This Privacy Policy describes how Flowstates Inc, located at 330 Madison Avenue, 27th Floor, New York, NY 10017, United States, SR: 20223077628, EIN: 88-3465626 ("Flowstates," "we," "us," or "our"), collects, uses, discloses, stores, transfers, and protects Personal Data.
Flowstates owns and provides flowstates.net, which together comprise a proprietary software-as-a-service marketing platform for sending SMS, RCS, and other electronic messages, including A2P application-to-person messages (the "Flowstates Services").
We take privacy seriously and have designed our internal operations and the Flowstates Services with data protection, security, and responsible communications practices in mind.
01Contact Details
Controller / Business / Responsible Entity:
Flowstates Inc
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Privacy Contact / Data Protection Officer:
Email: dataprotectionofficer@flowstates.net
For privacy rights requests, data protection questions, complaints, or Colombian consultas or reclamos, please contact us using the email address above.
02Scope of This Privacy Policy
This Privacy Policy applies to Personal Data we process when:
- you visit our website;
- you create or use a Flowstates account;
- you communicate with us;
- you receive customer support;
- you subscribe to our marketing communications;
- you interact with our cookies, pixels, or similar technologies;
- you are a business customer, supplier, partner, or representative of one; or
- your Personal Data is processed through the Flowstates Services on behalf of one of our Customers.
This Privacy Policy does not replace any Data Processing Agreement, Customer agreement, messaging terms, or platform-specific terms that apply to our Customers.
03Our Role: Controller, Processor, Service Provider, or Encargado
Flowstates may process Personal Data in different roles depending on the context.
3.1 Where Flowstates Acts as Controller
Flowstates acts as a controller when we determine the purposes and means of processing Personal Data, including when we process account registration information, billing information, website data, support records, business contact data, marketing communications, and security logs for our own business purposes.
3.2 Where Flowstates Acts as Processor or Service Provider
Flowstates acts as a processor, service provider, or contractor when we process Personal Data on behalf of our Customers through the Flowstates Services. In that context, the Customer determines the purposes and means of processing, and Flowstates processes the data only on the Customer's documented instructions, under the applicable Data Processing Agreement, Terms of Service, and applicable law.
3.3 Colombian Law Roles
For purposes of Colombian data protection law, Flowstates may act as a Responsable del Tratamiento when it determines the purposes and means of processing, or as an Encargado del Tratamiento when it processes Personal Data on behalf of a Customer.
04Key Definitions
- Customer
- a business or organization that registers for or uses the Flowstates Services.
- End User
- an individual customer, contact, subscriber, website visitor, or recipient whose data is processed by a Flowstates Customer through the Flowstates Services.
- End User Messages
- SMS, RCS, or other electronic messages sent by Customers to End Users through the Flowstates Services.
- Personal Data or Personal Information
- information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an identified or identifiable person, household, or device.
- Processing
- any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, deletion, or analysis.
- Sensitive Personal Data
- Personal Data treated as sensitive under applicable law, which may include health data, biometric data, precise geolocation, government identifiers, account login credentials, racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, sexual orientation, children's data, or other protected categories.
- Data Processing Agreement or DPA
- the agreement governing Flowstates' processing of Personal Data on behalf of a Customer.
05Personal Data We Process as Controller
The table below describes the main categories of Personal Data we process as controller.
