Flowstates messaging platform logo

    Legal

    Privacy Policy

    Last Revised: 11/05/2026Effective Date: 12/05/2026

    This Privacy Policy describes how Flowstates Inc, located at 330 Madison Avenue, 27th Floor, New York, NY 10017, United States, SR: 20223077628, EIN: 88-3465626 ("Flowstates," "we," "us," or "our"), collects, uses, discloses, stores, transfers, and protects Personal Data.

    Flowstates owns and provides flowstates.net, which together comprise a proprietary software-as-a-service marketing platform for sending SMS, RCS, and other electronic messages, including A2P application-to-person messages (the "Flowstates Services").

    We take privacy seriously and have designed our internal operations and the Flowstates Services with data protection, security, and responsible communications practices in mind.

    01Contact Details

    Controller / Business / Responsible Entity:

    Flowstates Inc
    330 Madison Avenue, 27th Floor
    New York, NY 10017
    United States

    Privacy Contact / Data Protection Officer:

    Email: dataprotectionofficer@flowstates.net

    For privacy rights requests, data protection questions, complaints, or Colombian consultas or reclamos, please contact us using the email address above.

    02Scope of This Privacy Policy

    This Privacy Policy applies to Personal Data we process when:

    • you visit our website;
    • you create or use a Flowstates account;
    • you communicate with us;
    • you receive customer support;
    • you subscribe to our marketing communications;
    • you interact with our cookies, pixels, or similar technologies;
    • you are a business customer, supplier, partner, or representative of one; or
    • your Personal Data is processed through the Flowstates Services on behalf of one of our Customers.

    This Privacy Policy does not replace any Data Processing Agreement, Customer agreement, messaging terms, or platform-specific terms that apply to our Customers.

    03Our Role: Controller, Processor, Service Provider, or Encargado

    Flowstates may process Personal Data in different roles depending on the context.

    3.1 Where Flowstates Acts as Controller

    Flowstates acts as a controller when we determine the purposes and means of processing Personal Data, including when we process account registration information, billing information, website data, support records, business contact data, marketing communications, and security logs for our own business purposes.

    3.2 Where Flowstates Acts as Processor or Service Provider

    Flowstates acts as a processor, service provider, or contractor when we process Personal Data on behalf of our Customers through the Flowstates Services. In that context, the Customer determines the purposes and means of processing, and Flowstates processes the data only on the Customer's documented instructions, under the applicable Data Processing Agreement, Terms of Service, and applicable law.

    3.3 Colombian Law Roles

    For purposes of Colombian data protection law, Flowstates may act as a Responsable del Tratamiento when it determines the purposes and means of processing, or as an Encargado del Tratamiento when it processes Personal Data on behalf of a Customer.

    04Key Definitions

    Customer
    a business or organization that registers for or uses the Flowstates Services.
    End User
    an individual customer, contact, subscriber, website visitor, or recipient whose data is processed by a Flowstates Customer through the Flowstates Services.
    End User Messages
    SMS, RCS, or other electronic messages sent by Customers to End Users through the Flowstates Services.
    Personal Data or Personal Information
    information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an identified or identifiable person, household, or device.
    Processing
    any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, deletion, or analysis.
    Sensitive Personal Data
    Personal Data treated as sensitive under applicable law, which may include health data, biometric data, precise geolocation, government identifiers, account login credentials, racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, sexual orientation, children's data, or other protected categories.
    Data Processing Agreement or DPA
    the agreement governing Flowstates' processing of Personal Data on behalf of a Customer.

    05Personal Data We Process as Controller

    The table below describes the main categories of Personal Data we process as controller.

