Privacy Policy
CySo Solutions Ltd · Last updated: 10 October 2026
Summary
Personal data we process
Account data: your email address, and the name and photo Google or Microsoft provide if you sign in with them.
The business records you enter: your customers, jobs, quotations, invoices, receipts, expenses, suppliers, employees and payroll details, photos and signatures, and a device location when a job is started or stopped or when staff clock in or out.
Your subscription status from Stripe (never your card details) and technical error logs.
Purposes
To provide the Service you signed up for, bill your subscription, keep the Service secure, fix errors and meet our legal obligations — and, only when you ask for it, to send emails and SMS, run the AI Assistant, or share data with an AI app you connect.
Recipients
Our processors: Google Cloud and Firebase (sign-in, database and the included AI, in the EU), Cloudflare (hosting, the encrypted store for credentials you connect, and CySo Storage files in the EU), Stripe (billing), our own self-hosted error monitor, and our sending mailbox for emails you send without your own email server.
Services you choose to connect receive only what that connection needs: your cloud storage, email or SMS provider, the provider of an AI key you add, an AI app you connect with a connector key (for example ChatGPT or Claude), and banking or accounting software. We do not sell your personal data.
Retention
Your records are kept while your account is open. When you close it you have 30 days to export them; then they are permanently deleted, apart from the billing records we must keep for 7 years for tax. If a subscription is cancelled because it was not paid and the account then has no paid plan and nobody signs in to it for six months, it is closed the same way (with the same 30 days to export or reverse), after warning emails 30 and 7 days before. AI connector access tokens expire after 1 hour and renewal tokens after 30 days without use. Section 5 gives the period for each kind of data.
Your controls
Export your data, correct it, or close your account yourself in Settings. In Settings → AI you can switch the AI Assistant or the AI connector off, choose what each connector key may do, hide client names from an AI app, or revoke a key at any time. You can disconnect any storage, email, SMS, banking or accounting connection in Settings.
For anything else, including your rights under the GDPR (Section 10), write to [email protected].
1. Introduction
1.1 This Privacy Policy explains how CySo Solutions Ltd ("we", "us", "our") collects, uses, stores, and shares personal data when you use CySo Flow, our field-service management application available at https://flow.cysosolutions.com (the "Service").
1.2 CySo Solutions Ltd is incorporated and registered in the Republic of Cyprus. As a Cypriot company, we are subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR") directly and to any supplementing Cypriot legislation.
1.3 We are committed to protecting your personal data and to being transparent about how we use it. Please read this policy carefully. If you have any questions, you may contact us at any time using the details in Section 2.
1.4 This policy applies to all users of the Service, including business administrators ("Admins"), field technicians ("Technicians"), and solo users ("Solo Users"). Where a distinction between these roles is relevant, we make that clear in the relevant section.
2. Who Is Responsible for Your Data
2.1 CySo Flow has two kinds of personal data in it, and different people are legally responsible for each. Getting this the right way round matters, because it decides who you go to about your data — so it is stated here before anything else.
2.2 Data a business puts INTO the Service — its customers, its employees, its suppliers and their records. The BUSINESS is the data controller. CySo Solutions Ltd is that business’s processor under Article 28 GDPR: we hold and process the data on their documented instructions and we do not decide what it is used for. If you are a customer or an employee of a business that uses CySo Flow and you want to see, correct or erase your data, the business is your first point of contact. We will help them respond, and we will pass on any request that reaches us directly.
2.3 Data CySo Solutions Ltd needs to run its OWN business — the account holder’s name and contact details, billing records, support correspondence and the security logs of their use of the Service. For this, CySo Solutions Ltd is the data controller: CySo Solutions Ltd, Republic of Cyprus. Email: [email protected]. Website: https://flow.cysosolutions.com
2.4 The terms on which we act as a processor — our security obligations, our use of sub-processors, what happens on a breach, and what we do with the data when an account closes — are set out in the Data Processing Agreement at https://flow.cysosolutions.com/dpa, which applies automatically to every business using the Service.
2.5 For all privacy-related enquiries, requests to exercise your rights, or complaints, contact us at [email protected]. We aim to respond within 30 calendar days.
