Privacy Policy
Last updated: 12 September 2026
This policy explains what personal data Flowstate collects through this website, why we collect it, and what rights you have over it. It applies to flowstatesystems.ai.
Who we are
Flowstate is a marketing and automation business based in Derry, Northern Ireland, operating across the UK and Ireland. For any privacy question, or to exercise any of the rights below, contact kevin@flowstatesystems.ai.
What we collect
- Details you give us. When you complete an application or book a call: your name, email address, phone number, and the answers you provide about your business (such as sector, approximate monthly revenue, current advertising spend, and timescales).
- Usage and device data. Pages viewed, approximate location derived from IP address, browser and device type, and the advertising or referral source that brought you here.
- Booking details. If you schedule a call, the date and time you choose and any notes you add.
Why we use it, and our lawful basis
- To respond to your enquiry and hold the call you requested. This is necessary to take steps at your request before entering a contract.
- To follow up if you don't complete a booking. We rely on our legitimate interest in contacting people who have asked us about our services. You can opt out at any time and we will stop.
- To measure and improve our advertising. We rely on your consent for non-essential cookies and similar advertising technologies.
Website analytics
With your permission, we use Google Analytics to understand how visitors find and use this website, and which pages lead to enquiries. Google receives usage information such as pages viewed, device information and online identifiers. We do not intentionally send your name, email address, phone number or enquiry answers to Google Analytics. You can change your analytics choice through Cookie settings.
Advertising and analytics
With your advertising permission, we use the Meta pixel and Meta's Conversions API to understand which adverts lead to enquiries and bookings. This means limited information about your actions on this site — for example that you submitted an application or booked a call — is shared with Meta, along with identifiers such as cookie values and, where available, a securely hashed version of your email address or phone number. Hashed details can still be matched to a person by Meta; hashing does not make this information anonymous. Meta processes this data under its own privacy policy. You can control ad personalisation in your Meta account settings.
Who we share it with
We do not sell your personal data. We share it only with the providers that run our systems, and only so they can provide those services to us:
- Our customer relationship management and scheduling platform, which stores your enquiry and manages the booking.
- Our website hosting provider and restricted booking-reservation database.
- Google, for website analytics when you allow it.
- Meta Platforms, for the advertising measurement described above.
- Email and video-call providers used to confirm and hold your call.
Some providers are based outside the UK and EEA. Where that happens, transfers are covered by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
How long we keep it
Enquiry and booking records are kept for up to 24 months from your last interaction with us, after which they are deleted or anonymised. If you become a client, we keep records for as long as we work together and for six years afterwards to meet legal and accounting duties.
Your rights
Under UK and EU data protection law you have the right to access a copy of your data, to have inaccurate data corrected, to have your data erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you may withdraw it at any time. Email kevin@flowstatesystems.ai and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EU.
Application forms and booking protection
On the application form, your name and valid email may be saved after you move past the email field, before the full application is submitted. This lets us respond if you do not finish the booking. Calendar requests use short-lived request tokens and rate limits to protect availability. Our booking-reservation database stores protected identifiers and booking references to prevent duplicate bookings; it does not store your raw form answers. Verified reservation references are removed by a daily cleanup once they have been unchanged for 120 days. Expired request-rate records are removed after a one-day grace period. Requests with an uncertain outcome are retained for reconciliation to avoid duplicate bookings and are not automatically retried or deleted.
Your website choices
Analytics and advertising are separate optional choices and start off. You can reject both and still enquire or book. Use Cookie settings on any page to change or withdraw your choice. Choices are remembered for up to six months. Withdrawal stops future optional measurement; it does not remove data already received by a provider.
Google Analytics user and event data retention is set to two months without resetting the user retention period on new activity. This setting does not remove most aggregated standard reports.
Cookies
We use cookies that are strictly necessary for the site to function, and — with your consent — advertising cookies set by Meta to measure campaign performance. You can clear or block cookies in your browser settings; the site will still work, but our measurement will be less accurate.
Changes
If we change this policy we will update the date at the top of this page.