Legal

Privacy Policy

Last updated: 5 September 2026

This policy explains how Streamflow Solutions ("we", "us", "our") collects, uses, and protects personal data when you visit our website, contact us, or use our services. We are committed to processing personal data lawfully, fairly, and transparently under the EU General Data Protection Regulation and the UK GDPR (together, the "GDPR") and applicable national law.

1. Who we are (data controller)

Streamflow Solutions - done-for-you operations automation for hospitality, ecommerce, and fintech businesses.
The controller is Ivan Skachek, a registered private entrepreneur in Ukraine, trading as Streamflow Solutions. A sole trader, not a company.

Contact: [email protected]

For the personal data we process on behalf of our clients (for example, guest data inside a client's review or messaging automations), the client is the controller and Streamflow Solutions acts as a processor under a separate Data Processing Agreement. This policy covers data for which we are the controller.

2. What data we collect

CategoryExamplesSource
Contact & enquiry dataName, email, phone, company, message contentYou, via forms or email
Booking dataCall scheduling details via our booking toolYou
Usage & analytics dataPages viewed, approximate region, device/browser typeAutomatically, via privacy-friendly analytics
CommunicationsEmails and messages you exchange with usYou

We do not seek to collect special-category data and ask that you do not send it to us through our forms.

3. Why we use it and our lawful basis

Where we rely on legitimate interests, you may object at any time (see Section 7).

4. Who we share it with

We use a small set of trusted processors to run our business, each bound by data-processing terms and appropriate safeguards:

We do not sell personal data. Where a processor is located outside the EEA, transfers are protected by an adequacy decision or Standard Contractual Clauses.

5. Google user data

This section covers clients who connect a Google account so that we can answer reviews on their Google Business Profile. It does not apply to visiting this website, and none of it is collected from you by browsing. For this data the client is the controller and we act as their processor.

What we ask for. One scope, https://www.googleapis.com/auth/business.manage, through the Google Business Profile APIs. The client grants it from their own Google account on Google's consent screen, and sees the scope before agreeing to it. We request no other Google scope. We do not access Gmail, Drive, Calendar, Contacts, Photos, Ads or Analytics.

Google user data we accessWhy we access it
Business locations on the connected profile, with their names and identifiersTo know which profile and which location a review belongs to
Reviews on those locations: star rating, review text, the reviewer's public display name, the date, and any reply already publishedTo find a review that has not been answered, and to write a reply that answers what it actually says
Review repliesTo publish the reply once the client has approved it
The OAuth tokens Google issues for the connected accountTo hold the authorisation the client granted, so the connection keeps working without asking them again

How we use it. We draft a reply to each unanswered review and, once the client approves it, publish that reply to the review it answers. Drafting uses an AI model, which receives the text of the review in order to write a reply to that one review for that one business. Nothing is published without the client's approval.

How we store and protect it. Review content and drafted replies are held in our EU-hosted database, encrypted in transit and at rest, reachable only by the client's own users and the engineers who run the service. The OAuth tokens are held as secrets, are never exposed to a browser, and are never written to logs.

How we share it. We do not sell Google user data, we do not use it for advertising, and we do not use it to build profiles for any purpose other than answering that client's reviews. It reaches only the processors needed to run the service: our EU hosting, and the AI provider that drafts the reply. We do not permit our AI providers to train their models on this content, and we do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models.

How long we keep it, and how to stop it. A client can disconnect at any time, either by asking us or from their own Google account permissions page. Revoking ends our access immediately. Within 30 days of a disconnection or of the engagement ending we delete the review content, the drafted replies and the stored tokens for that profile, except where Section 6 requires us to keep a record for a statutory period.

Limited Use. Streamflow Solutions' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. How long we keep it

DataRetention
Enquiries that do not become clientsUp to 24 months from last contact, then deleted
Client records & contractsDuration of the engagement, then the statutory retention period set by Article 44.3 of the Tax Code of Ukraine. That period is counted from the date the tax return prepared using those documents was filed, or from the statutory filing deadline where no return was filed.
Accounting & invoicesThe statutory retention period set by Article 44.3 of the Tax Code of Ukraine, counted from the same date
Website analyticsAggregated; retained no longer than necessary

7. How we protect it

We apply appropriate technical and organisational measures: encryption in transit (HTTPS), access controls and least-privilege on our systems, secret management for API credentials, and regular review of the processors we use. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and the relevant authority of any breach where the law requires.

8. Your rights

Under the GDPR you have the right to:

To exercise any right, email [email protected]. We respond within one month. You also have the right to lodge a complaint with your supervisory authority - in the UK, the Information Commissioner's Office (ICO); or the supervisory authority in your country of residence.

9. Cookies & analytics

We keep cookies to a minimum and use no advertising cookies. Beyond what is strictly necessary, the tools below load only after you accept them in our consent banner. If you decline, they never run.

You can change your choice at any time by clearing this site's data in your browser, which brings the consent banner back. You can also block or delete cookies in your browser settings; strictly necessary cookies cannot be switched off without affecting the site.

10. Children

Our website and services are intended for businesses and are not directed at children. We do not knowingly collect data from anyone under 16.

11. Changes to this policy

We may update this policy from time to time. The "Last updated" date above reflects the current version. Material changes will be highlighted on this page.

Contact

Questions about this policy or your data? Email [email protected] and we'll help.