3. Categories of Personal Data We Collect and Process
3.1 Sign-in Identity Data. You may sign in with an email address and password, with a one-time link sent to your email address, or with a Google or Microsoft account. In every case we hold your email address; where you sign in with Google or Microsoft we also receive the account name and profile photo those services provide. Authentication is handled by Firebase Authentication, which stores the password itself — we never see or hold it. This data is used to create and maintain your user account.
3.2 Business Customer Data. Admins and Solo Users may enter personal data about their business customers into the Service, including names, email addresses, telephone numbers, and postal addresses. This data is entered directly by the Admin or Solo User and is stored in our database on their behalf.
3.3 Appointment and Job Data. The Service stores appointment dates and times, job descriptions, assigned Technician details, and financial information including rates, VAT amounts, and payment records associated with each job.
3.4 Photographic Data. Technicians and Admins may upload photographs of job sites through the Service. These images are compressed and stored in our database or, if you use CySo Storage, in our file store (Cloudflare R2, EU jurisdiction). Photographs may incidentally contain images of persons present at a job site.
3.4a Documents in Your Chosen Cloud Storage. The Service can generate PDF documents (service reports, tax invoices, and payment receipts) and, where you have connected a cloud storage provider, save copies of those documents to that provider on your behalf. Supported providers are CySo Storage (our own file store on Cloudflare R2 in the EU jurisdiction, where we hold the files as your processor), Google Drive, Microsoft OneDrive, Dropbox, and any WebDAV-compatible server you configure. These documents contain customer personal data (such as name, address, contact details, and signature). Files saved to Google Drive, OneDrive, Dropbox or a WebDAV server reside in your own storage account and are subject to that provider's own terms and privacy policy. You may also choose on-device (local) storage, in which case documents never leave your device.
3.5 GPS Location Data. When a Technician presses "Start Work" or "Stop Work" on an assigned job, the Service captures the geographic coordinates (latitude and longitude) of the Technician's device at that moment. This data is associated with the specific job record. Full details are set out in Section 6.
3.6 Technician Field Notes. Technicians may enter free-text notes about a job. These notes are stored as part of the job record and are visible to the Admin of the Technician's team.
3.7 Subscription and Billing Data. When you subscribe to a paid plan, billing is handled entirely by Stripe. CySo Solutions Ltd does not collect, see, or store your payment card details. At checkout Stripe collects your billing name and address and, if you give one, your VAT number, which Stripe validates (for EU numbers, against the EU VIES system) to work out the VAT due. We receive from Stripe the subscription status, the plan selected, transaction identifiers, and your billing address and VAT number. If a VAT number cannot be verified, our accounts team is alerted by email to check it. We also use your account email to send payment-failure, cancellation and account-closure notices.
3.8 Google Access Tokens. If you connect your Google account for Google Drive (access limited to the files the Service itself creates) or Google Calendar, the access token Google issues is held only in your browser for the current session and expires within about an hour. We do not store Google tokens on our servers. For Dropbox and Microsoft OneDrive, see 7.3a.
3.9 Technical and Usage Data. We may collect limited technical data necessary to operate the Service, including browser type, device type, and error logs. This data does not ordinarily identify you individually.
3.10 Data on Your Device. Your browser keeps your preferences and settings (localStorage) and a copy of your business records, including customer data, in its own storage (IndexedDB) so that the Service loads quickly and keeps working offline. This copy stays on your device and is not shared with anyone else; you can remove it at any time by clearing this site's data in your browser.
3.11 Quotations, Service Reports and Receipts. The Service allows you to create quotations, service reports, and payment receipts. These documents contain customer personal data (such as name and contact details) and financial line items, and are stored in our database on your behalf as part of the job/billing record.
3.12 Client Approval and Electronic Signature Data. When you send a quotation for online approval, a minimal, PII-free copy of the quotation (description, line items, amounts) is published to a uniquely-tokenised approval page. If your customer approves it, the Service stores the customer's electronic signature (a hand-drawn image) together with any note they add and a timestamp. An electronic signature may, depending on context, constitute biometric or special-category data under Article 9 GDPR; we process it only to evidence the customer's acceptance of the quotation, on the basis of contract and the legitimate interest of recording consent to the work. Approval records are automatically deleted 60 days after publication.
