Privacy Policy (POPIA)

Last Updated: 8 August 2026 · Applicable Law: Protection of Personal Information Act, 4 of 2013 (POPIA)

1. Purpose

FlowIQ is a service operated by FLOWIQDEV (PTY) LTD ("FlowIQ", "we", "us" or "our"). FlowIQ respects user privacy and processes personal information in accordance with POPIA.

This policy explains how personal information is collected, used, stored, and protected.

2. Information We Collect

FlowIQ may process:

  • Account details (name, email, company name)
  • Login credentials (encrypted)
  • Usage and interaction data
  • Website session and behavior analytics data used to improve public website usability and conversion paths
  • Business and operational data uploaded by users
  • Commerce integration data authorised by a merchant, including Shopify products, SKUs, inventory, locations, customers, orders, fulfilment, pricing, and primary product images
  • Customer Desk messaging data authorised by an organisation, including WhatsApp contact and profile details, messages, voice-note transcripts, images, audio, video, documents, message and delivery identifiers, and conversation history
  • Technical data (IP address, browser type, device data)

FlowIQ does not verify the accuracy of uploaded data.

3. Purpose of Processing

Personal information is processed to:

  • Provide and operate the Platform
  • Authenticate users
  • Improve performance and features
  • Understand public website journeys, session behavior, funnels, and usability friction
  • Communicate service-related notices
  • Import, reconcile, and synchronise merchant-authorised commerce records
  • Send, receive, route, secure, and support organisation-authorised customer conversations through Meta and WhatsApp
  • Comply with legal obligations

4. Data Ownership

  • Users retain ownership of all uploaded data
  • FlowIQ acts as a data operator, not a data owner
  • Users confirm they have lawful authority to upload all data

5. Data Security

FlowIQ implements reasonable technical and organisational safeguards.

However:

  • No system is completely secure
  • FlowIQ does not guarantee prevention of breaches or data loss
  • Users remain responsible for backups and redundancy
  • Users remain responsible for endpoint security, credential security, and access governance in their own environments

6. Data Retention

  • Data is retained only as long as necessary for platform operation or legal compliance
  • Shopify customer-data access audit records are retained for 365 days and then purged automatically
  • Verified Shopify customer-redaction and shop-redaction requests remove or anonymise the applicable Shopify-derived personal data
  • Upon account termination, data may be deleted or anonymised at FlowIQ's discretion unless legally required otherwise
  • Users should export required records before account termination or closure

7. Data Sharing

FlowIQ:

  • Does not sell personal data
  • May share data with trusted service providers strictly for platform operation
  • May use trusted analytics providers, including Smartlook, to understand public website behavior, with sensitive recording disabled by default where supported
  • May disclose data if legally required

8. User Rights (POPIA)

Users may request to:

  • Access personal data
  • Correct inaccurate data
  • Delete personal data (subject to legal limits)

Requests can be sent to: support@flowiq.info

9. Shopify Integration Data

When a merchant authorises the FlowIQ Shopify app, FlowIQ processes only the Shopify data required for the merchant-selected import, reconciliation, inventory, order, fulfilment, and reporting functions.

  • Shopify access tokens are kept server-side and are not returned to the browser
  • Shopify customer data is used for store management and FlowIQ application functionality, not advertising or sale
  • Verified Shopify data-access requests are exported to the applicable merchant for fulfilment
  • Verified Shopify customer and shop redaction requests are applied to Shopify-derived records
  • Disconnecting or uninstalling removes the Shopify connection and prevents further synchronisation

Shopify merchants and their customers may request assistance at support@flowiq.info.

10. Google Email and Google User Data

When an organisation administrator connects a Google or Gmail account, FlowIQ uses the minimum Google permissions needed for the features the administrator chooses.

Data accessed and how it is used

  • The normal Google email connection accesses the connected account's basic identity, verified email address, OAuth permission details, and the gmail.send permission to send email on the user's behalf. FlowIQ processes the recipients, subject, message content, and attachments supplied for each requested outbound email.
  • The normal send-only connection cannot read, search, modify, delete, or manage messages in the connected inbox.
  • Incoming Documents is optional and requires a separate, explicit read-only permission. If enabled, FlowIQ uses that permission only to search for messages matching the organisation's configured recipient address or Gmail label and to retrieve the message and attachment identifiers, sender, recipient, subject, received time, supported PDF or image attachments, file hashes, processing status, validation warnings, and extracted draft fields needed for the visible InvoiceIQ or PurchaseIQ capture workflow.
  • Incoming Documents does not modify or delete email, mark messages as read, send replies, or retain unrelated message body content.
  • Google user data is used only to provide the email sending, incoming-document capture, security, support, and user-facing workflow functions requested by the organisation.

