Privacy Policy

1. Who we are, and how we define data

flowit AG ("we", "us") operates the website www.flowit.ai. We collect and use data on this website to provide the best service.

We distinguish between two categories of data:    

  • Personal data is any information relating to an identified or identifiable natural person, for example your name, address, phone number, email address, or IP address.
  • Anonymous data is information that cannot reasonably be linked back to a person, for example aggregated statistics about website usage. Anonymous data is not subject to data protection laws referred to in section 2.

2. When this policy applies, and our legal basis

We are subject to both the Swiss Federal Act on Data Protection (FADP/DSG) and, where we offer services to or address individuals in the EU/EEA, the EU General Data Protection Regulation (GDPR). These laws overlap substantially but aren't identical.

Where we rely on the GDPR, our legal basis is one of the following:

  • Legitimate interest (Art. 6(1)(f)): for operating our website, responding to inquiries, and managing customer/prospect relationships.
  • Contract or pre-contractual steps (Art. 6(1)(b)): where your data is needed to prepare or perform a contract with you.
  • Consent (Art. 6(1)(a)): for cookies, marketing, and anything else where we ask for your opt-in first.

Under the Swiss DSG, we don't need a specific legal basis in the same sense; processing must simply comply with the DSG's general principles (good faith, proportionality, purpose limitation, transparency) and not unjustifiably infringe your personality rights (Art. 30 FADP/DSG). Where we rely on your consent, we state so explicitly. This privacy policy informs you, in accordance with Art. 19 of the Swiss Federal Act on Data Protection (FADP/DSG), about how we process your personal data.

3. How we handle anonymous data

We process website data in anonymized and aggregated form, for example to understand overall traffic patterns. This kind of data cannot be traced back to you individually, so it falls outside the scope of data protection law. We use it to keep the website running smoothly, offer you the best possible service, and to understand how it's used at a general level.

4. What anonymous data we collect, and for which purposes

  • Technically necessary cookies, to operate core website features (e.g., remembering your cookie preferences). These are session- or short-duration cookies that don't identify you personally.
  • Aggregated usage statistics, compiled from website traffic, which help us understand overall visitor numbers and behavior without identifying individuals.

If a tool listed in section 7 also processes identifiable information alongside anonymous statistics (for example, an analytics tool that also logs IP addresses), we treat that processing as personal data instead. The handling of personal data is covered in sections 5 and 6.

5. How we handle personal data

We collect personal data only to the extent necessary for a specific purpose, communicated to you either in this policy or at the point of collection. We don't sell personal data, and we don't use it for purposes incompatible with why it was collected. Depending on the purpose, our legal basis is legitimate interest, a contract, or your consent for both FADP/DSG and DSGVO (see section 2).

6. What personal data we collect, and for which purposes

Website access. When you visit our website, your browser automatically transmits data to our server (IP address, date/time of access, file requested, referrer URL, browser and operating system). We log this temporarily to keep the site secure and running, and delete it after 30 days at the latest.

Contact and inquiries. When you contact us by phone, email, or through a form on our website, we collect what you provide: name, email address, phone number, and the content of your message or request (for demo bookings, and your preferred date/time and area of interest). We use this to respond to you. With exception of the demo booking page, which uses services of Google, all website forms are hosted natively by Webflow (see section 7).

CRM and lead management. Data submitted through our website forms is also captured by HubSpot's tracking script and stored in our CRM. This allows us to manage the ongoing relationship with you as a customer or prospect. If you no longer want us to retain this data, you can object at any time.

Cookies, analytics, and advertising. Beyond the technically necessary cookies described in section 4, we use functional and advertising cookies, along with analytics and session-recording tools (Google Analytics, Google Tag Manager, Hotjar), to understand how visitors use our site and, where you've consented, to personalize content. These tools process identifiable data such as your IP address, and in some cases device fingerprinting. This processing relies on your consent via our cookie banner, which you can withdraw at any time.

Spam and abuse protection. We use Google reCAPTCHA on our forms to distinguish real visitors from automated traffic, which involves processing data such as your IP address and interaction patterns (mouse movement, typing).