| Category | Examples | Sources | Purposes | Legal Basis (GDPR) | Retention |
|---|---|---|---|---|---|
| Account registration data | Name, email, job title, company name, address, country, login details | You, your employer, account administrators | Create and manage accounts, provide services, authenticate users | Performance of contract; legitimate interests | Account duration plus a defined post-closure period |
| Business customer data | Business representative names, emails, phone numbers, role, company details | You, your employer, public business sources | Manage customer relationships, service notices, contracts | Performance of contract; legitimate interests | Business relationship plus a defined period |
| Payment method data | Card details, billing information, payment status | You, payment processors | Process payments, prevent fraud, manage subscriptions | Performance of contract; legal obligations | Flowstates does not store full card details; processors retain under their own policies |
| Invoicing and tax data | Names, emails, billing address, tax info, invoice records | You, your employer, payment processors | Issue invoices, accounting, tax compliance | Legal obligations; legitimate interests | Period required by tax, accounting, and legal requirements |
| Customer support records | Name, email, phone, support messages, screenshots, files | You, support interactions | Respond to inquiries, troubleshoot, improve services | Performance of contract; legitimate interests | Defined period after ticket closure |
| Marketing data (existing customers) | Name, business email, company, role, preferences, engagement | You, account activity, marketing tools | Product updates, newsletters, offers, service info | Legitimate interests; consent where required | Until unsubscribe or objection, plus suppression records |
| Marketing data (non-customers) | Name, email, company, role, preferences, consent records | You, forms, events, referrals, public business sources | Newsletters, product info, event invitations, promotions | Consent; legitimate interests where permitted | Until unsubscribe or objection, plus suppression records |
| Website and usage data | IP, device IDs, browser, session data, pages viewed, logs | Browser, device, cookies, analytics tools | Operate website, understand usage, secure platform, prevent fraud | Legitimate interests; consent where required | Defined retention based on log type |
| Cookie, pixel, tracking data | Cookie IDs, IP, visit duration, interactions, ad IDs, inferred interests | Browser, device, cookies, pixels, analytics partners | Analytics, advertising, attribution, fraud prevention | Consent where required; legitimate interests for strictly necessary | As described in our Cookie Policy |
| Security and fraud data | IPs, authentication logs, access logs, abuse indicators, device data | Use of services, security tools | Protect accounts, prevent DDoS, fraud, spam, abuse | Legitimate interests; legal obligations | Defined retention; longer where needed for investigation |
| Legal and compliance records | Contracts, consents, opt-outs, complaints, rights requests, disputes | You, Customers, service providers, authorities | Demonstrate compliance, respond to legal requests, enforce terms | Legal obligations; legitimate interests | As long as necessary for compliance and audit |
06Personal Data We Process on Behalf of Customers
Customers use the Flowstates Services to send SMS, RCS, and other electronic messages to End Users. In this context, the Customer is generally the controller or business, and Flowstates is generally the processor, service provider, contractor, or encargado.
Customers are responsible for:
- providing lawful notices to End Users;
- obtaining and documenting all legally required consents and authorizations;
- determining the lawful basis or authorization for processing;
- ensuring that their messages are lawful and non-deceptive;
- honouring opt-outs and suppression requests;
- maintaining accurate contact lists;
- ensuring that End User data submitted to Flowstates may lawfully be processed; and
- complying with applicable SMS, RCS, email, consumer protection, marketing, and privacy laws.
Flowstates processes End User Personal Data only to provide the Flowstates Services, comply with Customer instructions, maintain security and service integrity, prevent abuse, comply with law, and perform related activities described in our DPA.
6.1 End User Data Processed Through the Flowstates Services
| Data Type | Examples | Processing Purpose |
|---|---|---|
| Basic End User information | Name, phone, IP, delivery address, country prefix | Personalization, delivery, routing, fraud prevention, compliance |
| Event and user actions | Purchase, cart abandoned, newsletter subscribed, checkout activity | Segmentation, campaign triggering, personalization, analytics |
| Storefront / website data | Discount codes, platform type, order metadata, abandoned cart URL | Plugin functionality, cart recovery, campaign delivery |
| Plugin and widget data | Plugin version, widget version, configuration | Compatibility, debugging, troubleshooting, maintenance |
| Cart and transaction data | Cart value, contents, payment method type, coupon, cart URL | Cart recovery, personalization, analytics, service delivery |
| Consent and preference data | Marketing opt-ins, SMS consent, unsubscribe status, suppression | Compliance evidence, opt-out management, suppression |
| Traffic and delivery data | Routing, timestamps, delivery status, carrier data, billing metadata | Message delivery, billing, analytics, troubleshooting |
| SMS/RCS message content | Message body, templates, campaign content | Delivering messages configured by the Customer |
| Security logs | IPs, access logs, abuse indicators | Preventing fraud, spam, DDoS, unauthorized access, misuse |
Some data may be aggregated or de-identified. Where information can reasonably be linked to an individual, household, or device, we treat it as Personal Data or Personal Information as required by applicable law.
