Last updated: September 1, 2026
Privacy Policy
FlowDesk is an AI payment assistant for freelancers: it stores the invoices you enter, sends automated payment reminders to your clients, collects client responses, and helps you decide what to do next. This page explains what personal data that involves, why we process it, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Data controller
The data controller responsible for your personal data is:
- Mikołaj Gurdek
- Poland
- Email: support@flowdesks.org
If you are based in the EU/EEA and have concerns we have not resolved, you may lodge a complaint with your local supervisory authority.
2. Data we process about you (the account holder)
- Account & authentication data — your email address, a securely hashed password (or the identifier returned by a social sign-in provider you choose), session tokens, and timestamps such as account creation and last sign-in.
- Subscription & billing data — your plan (Starter, Pro or Business), subscription status, trial start date and whether a trial has already been used, renewal/cancellation dates, and the customer and subscription identifiers returned by our payment provider. We never receive or store your full card details.
- Usage data — the number of active (unpaid) invoices you hold, used to enforce plan limits.
- Technical data — IP address, browser and device information, and request/error logs generated by our hosting provider to operate and secure the service.
3. Data you enter about your clients
When you create an invoice in FlowDesk, you provide personal data about your client. You decide what to enter; FlowDesk stores and processes it on your behalf. This typically includes:
- Client identity & contact — client (or company) name and the client email address reminders are sent to.
- Invoice details — invoice number, amount, currency, issue and due dates, invoice status (active, paused, disputed, paid), and any payment link or notes you add.
- Chasing & automation data — the chasing tone/mode you selected, which reminder stages were sent and when, delivery outcomes, pauses, escalations, and promised payment dates.
- Email communications — the reminder and confirmation emails FlowDesk sends on your behalf, and a log of those sends.
- Client replies — messages from your client that you paste into FlowDesk, or that your client submits through a FlowDesk link, together with the interpretation FlowDesk derives from them (for example: payment promised, payment already sent, dispute, or a blocker such as a missing purchase order).
- Payment Handshake responses — what your client submits through the secure single-purpose confirmation link before the due date: whether they are ready to pay, an expected payment date, and any issue they report (for example a needed correction, a missing PO number, or an approval still pending), plus a free-text comment they choose to add.
For this client data you are the controller and we act as your processor: we process it only to deliver the FlowDesk features you use. You are responsible for having a lawful basis to enter your clients' data and to contact them about payment.
4. Payment Handshake links
A Payment Handshake link contains a long, unguessable token tied to one invoice. Anyone holding the link can see only that invoice's basic details (client name, invoice number, amount, currency, due date) and submit a response. The page requires no account, is limited to a single invoice, and does not expose your other invoices, your client list, or your account data.
5. Why we process it (legal bases)
- Performance of a contract (Art. 6(1)(b) GDPR) — to create your account, store your invoices, send automated reminders and handshake requests, run the plan you subscribed to, and handle trials and billing.
- Legitimate interests (Art. 6(1)(f) GDPR) — to secure the service, prevent abuse and email spam, keep delivery logs and suppression lists, and diagnose faults.
- Legal obligation (Art. 6(1)(c) GDPR) — to keep records required by tax and accounting law.
- Consent (Art. 6(1)(a) GDPR) — where you agree to a specific optional processing activity; you may withdraw consent at any time.
6. Automated processing and AI
FlowDesk uses an AI language model to read free-text messages — client replies you log and Payment Handshake comments — and classify them (for example: payment promised with a date, payment claimed sent, dispute, or a specific blocker). Only the message text and the minimum invoice context needed for that classification are sent to the model provider.
The classification is a suggestion. The decision that follows — pausing reminders, waiting for a promised date, or flagging the invoice for your attention — is made by FlowDesk's own rules, and you can override any of it. No automated decision is taken that has a legal effect on your client within the meaning of Art. 22 GDPR.
7. Automated emails we send on your behalf
Reminder, Payment Handshake and payment-related emails are addressed to the client email you entered and are sent from FlowDesk's sending domain on your behalf. We keep a send log and delivery state so the same reminder is not sent twice, and we maintain a suppression list of addresses that must no longer be contacted (for example after an unsubscribe or repeated delivery failure). Recipients can stop these emails using the unsubscribe link they contain.
8. How and where data is stored
Data is stored in a managed cloud database and hosted on managed cloud infrastructure. Traffic is encrypted in transit (TLS) and data at rest is encrypted by the underlying provider. Access is restricted, and we use Row-Level Security so each account can only reach its own invoices, logs and client records. Secrets and API keys are held in an encrypted secret store, not in application code.
9. Processors we use
FlowDesk relies on the following categories of processors:
- Hosting, database and authentication — managed cloud backend that runs the application, stores your data and handles sign-in.
- Transactional email provider — delivers reminder, Payment Handshake and account emails.
- AI model provider — classifies free-text client replies and handshake comments (see section 6).
- Payment & subscription provider (Creem) — acts as Merchant of Record for FlowDesk subscriptions, takes your payment details directly, and handles taxes and invoicing for your subscription.
Where a processor is located outside the EEA, transfers are protected by Standard Contractual Clauses or an equivalent safeguard. We do not sell your data and do not use it for advertising.
10. Retention and deletion
- Invoices, reminder logs, replies, promises, escalations and handshake records are kept while your account is active.
- You can delete an individual invoice at any time from its detail page. Deleting an invoice permanently removes it and its chasing history, and stops all scheduled reminders for it. Other invoices and your subscription are unaffected.
- If you delete your account, we delete or anonymise personal data within 30 days, except where we must keep records for legal, tax or accounting reasons.
- Email delivery and suppression logs are kept only as long as needed to prevent duplicate or unwanted sending.
11. Security
We use encrypted connections, hashed credentials, per-account database access rules, server-side authorisation on every data operation, single-purpose tokens for client-facing links, and an encrypted store for API keys. No system is perfectly secure; if a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent authority as required by law.
12. Your rights
Under the GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") of your data.
- Restriction of processing in certain circumstances.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection to processing based on our legitimate interests.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email support@flowdesks.org. We respond within 30 days. If you are a client of a FlowDesk user and want your data corrected or removed, contact the freelancer who invoiced you; you may also contact us and we will forward the request.
13. Cookies and local storage
FlowDesk uses strictly necessary cookies and browser local storage to keep you signed in, maintain your session, and remember that you dismissed the cookie notice. We do not use advertising cookies or third-party tracking pixels, and we do not currently run a third-party analytics tool. If we add analytics that rely on non-essential cookies, we will ask for your consent before setting them.
14. Children
FlowDesk is not intended for individuals under 16. We do not knowingly collect data from children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.
16. Contact
Questions about this policy or your data: support@flowdesks.org.