    CategoryExamplesSourcesPurposesLegal Basis (GDPR)Retention
    Account registration dataName, email, job title, company name, address, country, login detailsYou, your employer, account administratorsCreate and manage accounts, provide services, authenticate usersPerformance of contract; legitimate interestsAccount duration plus a defined post-closure period
    Business customer dataBusiness representative names, emails, phone numbers, role, company detailsYou, your employer, public business sourcesManage customer relationships, service notices, contractsPerformance of contract; legitimate interestsBusiness relationship plus a defined period
    Payment method dataCard details, billing information, payment statusYou, payment processorsProcess payments, prevent fraud, manage subscriptionsPerformance of contract; legal obligationsFlowstates does not store full card details; processors retain under their own policies
    Invoicing and tax dataNames, emails, billing address, tax info, invoice recordsYou, your employer, payment processorsIssue invoices, accounting, tax complianceLegal obligations; legitimate interestsPeriod required by tax, accounting, and legal requirements
    Customer support recordsName, email, phone, support messages, screenshots, filesYou, support interactionsRespond to inquiries, troubleshoot, improve servicesPerformance of contract; legitimate interestsDefined period after ticket closure
    Marketing data (existing customers)Name, business email, company, role, preferences, engagementYou, account activity, marketing toolsProduct updates, newsletters, offers, service infoLegitimate interests; consent where requiredUntil unsubscribe or objection, plus suppression records
    Marketing data (non-customers)Name, email, company, role, preferences, consent recordsYou, forms, events, referrals, public business sourcesNewsletters, product info, event invitations, promotionsConsent; legitimate interests where permittedUntil unsubscribe or objection, plus suppression records
    Website and usage dataIP, device IDs, browser, session data, pages viewed, logsBrowser, device, cookies, analytics toolsOperate website, understand usage, secure platform, prevent fraudLegitimate interests; consent where requiredDefined retention based on log type
    Cookie, pixel, tracking dataCookie IDs, IP, visit duration, interactions, ad IDs, inferred interestsBrowser, device, cookies, pixels, analytics partnersAnalytics, advertising, attribution, fraud preventionConsent where required; legitimate interests for strictly necessaryAs described in our Cookie Policy
    Security and fraud dataIPs, authentication logs, access logs, abuse indicators, device dataUse of services, security toolsProtect accounts, prevent DDoS, fraud, spam, abuseLegitimate interests; legal obligationsDefined retention; longer where needed for investigation
    Legal and compliance recordsContracts, consents, opt-outs, complaints, rights requests, disputesYou, Customers, service providers, authoritiesDemonstrate compliance, respond to legal requests, enforce termsLegal obligations; legitimate interestsAs long as necessary for compliance and audit

    06Personal Data We Process on Behalf of Customers

    Customers use the Flowstates Services to send SMS, RCS, and other electronic messages to End Users. In this context, the Customer is generally the controller or business, and Flowstates is generally the processor, service provider, contractor, or encargado.

    Customers are responsible for:

    • providing lawful notices to End Users;
    • obtaining and documenting all legally required consents and authorizations;
    • determining the lawful basis or authorization for processing;
    • ensuring that their messages are lawful and non-deceptive;
    • honouring opt-outs and suppression requests;
    • maintaining accurate contact lists;
    • ensuring that End User data submitted to Flowstates may lawfully be processed; and
    • complying with applicable SMS, RCS, email, consumer protection, marketing, and privacy laws.

    Flowstates processes End User Personal Data only to provide the Flowstates Services, comply with Customer instructions, maintain security and service integrity, prevent abuse, comply with law, and perform related activities described in our DPA.

    6.1 End User Data Processed Through the Flowstates Services

    Data TypeExamplesProcessing Purpose
    Basic End User informationName, phone, IP, delivery address, country prefixPersonalization, delivery, routing, fraud prevention, compliance
    Event and user actionsPurchase, cart abandoned, newsletter subscribed, checkout activitySegmentation, campaign triggering, personalization, analytics
    Storefront / website dataDiscount codes, platform type, order metadata, abandoned cart URLPlugin functionality, cart recovery, campaign delivery
    Plugin and widget dataPlugin version, widget version, configurationCompatibility, debugging, troubleshooting, maintenance
    Cart and transaction dataCart value, contents, payment method type, coupon, cart URLCart recovery, personalization, analytics, service delivery
    Consent and preference dataMarketing opt-ins, SMS consent, unsubscribe status, suppressionCompliance evidence, opt-out management, suppression
    Traffic and delivery dataRouting, timestamps, delivery status, carrier data, billing metadataMessage delivery, billing, analytics, troubleshooting
    SMS/RCS message contentMessage body, templates, campaign contentDelivering messages configured by the Customer
    Security logsIPs, access logs, abuse indicatorsPreventing fraud, spam, DDoS, unauthorized access, misuse

    Some data may be aggregated or de-identified. Where information can reasonably be linked to an individual, household, or device, we treat it as Personal Data or Personal Information as required by applicable law.

