Privacy Policy of FlowLeo App / flowleoapp.com

Welcome to the privacy policy of FlowLeo App / flowleoapp.com. This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.

Latest update: January 02, 2026

Summary

Data we collect automatically

We automatically collect data from you for example when you visit FlowLeo App / flowleoapp.com.

  • Trackers
  • Usage Data
  • Universally unique identifier (UUID)
  • crash data
  • +3

Trusted third parties help us to process it

  • Apple Inc.
  • Google Ireland Limited
  • Google LLC
  • Tally BV

How we use them

  • Contacting the User
  • Hosting and backend infrastructure
  • Managing contacts and sending messages
  • Infrastructure monitoring
  • Platform services and hosting
  • Interaction with data collection platforms and other third parties
  • Handling activities related to productivity

Data you give to us

We collect the data you give to us for example when you sign up for our newsletter.

  • email address
  • password
  • social media accounts
  • first name
  • +3

Trusted third parties help us to process it

  • Google Ireland Limited
  • Google LLC
  • Tally BV

How we use them

  • Contacting the User
  • Registration and authentication
  • Interaction with data collection platforms and other third parties

Owner and Data Controller

Nils Kauwertz
Fuerstenwall 128
40217 Duesseldorf
Germany

Owner contact email: hello@flowleoapp.com

Type of Data we collect

Among the types of Personal Data that FlowLeo App / flowleoapp.com collects, by itself or through third parties, there are:

  • email address
  • Trackers
  • Usage Data
  • password
  • social media accounts
  • Universally unique identifier (UUID)
  • crash data
  • device information
  • first name
  • last name
  • answers to questions
  • Data communicated while using the service

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using FlowLeo App / flowleoapp.com.
Unless specified otherwise, all Data requested by FlowLeo App / flowleoapp.com is mandatory and failure to provide this Data may make it impossible for FlowLeo App / flowleoapp.com to provide its services. In cases where FlowLeo App / flowleoapp.com specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Any use of Cookies – or of other tracking tools — by FlowLeo App / flowleoapp.com or by the owners of third-party services used by FlowLeo App / flowleoapp.com serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.

Users are responsible for any third-party Personal Data obtained, published or shared through FlowLeo App / flowleoapp.com.

Mode and place of processing the Data

Methods of processing

The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of FlowLeo App / flowleoapp.com (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.

Place

The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.

Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.

Retention time

Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.

The purposes of processing

The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:

  • Contacting the User
  • Registration and authentication
  • Hosting and backend infrastructure
  • Managing contacts and sending messages
  • Infrastructure monitoring
  • Platform services and hosting
  • Interaction with data collection platforms and other third parties
  • Handling activities related to productivity
  • Managing data collection and online surveys
  • Analytics

Detailed information on the processing of Personal Data

Analytics

The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.

PostHog (Product Analytics)

This service is used to analyze product usage and improve the functionality
and usability of the application.

Only technical usage data (such as screen views and feature interactions)
is processed. No user-generated content and no health-related data
(e.g. mood entries, notes or tags) are processed or transmitted via this service.

Contacting the User

Mailing list or newsletter

Personal Data processed: email address +2

By registering on the mailing list or for the newsletter, the User’s email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning FlowLeo App / flowleoapp.com. Your email address might also be added to this list as a result of signing up to FlowLeo App / flowleoapp.com or after making a purchase.

Personal Data processed:
  • email address
  • Trackers
  • Usage Data
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information

Handling activities related to productivity

This type of service helps the Owner to manage tasks, collaboration and, in general, activities related to productivity. In using this type of service, Data of Users will be processed and may be retained, depending on the purpose of the activity in question.
These services may be integrated with a wide range of third-party services disclosed within this privacy policy to enable the Owner to import or export Data needed for the relative activity.

Google LLC

Gmail

Company: Google LLC

Place of processing: United States

Personal Data processed: Usage Data

Gmail is a service that manages email communication provided by Google LLC. Such email communication is not scanned by Google for advertising purposes. In addition, Google does not collect or use data inside this service for advertising purposes in any other way.

Personal Data processed:
  • Usage Data
Service provided by:
Category of Personal Information collected according to the CCPA
  • internet or other electronic network activity information

Hosting and backend infrastructure

This type of service has the purpose of hosting Data and files that enable FlowLeo App / flowleoapp.com to run and be distributed or to provide a ready-made infrastructure to run specific features or parts of FlowLeo App / flowleoapp.com.