Email marketing. If you subscribe to our newsletter, we collect your email address and use HubSpot to send it. This relies on your consent, which you can withdraw at any time by unsubscribing.

Social media. Our website links to our profiles on LinkedIn, YouTube, Facebook, and Instagram. No data is sent to these platforms just by visiting our site, only if you click through, at which point the social platforms own privacy policies apply.

7. Sharing personal data with third parties

We share personal data with external providers only where necessary to run our website and services, and only to the extent needed for that purpose. We are continuously working with all providers to ensure your data is used only as instructed and protected by appropriate technical and organizational measures by evaluating and updating data processing agreements .

Where a provider is located outside Switzerland or the EU/EEA (e.g., in the US), we only transfer data where at least one of the following applies:

  • an applicable adequacy decision (e.g., the EU-US Data Privacy Framework and its Swiss-US extension);
  • standard contractual clauses, supplemented with additional safeguards where necessary; or
  • another legal safeguard recognized under the GDPR or the Swiss DSG.

We may also disclose personal data to public authorities (e.g., tax authorities or courts) where legally required to do so.

8. Third parties involved

Provider

Purpose

Location / transfer basis

Related Links

AWS (Amazon Web Services, Inc., Seattle, USA)
Website hosting
EU and/or US; EU-US and Swiss-US Data Privacy Framework
Webflow, Inc. (San Francisco, USA)
Website platform; hosts our forms
US; EU-US and Swiss-US Data Privacy Framework
HubSpot, Inc. (Cambridge, USA)
CRM, lead management, email newsletter
EU; EU-US and Swiss-US Data Privacy Framework
Google (Google LLC / Google Ireland Ltd.)
Google Analytics 4, Google Tag Manager, reCAPTCHA
EU and/or US; EU-US and Swiss-US Data Privacy Framework
Hotjar Limited (part of Contentsquare, Malta)
Session recording / website visitor behavior analytics
EU (Malta)
LinkedIn Ireland Unlimited Company
Social media link
EU (Ireland)
Meta Platforms Ireland Limited
Social media link
EU (Ireland)
Kertos (Munich, Germany)
External data protection officer
EU (Germany)

9. Storage and deletion

We retain personal data only as long as necessary for the purpose it was collected for, or as required by law. In practice:  

  • Website access logs: retained for a limited period for security and technical operation purposes (e.g. detecting and investigating misuse or technical faults), after which they are deleted or anonymized.
  • Inquiries and form submissions: retained for as long as needed to handle your request and, where an ongoing or prospective business relationship exists, may be kept longer in our CRM system until no longer relevant or until deletion is requested.
  • Cookie-based data: retention depends on the cookie type — session cookies are deleted when you close your browser; persistent cookies remain until their set expiry date or until you clear your browser data.
  • Newsletter data: retained for as long as you remain subscribed. Unsubscribing stops future communication via the selected channel; your contact data may continue to be stored unless you separately request its deletion.

Where data is stored in our CRM to manage a customer or prospect relationship, you can request deletion or object to this at any time (see section 10).

10. Your rights, and how to contact us

Under the GDPR and/or the Swiss DSG, you have the right to:

  • Access: confirmation of whether we process your data, and details about that processing.
  • Rectification: correction of inaccurate or incomplete data.
  • Erasure: deletion of your data where processing is no longer justified.
  • Restriction: limiting how we process your data in certain circumstances.
  • Data portability: receiving your data in a structured, machine-readable format (GDPR only).
  • Objection: objecting to processing based on your situation, including for direct marketing.
  • Withdraw consent: at any time, where processing is based on consent, without affecting past lawfulness.

To exercise any of these rights, or with any other questions, contact us at:

flowit AG, Hardstrasse 235, 8005 Zurich, Switzerland

Our data protection officer in Switzerland: Bilâl Tharis

Our data protection officer in the EU: Kertos, Briennerstrasse 41, 80333 Munich, Germany - dsb@kertos.io

You also have the right to lodge a complaint with a supervisory authority: the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or your local data protection authority in the EU/EEA.

11. Last updated

This policy was last updated on 26.08.2026. We may update it at any time, for example to reflect changes in our services, our use of third-party providers, or applicable law. The version in effect is always the one published on this page.