3.13 Activity / Audit Log Data. To allow a team Admin to see who did what and when, the Service records an activity log of actions taken within an account (for example creating, editing, issuing, or deleting a record, sharing a quotation, or a Technician starting and completing a job). Each entry contains the acting user's name or email, the action, the affected record, a short summary, and a timestamp. This data is visible only to the account Admin/owner.
3.14 Email (SMTP) Credentials. If you choose to send documents from your own email server, the non-secret connection details (host, port, username, from-address) are stored as account settings, and your email password is encrypted (AES-256-GCM) and held in a server-side key-value store operated on Cloudflare infrastructure. Your email password is never stored on your device and is never returned to the browser; it is used solely to send the emails you initiate.
3.15 Supplier and Procurement Data. If you use the Purchasing feature, you may enter personal data about your suppliers (such as a contact name, email address, telephone number and company). When you send a supplier a purchase order, a minimal, PII-free copy of the order (your own business name, an order reference, and the requested items and quantities) is published to a uniquely-tokenised acceptance page; on that page the supplier is referenced only by an opaque identifier and their contact details are never exposed. If the supplier accepts, the Service stores their acceptance, an estimated delivery date, an invoice reference and any note. These public acceptance records are automatically deleted 21 days after publication; the underlying supplier record and purchase order are retained as part of your business/accounting records. The purchase-order email is sent from your own configured email server.
3.16 Expense Records. If you use the Expenses feature, the Service stores expense entries you create (amount, VAT, category, the account paid from, and an optional supplier/payee name and note). Expense records may contain third-party personal data (such as a payee name) and are processed on the basis of performance of a contract and compliance with your legal obligations (e.g. tax and accounting). A future release may allow attaching a receipt image; where offered, such images are stored in your chosen cloud storage provider (see Section 3.4a), not in our database.
3.17 Employee and Payroll Data. If you use the Employees & Payroll feature, Admins enter and the Service stores personal data about their employees, including name, email, salary and pay elements, hire/start date, and statutory identifiers — namely the employee's Tax Identification Number (Tax File Number), Social Insurance Number, and internal employee/badge numbers. These are national identifiers and sensitive employment data. The Admin is the controller of their employees' data and CySo Solutions Ltd acts as processor (see 2.3). This data is processed to operate payroll and to meet the Admin's legal obligations for payroll, tax and social-insurance reporting (Article 6(1)(b) and 6(1)(c) GDPR). It is stored in our database on the Admin's behalf; payroll and tax records are typically retained for up to seven (7) years in accordance with Cyprus accounting and tax law.
3.18 Equipment and Servicing Data. If you use the Equipment (Services) feature, the Service stores records of serviceable assets you create (such as vehicles, machinery or tools), including a name, an identifier you choose (for example a registration plate, serial number or asset tag), a type, any custom fields you define, optional photographs, and a dated history of the services performed on each asset (service date, the jobs done, an optional cost, technician name and notes). Each asset is paired to one of your clients, so these records may contain third-party personal data (for example a client's vehicle registration). This data is processed on the basis of performance of a contract. Photographs are compressed and stored within the asset record. When a client is deleted, their equipment records and the associated service history are erased together with the client's other data (see Section on erasure).
3.19 SMS Notifications. If you enable SMS and connect your own SMS provider (Twilio-compatible), the non-secret connection details (account identifier and sender number) are stored as account settings, and your provider auth token is encrypted (AES-256-GCM) and held in a server-side key-value store on Cloudflare infrastructure — never on your device and never returned to the browser. When you send a payment reminder, or when you book an appointment for a customer, the Service transmits that customer's mobile number and the message text to your SMS provider so it can deliver the text. Your SMS provider (for example Twilio, Inc.) acts as a further processor and may process this data outside the EEA (see Section 8); message delivery is subject to their terms. As the controller of your customers' data, you are responsible for having a lawful basis to send them SMS messages.