Some services among those listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.

Google Ireland Limited

Firebase Cloud Firestore

Company: Google Ireland Limited

Place of processing: Germany

Personal Data processed: Usage Data +1

Firebase Cloud Firestore is a hosting and backend service provided by Google Ireland Limited.

Personal Data processed:
  • Usage Data
  • various types of Data as specified in the privacy policy of the service
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information
Google LLC

Firebase Cloud Functions

Company: Google LLC

Place of processing: United States

Personal Data processed: Usage Data +1

Firebase Cloud Functions is a hosting and backend service provided by Google LLC.

Personal Data processed:
  • Usage Data
  • various types of Data as specified in the privacy policy of the service
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information

Framer (Website Hosting)

This service is used for hosting and delivering the public website.
It processes technical data such as IP addresses, device information
and usage data to ensure secure and reliable website operation.

No user accounts or health-related data are processed via this service.

Infrastructure monitoring

This type of service allows FlowLeo App / flowleoapp.com to monitor the use and behavior of its components so its performance, operation, maintenance and troubleshooting can be improved.
Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of FlowLeo App / flowleoapp.com.

Google LLC

Crashlytics

Company: Google LLC

Place of processing: United States

Personal Data processed: crash data +3

Crashlytics is a monitoring service provided by Google LLC.

Personal Data processed:
  • crash data
  • device information
  • Trackers
  • Universally unique identifier (UUID)
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information

Interaction with data collection platforms and other third parties

This type of service allows Users to interact with data collection platforms or other services directly from the pages of FlowLeo App / flowleoapp.com for the purpose of saving and reusing data.
If one of these services is installed, it may collect browsing and Usage Data in the pages where it is installed, even if the Users do not actively use the service.

Tally BV

Tally

Company: Tally BV

Place of processing: Belgium

Personal Data processed: answers to questions +6

Tally is a form builder and data collection platform provided by Tally BV.

Personal Data processed:
  • answers to questions
  • Data communicated while using the service
  • email address
  • first name
  • last name
  • Trackers
  • Usage Data
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information
  • inferences drawn from other personal information

Managing contacts and sending messages

This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User.
These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.

Google LLC

Firebase Cloud Messaging

Company: Google LLC

Place of processing: United States

Personal Data processed: Trackers +1

Firebase Cloud Messaging is a message sending service provided by Google LLC. Firebase Cloud Messaging allows the Owner to send messages and notifications to Users across platforms such as Android, iOS, and the web. Messages can be sent to single devices, groups of devices, or specific topics or User segments.

Personal Data processed:
  • Trackers
  • various types of Data as specified in the privacy policy of the service
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information

Loops.so (Email Service)

This service is used to send transactional, onboarding and product-related
communication emails to users (e.g. account-related notifications and important
product updates).

The service processes email addresses and related technical identifiers only.
No health-related data is processed or transmitted via this service.

Managing data collection and online surveys

This type of service allows FlowLeo App / flowleoapp.com to manage the creation, deployment, administration, distribution and analysis of online forms and surveys in order to collect, save and reuse Data from any responding Users.
The Personal Data collected depend on the information asked and provided by the Users in the corresponding online form.

These services may be integrated with a wide range of third-party services to enable the Owner to take subsequent steps with the Data processed - e.g. managing contacts, sending messages, analytics, advertising and payment processing.

FlowLeo App / flowleoapp.com

User-generated health-related data

Company: FlowLeo App / flowleoapp.com

This service enables users to voluntarily enter and manage information related
to their mood and mental well-being for personal self-tracking and reflection.

The processing of this data is based exclusively on the user’s explicit consent
in accordance with Art. 9(2)(a) GDPR and Art. 6(1)(a) GDPR.
The app cannot be used without this consent.

This data is not used for medical diagnosis, treatment, profiling or advertising.

Platform services and hosting

These services have the purpose of hosting and running key components of FlowLeo App / flowleoapp.com, therefore allowing the provision of FlowLeo App / flowleoapp.com from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data.
Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.

Apple Inc.

App Store Connect

Company: Apple Inc.

Place of processing: United States

Personal Data processed: Trackers +2

FlowLeo App / flowleoapp.com is distributed on Apple's App Store, a platform for the distribution of mobile apps, provided by Apple Inc.