07Customer Messaging Responsibilities
Because the Flowstates Services are used for SMS, RCS, and other electronic messaging, Customers must comply with all applicable messaging, privacy, marketing, telecommunications, consumer protection, and anti-spam laws.
Customers must not use the Flowstates Services to send unlawful, deceptive, misleading, harassing, unauthorized, or non-compliant messages.
Customers must obtain and maintain evidence of all required consents and authorizations before sending messages. Customers must also provide legally required disclosures, identify the sender where required, include or support required opt-out instructions, and honour opt-outs, revocations, STOP requests, unsubscribe requests, suppression requests, and other legally valid objections.
Flowstates may suspend, restrict, or terminate messaging activity where we believe it is necessary to protect End Users, prevent abuse, preserve service integrity, comply with law, respond to carrier or regulator requirements, or enforce our Terms of Service.
08Sensitive Personal Data
Flowstates does not require Customers to submit Sensitive Personal Data through the Flowstates Services.
Customers must not submit Sensitive Personal Data, protected health information, children's data, biometric data, government identifiers, or other regulated data to the Flowstates Services unless:
- the Customer has obtained all legally required consent or authorization;
- such processing is permitted by the applicable agreement with Flowstates;
- the Customer has completed any required additional documentation, including a Business Associate Agreement where HIPAA applies; and
- Flowstates has confirmed that the relevant Flowstates Services are configured to support that processing.
The Flowstates Services are not intended for the processing of Protected Health Information under HIPAA unless Flowstates and the Customer have entered into a separate Business Associate Agreement.
Where we process Sensitive Personal Data as controller, we do so only where permitted by applicable law and, where required, with explicit consent.
09Children's Privacy
The Flowstates Services are intended for business customers and are not directed to children or minors under 18.
We do not knowingly collect Personal Data from children under 13. Customers must not use the Flowstates Services to send marketing messages to children or minors unless they have obtained all legally required consents and authorizations.
For Colombian data subjects, the processing of Personal Data of children and adolescents is restricted and must respect their superior interests and fundamental rights.
If you believe a child or minor has provided Personal Data to Flowstates, please contact us at dataprotectionofficer@flowstates.net.
10Cookies, Pixels, and Similar Technologies
We use cookies, pixels, tags, SDKs, and similar technologies on flowstates.net and within the Flowstates Services.
These technologies may be used for:
- strictly necessary website and service functionality;
- account authentication;
- security and fraud prevention;
- analytics and performance measurement;
- remembering preferences;
- advertising, retargeting, and attribution; and
- understanding how users interact with our website and services.
We may use technologies provided by analytics and advertising partners, including Google and Meta/Facebook, subject to our configuration choices and applicable law.
Where required by law, we obtain consent before using non-essential cookies, pixels, or similar technologies. You may manage cookie preferences through our .
11How We Share Personal Data
We may disclose Personal Data to the following categories of recipients:
- Flowstates staff and authorized personnel, subject to access controls and confidentiality obligations;
- hosting, cloud infrastructure, and database providers;
- SMS, RCS, telecommunications, carrier, and message delivery providers;
- payment processors and billing providers;
- customer support and communications tools;
- analytics and performance measurement providers;
- advertising and marketing partners, where permitted by law and subject to your choices;
- security, fraud prevention, and abuse detection providers;
- professional advisers, including lawyers, accountants, auditors, and insurers;
- public authorities, courts, regulators, law enforcement, or other third parties where required or permitted by law;
- parties involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar corporate transaction; and
- Customers, where we process End User data on their behalf.
We do not sell Personal Data for money. However, our use of certain advertising cookies, pixels, or similar technologies may be considered a "sale," "sharing," or use for targeted advertising under some U.S. state privacy laws, including California law. See the California Privacy Notice below for more information and your choices.
12Subprocessors and Service Providers
We use third-party subprocessors, service providers, contractors, and vendors to help provide, secure, maintain, and improve the Flowstates Services.
