Legal
Privacy Policy
Last updated: 5 September 2026
This policy explains how Streamflow Solutions ("we", "us", "our") collects, uses, and protects personal data when you visit our website, contact us, or use our services. We are committed to processing personal data lawfully, fairly, and transparently under the EU General Data Protection Regulation and the UK GDPR (together, the "GDPR") and applicable national law.
1. Who we are (data controller)
Streamflow Solutions - done-for-you operations automation for hospitality, ecommerce, and fintech businesses.
The controller is Ivan Skachek, a registered private entrepreneur in Ukraine, trading as Streamflow Solutions. A sole trader, not a company.
Contact: [email protected]
For the personal data we process on behalf of our clients (for example, guest data inside a client's review or messaging automations), the client is the controller and Streamflow Solutions acts as a processor under a separate Data Processing Agreement. This policy covers data for which we are the controller.
2. What data we collect
| Category | Examples | Source |
|---|---|---|
| Contact & enquiry data | Name, email, phone, company, message content | You, via forms or email |
| Booking data | Call scheduling details via our booking tool | You |
| Usage & analytics data | Pages viewed, approximate region, device/browser type | Automatically, via privacy-friendly analytics |
| Communications | Emails and messages you exchange with us | You |
We do not seek to collect special-category data and ask that you do not send it to us through our forms.
3. Why we use it and our lawful basis
- To respond to enquiries and provide quotes - lawful basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)).
- To deliver and administer our services - lawful basis: contract (Art. 6(1)(b)).
- To send relevant follow-ups about your enquiry - lawful basis: legitimate interests (Art. 6(1)(f)) in growing our business, balanced against your rights.
- To understand and improve our website - lawful basis: legitimate interests in maintaining a working, secure site; analytics are aggregated and privacy-friendly.
- To meet legal and accounting obligations - lawful basis: legal obligation (Art. 6(1)(c)).
Where we rely on legitimate interests, you may object at any time (see Section 7).
4. Who we share it with
We use a small set of trusted processors to run our business, each bound by data-processing terms and appropriate safeguards:
- Hosting & infrastructure - website hosting and our self-hosted automation server.
- Email delivery - to send transactional and follow-up emails.
- Scheduling - to let you book a call.
- Analytics - privacy-friendly, aggregated website analytics.
- Payments & e-signature - for clients who contract with us.
We do not sell personal data. Where a processor is located outside the EEA, transfers are protected by an adequacy decision or Standard Contractual Clauses.
5. Google user data
This section covers clients who connect a Google account so that we can answer reviews on their Google Business Profile. It does not apply to visiting this website, and none of it is collected from you by browsing. For this data the client is the controller and we act as their processor.
What we ask for. One scope, https://www.googleapis.com/auth/business.manage, through the Google Business Profile APIs. The client grants it from their own Google account on Google's consent screen, and sees the scope before agreeing to it. We request no other Google scope. We do not access Gmail, Drive, Calendar, Contacts, Photos, Ads or Analytics.
| Google user data we access | Why we access it |
|---|---|
| Business locations on the connected profile, with their names and identifiers | To know which profile and which location a review belongs to |
| Reviews on those locations: star rating, review text, the reviewer's public display name, the date, and any reply already published | To find a review that has not been answered, and to write a reply that answers what it actually says |
| Review replies | To publish the reply once the client has approved it |
| The OAuth tokens Google issues for the connected account | To hold the authorisation the client granted, so the connection keeps working without asking them again |
How we use it. We draft a reply to each unanswered review and, once the client approves it, publish that reply to the review it answers. Drafting uses an AI model, which receives the text of the review in order to write a reply to that one review for that one business. Nothing is published without the client's approval.
How we store and protect it. Review content and drafted replies are held in our EU-hosted database, encrypted in transit and at rest, reachable only by the client's own users and the engineers who run the service. The OAuth tokens are held as secrets, are never exposed to a browser, and are never written to logs.
How we share it. We do not sell Google user data, we do not use it for advertising, and we do not use it to build profiles for any purpose other than answering that client's reviews. It reaches only the processors needed to run the service: our EU hosting, and the AI provider that drafts the reply. We do not permit our AI providers to train their models on this content, and we do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models.
How long we keep it, and how to stop it. A client can disconnect at any time, either by asking us or from their own Google account permissions page. Revoking ends our access immediately. Within 30 days of a disconnection or of the engagement ending we delete the review content, the drafted replies and the stored tokens for that profile, except where Section 6 requires us to keep a record for a statutory period.
Limited Use. Streamflow Solutions' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become clients | Up to 24 months from last contact, then deleted |
| Client records & contracts | Duration of the engagement, then the statutory retention period set by Article 44.3 of the Tax Code of Ukraine. That period is counted from the date the tax return prepared using those documents was filed, or from the statutory filing deadline where no return was filed. |
| Accounting & invoices | The statutory retention period set by Article 44.3 of the Tax Code of Ukraine, counted from the same date |
| Website analytics | Aggregated; retained no longer than necessary |
7. How we protect it
We apply appropriate technical and organisational measures: encryption in transit (HTTPS), access controls and least-privilege on our systems, secret management for API credentials, and regular review of the processors we use. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and the relevant authority of any breach where the law requires.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), subject to legal retention;
- Restrict or object to processing, including processing based on legitimate interests and any direct marketing;
- Data portability - receive your data in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent.
To exercise any right, email [email protected]. We respond within one month. You also have the right to lodge a complaint with your supervisory authority - in the UK, the Information Commissioner's Office (ICO); or the supervisory authority in your country of residence.
9. Cookies & analytics
We keep cookies to a minimum and use no advertising cookies. Beyond what is strictly necessary, the tools below load only after you accept them in our consent banner. If you decline, they never run.
- Strictly necessary - required for the site to function and to keep it secure. These do not require consent and are always on.
- Microsoft Clarity - website analytics and session insights (pages viewed, clicks, scrolling) used to improve the site. Loads only with your consent.
- Business visitor identification (RB2B / LiveIntent) - where available, identifies the company associated with a visit (not the individual) using LiveIntent identity resolution, so we can follow up with relevant businesses. Loads only with your consent.
- Currency localisation - to show prices in your local currency we look up your approximate country from your IP address via a geolocation provider (ipapi.co) and remember your choice in your browser's local storage. No advertising and no cross-site tracking.
You can change your choice at any time by clearing this site's data in your browser, which brings the consent banner back. You can also block or delete cookies in your browser settings; strictly necessary cookies cannot be switched off without affecting the site.
10. Children
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the current version. Material changes will be highlighted on this page.
Contact
Questions about this policy or your data? Email [email protected] and we'll help.