Effective July 28, 2026
Privacy Policy
This policy explains when Fliox acts as controller of platform data and when it acts only as processor for a customer business handling its own client case material.
Controller and contact details
For the processing described in the controller part of this policy, the controller is Ruslan Zakharov, sole trader (empresario individual), trading as Fliox, Calle Felipe Menéndez, 33206 Gijón, Asturias, Spain.
Privacy requests: privacy@fliox.io. Security reports: security@fliox.io. No data protection officer has been appointed; Fliox reviews that position whenever its scale or processing changes materially.
The competent supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, www.aepd.es.
When Fliox is controller and processor
Fliox acts as controller for accounts, authentication, security, subscriptions and invoices, support, service notices, the public template catalogue, external-tool connections, bounded AI-feature metering, and privacy or incident records.
For client case material placed in a company workspace, including projects, documents, intake submissions, generated forms and portal data, the customer business determines the purposes and means. That business is the controller and Fliox acts as its processor under the Data Processing Agreement.
If you are a client of a business using Fliox, contact that business about your case. If you contact Fliox, we will forward the request and tell you who the controller is.
Purposes and lawful bases
Account creation, authentication and delivery of requested features rely on Article 6(1)(b), performance of the service contract. Subscription administration also relies on Article 6(1)(b), while invoice and accounting retention relies on Article 6(1)(c).
Service security, abuse prevention, reliability, support for operational issues, external-tool audit records and protection of AI quotas rely on Article 6(1)(f), Fliox’s documented legitimate interests. Privacy requests and incidents rely on Article 6(1)(c), with Article 6(1)(f) used where records are needed to establish or defend legal claims.
Depending on the purpose, Fliox processes name, email, verification state, password hash, optional Google identifier, session and device data, security events, IP address, user agent, billing and invoice metadata, support messages, published templates, connection scope grants, and limited AI-operation metadata.
Fliox does not sell personal data, use it for advertising or behavioural profiling, or use customer content to train artificial-intelligence models.
Sources and optional Google sign-in
Most controller data comes directly from you. If a customer invites you, that customer supplies your name and email. If you choose Google sign-in, Google returns a stable account identifier, email, email-verification state and display name.
Google is an independent controller for its authentication service; Fliox becomes controller of the limited claims it receives. Disconnecting Google or deleting a Fliox account does not delete the Google account.
Recipients and international transfers
Fliox uses processors for hosting, database and file storage, transactional email, payments, reliability monitoring and bounded AI assistance. The current providers, locations and transfer mechanisms are listed on the Subprocessors page.
Where a recipient is outside the EEA, or can access data from outside it, Fliox uses an applicable adequacy decision, including the EU-US Data Privacy Framework where valid and applicable, or the European Commission’s Standard Contractual Clauses with supplementary safeguards. Information about the applicable safeguard may be requested at privacy@fliox.io.
Data may also be disclosed to professional advisers under confidentiality, a successor to the business subject to the same commitments, or a public authority or court where disclosure is legally required.
How long data is retained
Account and profile data remains while the account is active. When an erasure request is accepted, sign-in data is erased or anonymised and all sessions are revoked.
Accounting books, invoices and supporting business records are retained for six years from the last relevant entry. Privacy-rights requests and complaint files are retained for five years after closure where needed to establish, exercise or defend legal claims. Security and authentication logs are retained for no longer than 180 days unless a specific incident or legal hold requires longer.
Unconverted public intake requests and their receipt and anti-abuse metadata are deleted after 12 months of inactivity unless the receiving business chooses a shorter period. Converted requests follow the customer’s project-retention instructions.
Encrypted backup objects are rotated after 30 days. Erased live data can remain in a backup until that rotation completes and is not restored into normal use after recovery. Company customer content otherwise follows the customer’s documented instructions and the Data Processing Agreement.
Your rights
You may request access, rectification, erasure, restriction, or portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier processing.
Write to privacy@fliox.io or use the available account controls. Requests are free unless manifestly unfounded or excessive. Fliox normally responds within one month; for a complex request or several requests, it may extend that period by up to two further months and will explain the extension within the first month.
You may complain to the AEPD. The AEPD normally expects you to contact the controller first.
Account erasure and company records
Deleting an account revokes sessions and removes or anonymises account, credential and profile data. Pending invitations are closed and active memberships are removed.
Company-owned project history, comments, assignments and audit entries remain under the customer controller’s retention instructions, with the former user’s identity replaced by a non-identifying marker. Assignments and client projects therefore do not block account deletion.
Deletion is blocked only while the user is a sole active owner of a company workspace. Ownership must first be transferred or the workspace deleted. Some records may remain where Article 17(3) GDPR permits retention, including accounting records and evidence needed for legal claims.
Security, storage and tracking
Fliox applies encryption in transit and at rest, least-privilege access, tenant-isolation controls, administrative audit records, backup rotation and an incident process. No system is perfectly secure.
Fliox does not use advertising, marketing attribution, product analytics, session recording, or email open or click tracking. Strictly necessary storage and user-selected interface preferences are described in the Cookie and Local Storage Policy. No cookie banner is shown while that essential-only configuration remains true.
Sensitive case data
Company workspaces may contain health, family, civil-status or criminal-record information where the customer controller has a lawful basis under Articles 9 and 10 GDPR and applicable Spanish law.
Public intake forms must not request special-category or criminal-record data, and submitters must not volunteer it in free-text fields. Such data must not be sent to the AI feature.
Artificial-intelligence assistance
AI assistance is limited to suggesting workflow templates and detecting fields or improving labels on blank reusable forms. Inputs are limited to generic instructions, blank rendered pages and technical field names, types and options. Filled values, completed documents, intake answers, client identities and project case files are not sent.
Outputs are private drafts requiring human review. They are not published or acted on automatically and must not be used to assess a person’s eligibility. There is no automated decision-making within Article 22 GDPR.
External tools and agents
A user may authorise a third-party tool through explicit scopes. Company-data access requires owner authorisation; personal access is granted separately. Fliox records the grant, limits it to the authorised scopes, and permits revocation.
The third party then processes the data under its own terms and may make international transfers. The authorising user or customer must assess that provider and have a lawful basis before granting access. Fliox remains responsible for the security of its own authorisation and access controls.
Fliox as processor for customer case material
Fliox processes company customer content only on documented customer instructions, applies the DPA’s confidentiality and security measures, uses authorised subprocessors, assists with rights requests and breaches, and returns or deletes content when instructed or when the agreement ends, subject to legal retention and backup rotation.
Fliox does not use that material for advertising, profiling, its own analytics, model training or another independent purpose. The customer decides the lawful basis, collection scope and live retention of its client case material.
Children and policy changes
Fliox accounts are for adults acting professionally and the service is not directed to children. A customer may lawfully hold information about minors in a client case; that processing remains the customer’s responsibility as controller.
Fliox will publish a new version and effective date when this policy changes. Customers will receive advance notice of a material change where required. Previous versions are available on request.