Our subprocessors are required to process Personal Data under contract and only for the purposes authorized by Flowstates or our Customers. We require subprocessors to use appropriate confidentiality, security, and privacy safeguards.
Where required by our DPA, we provide Customers with notice of new subprocessors and an opportunity to object.
13International Transfers
Our primary data servers are hosted in Frankfurt, Germany. Personal Data may also be processed in the United States, the European Economic Area, and other countries where Flowstates or its subprocessors operate.
Where we transfer Personal Data from the EEA, UK, Switzerland, Colombia, or another jurisdiction that restricts international transfers, we use appropriate safeguards where required, such as:
- Standard Contractual Clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- adequacy decisions, where applicable;
- data processing or transmission agreements;
- contractual safeguards required under Colombian data protection law; or
- another lawful transfer mechanism.
You may contact us at dataprotectionofficer@flowstates.net for more information about the transfer safeguards we use.
14Data Retention
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
| Data Category | Retention Period or Criteria |
|---|---|
| Account registration data | Account duration plus a defined post-closure period |
| Business customer relationship data | Business relationship plus a defined period |
| Billing and invoice records | Period required by tax, accounting, and legal requirements |
| Payment card data | Processed by payment providers; not stored by Flowstates |
| Customer support records | Defined period after ticket closure unless needed for disputes, security, or legal purposes |
| Marketing contacts | Until unsubscribe, withdrawal of consent, or objection, plus suppression records |
| Consent and opt-out records | As long as needed to demonstrate compliance and maintain suppression lists |
| Usage and analytics logs | Defined retention based on log type |
| Security logs | Defined retention; longer where needed for investigation, fraud prevention, or legal claims |
| SMS/RCS delivery and traffic logs | Defined retention; longer where required for billing, compliance, abuse prevention, or legal claims |
| End User data processed on behalf of Customers | As instructed by the Customer and under the DPA; generally deleted within 15 business days after account termination unless legally required or contractually permitted to retain longer |
| Cookies and pixels | As described in our Cookie Policy |
| Backups | Deleted or overwritten according to our backup cycle |
Where Flowstates acts as a processor, service provider, contractor, or encargado, deletion may be subject to Customer instructions, legal obligations, backup cycles, security requirements, or dispute preservation needs.
15Data Security
We use reasonable and appropriate technical, organizational, and administrative safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
These safeguards may include:
- encryption in transit and, where appropriate, at rest;
- secure hosting environments;
- access controls and role-based permissions;
- authentication controls;
- network security measures;
- logging and monitoring;
- staff confidentiality obligations;
- vendor security review;
- incident response procedures; and
- physical security measures where relevant.
No method of transmission or storage is completely secure. We use safeguards designed to protect Personal Data, but we cannot guarantee absolute security.
16Your Privacy Rights
Depending on where you live and the law that applies, you may have rights over your Personal Data.
These may include the right to:
- request access to your Personal Data;
- request a copy of your Personal Data;
- request correction of inaccurate Personal Data;
- request deletion of Personal Data;
- request restriction of processing;
- object to processing;
- withdraw consent where processing is based on consent;
- request data portability;
- opt out of marketing communications;
- opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
- limit the use or disclosure of Sensitive Personal Information where applicable;
- appeal certain rights request decisions where applicable; and
- lodge a complaint with a supervisory authority or regulator.
To exercise your rights, contact: dataprotectionofficer@flowstates.net
We may need to verify your identity before responding to your request. We will respond within the time required by applicable law.
Where we process Personal Data on behalf of a Customer, we may forward your request to the relevant Customer or instruct you to contact the Customer directly. We will assist Customers with rights requests as required by our DPA and applicable law.
17GDPR / EEA / UK / Swiss Privacy Rights
Where the GDPR, UK GDPR, or Swiss data protection law applies, you may have the following rights:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to data portability;
- right to object;
- right to withdraw consent at any time, without affecting processing carried out before withdrawal;
- right not to be subject to automated decision-making producing legal or similarly significant effects, where applicable; and
- right to lodge a complaint with your local data protection supervisory authority.
