Updated 8 July 2026
JKOVE Oy (Business ID 3111634-8, Finland)
Contact for privacy matters: hello@flovei.com
JKOVE Oy is the data controller for the personal data described in this policy: your account data and data about your use of the service.
Where you enter personal data concerning your clients, prospects, or contacts into the service, JKOVE Oy processes that data only on documented instructions and solely to provide the service — as a data processor for you or your organization, or as a sub-processor where you process the data on behalf of another controller. That processing is governed by our Data Processing Addendum. Responsibility for the lawfulness of the processing and for informing the individuals concerned remains with the controller of that data — you, your organization, or the controller on whose behalf you act.
Providing the data required for registration (email address and name) is a prerequisite for using the service; without it an account cannot be created. All other data is provided voluntarily.
The service is not intended for special categories of personal data (GDPR art. 9), and the terms of service prohibit entering such data.
Local, in-browser processing: certain features let you analyze documents you choose. These documents are processed entirely within your browser: their contents are not transmitted to, or stored on, our servers, and our error monitoring is configured to exclude their contents.
We use the following service providers to run the service. The current list, each provider's role, location, and transfer mechanism are maintained at flovei.com/subprocessors:
Content you enter into the service is stored only in the EU, and the service's server functions and error monitoring data reside in the EU. Personal data is processed in the United States only for ancillary functions (delivery of transactional emails to users and bot protection on public forms); no content you enter into the service is stored outside the EU.
GDPR-compliant data processing agreements are in place with each provider. Where processing takes place outside the EU/EEA, transfers are based on the European Commission's Standard Contractual Clauses (2021/914) and/or the EU-U.S. Data Privacy Framework, as applicable to each provider.
Personal data is not disclosed to other third parties unless there is a statutory obligation to do so.
The service records usage events (such as which parts of the service are used and when) into its own database to understand and improve the service. This data is not shared with advertising or analytics companies, is not used for any purpose other than service development and operation, and is not combined with data from other sources. A temporary session identifier is kept only in the app's memory while it is open; it is not stored on your device.
The service offers optional connections to third-party services (such as calendar providers and professional networks). Each connection is established only with your explicit authorization (OAuth), requests the minimum scope needed (calendar access is read-only), and can be revoked at any time in the service settings or at the third party. Credentials are stored encrypted. Your use of a third-party service is governed by that provider's own terms and privacy policy; such providers are independent controllers of their own services.
You have the following rights under the GDPR:
To exercise these rights, contact hello@flovei.com. We respond without undue delay and at the latest within one month. If your request concerns data we process on behalf of another controller (section 2), we will direct you to that controller and assist them in responding.
The service does not make automated decisions that produce legal or similarly significant effects concerning you (GDPR art. 22).
Data in transit is encrypted (HTTPS/TLS) and data at rest is encrypted at the infrastructure level. Passwords are stored as one-way hashes. Access to data is restricted with row-level access controls: data is visible only to the account that entered it and, where the user is part of a team, to the team roles the service's sharing model authorizes (such as a team lead's access to their own team's data) — never to other teams. Credentials for optional integrations are additionally encrypted at the application level. Access to production data is restricted on a need-to-know basis. The service's database is backed up automatically at regular intervals.
The service uses only cookies and browser storage that are strictly necessary for its operation, such as maintaining session and login state (Act on Electronic Communications Services, 917/2014). No advertising or third-party tracking cookies are used, which is why the service does not show a cookie banner.
This privacy policy may be updated from time to time. Users will be informed of significant changes within the service or by email.