Privacy Policy
Version 2.0 · Effective 2026-07-15. This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the equivalent UK and Swiss law. It applies to personal data X-com processes as controller. Personal data our customers process through the platform is governed by our Data Processing Addendum, where the customer is controller and X-com is processor.
1. Who we are (Art. 13(1)(a)–(b))
- Controller: Connect & Flow (operating the “X-com” service at layer-link-chat.lovable.app) — an unincorporated sole operator running a closed beta. A registered legal entity and postal address will be published here on incorporation, prior to general availability. Written contact is available via the email addresses in §14.
- EU representative (Art. 27): not appointed. During the closed beta, the service is not marketed to data subjects in the EU/EEA; an Art. 27 representative will be designated and named here before any EEA-targeted release.
- UK representative (UK GDPR Art. 27): not appointed. Same basis as above; a UK representative will be designated and named here before any UK-targeted release.
- Data Protection Officer: not appointed. The controller has assessed Art. 37(1) GDPR and does not currently meet the mandatory-DPO threshold (no large-scale monitoring of data subjects, no large-scale processing of special-category data). This assessment is reviewed at each material change and on incorporation.
- Lead supervisory authority: to be confirmed on incorporation and establishment of a main establishment in the EU; until then, data subjects may lodge complaints with the supervisory authority of their habitual residence or place of the alleged infringement (Art. 77 GDPR).
- Data protection contact: privacy@connectandflow.app.
2. Personal data we process (Art. 13/14)
| Category | Examples | Source |
|---|---|---|
| Account & profile | Name, email, workspace, role, display name, avatar | You (or your workspace admin on your behalf) |
| Authentication | Hashed password (bcrypt), OAuth identifiers, session tokens, 2FA state | You, identity providers (Google, etc.) |
| Workspace content | Messages, threads, tasks, files, huddle metadata | You and your workspace members (X-com acts as processor here) |
| External identifiers | Email addresses, provider user IDs from connected channels | Connected services (Slack, email, helpdesks) via our subprocessors |
| Usage & device | Access logs, IP address, user agent, timestamps, feature events | Automatically from your device |
| Support & comms | Emails to support, in-app messages, incident correspondence | You |
| Billing | Company name, VAT ID, invoicing address, last-4 of card, transaction IDs | You and Stripe (we do not store full card numbers) |
| Cookies & similar | Strictly necessary; optional analytics only with consent | Your browser — see cookie policy |
3. Purposes and lawful bases (Art. 13(1)(c)–(d), Art. 6)
| Purpose | Lawful basis | Legitimate interest (if applicable) |
|---|---|---|
| Provide, operate, and support the service; account admin; billing | Art. 6(1)(b) — contract | — |
| Security, abuse prevention, fraud detection, incident response | Art. 6(1)(f) — legitimate interests | Protecting the service, its users, and third parties from harm; meeting our own security obligations |
| Service communications (outages, security notices, product changes) | Art. 6(1)(f) — legitimate interests | Keeping customers informed of changes that affect their use of the service |
| Compliance with legal obligations (tax, accounting, lawful requests) | Art. 6(1)(c) — legal obligation | — |
| Product analytics and improvement | Art. 6(1)(a) — consent (where required) | — |
| Establishing, exercising, or defending legal claims | Art. 6(1)(f) — legitimate interests | Preserving evidence and enforcing our contracts |
| Marketing to existing business customers about similar services | Art. 6(1)(f) + soft opt-in; opt-out in every message | Informing existing customers of relevant offerings |
We do not process special categories of personal data (Art. 9) for our own purposes. If your workspace uploads such data as content, it is governed by the DPA.
4. Recipients (Art. 13(1)(e))
- Subprocessors — hosting, storage, email, error monitoring, payments, and support tooling. Current list, region, and transfer mechanism per vendor: /trust/subprocessors.
- Your workspace administrators — for account, role, and audit management.
- Professional advisors — auditors, lawyers, insurers, under confidentiality.
- Authorities — where required by law (see Section 9 on government requests).
- Successors — a buyer or successor entity in the event of a merger, sale, or restructuring, subject to equivalent protection.
