we will not be able to reply to you outside the chat window.
13.3. Once payments are launched, providing billing data will be required to purchase a paid plan, and its processing will result from the law.
§ 14. Automated decision-making and profiling
14.1. We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). We do not profile Visitors or Panel Users for marketing purposes.
14.2. The AI Assistant automatically writes answers to questions on the basis of the Customer's materials. It does not assess people and does not make decisions about them. Automated technical mechanisms, such as message limits or blocking traffic that looks like an attack, serve the security of the Service and are not decisions within the meaning of Article 22 GDPR.
§ 15. How AI works and what data goes to model providers
15.1. Knowledge search. Questions put to the Assistant and the excerpts of content the Customer has added as knowledge are converted into numeric vectors (embeddings). This allows the Assistant to find the excerpts that match the question. We convert questions on our own server in Germany (OVH) and the Customer's content excerpts via deAPI. Only when our server is temporarily unable to process a question do we send it to deAPI for this purpose, so that the Assistant can still answer.
15.2. Writing answers. To write an answer, we send the following through OpenRouter to the provider of the selected model:
- instructions for the Assistant (including the Customer's settings),
- up to 6 matching excerpts of the Customer's knowledge (text, title and source address),
- the Visitor's question,
- up to the 6 latest messages of the conversation.
15.3. What we do not send to the model: the Visitor identifier, IP address, the address of the page where the conversation takes place, contact-form data or the user identifier passed on by the Customer.
15.4. Panel. The "Suggest an answer" feature converts the question into a vector in the same way as the chat (section 15.1) and sends the question and the matching knowledge excerpts to the model. During account setup we fetch the Customer's public home page and send its domain name and the initial excerpts of its text to the model, in order to suggest a welcome message.
15.5. No redaction of data. We do not automatically remove personal data from the content of questions. If a Visitor enters personal data in a question, it is sent together with the question to the model provider and, in the situation described in section 15.1, also to deAPI. We therefore ask you not to enter sensitive data, document numbers, health data or passwords in the chat.
15.6. Model training. We do not train or fine-tune AI models on Customers' or Visitors' data. We route requests only to providers that, according to OpenRouter, do not collect data from requests (setting data_collection: deny). Providers may process requests for a limited time on the terms set out in their agreements, e.g. to detect abuse.
15.7. AI labelling. The chat window always states that the conversation is with AI (an "AI" badge and an information sentence that the Customer cannot remove), in accordance with Article 50(1) of Regulation (EU) 2024/1689 (Artificial Intelligence Act). Answers created by AI may contain errors.
§ 16. Cookies and browser storage
16.1. We use only cookies and browser storage that are necessary for the features you knowingly use. We do not use analytics, advertising or third-party cookies. Under Article 399 of the Polish Electronic Communications Law of 12 July 2024 (Prawo komunikacji elektronicznej), storing information on your device does not require your consent where it is strictly necessary to provide a service you have explicitly requested. This is the case for each entry in the table in section 16.2: the session cookie is necessary for you to use the panel after logging in, flowhelp_locale remembers the panel language you chose yourself, and the Visitor identifier is created only when you start using the chat and serves to conduct that conversation. We nevertheless describe below everything we store in your browser.
16.2. The flowhelp.ai website does not set cookies. Below we list all cookies and browser storage entries we use.
| Name | Type | Where | Purpose | Retention |
|---|---|---|---|---|
__Secure-better-auth.session_token | cookie (HttpOnly, Secure, SameSite=Lax) | set by app.flowhelp.ai, on the .flowhelp.ai domain (the browser also sends it to our other subdomains) | keeping you logged in to the panel | 7 days (extended when you use the panel) or until you log out |
flowhelp_locale | cookie (HttpOnly, Secure, SameSite=Lax) | app.flowhelp.ai | remembering the panel language you chose with the language switcher or by going to the panel from the language version of the flowhelp.ai website you selected | 1 year |
flowhelp:visitor:<key> | local storage (localStorage); if unavailable, session storage (sessionStorage) | flowhelp.ai (conversation with Eric) and Customers' websites with the Widget | a random Visitor identifier that allows the conversation to continue, links subsequent conversations from that browser and protects against abuse; created only when you start using the chat (on the first message, rating of an answer or submission of the form) | until browser data is cleared (sessionStorage: until the tab is closed) |
16.3. The Widget on Customers' websites does not use cookies. A Customer may use its own cookies on its website; they are described in the Customer's privacy policy.
16.4. You can delete cookies and site data in your browser settings at any time. Deleting the session cookie will log you out of the panel, and deleting the Visitor identifier will start a new conversation.
§ 17. Security
17.1. In particular, we apply the following measures:
- encrypted connections (TLS 1.2 and 1.3) and HSTS on the website and in the panel;
- a firewall that blocks incoming traffic by default; the application is not reachable from the internet directly, only through a reverse proxy server;
- separation of Customers' data at database level (Row-Level Security), verified by automated tests;
- passwords stored only as cryptographic hashes (salted scrypt);
- team roles that determine access to data in the panel; export of conversations only for the owner and administrator;
- limits on login attempts and messages, an allowlist of domains for the Widget and HMAC signatures for Customers' user identifiers;
- data minimisation in logs (application logs without conversation content, e-mail addresses masked; database diagnostic logs may exceptionally contain fragments of content) and short log retention periods;
- daily database backups, kept for 14 days;
- administrative access to servers only for authorised members of the management board; administration is supported by AI tools (section 9.1, item 6), which access data only to the extent necessary for a specific task.
17.2. We do not currently offer two-factor authentication, so we recommend using a strong password that you do not use for other services.
17.3. No method of transmitting or storing data is completely secure. If a personal data breach occurs, we will act in accordance with Articles 33 and 34 GDPR and, for data entrusted to us by Customers, notify the Customer in accordance with the Data Processing Agreement.
§ 18. Changes to the policy and entry into force
18.1. We may change this policy, e.g. when the Service's features, providers or the law change. The current version is always available on flowhelp.ai, with its version number and effective date.
18.2. We will inform the owners and administrators of workspaces of material changes before they take effect, by e-mail and at the workspace notification address (if one is set), and additionally in the panel. Changes to the list of processors for data entrusted to us by Customers are announced in accordance with the Data Processing Agreement.
18.3. The Polish version of this policy is binding. Versions in other languages are translations; in case of any discrepancy, the Polish version prevails.
18.4. This policy, version 1.1 of 2 October 2026, is effective from the day it is published on the Website.