Privacy Policy
FlowSpace Privacy Policy
Founding-scope reconciliation: 2026-09-29 — recording remains in production scope; automatic transcription, generated summaries, recent-caller context and cross-call conversational memory are deferred.
Version: FPP-PUBLIC-2026-09-16-v1 Effective date: 16 September 2026 Last scope update: 29 September 2026
FlowSpace is operated by Adarsh, proprietor operating FlowSpace.
Address: VALIYAPARAMBATH, NADAKKUTHAZHA PO, Vatakara, Kozhikode, Kerala, India, 673104 Privacy / support email: support@flowspaceos.app WhatsApp: +91 88911 34930
This Privacy Policy explains how FlowSpace collects, uses, stores, shares and protects personal data when people use FlowSpace, contact a business through a FlowSpace-powered receptionist, participate in a FlowSpace Browser Trial, or contact FlowSpace support.
1. Who this Policy covers
This Policy applies to:
- FlowSpace account/dashboard users;
- businesses using FlowSpace;
- callers speaking with a FlowSpace-powered receptionist;
- people whose details are captured as Leads, callback requests or appointments;
- Browser Trial users;
- people contacting FlowSpace support.
A business using FlowSpace may also have its own privacy obligations to its customers and callers.
2. Data we may process
Depending on how FlowSpace is used, we may process:
Account and business data
- name;
- business name;
- email address;
- phone number;
- account identifiers and roles;
- Business Profile information;
- services, prices, business hours, FAQs and booking instructions;
- policy/contract acceptance records.
Payment and commercial data
- amount paid;
- payment date/time;
- UPI/payment reference or UTR;
- invoice/receipt information;
- plan and billing-cycle information;
- provisioning/activation records;
- refund/cancellation/dispute records.
FlowSpace does not need your UPI PIN or banking password.
Call and caller data
Production calls may involve:
- caller and called phone numbers;
- call identifiers;
- call date/time, duration and status;
- audio and call recordings;
- spoken conversation content;
- AI responses;
- language/context;
- technical call/media events;
- structured call outcomes and linked business-action state.
Deferred call-intelligence features
Automatic post-call transcription, generated call summaries, recent-caller context and cross-call conversational memory are not part of the initial founding production scope. FlowSpace does not create these artifacts as a normal founding-call processing step.
Leads, callbacks and appointments
Depending on what a caller provides, FlowSpace may process:
- name;
- phone number;
- callback number;
- email address;
- enquiry/requirement;
- qualification answers;
- callback requests;
- appointment preferences;
- booking details;
- Lead status.
Calendar data
Where Google Calendar is connected, FlowSpace may process the information needed to check relevant availability and create/manage supported bookings.
Technical and security data
FlowSpace may process:
- IP address;
- browser/device/session information;
- authentication events;
- request identifiers;
- usage counters;
- error/latency information;
- security events;
- access/audit logs;
- infrastructure/application telemetry.
Support and complaint data
FlowSpace may retain support messages, emails, WhatsApp communications, troubleshooting information, complaints and related evidence.
3. Recording
Production FlowSpace calls are recorded by default. Automatic transcription is not part of the initial founding production scope.
At the start of a production call, the receptionist provides a short disclosure in the configured/default language. A typical English disclosure is:
Hi, I'm [Agent Name], from [Business Name]. This call is recorded to help with your enquiry.
The founding phone service does not provide an unrecorded AI-call mode. A caller who does not want recording should use another contact method offered by the business.
A recording can occasionally be unavailable because of provider or technical failure.
4. Why FlowSpace uses personal data
FlowSpace may use personal data to:
- create and secure accounts;
- configure and operate the receptionist;
- answer inbound enquiries;
- use the business's approved information during calls;
- create Leads, callback requests and appointments;
- provide recordings and structured call outcomes to the relevant business;
- create/manage supported Calendar bookings;
- provide customer support;
- measure plan usage and enforce limits;
- verify payments;
- provision and maintain the Service;
- troubleshoot failed calls or AI behavior;
- investigate fraud, abuse, security incidents or disputes;
- maintain audit/evidence records;
- comply with applicable legal obligations.
FlowSpace does not sell caller or customer personal data to advertisers.
5. AI processing
FlowSpace uses AI/model providers, currently including Google's Gemini API, to operate real-time voice conversations. Automatic post-call transcription is deferred from the initial founding product.
For paid production Service, FlowSpace intends to use Google services through a paid/billing-enabled production project. FlowSpace does not intentionally opt production customer/caller conversations into optional model-training or feedback-sharing programs.
Browser Trial
The Browser Trial uses a separate pool of free/unpaid Gemini API projects/keys.
Under Google's current terms for unpaid Gemini API services, content submitted to unpaid services may be used to provide, improve and develop Google products and machine-learning technologies, and human reviewers may process inputs/outputs.
Accordingly:
- do not use the Browser Trial to share sensitive or confidential information;
- Trial conversations do not have the same provider data-treatment posture as paid production;
- Trial data is kept separate from paid production data;
- FlowSpace does not represent the unpaid Trial as a "no-training" environment.
