Privacy Policy for the “FLOW” APP

Ultimo aggiornamento: v.1 – 18/06/2025

Premise

The FLOW app allows the exchange of virtual business cards between professionals and can be used by both private users and companies for their employees.

  • In the case of private users who use the app independently, FLOW acts as Data Controller of their personal data, subject to all the related obligations set forth in Regulation (EU) 2016/679 (GDPR).
  • When a company uses FLOW to manage the virtual business cards of its employees or collaborators, it assumes the role of Data Controller, with all the obligations set forth in Regulation (EU) 2016/679 (GDPR), including providing a privacy policy and managing data subject rights. In this case, FLOW assumes the role of Data Processor pursuant to Article 28 of the GDPR, processing the data according to the company’s instructions and ensuring the security and confidentiality of the information.

 

Therefore, pursuant to Article 13 of Regulation (EU) 2016/679 (GDPR), this information is provided by FLOW as Data Controller and applies exclusively to private users who use FLOW independently. It describes how the personal data of application users is collected, used, stored, and protected.

 

1.Data controller

The Data Controller – which provides you with this information – is FLOW S.r.l.
Address: Piazzale Filippo il Macedone, 89 00124 Rome
Privacy email: info@flowcard.it
PEC: flow_srl@legalmail.it

 

2.Type of personal data processed

The App processes the following personal data entered directly by the user when creating their virtual business card:

  • Identification data: first name, last name, profile photo
  • Professional data: profession, role, company, work address
  • Contact information: email, telephone number, website
  • Professional social media channels: links to LinkedIn, Instagram, Twitter, Facebook, etc.
  • Other optional content: personal/professional description, portfolio link, online CV
  • Technical data (IP address, device type, operating system, log data, etc.)

 

The provision of technical operational data (e.g., IP address, device type, operating system, log data) occurs automatically when using the App and cannot be refused, as it is strictly necessary for the technical and optimal functioning of the App itself.

The provision of certain personal data (e.g., first name, last name, email address, profession, contact details) is necessary to create a profile and use the basic features of the App, such as generating and exchanging virtual business cards. Without this data, it will not be possible to create an account or use the service.

The provision of additional data—such as links to social media profiles, personal/professional description, profile photo, or other elements freely inserted into your business card—is optional and occurs voluntarily on the part of the user. Processing is based on the consent expressed through the provision of the data. Although optional, provision of data may be necessary to access certain advanced features (e.g., improved visibility in results, targeted networking, multi-channel presentation). Failure to provide consent will not affect the basic use of the app, but may partially limit its functionality. Consent can be revoked at any time by simply modifying or deleting the data from your profile. Revocation does not affect the lawfulness of the processing carried out before its revocation.

 

3.Purpose, legal basis of processing, retention periods

 

 

Data category

Purpose of the processing

Legal basis

Storage timese

Technical data (e.g. IP address, device type, operating system, log data)

Technical operation of the App; system security; abuse prevention

Legitimate interest (art. 6.1.f GDPR)

Up to 12 months after treatment, unless audit or safety requirements are met

 

Identification data (name, surname, profile photo)

Creating a user profile and generating a business card

Performance of the contract (Article 6.1.b GDPR)

For the duration of the relationship and until the account is cancelled

Contact details (email, telephone)

Communication between users; visibility on the business card

Performance of the contract (Article 6.1.b GDPR)

For the duration of the relationship and until the account is cancelled

Professional data (role, company, job description, work address)

Building a professional network; targeted networking

Performance of the contract (Article 6.1.b GDPR)

For the duration of the relationship and until the account is cancelled

Links to professional social networks (e.g. LinkedIn, Twitter, Instagram, Facebook)

Multi-channel connection; extended profile visibility

Consent of the interested party (Article 6.1.a GDPR)

Until consent is withdrawn/voluntary cancellation

Optional content (personal bio, portfolio, online CV)

Profile customization; professional promotion

Consent of the interested party (Article 6.1.a GDPR)

Until consent is withdrawn/voluntary cancellation

Data for marketing purposes (emails for sending newsletters, invitations to events)

Sending promotional or informative communications, if requested

Consent of the interested party (Article 6.1.a GDPR)

Until consent is withdrawn

Anonymous and aggregated data

Statistical analysis and service improvement

Legitimate interest (art. 6.1.f GDPR)

Kept anonymously indefinitely

 

4.Processing Methods
The processing of Users’ Personal Data is carried out using computerized and/or electronic means, adopting appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction.

The Data is processed at the Data Controller’s operating offices and in any other locations where the parties involved in the processing are located. For further information, please contact the Data Controller.

 

5.Communication and dissemination of data
For the purposes set out in point 3 above, your personal data may be disclosed to the following categories of parties: (i) company employees and/or collaborators authorized to process data and instructed by the company; (ii) companies acting as appointed data processors—as well as their employees and/or collaborators authorized to process data and instructed by the data processor. (e.g., IT service providers such as hosting, cloud computing) (iii) The data may be visible to other users of the App only if expressly authorized by the user by a) spontaneously sharing their profile with another user, or b) activating/deactivating their profile visibility settings.

 

6.Accesso tramite servizi di terze parti

L’utente ha la possibilità di accedere o registrarsi all’App anche tramite servizi di autenticazione di terze parti, come ad esempio Google / Gmail o eventuali altri provider, es. Apple, Facebook, LinkedIn

Nel momento in cui l’utente sceglie questa modalità:

  • Personal data transmitted by the third party (e.g., first name, last name, email address, profile photo, user ID) will be processed.
  • Processing is based on the consent provided by the external provider and pursuant to the request for access/registration to the App (Article 6.1.a and 6.1.b of the GDPR).
  • The App will not access other data in the Google account profile or the provider, except as strictly necessary for authentication.
  • The provider remains the independent data controller for data managed through its authentication services.
  • Users are therefore advised to consult the privacy policy of the external provider to learn about the methods, purposes, and retention periods of the data.

 

7.Social Network Links
The user profile may contain deliberately inserted links to social networks or other external sites (e.g., LinkedIn, Facebook, Instagram). Clicking on these links will redirect the user outside the App, where the privacy policies of the respective sites apply. The Data Controller is not responsible for the data processing carried out by these third parties. The collection and use of information by these third parties are governed by their respective privacy policies, to which we encourage you to refer.

 

8.Data transfer outside the EU
Data will not be transferred outside the European Economic Area. Any transfers to non-European countries—in the absence of adequacy decisions from the European Commission—will be based on the “Standard Contractual Clauses” issued by the Commission to ensure proper processing.

 

9.Data Subject Rights
The user may exercise the following rights at any time:

  • Access to data (Article 15)
  • Rectification (Article 16)
  • Erasure (Article 17)
  • Restriction of processing (Article 18)
  • Data portability (Article 20)
  • Objection (Article 21)
  • Withdrawal of consent (Article 7.3)
  • Complaint to the Italian Data Protection Authority (www.garanteprivacy.it)

Requests can be sent to: info@flowcard.it

 

10.Changes to this Policy
This Policy may be updated to reflect regulatory or functional changes to the App. Users will be notified via a notification or in-app update.

+2,000 already trust us

More story views, More Sales.