App Store Connect enables the Owner to manage FlowLeo App / flowleoapp.com on Apple's App Store. Depending on the configuration, App Store Connect provides the Owner with analytics data on user engagement and app discovery, marketing campaigns, sales, in-app purchases, and payments to measure the performance of FlowLeo App / flowleoapp.com. App Store Connect only collects such data from Users who have agreed to share them with the Owner. Users may find more information on how to opt out via their device settings here.

Personal Data processed:
  • Trackers
  • Universally unique identifier (UUID)
  • Usage Data
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers
  • internet or other electronic network activity information

Registration and authentication

By registering or authenticating, Users allow FlowLeo App / flowleoapp.com to identify them and give them access to dedicated services.
Depending on what is described below, third parties may provide registration and authentication services. In this case, FlowLeo App / flowleoapp.com will be able to access some Data, stored by these third-party services, for registration or identification purposes.
Some of the services listed below may also collect Personal Data for targeting and profiling purposes; to find out more, please refer to the description of each service.

Google LLC

Firebase Authentication

Company: Google LLC

Place of processing: United States

Personal Data processed: email address +2

Firebase Authentication is a registration and authentication service provided by Google LLC. To simplify the registration and authentication process, Firebase Authentication can make use of third-party identity providers and save the information on its platform.

Personal Data processed:
  • email address
  • password
  • social media accounts
Service provided by:
Category of Personal Information collected according to the CCPA
  • identifiers

Further information about the processing of Personal Data

Special Categories of Personal Data (Health Data)

FlowLeo App processes special categories of personal data in accordance with Art. 9 GDPR, in particular health data.

What Health Data We Process

This service enables users to voluntarily enter and manage information related to their mood and well-being for personal self-tracking and reflection.

When using FlowLeo App, users may voluntarily enter the following data:
- Information about mood and emotions
- Self-documented information about mental well-being
- Personal notes and observations
- Historical data on the development of your well-being

Legal Basis for Processing

The processing of these special categories of personal data is based exclusively on your explicit consent in accordance with Art. 9(2)(a) GDPR and Art. 6(1)(a) GDPR.

Without this consent, we cannot provide the core features of the app and you will not be able to use the service.

Consent Declaration:

By using the app and entering health data, you explicitly consent to the processing of your health data for the purpose of providing the app's functions (mood tracking, trend analysis, personal reflection). You give your explicit consent by actively ticking the consent checkbox during onboarding.

Purpose Limitation

This data is not used for medical diagnoses, treatment, profiling, or advertising purposes. The service is exclusively for personal self-tracking and reflection.

Your Rights

You have the right to withdraw your consent to the processing of your health data at any time without giving reasons. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal. After withdrawal, your health data will be deleted unless there are legal retention obligations.

Security Measures

Your health data is handled with the highest security standards: encryption during transmission (TLS/SSL), encrypted storage in Firebase Cloud Firestore (EU servers), strict access restrictions - only you have access to your data, regular security reviews.

Retention Period

Your health data is stored as long as you use the app and your account is active. Upon deletion of your account, all health data will be completely and irrevocably deleted within 30 days.

Disclosure to Third Parties

Your health data is not shared with third parties, sold, or used for advertising purposes. The technical infrastructure is provided by Firebase (Google Ireland Limited), acting as a data processor in accordance with Art. 28 GDPR.

Contact for data protection requests

For questions about the processing of your health data, our data protection officer is available:

Nils Kauwertz
Fürstenwall 128
40217 Duesseldorf
Germany
Email: hello@flowleoapp.com

For complaints, you can contact the competent data protection supervisory authority at any time:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Duesseldorf
Phone: 0211/38424-0
Email: poststelle@ldi.nrw.de

Further Information for Users in the European Union

Legal basis of processing

The Owner may process Personal Data relating to Users if one of the following applies:

  • Users have given their consent for one or more specific purposes.
  • provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
  • processing is necessary for compliance with a legal obligation to which the Owner is subject;
  • processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
  • processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.

Further information about retention time

Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.

Therefore:

  • Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
  • Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.

The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority.

Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.

The rights of Users based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Data processed by the Owner.

In particular, Users have the right to do the following, to the extent permitted by law:

  • Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
  • Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
  • Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
  • Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
  • Restrict the processing of their Data. Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
  • Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Owner.
  • Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
  • Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.

Users are also entitled to learn about the legal basis for Data transfers abroad including to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.

Details about the right to object to processing

Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.

Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.

How to exercise these rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users’ request, the Owner will inform them about those recipients.

