Privacy notice

Two relationships are described here. In one we process message data on a customer's instructions. In the other we hold the details of people who contact us about our own business.

  • Updated24 August 2026
  • EntityFlowora Media Ltd

Who we are

Flowora Media Ltd is registered in Ireland under company number 712049, with its registered office at 77 Sir John Rogerson's Quay, Dublin 2, D02 VK60, Ireland. Questions about anything on this page go to compliance@flowora.media, which reaches the compliance desk rather than a general inbox.

Where we are a processor

When a licensed operator uses the platform to send messages, that operator is the controller and we are the processor. We act on their documented instructions and on nothing else. In that role we handle:

  • Destination numbers in international form, and the message bodies sent to them
  • Consent records: state, lawful basis, capture source, capture date and change history
  • Delivery receipts, rejection reasons, inbound replies and opt-out keywords
  • Technical metadata such as route, network, timing and message class

We do not build profiles, do not enrich this data with anything bought from elsewhere, and do not use it to train models. It is stored in the residency region the customer chose and is deleted on their schedule, subject to the retention floor described below.

Where we are a controller

For our own business we hold the details of people who contact us, attend a call, or work at a customer or supplier: name, employer, work email, the market they asked about and the correspondence itself. The lawful basis is legitimate interest in running a business-to- business service, and in most cases the contractual necessity of administering an account.

We do not send marketing to consumers and we do not sell contact data to anyone.

Residency and transfers

Each customer nominates Dublin, Frankfurt or Toronto. Message records, consent records and audit trails live in that region and are enforced there at the storage layer. Two transfers are unavoidable and we would rather state them than imply they do not happen:

  • A destination number and message body must reach the network that serves that number, which may be outside the residency region
  • Aggregate volume counts carrying no personal data are used for capacity planning and invoicing

Where a transfer leaves the EEA or the UK it relies on an adequacy decision where one exists, and on standard contractual clauses with a transfer risk assessment where one does not.

Sub-processors

We use a small number of sub-processors: regional cloud hosting in each residency region, the mobile networks and, in aggregated markets, the local partner that reaches them. The current list, with the role and location of each, is available under our processing terms and we give thirty days notice of an addition.

Retention

Message content and delivery records: thirteen months by default, adjustable by the customer. Consent records: kept for as long as the customer's account is active, then for the period their own obligations require. Business contact records: three years from the last meaningful contact. Records we are required by law to keep have a documented floor that overrides a shorter instruction, and we say so at the time rather than silently.

Your rights

If your data reached us through an operator, they are the controller and we will pass your request to them and help them answer it. Where we are the controller you have the usual rights of access, rectification, erasure, restriction, portability and objection. Write to compliance@flowora.media and we will respond inside one month.

You can also complain to a supervisory authority. Ours is the Data Protection Commission in Ireland; you may instead go to the authority where you live or work.

Security

Data is encrypted in transit and at rest. Access is role based, logged and reviewed quarterly, and support tooling is scoped to the same residency boundary as the platform, so an engineer outside the region gets no view rather than a redacted one. We hold ISO 27001 certification, produce a SOC 2 Type II report annually and commission an external penetration test twice a year.

Changes

Material changes are notified to account contacts before they take effect. The date at the top of this page is the last revision.