How we handle data
The short version: this site uses no advertising cookies and no trackers. The contact form sends nothing on its own — it writes the message and opens your WhatsApp. Whoever subscribes to a system provides account and billing data, which we use to create the access and charge the monthly fee. We do not sell data. You can ask for access, correction or deletion on the data officer's WhatsApp.
1. Who the controller is
The controller of the data handled on this site and in the subscription of our systems is FLOWLABS DESENVOLVEDORA DE SOFTWARE INTELIGENTE LTDA, CNPJ 68.584.969/0001-90, based at Avenida Barão de Itapura, 610, sala 213, Botafogo, Campinas / SP, ZIP 13020-430, Brazil ("flowlabs", "we").
This policy follows the Brazilian General Data Protection Law (Law 13.709/2018 — LGPD) and explains, in plain words, what we handle, why, who we share it with, how long we keep it and what your rights are.
2. The data we handle
a) When you browse this site
- Technical access logs, generated by the hosting provider: IP address, date and time, page opened and browser type. They keep the site running and help with security and abuse prevention.
- Google fonts and map: the pages load fonts from Google servers and the rotaflow page shows a Google map. Loading that content sends your IP to Google, which may set its own cookies. The rest of the site has no cookies of ours, no advertising cookies and no third-party trackers.
b) When you use the contact form
The form on the contact page sends nothing to our servers: what you type (name, company, interest and your description of the problem) is used right there, in your browser, to write a message and open WhatsApp. The data only reaches us if you send the message. From then on, we handle your name, your number and the content of the conversation to answer you and prepare a proposal.
c) When you subscribe to a system through the site
- Sign-up: company/clinic name, type of activity, your name, WhatsApp, e-mail (which becomes your login), password, CPF or CNPJ (Brazilian tax IDs), city and state, chosen plan and payment method.
- Password: it exists only to create your access and is stored encrypted — we cannot read it.
- CPF or CNPJ: required to issue the charge and the subscription receipt or invoice.
- Robot and abuse prevention: we record the IP address and the time of the sign-up attempt, to limit automated and repeated sign-ups.
- Billing: name, tax ID, e-mail and WhatsApp are sent to our payment partner to create the charge. Card details are typed directly on its secure page — flowlabs never receives or stores the card number. We keep the payment status and the charge identifier.
d) The data that lives inside the systems
In rotaflow, prontuflow and streamerflow, the data a client company enters there (patients, drivers, creators, clients, documents) is theirs: the company is the controller and flowlabs acts as processor, handling that data only to provide the service and following their instructions. Requests about that data should go first to the company that entered it; we support whatever is needed. Each system has its own policy, with the detail of what happens inside it: rotaflow privacy and prontuflow privacy.
The data of the subscriber's own account (sign-up, login, billing and support) follows this policy, with flowlabs as controller. We work with role-based access, two-factor verification, audit logs and backups; health records and tax documents follow the legal retention periods.
3. What we use it for, and on what legal basis
- Answering your enquiry and preparing a proposal — preliminary steps of a contract at your request (art. 7, V) and legitimate interest (art. 7, IX).
- Creating the account, providing the service and giving support — performance of the contract (art. 7, V).
- Charging the monthly fee and issuing receipts/invoices — performance of the contract (art. 7, V) and legal obligation, including tax (art. 7, II).
- Notifying you about your account (end of trial, billing, relevant changes) — performance of the contract (art. 7, V).
- Security, auditing and fraud and abuse prevention — legitimate interest (art. 7, IX) and, for access logs, legal obligation (art. 7, II, with art. 15 of the Brazilian Internet Act).
- Defending our rights, if needed — regular exercise of rights (art. 7, VI).
We do not sell, rent or share data with third parties for marketing, and we do not use your data for advertising.
4. Who we share it with
To operate, we rely on service providers (sub-processors), which receive only what their function requires:
- Netlify — hosting for this site and the server functions; generates the technical access logs.
- Supabase — database, authentication (login and password) and file storage for the systems.
- Asaas — subscription billing by Pix or credit card and issuing receipts.
- Google — fonts and maps used on the pages and, when the client chooses to connect them, integrations such as Google Ads.
- Meta — WhatsApp, used for support and notices, and, when the client chooses to connect them, Instagram and Facebook.
- Anthropic — processing for the artificial intelligence features of the systems (for example, reading a document you uploaded, summarising an e-mail or suggesting a text), only at the moment you use the feature and with the minimum data needed. This data is not used to train models.
Some optional features of the systems use other specialised providers (for example, issuing tax documents, freight payment rails and photo and video editing). The current list can be requested through the data officer's channel. We also share data when the law requires it or upon order of a competent authority, and with the client company itself when it is the controller.
5. International transfer
Some of these providers store or process data outside Brazil, mainly in the United States. In those cases the transfer relies on the grounds permitted by articles 33 to 36 of the LGPD — in particular when it is necessary to perform the contract with you — and on providers that undertake contractual data-protection commitments and security measures equivalent to those required by Brazilian law.
6. How long we keep it
- Contact conversation and proposal: for as long as the enquiry and the negotiation last; if it does not become a contract, we delete it once it is no longer needed.
- Account and subscription data: while the subscription exists. After cancellation you have 30 days to export the data; it is then deleted or anonymised.
- Billing and tax documents: 5 years, as required by tax law.
- Access logs of the site and the systems: 6 months, as required by art. 15 of the Brazilian Internet Act.
- Sign-up attempt records (IP and time): for as long as needed to contain robots and abuse.
- Data entered inside the systems: according to the contract with the client company, which is the controller, respecting the legal retention periods.
7. Your rights
Article 18 of the LGPD grants you, at any time and free of charge, the right to:
- confirm whether we process your data and access a copy of it;
- correct incomplete, inaccurate or outdated data;
- request anonymisation, blocking or deletion of unnecessary or excessive data, or data processed outside the law;
- portability to another provider;
- know who we share your data with;
- know that you may withhold consent and what happens if you do;
- withdraw consent and ask for deletion of the data processed on that basis;
- ask for review of decisions taken solely by automated means (art. 20);
- complain to the ANPD, the Brazilian data protection authority.
How to exercise them
Talk to the data officer on WhatsApp +55 19 99733-5996, with "Privacidade" as the subject. We may ask for information to confirm it is really you. We answer within 15 days, the period set by art. 19 of the LGPD. If the request concerns data a client company entered into one of the systems, we forward it to them, as the controller, and support the response.
8. Data protection officer
The data officer channel (art. 41 of the LGPD) is WhatsApp +55 19 99733-5996, Monday to Friday, business hours (BRT). That is the channel where we guarantee an answer to privacy requests.
9. Cookies and browser storage
This site sets no cookies of its own, no advertising cookies and no third-party trackers, and builds no browsing profile. What exists is the Google content described in item 2 (fonts and the map on the rotaflow page), which may set Google's own cookies, and the Asaas payment page, which has its own. Inside the systems, the storage needed to keep you logged in and remember screen preferences is used.
10. Security
We use encrypted communication (HTTPS), data isolation per company, role-based access, two-factor verification, audit logs and backups. If a relevant security incident happens, we notify those affected and, when required, the ANPD, under art. 48 of the LGPD.
11. Professional use
This site and our systems are for professional use and are not intended for anyone under 18.
12. Updates to this policy
This policy may be updated to reflect changes in the systems or in the law. The version in force is always the one published on this page, with the date at the top; relevant changes are announced through the contacts on the account.