Where we rely on legitimate interests, you may object to processing. Where we rely on consent, you may withdraw consent at any time.
We do not use Personal Data for automated decision-making that produces legal or similarly significant effects without appropriate notice and lawful basis.
18U.S. State Privacy Rights
Residents of certain U.S. states may have additional privacy rights, depending on applicable law. These may include rights to access, confirm processing, delete, correct, obtain a portable copy of Personal Information, opt out of targeted advertising, opt out of sale, opt out of certain profiling, restrict certain uses of Sensitive Personal Information, and appeal a denied request.
To exercise U.S. state privacy rights, contact: dataprotectionofficer@flowstates.net
Where required, we will provide an appeal process if we deny your request.
19California Privacy Notice
This California Privacy Notice applies to California residents and supplements the rest of this Privacy Policy. It applies to the extent Flowstates is a "business" under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
19.1 Notice at Collection
| Category | Examples | Purposes | Sold or Shared? | Retention |
|---|---|---|---|---|
| Identifiers | Name, email, phone, IP, account ID, cookie ID | Account, service, support, security, marketing, analytics | May be shared via ad cookies/pixels; not sold for money | See Section 14 |
| Cal. Civ. Code § 1798.80 info | Business contact, billing, payment-related info | Billing, contracts, account admin, compliance | Not sold for money; may be disclosed to service providers | See Section 14 |
| Commercial information | Subscriptions, invoices, purchases, usage, campaign metadata | Provide services, billing, analytics, support, compliance | Not sold for money; may be disclosed to service providers | See Section 14 |
| Internet/network activity | IP, browser, device, interactions, service logs | Security, analytics, fraud prevention, advertising | May be shared for cross-context behavioral advertising | See Section 14 |
| Geolocation data | Approximate location from IP or phone country prefix | Security, localization, country prefix detection, compliance | Not sold for money; may be disclosed to service providers | See Section 14 |
| Professional/employment info | Job title, company, business role | Account admin, sales, support, marketing | Not sold for money; may be disclosed to service providers | See Section 14 |
| Inferences | Marketing interests, engagement, interaction patterns | Analytics, marketing, advertising, service improvement | May be shared for cross-context behavioral advertising | See Section 14 |
| Sensitive Personal Information | Login credentials; payment info processed by providers | Account security, authentication, payment processing | Not sold for money; not used to infer characteristics | See Section 14 |
We do not use or disclose Sensitive Personal Information for purposes that require a right to limit under California law, unless we provide the required notice and choice.
19.2 Categories of Sources
We collect Personal Information from:
- you;
- your employer or organization;
- account administrators;
- Customers;
- End Users' interactions with Customer websites or messages;
- browsers and devices;
- cookies, pixels, analytics tools, and advertising technologies;
- payment processors;
- service providers and subprocessors;
- communications with us; and
- publicly available business sources.
19.3 Business or Commercial Purposes
We collect, use, disclose, and, where applicable, share Personal Information for:
- providing the Flowstates Services;
- account creation and administration;
- authentication and security;
- billing and payment processing;
- customer support;
- SMS, RCS, and electronic message delivery;
- analytics and service improvement;
- marketing and advertising;
- cookie-based retargeting and attribution;
- fraud, spam, DDoS, and abuse prevention;
- legal, tax, accounting, and compliance purposes;
- enforcing agreements and policies; and
- responding to legal requests.
19.4 Disclosures for Business Purposes
In the preceding 12 months, we may have disclosed identifiers; § 1798.80 information; commercial information; internet or network activity; approximate geolocation data; professional or employment-related information; inferences; and Sensitive Personal Information where necessary for account security, authentication, payment processing, or compliance — to service providers, contractors, subprocessors, payment processors, hosting providers, telecommunications and messaging providers, support tools, analytics providers, security providers, professional advisers, and legal authorities.
19.5 Sale or Sharing of Personal Information
We do not sell Personal Information for money.
We may "share" the following categories for cross-context behavioral advertising through advertising cookies, pixels, or similar technologies:
- identifiers, such as cookie IDs, device identifiers, IP addresses, and similar online identifiers;
- internet or network activity information, such as website interactions and page views; and
- inferences, such as advertising or marketing interests.
