Privacy Policy
Version: 5 July 2026
Effective date: 5 July 2026
When Vanderstraeten Serge BV processes personal data on behalf of a customer through the Service, it acts as a processor. In that situation the Data Processing Addendum applies. The Data Processing Addendum forms part of the Terms of Service.
This Privacy Policy explains how Vanderstraeten Serge BV, with registered office at Zwaantje 22, 9940 Evergem, Belgium ("Vanderstraeten Serge BV", "we", "us" or "our"), processes personal data in connection with FlowForth.
FlowForth is a software application for planning, invoicing, communication, employee and client management, automated reminders and integrations such as email, WhatsApp, SMS, Peppol and accounting tools.
FlowForth is operated by Vanderstraeten Serge BV. Vanderstraeten Serge BV may also operate other trade names or business divisions, including Abrillantar and Vanderstraeten-Trading. These other divisions are separate business activities and are not part of the FlowForth Service unless expressly stated otherwise.
1. Scope of This Privacy Policy
This Privacy Policy applies to visitors of our website, customers and prospective customers, users of the Service, employees/contractors/representatives of our customers using the Service, and individuals who contact us for support, sales or administrative purposes.
Where our customer uses the Service to process personal data of its own clients, employees, suppliers or contacts, the customer is usually the controller of that data and we usually act as processor. In that case, the customer's own privacy policy should also be consulted, and the Data Processing Addendum included below applies.
2. Our Role: Controller and Processor
2.1 When We Act as Controller
We act as controller when we determine the purposes and means of processing, for example when we process account owner information, billing and payment information, website visitor data, sales/support communications, security logs, marketing preferences and our own administrative records.
2.2 When We Act as Processor
We act as processor when we process personal data on behalf of our customer through the Service, for example client contact details uploaded by the customer, employee planning data, invoice recipient data, messages and reminders sent by the customer, customer/supplier records and operational data, and Peppol, email, WhatsApp or SMS data processed according to the customer's instructions.
In such cases, the customer is responsible for having a valid legal basis, providing required notices, obtaining required consents and responding to data subject requests. The Data Processing Addendum forms part of the Terms of Service and applies to this processing.
3. Personal Data We Process
Depending on how the Service is used, we may process the following categories of personal data:
Account and user data
- name
- business email address
- telephone number
- company name
- role or function
- login credentials
- user permissions
- account settings
- language and notification preferences
Customer and contact data entered into the Service
- client names
- employee names
- supplier names
- company details
- addresses
- email addresses
- telephone numbers
- VAT numbers
- Peppol identifiers
- customer references
- notes, tags or internal comments
- communication history
Planning and operational data
- appointments
- work schedules
- service locations
- assigned employees
- job descriptions
- task status
- visit history
- time records
- planning changes
- operational notes
Invoicing and payment data
- invoice data
- credit note data
- payment status
- payment reminders
- bank references
- VAT and tax-related data
- accounting references
- Peppol transmission data
- invoice recipient and sender information
Communication data
- emails sent or received through the Service
- WhatsApp messages or message templates
- SMS messages
- automated reminders
- in-app notifications
- delivery status
- read or failure status where available
- message metadata
- support messages
Technical and security data
- IP address
- browser type
- device identifiers
- operating system
- login logs
- activity logs
- error logs
- security events
- API usage
- cookies or similar technologies
- approximate location derived from IP address
4. Purposes of Processing
- providing and operating the Service
- creating and managing accounts
- enabling planning, scheduling and operational workflows
- generating, sending and managing invoices
- enabling Peppol and electronic invoicing integrations
- enabling email, WhatsApp, SMS and other communication channels
- sending automated reminders and notifications where configured by the customer
- providing customer support
- troubleshooting and fixing errors
- securing the Service
- preventing fraud, abuse and unauthorised access
- billing and payment administration
- improving the Service
- analysing usage and performance
- complying with legal obligations
- enforcing our Terms of Service
- communicating about product updates, service notices or administrative matters
- sending marketing communications where permitted
5. Legal Bases for Processing
Where we act as controller, we rely on one or more of the following legal bases:
- Contract: where processing is necessary to provide the Service, manage accounts, process payments or perform an agreement
- Legal obligation: where processing is necessary for tax, accounting, invoicing, security, regulatory or legal compliance
- Legitimate interests: where processing is necessary for business operations, security, service improvement, fraud prevention, support, internal administration or B2B communication, provided these interests are not overridden by the rights and freedoms of individuals
- Consent: where required, for example for certain marketing communications, cookies or optional communication preferences
Where we act as processor, the customer determines the applicable legal basis.
6. Automated Messages, Email, WhatsApp and Reminders
The Service may allow customers to send automated messages and reminders through email, WhatsApp, SMS, Peppol or other channels. These messages may include appointment confirmations, planning updates, service notifications, employee instructions, client notifications, invoice reminders, payment follow-ups, administrative communications, customer service messages, and marketing messages where lawfully configured.
The customer is responsible for ensuring that recipients have been properly informed and that consent has been obtained where required, especially for marketing or non-essential electronic communications.
Recipients may be able to opt out of certain communications. Some operational, transactional or legally required messages may still be sent where permitted by law.
