Effective Date: 11/1/2026
This version replaces the Privacy Policy dated 8 April 2026.This Privacy Policy describes how FlowPath Corporation Inc. ("FlowPath", "we", "us") collects, uses, shares and protects personal information through its website (getflowpath.com) and its facilities-management application (together, the "Service"), where that information is processed, why we are allowed to hold it, how long we keep it, and how you can ask for it, correct it or have it deleted.
Who we are. FlowPath Corporation Inc. is a Delaware corporation with its principal place of business in Atlanta, Georgia, United States. Our postal address is 8735 Dunwoody Place, Suite 13432, Atlanta, GA 30350, USA. For anything to do with personal information, contact privacy@getflowpath.com.
1. Two kinds of personal information — and who is responsible for each
Customer Data. Most personal information in FlowPath is entered by our customers — the organisations that license the Service — and their users: user accounts, requester contact details, work orders, comments, photographs, attachments, location records, and the notifications the Service sends. For Customer Data our customer is the controller (or, in some jurisdictions, the accountable organisation) and FlowPath is its processor or service provider. We process Customer Data only to provide the Service as our customer configures it and on our customer's documented instructions, under our Data Processing Addendum.
If you use FlowPath through your employer, school, landlord, property manager or another organisation, that organisation decides how your information is used and is your first point of contact for questions and requests. We will forward any request we receive to the organisation concerned and help it respond.
FlowPath Business Data. FlowPath is the controller of the personal information it processes for its own purposes: contact and billing details of our customers' administrators and signatories; support conversations; account, security and audit records used to run and secure the Service; product telemetry and error data; information about visitors to our website; prospect and marketing records; and the accounts of people who sign up directly for a free trial or a sandbox. This Privacy Policy is written for FlowPath Business Data and, where it describes how the Service works, for Customer Data too.This Privacy Policy does not apply to third-party services our customers choose to connect to FlowPath (for example HR, procurement, finance, identity or calendar systems), or to our customers' own websites and systems. Those are governed by their providers' and our customers' own notices.
2. What we collect
Provided by you or your organisation. Account information (name, work email address, role, authentication credentials); requester contact details (name, email address, telephone number) where you submit or are named on a maintenance request; the operational content your organisation enters (work orders, assets, schedules, comments, files and attachments, which may contain personal information if a user includes it); vendor and contractor details entered in the vendor portal; support requests sent by email or through the in-application support chat; and, if you contact us commercially, your business contact details.
Generated by use of the Service. Sign-in and session records (including IP address and device information); audit logs of actions taken in the Service (who did what, when, from which IP address); feature-usage and performance data; error reports; and the contents of AI Assistant conversations where your organisation has licensed and enabled that feature.
Collected automatically. Server-side request logs; essential cookies and similar technologies that keep you signed in and the application secure; analytics and marketing cookies on our public website only (see section 9); and, on our public-facing forms (public work-order submission, public calendars, requester magic links and vendor sign-up), the signals Google reCAPTCHA uses to tell people from bots (see section 9).
From payment processing. Where a vendor pays for vendor-portal services, or a customer pays FlowPath by card, payment details are entered directly with our payment processor. FlowPath does not receive or store card numbers.We do not intentionally collect special-category or sensitive personal information (such as health, biometric or precise geolocation data about individuals, government identifiers or payment-card data), and our customer agreements prohibit customers from entering it. Location data in FlowPath describes buildings and facilities, not people.
3. Why we use personal information, and our lawful bases
We use personal information to provide, operate, maintain, secure and support the Service; to authenticate users and administer accounts; to send the notifications the Service is configured to send (email and SMS); to respond to support requests; to monitor performance and errors and fix them; to detect, prevent and investigate fraud, abuse and security incidents; to bill and collect payment; to communicate about the Service (renewals, changes to terms, security notices); to send marketing communications to business contacts who have not opted out; to comply with law; and to establish, exercise or defend legal claims.Where the UK GDPR, the EU GDPR or the Swiss Federal Act on Data Protection applies to FlowPath as a controller, we rely on the following lawful bases: performance of a contract (providing the Service and support to our customers and trial users); legitimate interests (securing and improving the Service, preventing abuse, business-to-business marketing to professional contacts, and running our business), balanced against your interests and rights; consent, where we ask for it (for example non-essential website cookies), which you may withdraw at any time; and legal obligation (tax, accounting and responding to lawful requests). Where we process Customer Data, the lawful basis is our customer's, and we act on its instructions.Where Canadian federal or provincial privacy law applies, we rely on the consent obtained by our customers from their users and on the consent implied by your dealings with us as a business contact, and we limit use to the purposes described here.
We do not sell personal information, do not share it for cross-context behavioural advertising, do not use Customer Data for advertising, and do not use Customer Data or AI conversations to train artificial-intelligence models.
4. Who we share personal information with
We share personal information only as necessary to run the Service, as our customers direct, or as the law requires. Recipients fall into these categories:
Cloud infrastructure providers that host the application, database, file storage, encryption keys and backups.
A container-orchestration and hosting-platform provider that operates our production workloads and web application firewall.
