flovei

Privacy Policy

Updated 8 July 2026

1. Data controller

JKOVE Oy (Business ID 3111634-8, Finland)

Contact for privacy matters: hello@flovei.com

2. Two roles: your data and your clients' data

JKOVE Oy is the data controller for the personal data described in this policy: your account data and data about your use of the service.

Where you enter personal data concerning your clients, prospects, or contacts into the service, JKOVE Oy processes that data only on documented instructions and solely to provide the service — as a data processor for you or your organization, or as a sub-processor where you process the data on behalf of another controller. That processing is governed by our Data Processing Addendum. Responsibility for the lawfulness of the processing and for informing the individuals concerned remains with the controller of that data — you, your organization, or the controller on whose behalf you act.

3. Purposes and legal bases of processing

  • Providing and operating the service — account creation, authentication, and the features you use. Legal basis: contract (GDPR art. 6(1)(b)).
  • Service communications — transactional emails such as sign-in and account messages. Legal basis: contract (art. 6(1)(b)).
  • Team invitations — delivering an invitation email to an address provided by an account holder. Legal basis: legitimate interest (art. 6(1)(f)): enabling teams to invite their members.
  • Security and abuse prevention — technical logs, rate limiting, and bot protection on public forms. Legal basis: legitimate interest (art. 6(1)(f)): keeping the service secure and available.
  • Error monitoring and service quality — diagnostic events when something goes wrong. Legal basis: legitimate interest (art. 6(1)(f)): detecting and fixing defects.
  • Product analytics — first-party usage events (see section 6). Legal basis: legitimate interest (art. 6(1)(f)): understanding and improving how the service is used. No third-party analytics or advertising technology is used.
  • Optional integrations, notifications, and summary emails — connections you choose to enable (see section 7), push notifications you subscribe to, and periodic service summary emails you have opted in to (every message includes an unsubscribe link). Legal basis: consent (art. 6(1)(a)), which you can withdraw at any time.
  • Pre-launch contact list — if you leave your email address on our website to be notified about the service. Legal basis: consent (art. 6(1)(a)).

Providing the data required for registration (email address and name) is a prerequisite for using the service; without it an account cannot be created. All other data is provided voluntarily.

4. Categories of data processed

  • Account and contact details (email address, name)
  • Authentication data (passwords are stored only as one-way hashes)
  • Content you enter into the service, which may include personal data of your own clients and contacts (processed on your behalf — see section 2)
  • Calendar data, if you enable the optional calendar connection: event titles, times, and descriptions from the calendars you select (read-only; where events contain personal data of your clients or contacts, it is processed on your behalf — see section 2)
  • Credentials for optional integrations (OAuth tokens), stored encrypted
  • Push notification subscription identifiers, if you enable notifications
  • First-party usage events (see section 6)
  • Technical log data (session information, timestamps, IP address)

The service is not intended for special categories of personal data (GDPR art. 9), and the terms of service prohibit entering such data.

Local, in-browser processing: certain features let you analyze documents you choose. These documents are processed entirely within your browser: their contents are not transmitted to, or stored on, our servers, and our error monitoring is configured to exclude their contents.

5. Recipients: service providers (sub-processors)

We use the following service providers to run the service. The current list, each provider's role, location, and transfer mechanism are maintained at flovei.com/subprocessors:

  • Supabase — database and authentication. Data is stored in the EU (AWS eu-north-1, Stockholm).
  • Vercel— hosting and serverless functions. Server functions run in the EU (Stockholm region); static content is delivered through Vercel's global edge network.
  • Resend — delivery of transactional emails (recipient address and message content).
  • Sentry — error monitoring. Event data is stored in the EU (Frankfurt, Germany). Configured to limit personal data in diagnostic events; user-entered content is masked in error recordings.
  • Cloudflare Turnstile — bot protection on public forms (processes technical browser signals and IP address).

Content you enter into the service is stored only in the EU, and the service's server functions and error monitoring data reside in the EU. Personal data is processed in the United States only for ancillary functions (delivery of transactional emails to users and bot protection on public forms); no content you enter into the service is stored outside the EU.

GDPR-compliant data processing agreements are in place with each provider. Where processing takes place outside the EU/EEA, transfers are based on the European Commission's Standard Contractual Clauses (2021/914) and/or the EU-U.S. Data Privacy Framework, as applicable to each provider.

Personal data is not disclosed to other third parties unless there is a statutory obligation to do so.

6. First-party analytics

The service records usage events (such as which parts of the service are used and when) into its own database to understand and improve the service. This data is not shared with advertising or analytics companies, is not used for any purpose other than service development and operation, and is not combined with data from other sources. A temporary session identifier is kept only in the app's memory while it is open; it is not stored on your device.

7. Optional integrations

The service offers optional connections to third-party services (such as calendar providers and professional networks). Each connection is established only with your explicit authorization (OAuth), requests the minimum scope needed (calendar access is read-only), and can be revoked at any time in the service settings or at the third party. Credentials are stored encrypted. Your use of a third-party service is governed by that provider's own terms and privacy policy; such providers are independent controllers of their own services.

8. Retention periods

  • Account data and content: retained while the account is active. Account deletion can be requested at any time (hello@flovei.com); data is deleted within 30 days of deletion, except where a statutory retention obligation applies. Backup copies expire on a rolling basis, at the latest within 90 days of deletion.
  • Usage events (analytics): deleted together with the account under the same 30-day rule.
  • Technical logs and diagnostic events: retained for limited periods determined by our infrastructure providers, at most 12 months.
  • Pre-launch contact list: retained until the notification purpose is fulfilled or you ask us to remove your address, whichever comes first.

9. Rights of the data subject

You have the following rights under the GDPR:

  • Right of access to your data
  • Right to rectification of inaccurate data
  • Right to erasure
  • Right to restriction of processing
  • Right to object to processing based on legitimate interest
  • Right to data portability
  • Right to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal)
  • Right to lodge a complaint with the supervisory authority (Office of the Data Protection Ombudsman, Finland, tietosuoja.fi)

To exercise these rights, contact hello@flovei.com. We respond without undue delay and at the latest within one month. If your request concerns data we process on behalf of another controller (section 2), we will direct you to that controller and assist them in responding.

10. Automated decision-making

The service does not make automated decisions that produce legal or similarly significant effects concerning you (GDPR art. 22).

11. Information security

Data in transit is encrypted (HTTPS/TLS) and data at rest is encrypted at the infrastructure level. Passwords are stored as one-way hashes. Access to data is restricted with row-level access controls: data is visible only to the account that entered it and, where the user is part of a team, to the team roles the service's sharing model authorizes (such as a team lead's access to their own team's data) — never to other teams. Credentials for optional integrations are additionally encrypted at the application level. Access to production data is restricted on a need-to-know basis. The service's database is backed up automatically at regular intervals.

12. Cookies

The service uses only cookies and browser storage that are strictly necessary for its operation, such as maintaining session and login state (Act on Electronic Communications Services, 917/2014). No advertising or third-party tracking cookies are used, which is why the service does not show a cookie banner.

13. Changes to this privacy policy

This privacy policy may be updated from time to time. Users will be informed of significant changes within the service or by email.

← Back to Flovei