Privacy

Privacy. Plain English.

How we collect, use, store, and protect your data — without the legalese. If anything's unclear, email privacy@flockr.co and we'll explain.

Last updated: [Month YYYY]UK GDPR compliantVersion 2.0
In short

The short version.

  • We collect only what we need to respond to you and deliver our service. Nothing more.
  • We never sell, rent, or trade your data with third parties.
  • Your data is stored in UK and EU data centres on AWS infrastructure.
  • You can access, correct, or delete your data at any time by emailing privacy@flockr.co.
  • You have the full set of UK GDPR rights. Details below.

01Who we are

This privacy policy applies to flockr.co and the Flockr platform (the "Service") operated by Flockr Limited ("Flockr", "we", "us", "our").

Flockr Limited is a company registered in England and Wales (company number 13883505). Our registered office is City Road, London, EC1V 2NJ, United Kingdom.

This policy explains what personal data we collect from you, how we use it, who we share it with, where it's stored, how long we keep it, and what rights you have. By using our website or services, you agree to the practices described here.

02What we collect

Information you give us directly

When you fill out a form, book a demo or discovery call, contact us, or sign up as a customer, we collect:

  • Your name
  • Your work email address
  • Your company name and role
  • The content of your message or enquiry
  • Any other information you choose to share with us

If you become a Flockr customer, we additionally collect billing details (processed by our payment provider, not stored by us), the catalogue and behavioural data necessary to deliver the Service, and account user details.

Information collected automatically

When you visit our website, we automatically collect:

  • Your IP address (truncated for analytics)
  • Your browser type and version
  • Your operating system
  • The pages you visit, time on each page, and how you got to our site
  • Approximate location (city level, derived from IP)

Information from third parties

We may receive information about you from:

  • Calendly (when you book a demo or discovery call)
  • LinkedIn (when you interact with our advertising or company page)
  • Customer relationship tools we use to track conversations with prospects and customers

03How we use your data

We use your personal data to:

  • Respond to enquiries you make through our website or by email
  • Deliver the Service to customers under the contract between us
  • Communicate with you about service updates, security notices, and account changes
  • Send marketing communications about Flockr — only with your consent, and you can opt out at any time
  • Improve our website and services based on aggregated usage data
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with legal obligations (tax records, regulatory requests, court orders)

05Who we share data with

We share your data only with:

Our service providers (data processors)

We use trusted third parties to operate our business. They process data on our behalf, under contracts that require them to protect your data. These include:

  • AWS (Amazon Web Services) — cloud infrastructure and data storage
  • Email service providers — for transactional and (with consent) marketing emails
  • Customer support and CRM tools — to manage enquiries and customer relationships
  • Calendly — to handle demo and discovery call bookings
  • Payment processors — for billing existing customers
  • Analytics providers — e.g. Google Analytics 4 (with anonymised IPs)

Legal authorities

When required by law or to protect our rights, safety, or property — or those of others.

Successors

In the event of a merger, acquisition, or asset sale, your data may transfer to the successor entity. You'll be notified before this happens.

We do not sell, rent, or trade your personal data to any third party. Ever.

06Where your data is stored

Your data is stored and processed in:

  • United Kingdom (London region)

We use AWS as our primary infrastructure provider, with data residency limited to the UK.

Some of our service providers (for example, analytics tools) may transfer data outside the UK and EU. Where this happens, we ensure appropriate safeguards are in place — including the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or transfers to countries the UK government has deemed to provide adequate protection.

07How long we keep data

We keep your data only as long as necessary for the purposes described in this policy, or as required by law. Our typical retention periods are:

  • Contact enquiries: 24 months after our last interaction
  • Customer data: for the duration of the contract, plus 7 years (UK statutory retention for business records)
  • Marketing preferences: until you unsubscribe, then deleted within 30 days
  • Website analytics: aggregated and anonymised after 14 months
  • Server logs: 90 days, then deleted

When data is no longer needed, we securely delete or anonymise it.

08Cookies and tracking

Our website uses cookies and similar technologies. A cookie is a small text file stored on your device when you visit a website.

The cookies we use

  • Strictly necessary cookies — required for the website to function (session, security, load balancing). Always active; cannot be disabled.
  • Analytics cookies — help us understand how visitors use our website. Active only with your consent.
  • Functionality cookies — remember your preferences. Active only with your consent.

We do not use advertising or targeting cookies on this website.

Third-party services that may set cookies

  • Webflow — website hosting platform
  • Google Analytics 4 — analytics (with anonymised IP addresses)
  • Calendly — when booking a call
  • LinkedIn Insight Tag — campaign analytics (when applicable)

Managing your cookie preferences

When you first visit our site, you'll see a cookie banner where you can accept or decline non-essential cookies. You can change your preferences at any time via the "Cookie settings" link in our footer, or by managing cookies through your browser settings.

For more information about cookies and how to manage them, visit the ICO's guidance at ico.org.uk/cookies.

09Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data (the "right to be forgotten")
  • Restrict how we process your data
  • Object to processing, especially for direct marketing
  • Data portability — receive your data in a structured, commonly-used format
  • Withdraw consent at any time, where we rely on consent
  • Not be subject to fully automated decision-making with legal or significant effects

To exercise any of these rights, email privacy@flockr.co. We'll respond within 30 days, though usually much faster.

If you're not satisfied with how we handle your data, you have the right to lodge a complaint with the UK's Information Commissioner's Office (ICO) at ico.org.uk.

10Security

We take the security of your data seriously. Our measures include:

  • Encryption in transit and at rest using industry-standard protocols (TLS 1.2+, AES-256)
  • Access controls with least-privilege principles and multi-factor authentication for all staff
  • Regular security reviews, dependency scanning, and penetration testing
  • Incident response procedures and breach notification within 72 hours where required by law
  • Vendor due diligence on all service providers

For responsible disclosure of security vulnerabilities, please email security@flockr.co. We acknowledge all reports within 24 hours and don't take legal action against good-faith security researchers.

11Children's data

Flockr's services are for business use and are not directed at children under 16. We don't knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please email privacy@flockr.co and we'll delete it promptly.

12Changes to this policy

We may update this policy from time to time to reflect changes in our practices, services, or legal obligations. The "last updated" date at the top of this page reflects the most recent change.

For material changes that affect how we use your data, we'll notify you by email (if we have it) or with a prominent notice on our website at least 30 days before the change takes effect.

Previous versions of this policy are available on request — email privacy@flockr.co.

13Contact us

For privacy questions, data requests, or to exercise any of your rights:

MailData Protection Officer
Flockr Limited
Capital Offices, City Road
London, EC1V 2NJ
United Kingdom
ICOIf unsatisfied with our response, contact the UK Information Commissioner's Office.