5. International transfers (Art. 13(1)(f), Ch. V)
Primary hosting is in the EU. Some subprocessors process data outside the EEA/UK/CH. For those transfers we rely on:
- Adequacy decisions where they exist (e.g. EU–US Data Privacy Framework for participating US recipients).
- Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller-to-processor) or Module 3 (processor-to-processor).
- UK International Data Transfer Addendum (IDTA) and the Swiss addendum where applicable.
- Supplementary measures (encryption in transit, encryption at rest, access controls) per our transfer impact assessment.
A copy of the safeguards for a specific transfer is available on request to privacy@x-com.example.
6. Retention (Art. 13(2)(a))
| Data | Retention | Criteria |
|---|---|---|
| Active account & profile | Life of the account + 90 days after closure | Contract term; recovery window |
| Workspace content (messages, tasks, files) | Per workspace setting: 30 / 90 / 365 days or indefinite; deleted 30 days after workspace termination | Customer controls; contractual necessity |
| Authentication logs | 13 months | Security incident investigation window |
Audit log (audit_log, admin_routing_events) | 6 years | Regulatory and evidential retention |
| Billing records & invoices | 10 years | Tax / accounting law (EU average) |
| Support correspondence | 3 years after last contact | Service quality; claim defence |
| Backups (PITR + snapshots) | 7 days PITR, 30 days snapshots | See backup drill policy |
| Marketing suppression list | Indefinite (to honour your opt-out) | Legal obligation to respect objections |
7. Your rights (Art. 13(2)(b)–(d), Art. 15–22)
Subject to conditions in the GDPR, you have the right to:
- Access your personal data and receive a copy (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erase your data ("right to be forgotten") (Art. 17).
- Restrict processing (Art. 18).
- Data portability — receive your data in a structured, machine-readable format (Art. 20).
- Object to processing based on legitimate interests, including direct marketing (Art. 21) — you may unsubscribe from every marketing email.
- Withdraw consent at any time where processing is based on consent, without affecting past lawful processing (Art. 7(3)).
- Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects (Art. 22) — see Section 10.
- Lodge a complaint with your supervisory authority. In the EU, find yours at edpb.europa.eu. In the UK, the ICO (ico.org.uk). In Switzerland, the FDPIC (edoeb.admin.ch).
To exercise a right, email privacy@x-com.example. We respond within one month (Art. 12(3)), extendable by two months for complex requests. We may need to verify your identity. Where you are a user of a customer's workspace, we may forward your request to that customer as controller.
8. Whether providing data is required (Art. 13(2)(e))
Providing account, authentication, and billing data is a contractual requirement; without it we cannot create or maintain your account or process payments. Providing analytics data is optional and depends on consent. There is no statutory obligation on you to provide personal data.
9. Government & law-enforcement requests
We disclose personal data to authorities only where legally compelled by an order valid in the relevant jurisdiction. Where legally permitted, we notify the affected customer before disclosure so they may seek a protective order. Statistics on such requests are published annually in our transparency report.
10. Automated decisions and profiling (Art. 13(2)(f))
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated routing, ranking, and spam/abuse detection may be used inside the product; these are reviewable by our staff and by your workspace administrators, and do not affect your legal status.
11. Children
The service is not directed to children under 16. We do not knowingly collect their personal data. If you believe a child has provided data, contact us and we will delete it.
12. Security
We apply the technical and organisational measures described at /trust (and Annex II of the DPA), including TLS in transit, AES-256 at rest, bcrypt password hashing, RLS on customer-company data, tested restores (see /trust/backup-drill), and an incident response process (see /legal/incident-response) aligned with the 72-hour notification duty under Art. 33.
13. Changes to this notice
Material changes will be announced at least 30 days in advance by email to workspace admins and in-product notice. The version and effective date at the top of this page change with every update. Prior versions are archived and available on request.
14. Contact
- Privacy inquiries: privacy@connectandflow.app
- Security: security@connectandflow.app
- Legal / DPA: legal@connectandflow.app
- Postal address: available on written request via the addresses above; a registered address will be published here on incorporation, prior to general availability.
This notice is published for the closed beta. Legal-entity, registered address, and Art. 27 representative details will be updated here on incorporation and before any EEA/UK-targeted release. This notice reflects Art. 13/14 requirements; jurisdictional supplements (Brazil LGPD, California CPRA, etc.) are added by request.