6. Service providers and sharing
FlowSpace may share/process data with service providers only as reasonably necessary to operate, secure and support the Service.
These may include:
The relevant FlowSpace business
Caller enquiries, recordings, structured call outcomes, Leads, callbacks and appointments may be made available to authorized users of the business that received the call.
Telecom provider
FlowSpace currently uses Plivo for relevant telephony functions. Plivo may process phone numbers, call metadata, audio/recordings and related provider information.
AI provider
Google's Gemini API may process audio, text and context needed for the real-time AI conversation.
Cloud infrastructure
FlowSpace may use AWS and other infrastructure providers for application hosting, databases, logs, storage and security functions.
Google Calendar
If the business connects Google Calendar, FlowSpace may exchange the minimum relevant Calendar information needed for supported booking/synchronization.
Professional/legal/security providers
Information may be shared with professional advisers, security providers or similar service providers where reasonably necessary and subject to appropriate obligations.
Authorities and legal process
FlowSpace may disclose information where reasonably required by applicable law, legal process or a binding order, or to protect rights, safety and security.
7. Recording access
FlowSpace intends to restrict recordings to authorized access.
Controls include or are being implemented for:
- authenticated dashboard access;
- tenant-scoped authorization;
- restricted FlowSpace operational access for legitimate support/security/dispute needs;
- access/audit records;
- authenticated or time-limited media retrieval;
- no intentional public publishing of recordings.
8. Security
FlowSpace uses or is implementing reasonable safeguards appropriate to the data processed, including:
- TLS/HTTPS/WSS encryption in transit;
- encryption at rest for relevant databases/object storage;
- access controls and tenant isolation;
- secure authentication/session handling;
- restricted secrets/credential access;
- access/security logging;
- backup/recovery controls where appropriate;
- private/authenticated recording access;
- retention/deletion controls;
- incident investigation and response procedures.
No internet service can guarantee absolute security.
9. Retention
FlowSpace aims not to retain personal data longer than reasonably required for the relevant purpose, subject to legal, security and dispute requirements.
The founding default is:
| Data | Default retention |
|---|---|
| Call recordings | Up to 90 days |
Other operational records, such as Calls, Leads, callbacks, Calendar events, account/configuration and usage information, may be retained while the account/service remains active and for a reasonable period afterwards for support, recovery, security, disputes and legal obligations.
Payment, invoice, agreement, provisioning, refund and dispute records may be retained for applicable accounting, tax, contractual or legal requirements.
Specific records may be preserved longer under a legal hold, complaint, fraud/security investigation or legal process.
10. Deletion
When data reaches the end of its applicable retention period, FlowSpace will delete it or make it no longer ordinarily accessible, subject to backup cycles, provider deletion behavior, legal holds, fraud/security investigation and mandatory retention requirements.
11. Privacy requests
Depending on the applicable law and context, a person may request reasonable assistance with:
- access to information FlowSpace holds about them;
- correction of inaccurate information;
- deletion of information no longer required;
- withdrawal of a consent where processing depends on consent;
- complaints about processing.
Send requests to:
support@flowspaceos.app
A caller without a FlowSpace account should provide enough information to locate the relevant call, such as the phone number used, approximate call date/time and business called.
FlowSpace may verify identity or authority before disclosing, changing or deleting data.
12. Business/customer responsibilities
Businesses using FlowSpace should:
- provide accurate caller-facing information;
- use caller data for legitimate purposes;
- restrict dashboard access to authorized people;
- comply with their own applicable privacy/sector obligations;
- avoid unnecessary sharing/download of recordings;
- respond appropriately to privacy requests relating to their use of the data.
13. People under 18
FlowSpace is intended for adult business use and is not designed or marketed as a service for children.
The Browser Trial is intended for users aged 18 or older.
A business whose ordinary intended caller base is likely to include people under 18 should contact FlowSpace before deploying the Service so the applicable provider/privacy requirements can be reviewed.
14. Processing locations
Some service providers may process or temporarily store data outside the Customer's state or outside India, subject to their infrastructure, terms and applicable law.
FlowSpace will comply with applicable restrictions on cross-border personal-data processing as they apply.
15. Security incidents
If FlowSpace becomes aware of a personal-data/security incident, it will investigate, contain and remediate the incident and make notifications required by applicable law.
16. Cookies and similar technologies
FlowSpace may use cookies or similar storage necessary for authentication, sessions, security, preferences and core application operation.
If FlowSpace later introduces non-essential advertising/marketing tracking, this Policy and applicable consent controls will be updated before deployment.
17. Policy updates
FlowSpace may update this Privacy Policy when the product, service providers or law changes.
The current version and effective date will be published with the Policy.
18. Contact
FlowSpace Operator: Adarsh, proprietor operating FlowSpace Email: support@flowspaceos.app WhatsApp: +91 88911 34930 Address: VALIYAPARAMBATH, NADAKKUTHAZHA PO, Vatakara, Kozhikode, Kerala, India, 673104