3.20 AI Assistant. If you use the optional AI Assistant, the messages you type, together with the business data needed to answer your request (for example a client's name, contact details, invoice numbers and amounts), are sent through our server to an AI model to generate a response and to carry out the actions you ask for. (a) Included AI: if you have not added a key of your own, we use Google's Gemini models through Google Cloud Vertex AI in the EU (europe-west1 region), as our sub-processor under our Google Cloud agreement. (b) Your own key: if you add your own API key from Anthropic (Claude), OpenAI or Google (Gemini), it is encrypted (AES-256-GCM) and held in a server-side key-value store on Cloudflare infrastructure — never on your device and never returned to the browser — and your requests go to that provider under your own agreement with it; that provider may process the data outside the EEA (see Section 8). As the controller of your and your customers' data, you are responsible for having a lawful basis to process it in this way. You can turn the assistant off or remove your key at any time in Settings; every action the assistant takes runs under your own account permissions, and it asks you to confirm before creating a record or sending anything.
3.21 AI connector. If you create an AI connector key in Settings → AI and connect an outside AI app (for example ChatGPT or Claude), that app can read and act on your business data only as that key allows, and only while your AI settings are switched on. You choose the AI provider and you are the controller of your clients' data: before connecting one, make sure you have a lawful basis to share it, tell your clients in your own privacy notice that you use such tools, and preferably use a business AI plan with a data processing agreement (on personal plans, switch off the use of your chats for model training). The data the app requests — for example customers' names and contact details, invoices, quotations, expenses, payment status, figures from your books and VAT returns, staff shifts, hours worked and leave, and (redacted) staff names and roles — is sent to that AI provider, which processes it under its own terms and may be outside the EEA; we ask you to confirm before a key or setting starts sharing your clients' contact details. An AI app can also hand an accounts, tax or shifts task to Flow's built-in assistant, which then runs on the AI described in 3.20 (the included AI or your own key) and can only take the actions that key allows. You can hide client names from an AI app per key: it then sees codes such as "Client 7F3A" instead of names and receives no client email address, phone number, postal address or VAT number. Actions you set to "Approve in app" are stored in your account until you decide; a pending request can no longer be approved after 24 hours, and requests are kept as a record in your account until it is closed. Connection tokens are stored only as one-way hashes; access tokens expire after 1 hour and renewal tokens after 30 days without use. Revoking the key disconnects the app within about a minute. You can switch the connector off, change a key's permissions or revoke it at any time.
3.22 Emails Sent From Our Address. If you have not set up your own email server, emails you send to your customers from the Service (for example a document) are sent from CySo's own sending address instead. To do this we store the message — the recipient's address, the subject and the text — in our database, where it is kept for 30 days as the record of the send and then deleted.
4. Legal Bases for Processing
4.1 We process your personal data only where we have a valid legal basis under Article 6 of the GDPR.
4.2 Google Account Identity Data — Performance of a contract (Art. 6(1)(b)). Processing your Google account name and email is necessary to create your user account and provide you with access to the Service.
4.3 Business Customer Data — Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). We store business customer data entered by the Admin as part of the core service functionality.
4.4 Appointment and Job Data — Performance of a contract (Art. 6(1)(b)). Storing appointment and job records is necessary to deliver the core scheduling and invoicing features of the Service.
4.5 Photographic Data — Performance of a contract (Art. 6(1)(b)). Job-site photographs are stored as part of the job record at the direction of the Admin or Technician.
4.6 GPS Location Data — Legitimate interests (Art. 6(1)(f)) and, where required, consent. We have a legitimate interest in providing Admins with a verifiable record of when and where a Technician commenced and completed work. Where applicable law requires explicit consent from the Technician for GPS monitoring, the Admin is responsible for obtaining that consent.
4.7 Technician Field Notes — Performance of a contract (Art. 6(1)(b)). Field notes are part of the job record and are necessary to provide the job-management functionality.
4.8 Subscription and Billing Data — Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). Processing subscription status is necessary to grant access to paid features; retention of transaction records may be required by applicable tax and accounting law.
4.9 Google OAuth Tokens — Consent (Art. 6(1)(a)). You provide explicit consent when you authorise the Google integration via the OAuth consent screen. You may withdraw this consent at any time.
