← Back to home

Privacy Policy

Last updated: 20 July 2026

1. Who we are

Flowgate Systems ("Flowgate", "we", "us", "our") is a trading name operated as a partnership based in Eastbourne, United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025, we are the data controller for personal data about our clients (coaches and course creators) and website visitors, and a data processor for the personal data of your leads that we process on your behalf (see section 6).

Contact: info@nextdesignwebsite.com

2. Scope and roles

Flowgate operates on two levels, and our role under data protection law is different for each:

  • Your data (client / account data): we are the controller. This section, and sections 3–5 and 7–13, explain how we use it.
  • Your leads' and call participants' data: where the bot handles Instagram/WhatsApp conversations, captures lead details, or (where enabled) records and analyses your sales calls, you are the controller and Flowgate is the processor acting on your documented instructions. Section 6 explains this and the split of responsibilities.

3. What data we collect

We collect the following categories of personal data:

  • Account information: name, email address, phone number or WhatsApp number.
  • Business information: details about your coaching business, services you offer, target audience, tone, qualification criteria, and (for the notetaker) a per-client currency setting.
  • Integration credentials: your ManyChat API key(s) — separate keys per channel where you connect both Instagram and WhatsApp — stored encrypted at rest using AES-256.
  • Conversation data: Instagram and WhatsApp DM messages processed through ManyChat on your behalf, including lead usernames or contact names, message content, and AI-generated qualification notes.
  • Payment data: billing is handled entirely by Stripe. We do not store card numbers or bank details. We retain your Stripe customer ID and subscription status.
  • Usage data: login timestamps, pages visited within the dashboard, and feature usage for service improvement and security.

Where the relevant features are enabled, we also process, as your processor (section 6), personal data about your leads and about the people on your recorded calls:

  • Lead contact details: the bot may ask a lead for their email address before sending a booking link; where given, it is stored against that conversation and used to match a subsequent booking to the lead.
  • Booking data (notetaker): when a lead books a call through your connected scheduler (Calendly, Cal.com, SavvyCal or OnceHub), we receive the scheduler's booking webhook, which includes the invitee's name, email, the meeting join URL, the scheduled time, and their answers to your booking-form questions (including their answer to the recording-consent question).
  • Call recordings and transcripts (notetaker — only where enabled): where you enable the notetaker and the participant has consented, a recording bot joins the call to capture audio/video, which is transcribed. The transcript is analysed by AI to detect the call outcome (won / lost / follow-up / no-show), any deal value and currency mentioned, and key objections. See section 5.

4. How we use your data and our lawful bases

For data where we are the controller (your account and business data), we process under the following lawful bases (Article 6, UK GDPR):

  • Performance of a contract (Art. 6(1)(b)): to provide the Flowgate service, process DM conversations, qualify leads, send booking links and notifications, and (where enabled) run the notetaker pipeline.
  • Legitimate interests (Art. 6(1)(f)): to improve and secure the service, prevent fraud and abuse, monitor service health, and communicate service updates. Where we rely on legitimate interests we balance our interests against your rights.
  • Consent (Art. 6(1)(a)): for optional marketing communications and for any non-essential cookies. You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): to comply with applicable tax, accounting and regulatory requirements.

When Flowgate processes your leads' and call participants' data as your processor, you are responsible for identifying and documenting the lawful basis for that processing (section 6). We do not determine the purposes of that processing and we do not use it for our own purposes.

5. AI meeting notetaker and call recording

The notetaker is an optional feature that, where you switch it on, records and transcribes the sales calls that leads book with you through your connected scheduler, and uses AI to detect whether the deal closed and for how much. It is off by default for every client and, at the date above, remains disabled pending independent legal sign-off. The following applies wherever it is enabled.

  • How consent is captured: recording consent is collected as a question on your booking form (e.g. "Do you consent to this call being recorded and transcribed to create meeting notes?"). The lead's answer travels back with the booking. Recording is fail-closed: a bot is only ever dispatched where consent is explicitly granted. If consent is declined, missing, or cannot be interpreted, no recording takes place.
  • Named participant: where a recording proceeds, a clearly named bot ("Flowgate Notetaker") joins the call as a visible participant.
  • No biometric processing: Flowgate does not create voiceprints, perform biometric speaker identification, or otherwise process voice for the purpose of uniquely identifying an individual. We transcribe speech to text and analyse the text. We do not process special-category biometric data through this feature.
  • What is produced: an audio/video recording and a transcript (held by our recording sub-processor and in our database), plus an extracted deal record (outcome, any value/currency, objections) shown on your dashboard.
  • Sub-processors and transfers: recording and transcription are provided by Recall.ai, and transcript analysis by OpenAI. Both are US-headquartered providers; see sections 8 and 9.
  • Your role: for recorded calls you are the controller. You are responsible for the lawfulness of recording each call, for informing all participants, and for honouring participant rights and any request to stop or delete. This is important where a participant may be located outside the UK — some jurisdictions require the consent of every party to a call. See section 6.

6. Data about your leads and call participants (Flowgate as processor)

When you connect ManyChat, a scheduler, or enable the notetaker, Flowgate processes personal data about your leads and call participants on your behalf. In this context you are the data controller and Flowgate is the data processor, acting only on your documented instructions and the terms of our agreement.

