1. Who is responsible for your data
Flowmynt, operated from India, is the controller (in India, the data fiduciary) of the personal data described in this Policy. Contact: sanjay@flowmynt.com,. This contact also serves as Flowmynt's grievance officer under Indian law and as the point of contact for data protection requests under the GDPR and UK GDPR.
Where Flowmynt processes personal data on behalf of a Client in the course of delivering software or integration services, Flowmynt acts as a processor (in India, a data processor) under the Client's instructions and the Data Processing Addendum. That processing is governed by the Client's own privacy notice, not by this Policy. If you are a customer of a Flowmynt Client, please contact that Client.
2. What this Policy covers
This Policy covers the Website at flowmynt.com, enquiries sent to Flowmynt by email or WhatsApp, business-development activity, and the management of Client relationships. It does not cover third-party websites, WhatsApp, Meta, email providers or Providers that you use to contact or work with Flowmynt; their own policies apply.
3. Personal data we collect
The Website has no user accounts, no analytics and no advertising trackers. Forms on the Website do not send anything to Flowmynt's servers. When you choose to send your details, the Website opens a WhatsApp message or an email draft in your own app, which you review and send yourself. We collect personal data in these ways:
- Enquiries you send us: name, company, work email, WhatsApp or phone number, the platform, Provider and market you describe, the journey you want and anything else you include in your message. Messages sent on WhatsApp are also processed by WhatsApp (Meta) under its terms.
- Client relationship data: contact details of your representatives, Order and invoice details, correspondence, credentials you share for the Services, and technical information about your systems and Providers.
- Business-development data: business contact details of representatives of regulated financial firms taken from public sources, including official regulator registers (for example the FCA, EBA, FINTRAC, SAMA and similar registers), company websites and professional networks. We use this to contact firms that may benefit from our services.
- Technical data: our hosting and infrastructure provider records standard server logs (IP address, browser type, requested pages, timestamps) for security, abuse prevention and capacity planning. We do not combine these logs with your enquiry data.
- Data you give us at meetings, demos and events, and public business information about you.
4. Why we use personal data and our legal bases
Under the GDPR and UK GDPR we rely on the bases below. Under India's Digital Personal Data Protection Act, 2023 we process personal data for the purposes for which you have given it to us voluntarily, for legitimate uses recognised by that Act, or with your consent.
- To respond to your enquiry, review compatibility and prepare a proposal: performance of a contract or steps at your request before entering into one.
- To deliver the Services, manage the Client relationship, invoice and collect payment: performance of a contract and compliance with legal obligations (accounting and tax).
- To contact regulated firms about our services: our legitimate interest in marketing business-to-business software to firms that hold the licences it is designed for. We only use business contact details, we do not profile individuals, and you can object at any time.
- To keep the Website and our systems secure, prevent fraud and enforce our Terms: our legitimate interest in protecting our business and our Clients.
- To comply with law, respond to lawful requests and establish, exercise or defend legal claims: legal obligation and legitimate interest.
- Where we ask for consent, for example for a testimonial or to name you as a client: consent, which you can withdraw at any time.
5. Marketing and your choices
We do not send bulk marketing email or automated marketing messages. Business-development contact is individual and relevant to the recipient's firm. Every message tells you how to opt out. If you ask us not to contact you, we will add your details to a suppression list so that we do not contact you again.
We do not sell personal data and do not share it with third parties for their own marketing.
8. International transfers
Flowmynt operates from India and works with Clients and service providers around the world, so personal data may be transferred to and processed in India and in other countries. Where the GDPR or UK GDPR applies, we transfer personal data outside the EEA or the UK only under an adequacy decision or with appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum, together with supplementary measures where needed. You can ask us for a copy of the relevant safeguard.
Where Indian law applies, we transfer personal data outside India only to countries that are not restricted by the Central Government under the Digital Personal Data Protection Act, 2023.
9. How long we keep personal data
- Enquiries that do not lead to an engagement: 24 months from our last contact, then deleted, unless you ask us to delete sooner or to keep in touch.
- Client relationship, Order, invoice and correspondence records: for the term of the relationship and 8 years after it ends, to meet accounting, tax and limitation-period requirements.
- Business-development contact data: reviewed at least every 12 months and deleted when no longer relevant, or immediately on request.
- Suppression-list entries: kept indefinitely, limited to the minimum data needed to honour your request.
- Server logs: up to 90 days unless needed for a security investigation.
- Credentials and technical access provided for the Services: deleted or returned at the end of the Services, subject to the Data Processing Addendum.
10. Security
We protect personal data with measures appropriate to its sensitivity, including access on a need-to-know basis, multi-factor authentication on business accounts, encryption in transit, encrypted devices, secure credential handling, vendor due diligence and incident response procedures. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to affect you, we will notify you and any competent authority as the law requires.
11. Your rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Erase your data, where there is no overriding reason to keep it.
- Restrict or object to processing, including objecting to direct marketing at any time.
- Receive data you provided to us in a portable format.
- Withdraw consent where processing is based on consent, without affecting processing before withdrawal.
- Nominate a person to exercise your rights if you die or become incapacitated (India).
- Complain to a supervisory authority. In the EEA, contact the authority in your member state; in the UK, the Information Commissioner's Office (ico.org.uk); in India, the Data Protection Board of India once operational. We would appreciate the chance to address your concern first.
To exercise a right, email sanjay@flowmynt.com. We may need to verify your identity. We respond within one month under the GDPR and UK GDPR, or within the period required by the applicable law, and we do not charge for requests unless they are manifestly unfounded or excessive.
12. Children
The Website and the Services are for businesses. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, contact us and we will delete it.
13. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
14. Third-party links and services
The Website links to WhatsApp, email and other third-party services and websites. Their privacy practices are their own. When you open a WhatsApp chat or email draft from the Website, the message is handled by that service and by your own device and account.
15. Changes to this Policy
We may update this Policy from time to time. The effective date at the top shows the latest version. Material changes will be highlighted on the Website and, for Clients, notified by email.
16. Contact
Privacy questions, requests and complaints: sanjay@flowmynt.com.
Privacy Policy of Flowmynt. Effective 22 September 2026.