A front-end hosting provider for the static parts of the web application.
Data-replication and analytics providers that maintain the analytics copy of the database behind reporting and the AI Assistant's data tools.
An application performance and error-monitoring provider that receives error and performance samples, access logs and an audit log, with sensitive fields masked before they leave our systems.
Transactional email and SMS providers that deliver the notifications the Service sends.
An in-application support-chat and help-centre provider.
A large-language-model provider, only where a customer has licensed and enabled the optional AI Assistant.
A hosted-search provider that indexes work-order, asset and location text for global search.
A payment processor for vendor-portal billing and FlowPath's own subscription payments.
A bot-protection provider (Google reCAPTCHA) on our public-facing forms.
Professional advisers — lawyers, accountants, auditors, insurers and consultants — under confidentiality.
Public authorities and courts, where required by law, subpoena or court order; we notify the affected customer where the law allows, challenge requests we consider unlawful, and disclose only the minimum required. FlowPath has never received a request from a public authority for customer data.
A successor or acquirer in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to this Privacy Policy.
Anyone our customer directs us to share with, including third-party services the customer connects to FlowPath.Every service provider that processes personal information on our behalf is bound by written data-protection terms. The current list of our sub-processors, with their locations and what each one processes, is provided to customers on request and forms part of our Data Processing Addendum; customers receive 30 days' notice of any change.
5. Where personal information is processed and how it is transferred
United States.
FlowPath is a United States company. All customer instance data — the application, database, file storage, backups and the analytics copy — is stored and processed in United States regions. FlowPath's staff are all based in the United States; there is no offshore development or support.
European Economic Area.
One service provider processes FlowPath's application performance and error-monitoring data in the Netherlands, with backups in Ireland. This is FlowPath's operational telemetry (error and performance samples with request context, access logs and an audit log, with sensitive fields masked at the point of collection), not customer instance data, and it is processed in the EEA only.
If you are in the United Kingdom, the EEA or Switzerland.
Your personal information is transferred to the United States, a country that has not been found to provide equivalent protection for your information and where it may be accessed by public authorities under United States law. For Customer Data, that transfer is protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (for UK data) and by the EU Standard Contractual Clauses with a Swiss rider (for EEA and Swiss data), which are incorporated in our Data Processing Addendum together with a documented transfer risk assessment. For FlowPath Business Data about you, we rely on the same Standard Contractual Clauses with our service providers and, where a transfer is necessary to perform a contract you or your organisation has asked for, on that necessity. FlowPath is not certified to the EU-U.S. Data Privacy Framework or its UK Extension. FlowPath has not appointed a representative in the United Kingdom or the European Union because it does not offer its Service to individuals there or monitor their behaviour; contact privacy@getflowpath.com for anything you would otherwise raise with a representative.
If you are in Canada.
Your personal information is stored and processed in the United States and may be subject to lawful access by United States authorities. Our customers are responsible for any notice their own law requires about processing outside Canada; our Data Processing Addendum, with its Canada annex, is the means by which they ensure comparable protection while FlowPath holds their data.
Quebec: the person in charge of the protection of personal information at FlowPath is Alex Cummings, Chief Executive Officer, reachable at privacy@getflowpath.com. FlowPath communicates personal information outside Quebec, to the United States, and provides customers with the information they need to conduct the privacy impact assessment that Quebec law requires of them before doing so.
6. How long we keep personal information
We keep personal information only as long as needed to provide the Service, meet legal obligations, resolve disputes and enforce our agreements.
Customer instance data: for the life of the customer's subscription. When an authorised administrator asks us to delete users, records, a workspace or the whole account, or when a subscription ends, we delete the data from active production systems within 30 days (including files and attachments) after returning it to the customer if requested.
Copies that remain after deletion, and when they expire. Deletion takes effect in our live systems first. Copies persist for a limited time in the following stores and are removed on these schedules; they are not accessed or used for any other purpose. Database point-in-time backups: 35 days. Daily backups: 14 days; weekly backups: 56 days; monthly snapshots: 7 years. File and attachment archives and infrastructure audit trails: 7 years, held in a locked archive that cannot be altered by the application or by ordinary credentials, so that individual records cannot be selectively removed. The analytics copy of the database and the search indices: deleted records are removed by a nightly job, within 7 days of deletion. Application server and container request logs: 72 hours. Application performance and error-monitoring data: 30 days at the provider, and FlowPath's own export kept for 1 year as a security log. Application and security audit logs: at least 60 days.
AI Assistant conversations and uploads: stored in the same systems as other customer data, on the same schedules. The model provider does not use them for training.
Free trials and sandboxes: a self-serve trial account with no sign-in for 90 days is deleted; a sandbox or demo account that has not become a customer account within 180 days of creation is deleted (unless it is part of an ongoing sales conversation). The job runs monthly and applies to every account regardless of country.
Business contact, billing and contract records: for the relationship plus the period required by tax, accounting and limitation law (generally up to seven years).
Marketing records: until you opt out or we have had no engagement from you for a reasonable period.
Website analytics: per the retention set in our analytics tools.