4.10 Technical and Usage Data — Legitimate interests (Art. 6(1)(f)). We have a legitimate interest in monitoring the technical performance and security of the Service.
5. Data Retention Periods
5.1 We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law.
5.2 Sign-in Identity Data. Retained for the duration of your active account, and destroyed together with the account at the end of the 30-day closure window described in clause 5.15.
5.3 Business Customer Data. Retained for the duration of the account holder's active subscription and for the 30-day closure window described in clause 5.15, to allow for data export.
5.4 Appointment and Job Data. Retained for the duration of the account holder's active subscription and for the 30-day closure window. Our own accounting records of what you paid us may be retained for up to 7 years where required by Cypriot or EU accounting and tax legislation; this does not include your customers’ records, which are destroyed with the account.
5.5 Photographic Data. Retained as part of the job record for the same period as Appointment and Job Data.
5.6 GPS Location Data. Kept as part of the job or attendance record it belongs to, for as long as that record is kept; it is deleted when the record is deleted and, in every case, when the account is closed (see 5.15).
5.7 Technician Field Notes. Retained as part of the job record for the same period as Appointment and Job Data.
5.8 Subscription and Billing Data. Transaction identifiers and subscription status records are retained for 7 years to comply with applicable tax and accounting obligations.
5.9 Storage and Integration Tokens. Google access tokens are never stored on our servers (see 3.8). The encrypted Dropbox and OneDrive refresh tokens are deleted when you disconnect that provider or your account is deleted.
5.10 Technical and Usage Data. Error logs and technical data are retained for a maximum of 90 days on a rolling basis.
5.11 Quotations, Service Reports and Receipts. Retained for the duration of the account holder's active subscription and for the 30-day closure window described in clause 5.15.
5.12 Client Approval and Signature Data. Automatically deleted 60 days after the quotation is published for approval.
5.13 Activity / Audit Log Data. Entries older than 365 days are deleted automatically the next time the account's activity log is opened, and every entry is deleted when the account is closed. Entries referencing a customer are deleted when that customer record is erased (see Section 10.4).
5.14 Email (SMTP) Credentials. The encrypted email password is retained until you remove it in Settings or your account is deleted.
5.15 Account closure. You may close your account yourself at any time from Settings → Data & Backup. Billing stops on the day you ask. Your data stays available to you for 30 days so you can export it, and you may cancel the closure at any point in that window. At the end of it we permanently destroy every record, every uploaded file, every link you shared, every stored credential and your sign-in itself. This is carried out automatically and we keep no copy. Three things survive, and only these: our own invoices to you (Cypriot tax law), the separate sign-in accounts of colleagues you invited (they belong to those people), and off-site backups, which are overwritten on their own rolling schedule and in any event within 90 days.
5.16 Emails sent from our address (see 3.22). Kept for 30 days, then deleted.
5.17 Accounts left after non-payment. If a subscription is cancelled because its payment failed for 30 days, the account moves to the free Basic plan and its data is kept. The same applies from the date a payment is reversed by a chargeback. If the account then has no paid plan and nobody on it (the owner or any invited user) signs in for six months, we treat it as abandoned and close it as described in clause 5.15, including the 30 days to export your data or reverse the closure, after warning the account email 30 days and 7 days before the closure date. Signing in, or subscribing again, before then keeps the account and stops the clock. Our own billing records are kept as in clause 5.8.
6. GPS Location Data — Specific Notice
6.1 Scope of GPS collection. GPS location data is collected exclusively from Technician-role accounts. It is not collected from Admin or Solo User accounts during normal use of the Service. GPS coordinates are captured at precisely two moments per job session: when the Technician taps "Start Work" and when the Technician taps "Stop Work". Continuous or background location tracking is not performed. Separately, if an employer uses the Time & Attendance feature, the employee's device location is captured when they clock in and when they clock out, to check it against the workplace area the employer set; again, there is no continuous tracking.
6.2 Purpose. GPS data is collected to create a verifiable record of job commencement and completion locations. This assists Admins in managing their field teams and verifying job completion.
6.3 Access to GPS data. GPS location records are visible only to the Admin of the team to which the Technician belongs. Technicians may view their own GPS data. GPS data is not shared with any other users, third parties, or made publicly available.