    07Customer Messaging Responsibilities

    Because the Flowstates Services are used for SMS, RCS, and other electronic messaging, Customers must comply with all applicable messaging, privacy, marketing, telecommunications, consumer protection, and anti-spam laws.

    Customers must not use the Flowstates Services to send unlawful, deceptive, misleading, harassing, unauthorized, or non-compliant messages.

    Customers must obtain and maintain evidence of all required consents and authorizations before sending messages. Customers must also provide legally required disclosures, identify the sender where required, include or support required opt-out instructions, and honour opt-outs, revocations, STOP requests, unsubscribe requests, suppression requests, and other legally valid objections.

    Flowstates may suspend, restrict, or terminate messaging activity where we believe it is necessary to protect End Users, prevent abuse, preserve service integrity, comply with law, respond to carrier or regulator requirements, or enforce our Terms of Service.

    08Sensitive Personal Data

    Flowstates does not require Customers to submit Sensitive Personal Data through the Flowstates Services.

    Customers must not submit Sensitive Personal Data, protected health information, children's data, biometric data, government identifiers, or other regulated data to the Flowstates Services unless:

    • the Customer has obtained all legally required consent or authorization;
    • such processing is permitted by the applicable agreement with Flowstates;
    • the Customer has completed any required additional documentation, including a Business Associate Agreement where HIPAA applies; and
    • Flowstates has confirmed that the relevant Flowstates Services are configured to support that processing.

    The Flowstates Services are not intended for the processing of Protected Health Information under HIPAA unless Flowstates and the Customer have entered into a separate Business Associate Agreement.

    Where we process Sensitive Personal Data as controller, we do so only where permitted by applicable law and, where required, with explicit consent.

    09Children's Privacy

    The Flowstates Services are intended for business customers and are not directed to children or minors under 18.

    We do not knowingly collect Personal Data from children under 13. Customers must not use the Flowstates Services to send marketing messages to children or minors unless they have obtained all legally required consents and authorizations.

    For Colombian data subjects, the processing of Personal Data of children and adolescents is restricted and must respect their superior interests and fundamental rights.

    If you believe a child or minor has provided Personal Data to Flowstates, please contact us at dataprotectionofficer@flowstates.net.

    10Cookies, Pixels, and Similar Technologies

    We use cookies, pixels, tags, SDKs, and similar technologies on flowstates.net and within the Flowstates Services.

    These technologies may be used for:

    • strictly necessary website and service functionality;
    • account authentication;
    • security and fraud prevention;
    • analytics and performance measurement;
    • remembering preferences;
    • advertising, retargeting, and attribution; and
    • understanding how users interact with our website and services.

    We may use technologies provided by analytics and advertising partners, including Google and Meta/Facebook, subject to our configuration choices and applicable law.

    Where required by law, we obtain consent before using non-essential cookies, pixels, or similar technologies. You may manage cookie preferences through our .

    11How We Share Personal Data

    We may disclose Personal Data to the following categories of recipients:

    • Flowstates staff and authorized personnel, subject to access controls and confidentiality obligations;
    • hosting, cloud infrastructure, and database providers;
    • SMS, RCS, telecommunications, carrier, and message delivery providers;
    • payment processors and billing providers;
    • customer support and communications tools;
    • analytics and performance measurement providers;
    • advertising and marketing partners, where permitted by law and subject to your choices;
    • security, fraud prevention, and abuse detection providers;
    • professional advisers, including lawyers, accountants, auditors, and insurers;
    • public authorities, courts, regulators, law enforcement, or other third parties where required or permitted by law;
    • parties involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar corporate transaction; and
    • Customers, where we process End User data on their behalf.

    We do not sell Personal Data for money. However, our use of certain advertising cookies, pixels, or similar technologies may be considered a "sale," "sharing," or use for targeted advertising under some U.S. state privacy laws, including California law. See the California Privacy Notice below for more information and your choices.

    12Subprocessors and Service Providers

    We use third-party subprocessors, service providers, contractors, and vendors to help provide, secure, maintain, and improve the Flowstates Services.

    Our subprocessors are required to process Personal Data under contract and only for the purposes authorized by Flowstates or our Customers. We require subprocessors to use appropriate confidentiality, security, and privacy safeguards.