Further information for Users in the United States

This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running FlowLeo App / flowleoapp.com and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as “we”, “us”, “our”).
The information contained in this section applies to all Users (Users are referred to below, simply as “you”, “your”, “yours”), who are residents in the following states: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana.
For such Users, this information supersedes any other possibly divergent or conflicting provisions contained in the privacy policy.
This part of the document uses the term Personal Information (and Sensitive Personal Information).

Notice at collection

The following Notice at collection provides you with timely notice about the categories of Personal Information collected or disclosed in the past 12 months so that you can exercise meaningful control over our use of that Information.
While such categorization of Personal Information is mainly based on California privacy laws, it can also be helpful for anyone who is not a California resident to get a general idea of what types of Personal Information are collected.

Identifiers

Personal Data processed: Email address; Trackers; Usage data; Social media accounts + 8

Personal Information collected or disclosed:
  • email address
  • Trackers
  • Usage Data
  • social media accounts
  • various types of Data as specified in the privacy policy of the service
  • Universally unique identifier (UUID)
  • crash data
  • device information
  • first name
  • last name
  • answers to questions
  • Data communicated while using the service
Sensitive Personal Information collected or disclosed

password

Purposes:
  • Contacting the User
  • Registration and authentication
  • Hosting and backend infrastructure
  • Managing contacts and sending messages
  • Infrastructure monitoring
  • Platform services and hosting
  • Interaction with data collection platforms and other third parties
Retention period:

for the time necessary to fulfill the purpose

Sold or Shared:

No

Targeted Advertising:

No

Third-parties:

Google LLC, Google Ireland Limited, Apple Inc., Tally BV

Internet or other electronic network activity information

Personal Data processed: Email address; Trackers; Usage data; Various types of data as specified in the privacy policy of the service + 7

Personal Information collected or disclosed:
  • email address
  • Trackers
  • Usage Data
  • various types of Data as specified in the privacy policy of the service
  • Universally unique identifier (UUID)
  • crash data
  • device information
  • first name
  • last name
  • answers to questions
  • Data communicated while using the service
Purposes:
  • Contacting the User
  • Hosting and backend infrastructure
  • Managing contacts and sending messages
  • Infrastructure monitoring
  • Platform services and hosting
  • Interaction with data collection platforms and other third parties
  • Handling activities related to productivity
Retention period:

for the time necessary to fulfill the purpose

Sold or Shared:

No

Targeted Advertising:

No

Third-parties:

Google Ireland Limited, Google LLC, Apple Inc., Tally BV

Inferences drawn from other personal information

Personal Data processed: Trackers; Usage data; First name; Last name + 3

Personal Information collected or disclosed:
  • Trackers
  • Usage Data
  • first name
  • last name
  • email address
  • answers to questions
  • Data communicated while using the service
Purposes:
  • Interaction with data collection platforms and other third parties
Retention period:

for the time necessary to fulfill the purpose

Sold or Shared:

No

Targeted Advertising:

No

Third-parties:

Tally BV

ℹ️ You can read the definitions of these concepts inside the “Definitions and legal references section” of the privacy policy.

To know more about your rights to limit the use of your sensitive personal information (“Limit the Use of My Sensitive Personal Information”) you can refer to the “Your privacy rights under US state laws” section of our privacy policy.

For more details on the collection of Personal Information, please read the section “Detailed information on the processing of Personal Data” of our privacy policy.

We won’t process your Information for unexpected purposes, or for purposes that are not reasonably necessary to and compatible with the purposes originally disclosed, without your consent.

What are the sources of the Personal Information we collect?

We collect the above-mentioned categories of Personal Information, either directly or indirectly, from you when you use FlowLeo App / flowleoapp.com.

For example, you directly provide your Personal Information when you submit requests via any forms on FlowLeo App / flowleoapp.com. You also provide Personal Information indirectly when you navigate FlowLeo App / flowleoapp.com, as Personal Information about you is automatically observed and collected.

Finally, we may collect your Personal Information from third parties that work with us in connection with the Service or with the functioning of FlowLeo App / flowleoapp.com and features thereof.

Your privacy rights under US state laws

You may exercise certain rights regarding your Personal Information. In particular, to the extent permitted by applicable law, you have:

  • the right to access Personal Information: the right to know. You have the right to request that we confirm whether or not we are processing your Personal Information. You also have the right to access such Personal Information;
  • the right to correct inaccurate Personal Information. You have the right to request that we correct any inaccurate Personal Information we maintain about you;
  • the right to request the deletion of your Personal Information. You have the right to request that we delete any of your Personal Information;
  • the right to obtain a copy of your Personal Information. We will provide your Personal Information in a portable and usable format that allows you to transfer data easily to another entity – provided that this is technically feasible;
  • the right to opt out from the Sale of your Personal Information; We will not discriminate against you for exercising your privacy rights.
  • the right to non-discrimination.

