Privacy Policy
How Flobase Ltd handles personal data in Siteflo.
Last updated 3 August 2026.
1. Who is responsible
Flobase Ltd, registered in England and Wales under company number 17166043, registered office 16 North Street, Steeple Bumpstead, Haverhill, England, CB9 7DP, is the data controller for information about you as a Siteflo user. We are registered with the Information Commissioner’s Office under registration reference C1912584.
For the records you enter about your own customers, you are the controller and we are your processor: we hold and process that data on your instructions, to provide the service.
Any privacy question: support@entryflo.co.uk.
2. What we collect
Account data — your name, email address, phone number, company name and business details, and the branding you upload.
Customer records you enter — names, addresses, contact details, site and equipment details, service history, photographs, quotes and invoices relating to your customers.
Billing data — your plan, subscription status and payment history. Card details go directly to Stripe and are never stored on our systems.
Technical data — authentication cookies needed to keep you signed in, and server logs including IP address and error diagnostics.
We do not use advertising cookies and we do not track you across other websites.
3. Why we use it, and our lawful basis
To provide the service — performance of our contract with you. This covers your account, your records, and the emails the service sends on your behalf, such as service reminders and booking confirmations to your customers.
To take payment — performance of our contract, and our legal obligation to keep accounting records.
To keep the service secure and working — our legitimate interest in protecting the service and diagnosing faults.
To contact you about the service — our legitimate interest in telling you about changes that affect you. Any marketing email would be sent only with your consent, and you can withdraw it at any time.
4. AI processing during import
When you import customers or contracts from a spreadsheet, Siteflo offers to match your columns to its fields automatically. To do this it sends your column headings and the first three rows of the fileto Anthropic’s API. Those rows may contain real customer data.
Nothing else in the file is sent, the data is used only to return a column mapping, and it is not used to train models. If you would rather no data left the platform, map the columns manually instead — the importer works either way.
5. Who we share it with
We do not sell personal data. We share it only with the providers that run the service for us, each bound to process it on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | London (eu-west-2) |
| Vercel | Application hosting and delivery | Global edge network |
| Resend | Transactional and notification email | Ireland (eu-west-1) |
| Stripe | Subscription billing and card payments | EU / US |
| Anthropic | AI column matching during spreadsheet import | US |
| Address lookup and calendar sync — only if you connect them | EU / US | |
| Xero / Intuit QuickBooks | Accounting sync — only if you connect them | EU / US |
We may also disclose data where the law requires it, or to establish or defend legal claims.
6. Where your data is held
Your database and files are held in the United Kingdom, and service email is sent from within the European Economic Area. Some providers listed above operate outside the UK. Where data is transferred abroad, it is protected by UK adequacy regulations or by the International Data Transfer Agreement or Addendum.
7. How long we keep it
We keep your account and its records for as long as your account is open, and for a short period afterwards so an account closed by mistake can be restored. After that it is deleted.
Records we must retain by law, such as invoices and other accounting records, are kept for six years.
8. Your rights
Under UK data protection law you can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time.
Email support@entryflo.co.uk and we will respond within one month. If you are one of our customers’ customers, please contact the business that holds your records — they control that data, and we will pass your request on to them.
You can also complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you raised it with us first.
9. Security
Data is encrypted in transit and at rest. Each business’s data is isolated at the database level so one account cannot read another’s. Credentials for connected accounting and calendar integrations are encrypted before storage. Access to production systems is limited to those who need it.
If a breach occurs that is likely to risk your rights, we will notify the ICO within 72 hours and tell you where the law requires.
10. Changes
We will update this policy as the service changes. The date at the top shows the current version, and we will tell you directly about changes that materially affect you.