Introduction
simpleflows B.V. ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website simpleflows.pro and use our subscription commerce services.
Data Controller
simpleflows B.V. is the data controller responsible for your personal data. Our contact details are:
Data Collection
The data we collect includes personal information that you provide directly to us, information we collect automatically when you use our services, and information we may receive from third parties. We collect the following types of personal information:
Information You Provide
- Contact Information: Name, email address, phone number, company name, and job title
- Account Information: Username, password, and account preferences
- Business Information: Company details, subscription data, and billing information
- Communication Data: Messages, feedback, and support requests
Information We Collect Automatically
- Technical Data: IP address, browser type, operating system, and device information
- Usage Data: Pages visited, time spent on our website, and interaction patterns
- Cookies and Tracking: Information collected through cookies and similar technologies
How We Use Your Information
We explain how we use your information for various purposes in accordance with our legitimate business interests and legal obligations. The use of your data includes:
Service Provision
- Providing and maintaining our subscription commerce platform
- Processing transactions and managing billing
- Delivering customer support and technical assistance
- Sending service-related communications
Business Operations
- Improving our services and developing new features
- Conducting analytics and research
- Preventing fraud and ensuring security
- Complying with legal obligations
Marketing and Communications
- Sending promotional materials (with your consent)
- Personalising your experience
- Conducting market research
Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: To provide our services and fulfil our contractual obligations
- Legitimate Interests: To operate and improve our business, prevent fraud, and ensure security
- Legal Compliance: To comply with applicable laws and regulations
- Consent: For marketing communications and optional data processing (where required)
Data Sharing and Disclosure
We may share your personal information in the following circumstances:
Service Providers
We work with trusted third-party service providers who assist us in operating our business, including:
- Cloud hosting and infrastructure providers
- Payment processors and financial institutions
- Customer support and communication tools
- Analytics and marketing platforms
Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal processes or government requests
- Protect our rights and property
- Ensure the safety of our users and the public
- Investigate potential violations of our terms
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:
- Account Data: Retained while your account is active and for 7 years after closure for legal compliance
- Transaction Data: Retained for 7 years for accounting and tax purposes
- Marketing Data: Retained until you withdraw consent or we determine it's no longer needed
- Technical Data: Typically retained for 12-24 months for security and analytics purposes
Your Rights
Under GDPR, you have the following rights regarding your personal data:
Access and Portability
- Right of Access: Request copies of your personal data
- Data Portability: Receive your data in a structured, machine-readable format
Correction and Deletion
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal requirements)
Processing Control
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for consent-based processing
To exercise these rights, please contact us at privacy@simpleflows.pro. We will respond to your request within 30 days.
International Data Transfers
As a Netherlands-based company, we primarily process data within the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions for specific countries
- Binding Corporate Rules or certification schemes
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Our security measures include:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Employee training on data protection
- Incident response procedures
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our website. For detailed information about our use of cookies, please refer to our Cookie Policy.
Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete such information promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending an email notification to registered users
- Displaying a prominent notice on our platform
Your continued use of our services after such changes constitutes acceptance of the updated Privacy Policy.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In the Netherlands, the relevant authority is:
Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Website: autoriteitpersoonsgegevens.nl
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
For general inquiries, you can also contact us at contact@simpleflows.pro or visit our Contact page.