6.4 Retention of GPS data. GPS coordinates are kept as part of the job or attendance record they belong to, for as long as that record is kept, and are deleted with it — and in every case when the account is closed.
6.5 Admin responsibility. The Admin is responsible for informing their Technicians that GPS data will be captured when they use the "Start Work" and "Stop Work" functions, and for obtaining any consent required under applicable employment law.
6.6 Technician rights. Technicians may exercise their data subject rights in respect of their GPS data by contacting us at [email protected] or by raising the matter with their Admin.
7. How We Share Your Data
7.1 We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes.
7.2 Within the Service. Data is shared between users only as described by the role structure: Admins see all data for their own business; Technicians see only jobs assigned to them; Solo Users see only their own data.
7.3 Third-party processors: (a) Google Firebase / Google Cloud (Google LLC) — authentication, database, storage; EU regions; Google Cloud DPA in place. (b) Stripe (Stripe Payments Europe Ltd) — subscription billing; GDPR-compliant; DPA in place. (c) Cloudflare (Cloudflare Inc) — CDN, hosting, serverless functions; an encrypted key-value store holding the credentials you connect (for example your email (SMTP) password, SMS and WhatsApp provider tokens, AI provider keys, Dropbox and OneDrive refresh tokens, banking and accounting connection keys) and the records of your API and AI connector keys (stored as one-way hashes); and, if you choose CySo Storage, your files (R2, EU jurisdiction); DPA available. (d) Google Workspace APIs — Google Drive (drive.file) and Google Calendar integrations performed using your own Google account credentials and OAuth authorisation. (e) GlitchTip (self-hosted by CySo Solutions Ltd on our own infrastructure) — application error monitoring; receives error events and your user identifier (UID) but is configured not to capture personal data by default. (f) Revolut Business API (Revolut) — where you connect it, the Service retrieves your incoming transaction records (date, description, amount) to help you reconcile payments against invoices; this uses your own Revolut credentials and authorisation. (g) Your SMS provider (for example Twilio, Inc.) — where you enable SMS, the Service sends the recipient's mobile number and the message text to your provider, using your own credentials, to deliver payment reminders and appointment confirmations; this provider processes that data under its own terms and may be located outside the EEA. (h) AI model providers for the AI Assistant (see 3.20) — for the included AI, Google Cloud Vertex AI (Google), EU region, as our sub-processor; where you add your own key, Anthropic, PBC, OpenAI or Google (Gemini API), which process the data under their own terms with you and may be located outside the EEA. (i) The outside AI app you connect through the AI connector (for example OpenAI's ChatGPT or Anthropic's Claude) — where you create a connector key and connect such an app, the data it requests within that key's permissions is sent to that provider, chosen by you and acting under its own terms; it may be located outside the EEA. (j) Other services you choose to connect — open banking (Enable Banking), accounting software (Xero or QuickBooks), a Traccar GPS server, WhatsApp messaging through your own Twilio account, or your own PostgreSQL database — receive the data needed for that integration, using your credentials, under their own terms. (k) Our own sending mailbox — where you have not set up your own email server, emails you send to your customers leave from CySo's address (see 3.22).
7.3a User-selected cloud storage providers. Where you choose to connect a cloud storage provider for document storage (Google Drive, Microsoft OneDrive (Microsoft Corporation), Dropbox (Dropbox International Unlimited Company), or a self-hosted WebDAV server), documents you generate are transmitted to and stored within that provider using your own account credentials and authorisation. These providers process that data under their own terms and as your own processor. For Dropbox and OneDrive we hold an encrypted refresh token so that the Service can save files for you; it is used only for that and is deleted when you disconnect the provider. We do not otherwise access the files stored there. You are responsible for the security and compliance of any WebDAV server you configure.
7.4 Legal requirements. We may disclose personal data if required by law, court order, or competent regulatory authority.
7.5 Business transfers. In the event of a merger, acquisition, or sale of our business, personal data may be transferred. We will notify affected users in advance.
8. International Data Transfers
8.1 We store your data in Google Cloud infrastructure located in the European Union. However, some third-party processors are located outside the EEA.