You may opt out of sale or sharing by managing your .
We also process legally recognized opt-out preference signals, such as Global Privacy Control, where required by law. Where your browser or device sends a valid opt-out preference signal, we will treat it as a request to opt out of sale or sharing for that browser or device. If you are logged into your account and we can associate the signal with your account, we may apply the opt-out to your account as required by law.
We do not have actual knowledge that we sell or share Personal Information of consumers under 16 years of age.
19.6 California Rights
- know what Personal Information we collect, use, disclose, sell, or share;
- access specific pieces of Personal Information;
- delete Personal Information, subject to exceptions;
- correct inaccurate Personal Information;
- opt out of sale or sharing;
- limit use or disclosure of Sensitive Personal Information where applicable;
- not receive discriminatory or retaliatory treatment for exercising privacy rights; and
- use an authorized agent to submit a request.
19.7 How to Exercise California Rights
Email: dataprotectionofficer@flowstates.net
We will verify your request by matching the information you provide with information we maintain. We may request additional information where necessary to verify your identity or authority to act on behalf of another person.
Authorized agents may submit requests on behalf of California residents. We may require proof of authorization and may ask the resident to verify their identity directly with us unless an exception applies.
19.8 Response Timelines
We will respond to California privacy requests within the period required by law. For requests to know, access, delete, or correct, we generally confirm receipt within 10 business days and respond within 45 calendar days, unless an extension is permitted. For opt-out requests, we will comply as soon as reasonably practicable and within the legally required period.
20Colombian Privacy Notice
This section applies to Personal Data processing subject to Colombian data protection law, including Law 1581 of 2012 and related regulations.
20.1 Responsible Entity
Responsable del Tratamiento:
Flowstates Inc
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Email: dataprotectionofficer@flowstates.net
20.2 Purposes of Processing
- providing and operating the Flowstates Services;
- managing accounts and business relationships;
- delivering SMS, RCS, and other electronic messages;
- providing customer support;
- billing, accounting, and tax compliance;
- fraud, spam, DDoS, and abuse prevention;
- security monitoring and incident response;
- analytics and service improvement;
- marketing communications where legally permitted;
- compliance with legal, regulatory, judicial, or contractual obligations;
- responding to consultations, claims, complaints, and rights requests; and
- any other purpose disclosed at the time of collection or authorized by the data subject.
20.3 Authorization
Where required by Colombian law, we will request prior, express, and informed authorization for the processing of Personal Data. Authorization may be obtained in writing, electronically, orally, by affirmative conduct, or by another mechanism that allows later consultation of the authorization.
When requesting authorization, we will inform data subjects of:
- the Personal Data to be collected;
- the purposes of processing;
- their rights as data subjects;
- the identity, address, email, and telephone number of Flowstates;
- the optional nature of providing Sensitive Personal Data or children's/adolescents' data, where applicable; and
- how to access this Privacy Policy.
20.4 Sensitive Data
The provision of Sensitive Personal Data is optional unless an exception applies under law. We will not condition any activity on the provision of Sensitive Personal Data unless legally permitted.
Where Sensitive Personal Data is processed, we will inform the data subject which data is sensitive, the purpose of processing, and the optional nature of providing such data, and we will obtain express consent where required.
20.5 Children and Adolescents
Processing Personal Data of children and adolescents is restricted. Where such processing is permitted, it must respect the superior interests of the child or adolescent and their fundamental rights.
20.6 Colombian Data Subject Rights
- know, update, and rectify their Personal Data;
- request proof of authorization granted for processing, unless an exception applies;
- be informed, upon request, about how their Personal Data has been used;
- file complaints with the Superintendencia de Industria y Comercio after completing the applicable consultation or claim process with Flowstates;
- revoke authorization and/or request deletion of Personal Data where applicable;
- access their Personal Data free of charge; and
- exercise any other right provided under Colombian law.