    Where required by our DPA, we provide Customers with notice of new subprocessors and an opportunity to object.

    13International Transfers

    Our primary data servers are hosted in Frankfurt, Germany. Personal Data may also be processed in the United States, the European Economic Area, and other countries where Flowstates or its subprocessors operate.

    Where we transfer Personal Data from the EEA, UK, Switzerland, Colombia, or another jurisdiction that restricts international transfers, we use appropriate safeguards where required, such as:

    • Standard Contractual Clauses;
    • the UK International Data Transfer Agreement or UK Addendum;
    • adequacy decisions, where applicable;
    • data processing or transmission agreements;
    • contractual safeguards required under Colombian data protection law; or
    • another lawful transfer mechanism.

    You may contact us at dataprotectionofficer@flowstates.net for more information about the transfer safeguards we use.

    14Data Retention

    We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

    Data CategoryRetention Period or Criteria
    Account registration dataAccount duration plus a defined post-closure period
    Business customer relationship dataBusiness relationship plus a defined period
    Billing and invoice recordsPeriod required by tax, accounting, and legal requirements
    Payment card dataProcessed by payment providers; not stored by Flowstates
    Customer support recordsDefined period after ticket closure unless needed for disputes, security, or legal purposes
    Marketing contactsUntil unsubscribe, withdrawal of consent, or objection, plus suppression records
    Consent and opt-out recordsAs long as needed to demonstrate compliance and maintain suppression lists
    Usage and analytics logsDefined retention based on log type
    Security logsDefined retention; longer where needed for investigation, fraud prevention, or legal claims
    SMS/RCS delivery and traffic logsDefined retention; longer where required for billing, compliance, abuse prevention, or legal claims
    End User data processed on behalf of CustomersAs instructed by the Customer and under the DPA; generally deleted within 15 business days after account termination unless legally required or contractually permitted to retain longer
    Cookies and pixelsAs described in our Cookie Policy
    BackupsDeleted or overwritten according to our backup cycle

    Where Flowstates acts as a processor, service provider, contractor, or encargado, deletion may be subject to Customer instructions, legal obligations, backup cycles, security requirements, or dispute preservation needs.

    15Data Security

    We use reasonable and appropriate technical, organizational, and administrative safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.

    These safeguards may include:

    • encryption in transit and, where appropriate, at rest;
    • secure hosting environments;
    • access controls and role-based permissions;
    • authentication controls;
    • network security measures;
    • logging and monitoring;
    • staff confidentiality obligations;
    • vendor security review;
    • incident response procedures; and
    • physical security measures where relevant.

    No method of transmission or storage is completely secure. We use safeguards designed to protect Personal Data, but we cannot guarantee absolute security.

    16Your Privacy Rights

    Depending on where you live and the law that applies, you may have rights over your Personal Data.

    These may include the right to:

    • request access to your Personal Data;
    • request a copy of your Personal Data;
    • request correction of inaccurate Personal Data;
    • request deletion of Personal Data;
    • request restriction of processing;
    • object to processing;
    • withdraw consent where processing is based on consent;
    • request data portability;
    • opt out of marketing communications;
    • opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
    • limit the use or disclosure of Sensitive Personal Information where applicable;
    • appeal certain rights request decisions where applicable; and
    • lodge a complaint with a supervisory authority or regulator.

    To exercise your rights, contact: dataprotectionofficer@flowstates.net

    We may need to verify your identity before responding to your request. We will respond within the time required by applicable law.

    Where we process Personal Data on behalf of a Customer, we may forward your request to the relevant Customer or instruct you to contact the Customer directly. We will assist Customers with rights requests as required by our DPA and applicable law.

    17GDPR / EEA / UK / Swiss Privacy Rights

    Where the GDPR, UK GDPR, or Swiss data protection law applies, you may have the following rights:

    • right of access;
    • right to rectification;
    • right to erasure;
    • right to restriction of processing;
    • right to data portability;
    • right to object;
    • right to withdraw consent at any time, without affecting processing carried out before withdrawal;
    • right not to be subject to automated decision-making producing legal or similarly significant effects, where applicable; and
    • right to lodge a complaint with your local data protection supervisory authority.