Additional rights for Users residing in California

In addition to the rights listed above common to all Users in the United States, as a User residing in California, you have:

  • The right to opt out of the Sharing of your Personal Information for cross-context behavioral advertising;
  • The right to request to limit our use or disclosure of your Sensitive Personal Information to only that which is necessary to perform the services or provide the goods, as is reasonably expected by an average consumer. Please note that certain exceptions outlined in the law may apply, such as, when the collection and processing of Sensitive Personal Information is necessary to verify or maintain the quality or safety of our service.

Additional rights for Users residing in Virginia, Colorado, Connecticut, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana

In addition to the rights listed above common to all Users in the United States, as a User residing in Virginia, Colorado, Connecticut, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Montana you have

  • The right to opt out of the processing of your personal information for Targeted Advertising or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you;
  • The right to freely give, deny or withdraw your consent for the processing of your Sensitive Personal Information. Please note that certain exceptions outlined in the law may apply, such as, but not limited to, when the collection and processing of Sensitive Personal Information is necessary for the provision of a product or service specifically requested by the consumer. In Maryland, your Sensitive Personal Information will be collected or processed only if strictly necessary to provide or maintain a specific product or service requested by you.

In Minnesota and Maryland Users also have the right to obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data

* Note that in some states like Minnesota you have the following specific rights connected to profiling:

  • The right to question the results of the profiling;
  • The right to be informed of the reason that the profiling resulted in the decision; if feasible
  • The right to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future;
  • The right to review personal data used in the profiling;
  • If inaccurate, the right to have the data corrected and the profiling decision reevaluated based on the corrected data;

Additional rights for users residing in Utah and Iowa

In addition to the rights listed above common to all Users in the United States, as a User residing in Utah and Iowa, you have:

  • The right to opt out of the processing of your Personal Information for Targeted Advertising;
  • The right to opt out of the processing of your Sensitive Personal Information. Please note that certain exceptions outlined in the law may apply, such as, but not limited to, when the collection and processing of Sensitive Personal Information is necessary for the provision of a product or service specifically requested by the consumer.

How to exercise your privacy rights under US state laws

To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

For us to respond to your request, we must know who you are. We will not respond to any request if we are unable to verify your identity and therefore confirm the Personal Information in our possession relates to you. You are not required to create an account with us to submit your request. We will use any Personal Information collected from you in connection with the verification of your request solely for verification and shall not further disclose the Personal Information, retain it longer than necessary for purposes of verification, or use it for unrelated purposes.

If you are an adult, you can make a request on behalf of a child under your parental authority.

How to exercise your rights to opt out

In addition to what is stated above, to exercise your right to opt-out of Sale or Sharing and Targeted Advertising you can also use the privacy choices link provided on FlowLeo App / flowleoapp.com.

If you want to submit requests to opt out of Sale or Sharing and Targeted Advertising activities via a user-enabled global privacy control, such as for example the Global Privacy Control (“GPC”), you are free to do so and we will abide by such request in a frictionless manner.

How and when we are expected to handle your request

We will respond to your request without undue delay, but in all cases within the timeframe required by applicable law. Should we need more time, we will explain to you the reasons why, and how much more time we need.

Should we deny your request, we will explain to you the reasons behind our denial (where envisaged by applicable law you may then contact the relevant authority to submit a complaint).

We do not charge a fee to process or respond to your request unless such request is manifestly unfounded or excessive and in all other cases where it is permitted by the applicable law. In such cases, we may charge a reasonable fee or refuse to act on the request. In either case, we will communicate our choices and explain the reasons behind them.

Additional information about Data collection and processing

Legal action

The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of FlowLeo App / flowleoapp.com or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.

Additional information about User's Personal Data

In addition to the information contained in this privacy policy, FlowLeo App / flowleoapp.com may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.

System logs and maintenance

For operation and maintenance purposes, FlowLeo App / flowleoapp.com and any third-party services may collect files that record interaction with FlowLeo App / flowleoapp.com (System logs) or use other Personal Data (such as the IP Address) for this purpose.

Information not contained in this policy

More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within FlowLeo App / flowleoapp.com and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.

Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.