20.7 Procedure for Consultas and Reclamos
Privacy / Data Protection Office
Email: dataprotectionofficer@flowstates.net
Requests should include:
- the data subject's full name;
- identification information sufficient to verify identity;
- contact details for response;
- a clear description of the request, consulta, or reclamo;
- supporting documents, where applicable; and
- if submitted by a representative, proof of authority to act.
Consultas will be answered within 10 business days from receipt. If we cannot respond within that period, we will explain the reason for the delay and provide a response within the additional period permitted by law.
Reclamos will be handled within 15 business days from receipt of a complete claim. If the claim is incomplete, we may request additional information. If we cannot respond within the initial period, we will explain the reason for the delay and provide a response within the additional period permitted by law.
A data subject may file a complaint with the Superintendencia de Industria y Comercio only after first completing the applicable consulta or reclamo process with Flowstates.
20.8 International Transfers and Transmissions From Colombia
Personal Data subject to Colombian law may be transferred or transmitted outside Colombia, including to the United States, Germany, and other countries where Flowstates or its subprocessors operate.
Where required, Flowstates will use contractual safeguards, transmission agreements, transfer mechanisms, authorization, or other measures required under Colombian data protection law.
20.9 Effective Date and Database Validity
This Colombian Personal Data processing policy is effective from 12/05/2026.
Flowstates' databases will remain valid for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, compliance, dispute resolution, or legitimate business purposes.
21Marketing Communications
We may send marketing communications to business contacts, Customers, and individuals who have consented or where otherwise permitted by law.
You may opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting us at dataprotectionofficer@flowstates.net.
We may continue to send non-marketing communications, including transactional, service, account, security, billing, legal, and support messages.
Commercial emails sent by Flowstates will include required sender information and opt-out mechanisms.
22SMS, RCS, and Messaging Opt-Outs
If you receive a message sent by a Flowstates Customer through the Flowstates Services, the Customer is generally responsible for that message and for honouring your messaging preferences.
You may be able to opt out by replying with a recognized opt-out keyword such as STOP, QUIT, CANCEL, END, UNSUBSCRIBE, or another method described in the message.
If you contact Flowstates about an End User message, we may forward your request to the relevant Customer or help process the request as required by law, contract, or platform rules.
23Do Not Track and Opt-Out Preference Signals
Some browsers provide "Do Not Track" settings. Because there is no uniform industry standard for responding to Do Not Track signals, our response may vary.
Where required by law, including California law, we will process recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of sale or sharing for the relevant browser, device, or account where applicable.
24Automated Decision-Making and Profiling
We do not use Personal Data for automated decision-making that produces legal or similarly significant effects without appropriate notice and lawful basis.
We may use analytics, segmentation, and campaign tools to help Customers configure messaging campaigns. Where Flowstates acts as a processor, Customers are responsible for determining whether their campaign configuration involves profiling or automated decision-making requiring notice, consent, opt-out rights, or other safeguards.
25Legal Requests and Compliance
We may disclose Personal Data where we believe disclosure is necessary or appropriate to:
- comply with applicable law;
- respond to subpoenas, court orders, warrants, lawful government requests, or legal process;
- cooperate with regulators or law enforcement;
- protect the rights, property, or safety of Flowstates, Customers, End Users, or others;
- investigate fraud, spam, abuse, security incidents, or unlawful activity;
- enforce our agreements and policies; or
- preserve evidence or defend legal claims.
26Business Transfers
If Flowstates is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, Personal Data may be disclosed or transferred as part of that transaction, subject to appropriate safeguards and applicable law.
27Third-Party Websites and Services
Our website and services may link to third-party websites, platforms, integrations, payment processors, or services. We are not responsible for the privacy practices of third parties. Their privacy policies govern their collection and use of Personal Data.
28Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last Revised" date at the top of this page indicates when it was last updated.
Where required by law, we will provide additional notice or obtain consent for material changes.
29Contact Us
For questions, privacy rights requests, complaints, Colombian consultas or reclamos, California privacy requests, GDPR requests, or data protection concerns, please contact:
Flowstates Inc
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Privacy Contact / Data Protection Officer:
Email: dataprotectionofficer@flowstates.net