7. Your rights and how to exercise them
Depending on where you live, you may have the right to: know what personal information we hold about you and receive a copy; correct it; have it deleted; restrict or object to its processing; receive it in a portable format; withdraw consent you have given; opt out of marketing; and complain to a supervisory authority — in the United Kingdom the Information Commissioner's Office, in the EEA your national data protection authority, in Switzerland the Federal Data Protection and Information Commissioner, in Canada the Office of the Privacy Commissioner of Canada or your provincial commissioner (in Quebec the Commission d'accès à l'information), and in the United States your state attorney general where state privacy law applies. We will not discriminate against you for exercising any right.
How to ask.
Email privacy@getflowpath.com (or write to the postal address above) and tell us what you would like us to do. We may need to verify your identity. We respond within one month, or within any shorter period the applicable law requires, and will tell you if we need longer for a complex request.
If your information is Customer Data.
Most requests about Customer Data can be actioned directly by your organisation's FlowPath administrator, who can view, correct and delete users and records inside the Service. If you contact us about Customer Data, we will forward your request to the organisation concerned, tell you we have done so, and assist it in responding; we will not otherwise act on Customer Data without our customer's instruction.
Marketing.
You may opt out of marketing emails at any time using the unsubscribe link in any message or by emailing privacy@getflowpath.com. Service-related messages (for example security notices, renewal notices and changes to terms) will continue for as long as you or your organisation use the Service.
8. AI Assistant
FlowPath offers optional AI-assisted features, including an AI Assistant and AI agent teams, built on third-party large-language-model APIs. They are off by default and are available only where a customer's administrator has licensed and assigned them. When enabled, prompts, the records the assistant retrieves as tool results, and any photographs or documents a user submits for analysis are sent to the model provider under written data-protection terms, in the United States, and are not used to train the provider's models. Documents uploaded for analysis are deleted from the provider by FlowPath after analysis. Conversation history is stored in FlowPath's own databases with the customer's other data.The AI Assistant runs inside FlowPath's infrastructure and enforces the same role-based access controls as the rest of the Service on every interaction — module access, settings access, workspace scoping, role restrictions, restricted user access and location scoping — so it can only see and do what the requesting user could. Actions the assistant proposes are presented for human review and approval before they are executed unless an administrator has deliberately enabled autonomous mode for a given assistant; autonomous agent teams are restricted to a fixed set of operational actions and cannot change user accounts, authentication settings or approval settings. Every proposed and executed action is recorded in the audit trail.
9. Cookies, website analytics and reCAPTCHA
The FlowPath application uses only cookies and similar technologies that are necessary to keep you signed in, protect your session and remember your preferences. Our public website may use analytics and marketing cookies; where the law requires consent for these, we ask for it, and you can manage preferences through your browser or our cookie tool.Our public-facing forms — public work-order submission, public calendars, requester magic links and vendor sign-up — are protected by Google reCAPTCHA. When you use one of those forms your browser communicates directly with Google, which receives your IP address and device and interaction signals for the purpose of distinguishing people from automated traffic, under Google's Privacy Policy (https://policies.google.com/privacy) and Terms of Service (https://policies.google.com/terms). FlowPath receives only a pass/fail token. reCAPTCHA is not used elsewhere in the Service and does not see customer instance data.
10. Security
FlowPath protects personal information with technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher) and at rest (AES-256, including backups), role-based access control enforced server-side, tenant isolation at the application and database layers, least-privilege staff access with multi-factor authentication, intrusion detection and continuous monitoring, security audit logging, a written Information Security Program with an Incident Response Plan, and cyber-risk insurance. FlowPath's Data & Security Overview describes these measures in detail and is available to customers on request. If a security incident affects Customer Data, FlowPath notifies the affected customer without undue delay and within 72 hours of becoming aware, and assists it with any notifications it must make.
11. Children's privacy
FlowPath's Service is designed for use by facilities, operations and administrative staff and is not intended for use by students or children. FlowPath does not knowingly collect personal information from children under 13 in a manner subject to the Children's Online Privacy Protection Act, and does not collect or maintain student personal information or "education records" as defined in the Family Educational Rights and Privacy Act. If we learn that such information has been provided to the Service, we will delete it promptly.
12. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, our service providers, technology or the law. The current version is always posted at getflowpath.com/privacy-policy with its effective date. If a change materially affects how we handle personal information, we will notify customers by email to their contract notice address at least 30 days before it takes effect, except where a change is required by law or regulation, corrects a non-substantive error, or increases your protection, in which case it may take effect when posted.
13. Contact FlowPath Corporation Inc.
Data-protection matters: privacy@getflowpath.com General support: support@getflowpath.com Postal: 8735 Dunwoody Place, Suite 13432, Atlanta, GA 30350, USA Person in charge of the protection of personal information (Quebec): Alex Cummings, Chief Executive OfficerOur Terms of Service are at getflowpath.com/terms-and-conditions. Our Data Processing Addendum, sub-processor list, transfer risk assessment and Data & Security Overview are available to customers on request.
Schedule a demo with our sales team and we can get you started.