8.2 Google LLC (US): transfers governed by Standard Contractual Clauses (SCCs) incorporated into Google's Cloud Data Processing Addendum.
8.3 Stripe Payments Europe Ltd is Irish-registered and processes data within the EEA. Onward transfers by Stripe are covered by SCCs.
8.4 Cloudflare Inc (US): transfers governed by SCCs incorporated into Cloudflare's Data Processing Addendum.
8.5 We have assessed these transfer mechanisms and are satisfied they provide adequate protection equivalent to that within the EEA.
8.6 You may request a copy of the relevant transfer safeguards by contacting [email protected].
8.7 Documents saved to a cloud storage provider you connect (OneDrive, Dropbox, or a WebDAV server) may be stored in regions you select or that the provider determines, which may be outside the EEA. Because these transfers are carried out using your own account and authorisation, you are responsible for ensuring an appropriate transfer mechanism is in place for your chosen provider and storage region. Selecting Google Drive (EU regions) or on-device local storage avoids reliance on additional providers.
9. Cookies and Local Storage
9.1 CySo Flow is a Progressive Web App and does not rely on traditional tracking cookies for advertising or analytics purposes.
9.2 We use browser localStorage and IndexedDB on your own device for your preferences and settings and for an offline copy of your business records (see 3.10).
9.3 Firebase Authentication may set session tokens in your browser that are strictly necessary for maintaining your authenticated session.
9.4 We do not use third-party advertising cookies or cross-site tracking technologies.
10. Your Rights Under the GDPR
10.1 As a data subject, you have the following rights under the GDPR, exercisable free of charge.
10.2 Right of access (Art. 15 GDPR). You have the right to obtain confirmation of whether we process personal data about you and to receive a copy of that data.
10.3 Right to rectification (Art. 16 GDPR). You have the right to request correction of any inaccurate personal data we hold about you.
10.4 Right to erasure (Art. 17 GDPR). You have the right to request deletion of your personal data where it is no longer necessary, where you have withdrawn consent, or where processing is unlawful, subject to legal retention obligations. When an Admin or Solo User deletes a customer record within the Service, the associated appointments, job execution logs, issued invoice records, quotations, service reports, payment receipts, quotation-approval records, linked calendar events, and related activity-log entries are also deleted. Copies of documents previously saved to a cloud storage provider you connected remain in your own storage account and must be deleted by you within that provider. A full export of your data (Articles 15 and 20) includes the activity log.
10.5 Right to restriction of processing (Art. 18 GDPR). You have the right to request restriction of processing in certain circumstances.
10.6 Right to data portability (Art. 20 GDPR). Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a machine-readable format.
10.7 Right to object (Art. 21 GDPR). You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
10.8 Rights related to automated decision-making. We do not make decisions about you solely by automated means that produce legal or similarly significant effects.
10.9 Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
10.10 How to exercise your rights. Send a written request to [email protected]. We will respond within 30 calendar days.
11. Right to Lodge a Complaint
11.1 If you believe our processing infringes the GDPR, you have the right to lodge a complaint with a supervisory authority.
11.2 As CySo Solutions Ltd is established in Cyprus, the lead supervisory authority is: Office of the Commissioner for Personal Data Protection — Iasonos 1, 1082 Nicosia, Cyprus — [email protected] — https://www.dataprotection.gov.cy
11.3 You may also lodge a complaint with the supervisory authority of the EU member state in which you habitually reside or work.
12. Data Security
12.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction, including TLS encryption, access controls, and role-based data visibility.
12.2 Data stored in Google Cloud Firestore benefits from Google's enterprise-grade security infrastructure, including encryption at rest and in transit.
12.3 No method of electronic transmission or storage is completely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.
12.4 In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Office of the Commissioner for Personal Data Protection within 72 hours and will notify affected individuals without undue delay where a high risk exists.
13. Children's Data
13.1 CySo Flow is a business-to-business service and is not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, please contact us at [email protected].
14. Changes to This Privacy Policy
14.1 We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email at least 30 days before the changes take effect.
14.2 The date of the most recent revision appears at the top of this policy. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
15. Contact Us
CySo Solutions Ltd — [email protected] — https://flow.cysosolutions.com