FlowLeap

Legal

Privacy Policy

This policy explains what personal information FlowLeap processes, why, and the rights available to you. It is aligned with the Protection of Personal Information Act (POPIA) and the General Data Protection Regulation (GDPR).

Who we are

FlowLeap provides AI colleagues that execute recurring accounting workflows for accounting firms. Our registered entity details and address are set out in the site footer.

For personal information we process on our own behalf — for example, enquiries submitted through this website — FlowLeap is the responsible party (controller). For personal information contained in client data processed inside a firm's workflows, the accounting firm is the responsible party and FlowLeap acts as an operator (processor) on its documented instructions.

What we collect

Enquiry and booking details: your name, firm name, role, number of staff, work email, phone number and the workflow you tell us costs the most time.

Chat details: if you start a conversation with our assistant, the messages you send and the contact details you provide.

Usage data: pages visited, referrer and approximate location derived from your IP address, collected through analytics.

Workflow data: where your firm has engaged FlowLeap, the ledger records, emails and documents your firm authorises us to process for the agreed workflows.

Why we process it

To respond to enquiries and arrange calls, on the basis of your consent or our legitimate interest in responding to a business enquiry.

To provide the service under our contract with your firm, including executing agreed workflows and maintaining the audit trail.

To keep the service secure, to meet legal obligations, and to improve the product in aggregate.

We do not sell personal information, and we do not use client data to train general-purpose models.

Who we share it with

Sub-processors that host and operate the service, including cloud infrastructure, database, email and model providers, each under contractual confidentiality and security obligations.

Systems you connect to your workflows — for example your ledger, email or document store — accessed only through the scopes you grant.

Authorities, where we are legally required to disclose.

A current list of sub-processors is available to firms on request.

International transfers

Some sub-processors are located outside South Africa and the EEA. Where personal information is transferred, we rely on lawful transfer mechanisms such as Standard Contractual Clauses together with appropriate technical safeguards.

Retention

Enquiry and chat records are kept for as long as needed to deal with the enquiry and for a reasonable period afterwards for record-keeping.

Workflow data is retained for the period set out in the firm's agreement, and deleted or returned on termination or on written request.

Security

Access is scoped per workflow through OAuth-based connections and can be revoked at any time. Firm data is isolated, actions are logged in a full audit trail, and access to production systems is restricted and reviewed. Our security practices are described in more detail on the Security page.

Your rights

You may request access to your personal information, correction or deletion, restriction of or objection to processing, and a copy in a portable format. You may also withdraw consent where processing is based on consent.

To exercise a right, email support@flowleap.ai. You may also lodge a complaint with the South African Information Regulator or your local supervisory authority.

Changes

We will update this policy when our processing changes and will note the effective date here. Material changes affecting firms are communicated directly.