We process this data solely to deliver the agreed service — qualifying leads, sending booking links, capturing a lead email to match bookings, and (where enabled) recording, transcribing and analysing booked calls. We do not sell it, share it beyond the sub-processors in section 8, or use it to train our own models or build any cross-client data product.

As the controller for this data, you are responsible for:

  • Having and documenting an appropriate lawful basis to process your leads' and participants' data (for example, legitimate interest in responding to enquiries, or consent).
  • Providing a privacy notice to your leads and participants, and, for recorded calls, informing every participant and obtaining any consent required in their jurisdiction.
  • Assessing whether your processing requires a Data Protection Impact Assessment (DPIA) — systematic monitoring and the large-scale or novel use of AI and call recording are the kinds of processing that may require one.
  • Responding to data subject requests (access, erasure, objection, etc.) from your leads and participants. We will assist you in meeting these requests as your processor.

The terms governing our processor role, including the security measures, sub-processor arrangements and our duty to act only on your instructions, are set out in our Data Processing Agreement.

7. Outbound messaging and direct marketing

Where you enable outbound outreach (off by default), the bot can send the first message to someone who has just taken a warm action towards your account — commenting a keyword, following, replying to a story, or clicking a "send message" ad. Flowgate does notsend unsolicited "cold" messages to people who have not engaged with you, and the feature is built to prevent that.

Depending on content and context, an automated opening message may amount to electronic direct marketing under the Privacy and Electronic Communications Regulations 2003 (PECR). You are the sender and the controller for these messages and are responsible for ensuring you have a lawful basis (consent or the "soft opt-in", where its conditions are met) and for honouring any objection or opt-out. Flowgate provides per-lead personalisation, exclusion lists and rate controls to support compliant use, but you remain responsible for how you configure and use outreach.

8. Sub-processors

We use the following sub-processors to deliver the service, each bound by a data processing agreement. A dedicated, maintained list is at flowgate › sub-processors.

  • Supabase — database, authentication and hosting (our project is hosted in the EU / eu-west-1).
  • Vercel (US) — hosting and delivery of the web dashboard and marketing site.
  • DigitalOcean — VPS hosting for the bot cron process.
  • OpenAI (US) — AI processing of DM conversations and (where enabled) call transcripts for lead qualification and deal analysis. OpenAI does not use data submitted via its API to train its models.
  • ManyChat (US) — Instagram and WhatsApp messaging integration.
  • Recall.ai (US) — meeting-recording and transcription for the notetaker (recording storage region: EU). Only used where the notetaker is enabled and consent is granted.
  • Stripe (US/UK/EU) — payment processing.
  • Resend (US) — transactional and notification email (including authentication emails and coach alerts).
  • Twilio (US) — WhatsApp notification delivery to coaches (provisioned; used only where WhatsApp alerts are enabled).

We will give notice of changes to our sub-processors via the sub-processor page and, for material changes, by email or dashboard notice.

9. International transfers

Several of our sub-processors are located in, or transfer data to, the United States. Where personal data is transferred outside the UK, we rely on an appropriate transfer mechanism under the UK GDPR, namely: the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge") where the receiving organisation is certified to it; and otherwise the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary measures where needed.

The specific mechanism relied on for each sub-processor is listed on the sub-processor page. You can request more detail on any transfer safeguard by contacting us.

10. Data retention

  • Account data: retained for the duration of your subscription plus 30 days, unless you request earlier deletion.
  • Conversation and lead data: retained for the duration of your subscription. Deleted within 30 days of account closure.
  • Call recordings and transcripts (notetaker): raw recordings are intended to be deleted promptly after transcription and analysis, retaining only the extracted deal data and (where needed for audit) the transcript, for the duration of your subscription. Recordings held by our recording sub-processor are subject to its retention controls. See section 5 and the open items noted in our DPA.
  • Billing records: retained for 6 years as required by UK tax law (HMRC).
  • Encrypted credentials: deleted upon account closure.

11. Your rights

Under UK GDPR, you have the right to:

  • Access your personal data (Subject Access Request).
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), subject to legal retention requirements.
  • Restrict processing in certain circumstances.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Data portability: receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email info@nextdesignwebsite.com. We will respond within one calendar month. If you are a lead or call participant of one of our clients, please contact that client (the controller) in the first instance; we will assist them in responding.

12. Security

We take reasonable technical and organisational measures to protect your data, including: encryption of sensitive credentials at rest (AES-256), Row Level Security on all database tables, HTTPS-only communication, per-tenant isolation, and regular security audits.

No system is 100% secure. If you discover a vulnerability, please report it to info@nextdesignwebsite.com.

13. Cookies

See our Cookie Policy for details on cookies and similar technologies used on our website.

14. Children

Flowgate is a business-to-business service intended for users aged 16 and over. We do not knowingly collect data from anyone under 16. If we become aware that a user is under 16, we will take steps to delete their account and associated data.

15. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or a dashboard notification. The "last updated" date at the top reflects the most recent revision.

16. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

ico.org.uk/make-a-complaint