7. WhatsApp and Third-Party Messaging Providers
When WhatsApp or another third-party messaging provider is used, personal data such as phone numbers, message content, metadata, delivery status and template information may be shared with or processed by that provider.
The availability and processing of WhatsApp messages may depend on WhatsApp Business rules, Meta platform terms, approved message templates, recipient consent or opt-in, messaging limits, recipient settings, country-specific rules and technical delivery conditions.
Customers should ensure that their use of WhatsApp and similar channels complies with applicable law and platform rules.
8. Peppol and Electronic Invoicing
Where the Service is used for Peppol or electronic invoicing, invoice data may be exchanged with Peppol access points, invoice recipients, accounting software, public authorities where applicable, and other technical service providers involved in e-invoice transmission.
Data processed for this purpose may include sender and recipient details, company and VAT information, Peppol identifiers, invoice lines, amounts, tax details, payment references, document metadata, and delivery/validation status.
Customers remain responsible for the correctness, legality and retention of their invoices and accounting records.
9. Cookies and Similar Technologies
The Service uses cookies and similar local storage technologies only where strictly necessary to operate the Service or to remember your preferences. Specifically, we use them for:
- Authentication, session management and security — a session cookie keeps you signed in and protects your account, and short-lived browser storage preserves the page you were on across the sign-in redirect.
- Remembering your preferences — your chosen language, light or dark theme, navigation layout, and the filters and sort order you last applied are stored locally in your browser so the Service returns as you left it.
We do not use advertising or marketing cookies, and we do not use third-party analytics or cross-site tracking cookies. Because we place no non-essential cookies, no cookie consent banner is presented. You can still clear or block this storage through your browser settings, though doing so may sign you out or reset your preferences.
If we introduce analytics, performance monitoring or marketing technologies in the future, we will update this Privacy Policy and, where required, ask for your consent before any non-essential cookies are placed.
10. Sharing of Personal Data
We may share personal data with hosting providers, cloud infrastructure providers, email delivery providers, WhatsApp/Meta or other messaging providers, SMS providers, Peppol access points, payment processors, accounting and invoicing integrations, analytics and monitoring providers, customer support tools, professional advisers, public authorities where legally required, business partners where necessary to provide requested integrations, and potential buyers, investors or successors in case of corporate restructuring, merger or sale.
We only share personal data where necessary and subject to appropriate contractual, technical and organisational safeguards. A current list of the sub-processors we engage is available on our Sub-processors page.
11. International Transfers
Some service providers may process personal data outside the European Economic Area. Where personal data is transferred outside the EEA, we will use appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, additional technical and organisational measures, or other lawful transfer mechanisms under applicable data protection law.
12. Retention Periods
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.
Typical retention periods include account data for the duration of the account and a reasonable period after termination; billing and accounting records for the legally required retention period; support communications for as long as needed for support, quality and legal purposes; security logs for a limited period unless needed to investigate abuse or security incidents; Customer Data according to the customer agreement, Data Processing Addendum or customer settings; and marketing data until withdrawal of consent or objection, unless retention is needed to maintain a suppression list.
Backups may be retained for a limited additional period for security and continuity purposes.
13. Security Measures
We use reasonable technical and organisational measures to protect personal data, including where appropriate access controls, authentication, role-based permissions, encryption in transit, secure hosting, logging and monitoring, backup procedures, vulnerability management, confidentiality obligations, supplier due diligence and incident response procedures.
No system is completely secure. Customers and users are responsible for protecting their own login details, devices and account access.
14. Data Subject Rights
Subject to applicable conditions and limitations, individuals may have the right to access their personal data, correct inaccurate data, delete personal data, restrict processing, object to processing, withdraw consent, receive data in a portable format, object to direct marketing, and lodge a complaint with a supervisory authority.
Where we process personal data as processor for a customer, we may refer the request to the relevant customer or assist the customer in handling the request in line with the Data Processing Addendum, which forms part of the Terms of Service.
Requests can be sent to support@flowforth.app. We may need to verify the identity of the requester before responding.
15. Direct Marketing
We may send marketing communications to business contacts where permitted by law. Where consent is required, we will ask for consent.
Recipients can opt out of marketing communications at any time by using the unsubscribe link, replying to the message, or contacting us at support@flowforth.app.
Opting out of marketing does not prevent us from sending service, security, billing, contractual or legally required communications.
16. Children
The Service is not intended for children and should not be used by individuals under 16 years old. We do not knowingly collect personal data from children.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will publish the updated version through the Service or our website and update the effective date. Where changes are material, we may notify customers by email, in-app notification or another appropriate method.
18. Contact Details
For privacy questions or data protection requests, contact:
Vanderstraeten Serge BV Zwaantje 22, 9940 Evergem, Belgium Email: support@flowforth.app Company number: 0886.954.241 VAT number: BE0886.954.241
If you are a client, employee, supplier or contact of one of our customers using FlowForth, the relevant customer may be the controller of your personal data. In that case, you may also need to contact that customer directly for privacy-related requests.
19. Supervisory Authority
Individuals also have the right to lodge a complaint with their local data protection authority. For Belgium, this is the Gegevensbeschermingsautoriteit / Autorité de protection des données.