Privacy Policy
This English version is a courtesy translation. The Spanish version (Política de Privacidad) is the binding text.
This policy explains which personal data I process when you visit flowsly.ai, book a call or write to me, what I use it for, who I share it with and what rights you have. It is written under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). It describes only processing that happens today; if I add a new channel I will update it before using it.
1. Controller
- Identity: Daniel Illingworth Uscocovich (Flowsly AI)
- Tax ID (NIF/NIE): Z0447965E
- Address: 43007 Tarragona, Spain. Full postal address available on request by email.
- Email: contacto@flowsly.ai
2. What data I process and where it comes from
When you book a call (Cal.com). The booking form asks for your name and email (required), whatever you choose to write in "Additional notes" about your business (optional) and, if you add guests, their email addresses. Cal.com also records the chosen date and time and your time zone. I do not ask for a phone number. Name and email are needed to schedule; without them you cannot book this way, but you can write to contacto@flowsly.ai. If you add guests, it is up to you to tell them you have shared their email with me.
Do not enter health data, ideology, offences or any other special category under art. 9 GDPR in the form. If I receive such data by mistake, I will delete it.
When you book you also accept Cal.com's terms and privacy policy. Cal.com processes your booking data on my behalf and, for the operation of its own platform, as an independent controller.
If you hire a service. The data needed for the contract and invoice: company or personal name, tax ID, address and payment details.
When you write to me. Your email address, your name and the content of the message.
Public information about your business. To prepare the call I may look at what your business itself publishes: your website, your Google profile, your social media and professional directories.
When you browse the website. The hosting server records technical data (IP address, browser, pages visited) for security. In addition, only if you accept the cookie banner, the Meta Pixel sends Meta the page URL, the referring page, your IP address, your browser (user-agent), the identifier of the ad you came from and, if you are logged in to Facebook or Instagram, identifiers of that account. Meta may read or set cookies on its own domains, which I do not control. Without your consent the pixel is not loaded. Details are in the Cookie Policy.
This site is aimed at business owners. I do not knowingly process data of anyone under 14.
3. What I use your data for and on what legal basis
- Holding the call and answering your enquiry. Sending you the confirmation, the meeting link and reminders by email, and answering what you ask. Legal basis: pre-contractual measures at your request (art. 6.1.b GDPR).
- Preparing the call with what you tell me. I read and analyse your form notes so I arrive at the meeting with a clear picture of your situation. Legal basis: pre-contractual measures (art. 6.1.b GDPR).
- Preparing the call with public information about your business. I look at what your business publishes (website, Google profile, social media) to understand how job requests reach you today. Legal basis: legitimate interest in preparing a relevant proposal (art. 6.1.f GDPR). You can object by writing to me before the call; in that case I will go into the meeting with only what you wrote in the form.
- AI tools in that preparation. For the two points above I rely on artificial intelligence models that run on my own equipment. Your data is not sent to any external AI provider or used to train models, and no logs of those queries are kept beyond my preparation notes.
- Including your guests in the meeting. If you add guests when booking, I use their email only to send them the meeting invitation. Legal basis: legitimate interest in holding the meeting you asked for (art. 6.1.f GDPR). I do not send them a separate notice beyond the invitation; it is up to you to tell them you have shared their email.
- Sending you the proposal you ask for. After the call I email you the proposal or figures we agreed on and answer your questions about it. Legal basis: pre-contractual measures at your request (art. 6.1.b GDPR). I do not send you advertising by email or messaging unless you expressly authorise it (art. 21 LSSI-CE); if you do, you can withdraw in every message.
- Providing the service if you hire me. Project management, invoicing and communications inherent to the engagement. Legal basis: performance of the contract (art. 6.1.b GDPR) and legal tax and accounting obligations (art. 6.1.c GDPR).
- Measuring ads and building audiences in Meta. The pixel sends Meta at most two events: the page view (PageView) and, if you complete a booking, the standard booking event (Schedule), which only signals that a booking happened and includes neither your name nor your email nor your notes. With them I know which ad generates visits and bookings. With that same data I can set up remarketing audiences in Meta Ads (showing you an ad again if you have visited the site) and lookalike audiences. Those audiences are advertising profiles (art. 4.4 GDPR): I decide them and I am responsible for them. Legal basis: your consent (art. 6.1.a GDPR), which you can withdraw from "Cookie preferences" in the footer.
- Keeping the site secure and available. Technical server logs. Legal basis: legitimate interest (art. 6.1.f GDPR).
Apart from those advertising profiles I do no profiling, and I make no automated decisions that produce legal effects on you or similarly significantly affect you (art. 22 GDPR). I personally review the pre-call analysis and it serves only to guide the conversation.
4. Who I share your data with
I do not sell your data or disclose it to third parties outside the activity, except where legally required. To operate I rely on these providers, which process data on my behalf as processors under a processing agreement per art. 28 GDPR:
- Cal.com, Inc. (United States): call bookings and email appointment reminders. Cal.com processes the booking data on my behalf and, for the operation of its platform (including an error-diagnostics service, Sentry, in the United States), as an independent controller.
- Google (Google Ireland Ltd., with onward processing by Google LLC in the United States): email and the calendar where meetings are recorded.
- Cloudflare, Inc. (United States): website hosting and security.
Meta Platforms Ireland Limited is a different case. For the collection and transmission of data through the Meta Pixel, Meta and I are joint controllers (art. 26 GDPR) under Meta's controller addendum. The essence of that arrangement: I inform you through this policy and handle your rights over the data collected on my site; Meta is the sole controller of how it uses that data within its platform and handles rights over that use; I am responsible for the audiences and campaigns I configure with it. You can exercise your rights against either of us. More information: facebook.com/privacy/policy; ad settings in your Facebook or Instagram account preferences.
The artificial intelligence tools I use to prepare calls run locally on my equipment and involve no disclosure of data to any third party.
5. International transfers
Cal.com, Inc., Cloudflare, Inc., Google LLC and Meta Platforms, Inc. are located in the United States. Cloudflare, Google LLC and Meta Platforms, Inc. are certified under the EU-US Data Privacy Framework, which the European Commission recognises as an adequate safeguard (Decision of 10 July 2023). The transfer to Cal.com relies on the standard contractual clauses approved by the European Commission, incorporated into its processing agreement. You can ask me for a copy of those clauses or more information about the safeguards at contacto@flowsly.ai. Beyond the above I make no transfers outside the European Economic Area.
6. How long I keep your data
- Enquiries and bookings that do not end in a contract: up to one year from the last interaction, unless you ask for deletion earlier. That deletion covers the booking in Cal.com, the emails and the calendar event in Google.
- Clients: for the duration of the relationship and, afterwards, for the limitation periods set by Spanish commercial and tax law (in general, six years for accounting records and four for tax records).
- Meta Pixel data: the
_fbpand_fbccookies expire after 90 days; the rest is kept by Meta under its policy. Your cookie-banner decision is stored only in your browser until you change it or clear the site data. - Technical server logs: kept by Cloudflare for a limited period under its logging policy (in general, less than 30 days). I do not access them or keep copies.
7. Your rights
You can at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw consent you have given without affecting the lawfulness of prior processing. Write to contacto@flowsly.ai stating which right you want to exercise; if there is reasonable doubt about your identity I may ask you to prove it. Exercising these rights is free of charge. I reply within one month at most.
If you believe the processing of your data does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Changes to this policy
I will update this policy when the way I process data changes (for example, if I add a new provider or contact channel) or when the law requires it. The version in force is always the one published on this page.
Last updated: 2 September 2026.