    Where we rely on legitimate interests, you may object to processing. Where we rely on consent, you may withdraw consent at any time.

    We do not use Personal Data for automated decision-making that produces legal or similarly significant effects without appropriate notice and lawful basis.

    18U.S. State Privacy Rights

    Residents of certain U.S. states may have additional privacy rights, depending on applicable law. These may include rights to access, confirm processing, delete, correct, obtain a portable copy of Personal Information, opt out of targeted advertising, opt out of sale, opt out of certain profiling, restrict certain uses of Sensitive Personal Information, and appeal a denied request.

    To exercise U.S. state privacy rights, contact: dataprotectionofficer@flowstates.net

    Where required, we will provide an appeal process if we deny your request.

    19California Privacy Notice

    This California Privacy Notice applies to California residents and supplements the rest of this Privacy Policy. It applies to the extent Flowstates is a "business" under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

    19.1 Notice at Collection

    CategoryExamplesPurposesSold or Shared?Retention
    IdentifiersName, email, phone, IP, account ID, cookie IDAccount, service, support, security, marketing, analyticsMay be shared via ad cookies/pixels; not sold for moneySee Section 14
    Cal. Civ. Code § 1798.80 infoBusiness contact, billing, payment-related infoBilling, contracts, account admin, complianceNot sold for money; may be disclosed to service providersSee Section 14
    Commercial informationSubscriptions, invoices, purchases, usage, campaign metadataProvide services, billing, analytics, support, complianceNot sold for money; may be disclosed to service providersSee Section 14
    Internet/network activityIP, browser, device, interactions, service logsSecurity, analytics, fraud prevention, advertisingMay be shared for cross-context behavioral advertisingSee Section 14
    Geolocation dataApproximate location from IP or phone country prefixSecurity, localization, country prefix detection, complianceNot sold for money; may be disclosed to service providersSee Section 14
    Professional/employment infoJob title, company, business roleAccount admin, sales, support, marketingNot sold for money; may be disclosed to service providersSee Section 14
    InferencesMarketing interests, engagement, interaction patternsAnalytics, marketing, advertising, service improvementMay be shared for cross-context behavioral advertisingSee Section 14
    Sensitive Personal InformationLogin credentials; payment info processed by providersAccount security, authentication, payment processingNot sold for money; not used to infer characteristicsSee Section 14

    We do not use or disclose Sensitive Personal Information for purposes that require a right to limit under California law, unless we provide the required notice and choice.

    19.2 Categories of Sources

    We collect Personal Information from:

    • you;
    • your employer or organization;
    • account administrators;
    • Customers;
    • End Users' interactions with Customer websites or messages;
    • browsers and devices;
    • cookies, pixels, analytics tools, and advertising technologies;
    • payment processors;
    • service providers and subprocessors;
    • communications with us; and
    • publicly available business sources.

    19.3 Business or Commercial Purposes

    We collect, use, disclose, and, where applicable, share Personal Information for:

    • providing the Flowstates Services;
    • account creation and administration;
    • authentication and security;
    • billing and payment processing;
    • customer support;
    • SMS, RCS, and electronic message delivery;
    • analytics and service improvement;
    • marketing and advertising;
    • cookie-based retargeting and attribution;
    • fraud, spam, DDoS, and abuse prevention;
    • legal, tax, accounting, and compliance purposes;
    • enforcing agreements and policies; and
    • responding to legal requests.

    19.4 Disclosures for Business Purposes

    In the preceding 12 months, we may have disclosed identifiers; § 1798.80 information; commercial information; internet or network activity; approximate geolocation data; professional or employment-related information; inferences; and Sensitive Personal Information where necessary for account security, authentication, payment processing, or compliance — to service providers, contractors, subprocessors, payment processors, hosting providers, telecommunications and messaging providers, support tools, analytics providers, security providers, professional advisers, and legal authorities.

    19.5 Sale or Sharing of Personal Information

    We do not sell Personal Information for money.

    We may "share" the following categories for cross-context behavioral advertising through advertising cookies, pixels, or similar technologies:

    • identifiers, such as cookie IDs, device identifiers, IP addresses, and similar online identifiers;
    • internet or network activity information, such as website interactions and page views; and
    • inferences, such as advertising or marketing interests.

    You may opt out of sale or sharing by managing your .

