Privacy Policy
Last updated 10 September 2026.
Who we are
FlowBase is a product of BUILTFORBUSINESS LLP ("FlowBase", "we", "us"). This policy explains what personal data we collect through the FlowBase dashboard and API, why, and what rights you have over it. It's written to be consistent with India's Digital Personal Data Protection Act, 2023 (DPDPA) — we process your data as a data fiduciary would be expected to: only what we need, disclosed here, never sold, and never handed to advertisers or trackers.
In short: no third-party trackers, no advertising cookies, no ad networks. We don't run analytics scripts, ad pixels, or session-replay tools on our marketing site or dashboard.
What we collect
- Email address — required to sign in (we use email-only, code-based authentication; we never ask for a password).
- Full name and organization name — collected once, when you create an account.
- Request metadata — IP address, timestamps, and a request ID for every API/dashboard request, used for security, rate limiting, and debugging.
- Audit log entries — a record of sensitive or administrative actions taken on your account, for accountability.
FlowBase offers a range of verification, identity, and document-processing APIs — biometric liveness/face-match, document OCR, PAN/GSTIN/Aadhaar-format identity checks, address/geo verification, watchlist and compliance screening, contact intelligence, e-signature, QR codes, and field verification, among others. If your organization uses any of these, we additionally process whatever you or your end customers submit through them — for example a reference photo, a captured selfie, an uploaded document, device geolocation (only if your customer grants permission), or the resulting verification scores/extracted fields. This processing happens on your instruction, scoped to what your own lawful basis/consent covers for your end users — see "Your responsibility as a customer" below. We do not collect government ID numbers today.
If your organization uses FlowBase Privacy (our consent-management and Data Principal Request tooling), we process, on your instruction and as your processor: the consent decisions and preference-centre activity your end users record, and the content of any access/correction/erasure/grievance requests they submit through it. We do not use this data for any purpose of our own.
How we use it
- To create and authenticate your account (sending sign-in codes by email).
- To operate the service — routing API requests to your organization, enforcing tenant isolation, and rate limiting.
- To maintain security and an audit trail of access to sensitive data.
- To communicate with you about your account or respond to support requests.
We do not sell your personal data.
Who we share it with
We use a small number of infrastructure providers to run the service: an email provider to deliver sign-in codes and verification codes, and a cloud hosting provider to run the database, object storage, and API. These providers process data only to provide their service to us and do not use it for their own purposes. We do not share your data with data brokers or advertisers, and we do not run third-party analytics or advertising trackers anywhere on this site or in the dashboard.
Data retention
Account and organization data is retained while your account is active. Source files that carry your end users' personal data — biometric selfies, the reference photos you upload, uploaded documents, and eSign PDFs (once a signature request reaches a final state) — are automatically deleted 7 days after capture by a daily background job, aligned with data-minimization principles under India's DPDP Act. This is an enforced default, not just a stated policy: an organization can opt in to holding its own files longer, per project, from Settings → Data Retention, if its own compliance obligations require it — see "Your responsibility as a customer" below. The verification/OCR/signature results (match scores, extracted fields, audit timestamps, hashes) are kept regardless, as your audit record; only the underlying image or PDF bytes are ever deleted.
If your organization uses FlowBase Privacy, your own retention policies configured there govern how long your end users' consent/request data is kept — see that product's own documentation for how retention policies and scheduled actions work.
Your rights as a data principal
Consistent with your rights under the DPDP Act, you can request access to, correction of, or erasure of your personal data, or raise a grievance, at any time by emailing support@flowbase.cc. We will verify your identity before acting on a request and respond within a reasonable time.
Grievance Officer: for now, the same address above (support@flowbase.cc) also serves as our grievance contact — we'll publish a dedicated Grievance Officer name/contact here if that becomes required of us under the DPDP Rules.
Your responsibility as a customer
If you use FlowBase's APIs to process data about your own end users (e.g. their documents, identity information, or consent decisions), you — not FlowBase — are responsible for having a lawful basis and any required consent to process that data, and for being the data fiduciary in respect of your own end users under the DPDP Act. FlowBase acts as a processor of the data you submit through the API on your behalf.
Security
Sensitive fields are masked by default in the dashboard. Every request is scoped to your authenticated organization — never a client-supplied identifier — so tenants cannot access each other's data. Access to sensitive data is logged. We rely on our hosting providers' standard security practices for infrastructure and encryption in transit (TLS).
In line with Section 43A of India's Information Technology Act, 2000 and the SPDI Rules, 2011, we maintain reasonable security practices proportionate to the sensitivity of the data we process — tenant isolation, an audit trail on sensitive-data access, TLS in transit, and the automated 7-day file deletion described above. We do not currently hold ISO/IEC 27001 certification.
Cookies & local storage
We do not use advertising or tracking cookies, and we do not embed third-party analytics, ad, or session-replay scripts. The dashboard stores your session tokens in your browser's local storage to keep you signed in — that's the only thing we store client-side.
Changes to this policy
We'll update the date at the top of this page when this policy changes, and post material changes here before they take effect.
Contact
Questions about this policy, or to exercise your rights: support@flowbase.cc