Storage, protection, and deletion

  • Google OAuth access and refresh tokens are encrypted and stored server-side. They are not returned to the browser.
  • Captured message metadata, supported attachments, processing records, and extracted draft fields are stored in private, organisation-scoped records. They remain part of the resulting review queue or business record until an authorised user deletes the supported record or requests deletion, subject to the organisation's business-record requirements and applicable law.
  • Disconnecting Google email stops new access, pauses incoming monitoring, deletes FlowIQ's encrypted OAuth credential, and attempts to revoke the Google token. Disconnecting does not automatically delete attachments, drafts, or business records already imported at the organisation's request; those records remain subject to the organisation's normal retention and deletion controls.
  • An authorised user may request deletion of applicable Google-derived data by contacting support@flowiq.info, subject to legal retention requirements.

Sharing, human access, advertising, and AI

  • FlowIQ does not sell Google user data or transfer it to advertising platforms, data brokers, or information resellers, and does not use it for advertising, retargeting, credit-worthiness, or lending.
  • Google user data is shared only with contracted service providers needed to deliver, host, secure, or support the requested FlowIQ feature, or where disclosure is required by law. Human access is limited to the user's instruction, necessary security or support investigation, or legal obligation.
  • Where Incoming Documents is enabled, a supported attachment may be processed by contracted document-processing or AI providers solely to extract information for the specific, visible FlowIQ draft-and-review workflow requested by the organisation.
  • FlowIQ does not use or transfer Google Workspace API data to develop, improve, or train generalised or non-personalised artificial intelligence or machine-learning models.

FlowIQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

11. Meta and WhatsApp Customer Desk Data

When an organisation administrator connects a WhatsApp Business account, FlowIQ processes Meta and WhatsApp data only to provide the Customer Desk messaging, customer support, approved sales assistance, human escalation, security, and audit functions that the organisation chooses.

Data processed and how it is used

  • FlowIQ may process WhatsApp phone numbers, profile names, Meta business and phone-number identifiers, message identifiers and status events, message text, conversation history, and customer-supplied images, audio, video, voice notes, or documents.
  • Messages and media may be analysed solely to understand and respond to the customer's request, route it to the appropriate team, preserve case context, or produce a reviewable draft. Organisation-approved knowledge and customer-safe business information may be used where the organisation has enabled those functions.
  • FlowIQ does not use WhatsApp customer messages or media for advertising, sell them, or use them to train a general-purpose AI model.

Connection security, access, and retention

  • Meta access tokens are encrypted and kept server-side. They are not displayed to organisation users or WhatsApp customers. Provider identifiers, granted permissions, connection status, and token-expiry information are retained only as needed to operate and secure the connection.
  • Customer Desk conversations, media, identity links, and reviewed relationship context are stored in private, organisation-scoped records. Access is limited to authorised users of the connected organisation and contracted providers needed to deliver, host, secure, or support the requested service.
  • Conversation, media, and relationship data follows the connected organisation's configured retention controls, applicable business-record requirements, and applicable law. Withdrawing relationship-memory permission prevents that memory from being used in future conversations.
  • Disconnecting WhatsApp stops new FlowIQ access, attempts to unsubscribe the Meta connection, and deletes FlowIQ's encrypted connection credential and provider connection identifiers. It does not automatically erase existing conversation history or business records created at the organisation's request.

Requesting access or deletion

An organisation administrator or WhatsApp customer may request access, correction, or deletion of applicable Meta or WhatsApp-derived personal information by emailing support@flowiq.info. A WhatsApp customer should include the phone number used, the name of the business contacted, and a description of the request.

FlowIQ will verify the requester's identity and the relevant organisation before deleting or anonymising applicable data. Some records may be retained where required by law, necessary to resolve security or legal matters, or lawfully required by the connected organisation as the responsible party.

12. Limitation

FlowIQ is not responsible for:

  • Data uploaded by users about third parties
  • User misuse of personal information
  • Compliance failures caused by user actions
  • Losses caused by compromised user credentials, third-party outages, or user-side backup failures

13. Changes

This policy may be updated at any time. Continued use constitutes acceptance.