    We also process legally recognized opt-out preference signals, such as Global Privacy Control, where required by law. Where your browser or device sends a valid opt-out preference signal, we will treat it as a request to opt out of sale or sharing for that browser or device. If you are logged into your account and we can associate the signal with your account, we may apply the opt-out to your account as required by law.

    We do not have actual knowledge that we sell or share Personal Information of consumers under 16 years of age.

    19.6 California Rights

    • know what Personal Information we collect, use, disclose, sell, or share;
    • access specific pieces of Personal Information;
    • delete Personal Information, subject to exceptions;
    • correct inaccurate Personal Information;
    • opt out of sale or sharing;
    • limit use or disclosure of Sensitive Personal Information where applicable;
    • not receive discriminatory or retaliatory treatment for exercising privacy rights; and
    • use an authorized agent to submit a request.

    19.7 How to Exercise California Rights

    Email: dataprotectionofficer@flowstates.net

    We will verify your request by matching the information you provide with information we maintain. We may request additional information where necessary to verify your identity or authority to act on behalf of another person.

    Authorized agents may submit requests on behalf of California residents. We may require proof of authorization and may ask the resident to verify their identity directly with us unless an exception applies.

    19.8 Response Timelines

    We will respond to California privacy requests within the period required by law. For requests to know, access, delete, or correct, we generally confirm receipt within 10 business days and respond within 45 calendar days, unless an extension is permitted. For opt-out requests, we will comply as soon as reasonably practicable and within the legally required period.

    20Colombian Privacy Notice

    This section applies to Personal Data processing subject to Colombian data protection law, including Law 1581 of 2012 and related regulations.

    20.1 Responsible Entity

    Responsable del Tratamiento:
    Flowstates Inc
    330 Madison Avenue, 27th Floor
    New York, NY 10017
    United States
    Email: dataprotectionofficer@flowstates.net

    20.2 Purposes of Processing

    • providing and operating the Flowstates Services;
    • managing accounts and business relationships;
    • delivering SMS, RCS, and other electronic messages;
    • providing customer support;
    • billing, accounting, and tax compliance;
    • fraud, spam, DDoS, and abuse prevention;
    • security monitoring and incident response;
    • analytics and service improvement;
    • marketing communications where legally permitted;
    • compliance with legal, regulatory, judicial, or contractual obligations;
    • responding to consultations, claims, complaints, and rights requests; and
    • any other purpose disclosed at the time of collection or authorized by the data subject.

    20.3 Authorization

    Where required by Colombian law, we will request prior, express, and informed authorization for the processing of Personal Data. Authorization may be obtained in writing, electronically, orally, by affirmative conduct, or by another mechanism that allows later consultation of the authorization.

    When requesting authorization, we will inform data subjects of:

    • the Personal Data to be collected;
    • the purposes of processing;
    • their rights as data subjects;
    • the identity, address, email, and telephone number of Flowstates;
    • the optional nature of providing Sensitive Personal Data or children's/adolescents' data, where applicable; and
    • how to access this Privacy Policy.

    20.4 Sensitive Data

    The provision of Sensitive Personal Data is optional unless an exception applies under law. We will not condition any activity on the provision of Sensitive Personal Data unless legally permitted.

    Where Sensitive Personal Data is processed, we will inform the data subject which data is sensitive, the purpose of processing, and the optional nature of providing such data, and we will obtain express consent where required.

    20.5 Children and Adolescents

    Processing Personal Data of children and adolescents is restricted. Where such processing is permitted, it must respect the superior interests of the child or adolescent and their fundamental rights.

    20.6 Colombian Data Subject Rights

    • know, update, and rectify their Personal Data;
    • request proof of authorization granted for processing, unless an exception applies;
    • be informed, upon request, about how their Personal Data has been used;
    • file complaints with the Superintendencia de Industria y Comercio after completing the applicable consultation or claim process with Flowstates;
    • revoke authorization and/or request deletion of Personal Data where applicable;
    • access their Personal Data free of charge; and
    • exercise any other right provided under Colombian law.

    20.7 Procedure for Consultas and Reclamos

    Privacy / Data Protection Office
    Email: dataprotectionofficer@flowstates.net

    Requests should include:

    • the data subject's full name;
    • identification information sufficient to verify identity;
    • contact details for response;
    • a clear description of the request, consulta, or reclamo;
    • supporting documents, where applicable; and
    • if submitted by a representative, proof of authority to act.

    Consultas will be answered within 10 business days from receipt. If we cannot respond within that period, we will explain the reason for the delay and provide a response within the additional period permitted by law.

    Reclamos will be handled within 15 business days from receipt of a complete claim. If the claim is incomplete, we may request additional information. If we cannot respond within the initial period, we will explain the reason for the delay and provide a response within the additional period permitted by law.

    A data subject may file a complaint with the Superintendencia de Industria y Comercio only after first completing the applicable consulta or reclamo process with Flowstates.

    20.8 International Transfers and Transmissions From Colombia

    Personal Data subject to Colombian law may be transferred or transmitted outside Colombia, including to the United States, Germany, and other countries where Flowstates or its subprocessors operate.

    Where required, Flowstates will use contractual safeguards, transmission agreements, transfer mechanisms, authorization, or other measures required under Colombian data protection law.

    20.9 Effective Date and Database Validity

    This Colombian Personal Data processing policy is effective from 12/05/2026.

    Flowstates' databases will remain valid for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, compliance, dispute resolution, or legitimate business purposes.

    21Marketing Communications

    We may send marketing communications to business contacts, Customers, and individuals who have consented or where otherwise permitted by law.

    You may opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting us at dataprotectionofficer@flowstates.net.

    We may continue to send non-marketing communications, including transactional, service, account, security, billing, legal, and support messages.

    Commercial emails sent by Flowstates will include required sender information and opt-out mechanisms.

    22SMS, RCS, and Messaging Opt-Outs

    If you receive a message sent by a Flowstates Customer through the Flowstates Services, the Customer is generally responsible for that message and for honouring your messaging preferences.

    You may be able to opt out by replying with a recognized opt-out keyword such as STOP, QUIT, CANCEL, END, UNSUBSCRIBE, or another method described in the message.

    If you contact Flowstates about an End User message, we may forward your request to the relevant Customer or help process the request as required by law, contract, or platform rules.

    23Do Not Track and Opt-Out Preference Signals

    Some browsers provide "Do Not Track" settings. Because there is no uniform industry standard for responding to Do Not Track signals, our response may vary.

    Where required by law, including California law, we will process recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of sale or sharing for the relevant browser, device, or account where applicable.

    24Automated Decision-Making and Profiling

    We do not use Personal Data for automated decision-making that produces legal or similarly significant effects without appropriate notice and lawful basis.

    We may use analytics, segmentation, and campaign tools to help Customers configure messaging campaigns. Where Flowstates acts as a processor, Customers are responsible for determining whether their campaign configuration involves profiling or automated decision-making requiring notice, consent, opt-out rights, or other safeguards.

    25Legal Requests and Compliance

    We may disclose Personal Data where we believe disclosure is necessary or appropriate to:

    • comply with applicable law;
    • respond to subpoenas, court orders, warrants, lawful government requests, or legal process;
    • cooperate with regulators or law enforcement;
    • protect the rights, property, or safety of Flowstates, Customers, End Users, or others;
    • investigate fraud, spam, abuse, security incidents, or unlawful activity;
    • enforce our agreements and policies; or
    • preserve evidence or defend legal claims.

    26Business Transfers

    If Flowstates is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, Personal Data may be disclosed or transferred as part of that transaction, subject to appropriate safeguards and applicable law.

    27Third-Party Websites and Services

    Our website and services may link to third-party websites, platforms, integrations, payment processors, or services. We are not responsible for the privacy practices of third parties. Their privacy policies govern their collection and use of Personal Data.

    28Changes to This Privacy Policy

    We may update this Privacy Policy from time to time. The "Last Revised" date at the top of this page indicates when it was last updated.

    Where required by law, we will provide additional notice or obtain consent for material changes.

    29Contact Us

    For questions, privacy rights requests, complaints, Colombian consultas or reclamos, California privacy requests, GDPR requests, or data protection concerns, please contact:

    Flowstates Inc
    330 Madison Avenue, 27th Floor
    New York, NY 10017
    United States

    Privacy Contact / Data Protection Officer:
    Email: dataprotectionofficer@flowstates.net