Privacy Policy
Updated on 08th May, 2025
- Introduction
Welcome to Flozi (“we”, “us”, “our”). We are committed to protecting your privacy and ensuring your personal data is handled securely and transparently. This Privacy Policy explains how we collect, use, and protect your information when you use our website and services (“Flozi App”).
By accessing or using Flozi, you agree to the practices described in this Privacy Policy. If you disagree, please do not use our services.
- Who We Are
Flozi is a platform that syncs Notion databases with Webflow CMS collections to streamline content workflows. Our services operate globally, with data hosting primarily in AWS Mumbai (ap-south-1) via MongoDB Atlas.
- Data Controller: Neue World OÜ, registered in 6 Sepapaja, Estonia - 15551
- Contact: hello@flozi.io
- Data We Collect
We collect information to provide and improve our services. This includes data that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device ("Personal Data").
Data Provided Directly by You:
- Account Information:
- Full Name
- Email Address
- Country
- Password (stored in encrypted form)
- Billing Information (if subscribing to paid plans, processed by our payment provider):
- Cardholder Name
- Last 4 digits of Card Number
- Card Brand
- Card Expiry Date
(Note: We do not store your full credit card number on our servers)
Data Collected Automatically:
- Usage Data: Information about how you access and use the Flozi App. This data is collected automatically as you interact with our service, primarily through third-party analytics tools such as Google Analytics.
- IP Address
- Browser Type and Version
- Operating System and Device Type
- Pages Visited, Time Spent on Pages
- Clickstream Data (interactions within the App)
- Usage frequency and patterns
Connected Account Data (accessed via secure tokens/credentials):
- Notion API Tokens (encrypted at rest)
- Webflow Access Tokens (encrypted at rest)
- Google Access and Refresh Tokens (if used, encrypted at rest)
- Metadata from connected services: This includes information about the content or structure you connect (e.g., Notion database IDs, Webflow collection names, property types relevant to syncing configuration) but not the content itself, unless explicitly necessary for the core syncing function as configured by you.
- How and Why We Use Your Data
We process your Personal Data for the following purposes, relying on specific legal bases as required by laws like the GDPR:
- To Provide and Maintain Our Services (Legal Basis: Performance of a Contract Art. 6(1)(b) GDPR): We use your Account Information, Connected Account Data, and relevant Usage Data to create, manage, and authenticate your account, connect your third-party services (Notion, Webflow, Google), perform the core syncing functionality you configure, and operate the Flozi App. Billing Information is used to process your subscription payments.
- For Account Creation and Authentication (Legal Basis: Performance of a Contract Art. 6(1)(b) GDPR): We use your Account Information (Name, Email, Encrypted Password) to establish and secure your user account, allowing you to log in and access the service. Connected Third-Party tokens are used to authenticate your access to those external services via Flozi.
- To Improve Our Platform (Legal Basis: Legitimate Interests Art. 6(1)(f) GDPR - improving user experience, service performance): We analyze aggregated and anonymized or pseudonymized Usage Data and, in some cases, relevant Connected Account Data (like the types of properties being synced, not their values) to understand how our service is used, identify performance issues, inform product development, and enhance user experience.
- To Communicate With You (Legal Basis: Performance of a Contract Art. 6(1)(b) GDPR for service-related communications; Legitimate Interests Art. 6(1)(f) GDPR or Consent Art. 6(1)(a) GDPR for marketing): We use your Account Information (specifically Email Address and Name) to send you essential service updates, security notifications, technical notices, and customer support responses. With your consent or based on our legitimate interest (where permitted by law), we may also send you newsletters and marketing communications about new features or offers, providing an easy way to opt-out.
- To Comply with Legal Obligations (Legal Basis: Compliance with a Legal Obligation Art. 6(1)(c) GDPR): We may process and retain certain Account Information, Billing Information, and Usage Data as required by applicable laws, regulations, or legal processes (e.g., accounting, tax, or law enforcement requests).
- Data Retention
We retain your Personal Data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
The criteria used to determine our retention periods include:
- Account Lifetime: We generally retain your account data (Account Information, Connected Account Data) for as long as your account is active. If you close your account, we will delete or anonymize this data within a reasonable timeframe, unless retention is required for legal or compliance reasons.
- Legal Obligations: We retain certain data (e.g., Billing Information) for periods required by law (e.g., for tax and accounting purposes).
- Service Improvement: We may retain anonymized or aggregated Usage Data for longer periods for analysis and service improvement, where this data can no longer be linked back to an identifiable individual.
After the applicable retention period, your data will be securely deleted or anonymized.
- Sharing Your Data
We do not sell or rent your Personal Data to third parties. We may share your data with the following categories of third parties, strictly for the purposes outlined in this Privacy Policy and under appropriate safeguards:
- Service Providers: We use third-party service providers to perform services on our behalf, such as:
- Cloud Hosting and Database Providers (e.g., Amazon Web Services (AWS), MongoDB Atlas): We share operational data necessary to store and run our services securely. Your data is hosted on servers managed by these providers in the regions specified (primarily AWS Mumbai).
- Payment Processors (e.g., Stripe): We share your Billing Information (Cardholder Name, limited card details, subscription amount) necessary to process your payments securely. We do not store your full card details.
- Analytics Providers (e.g., Google Analytics, as mentioned in Cookie Policy): We use these providers to collect and process Usage Data (often in pseudonymized or aggregated form) to help us analyze how users interact with our service and improve it.
- Communication Services (e.g., Email providers): We may share your Email Address and Name to send you service-related or marketing communications as described in Section 4.
- Connected Third Parties (Notion, Webflow, Google): When you use Flozi to connect your accounts, we access data from these services on your behalf using the tokens you provide. This data access is solely for the purpose of providing the syncing service you configure. We do not share your data with Notion, Webflow, or Google, but rather act as a service accessing data from them based on your instructions.
- Legal Authorities: We may disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court order or a government agency’s request).
We ensure that all third parties we share data with are bound by confidentiality obligations and implement appropriate security measures.
- Your Data Protection Rights
Under applicable data protection laws (such as GDPR and CCPA), you have certain rights regarding your Personal Data. Depending on your location and the nature of the data, these rights may include:
- The right to access the personal data we hold about you.
- The right to request the correction of inaccurate or incomplete data.
- The right to request the deletion of your personal data ("right to be forgotten").
- The right to request the restriction of processing your personal data.
- The right to object to the processing of your personal data (e.g., for direct marketing).
- The right to data portability, allowing you to receive your data in a structured, commonly used, and machine-readable format.
- Where processing is based on consent, the right to withdraw your consent at any time.
- The right not to be subject to automated decision-making, including profiling, that produces legal effects or similarly significantly affects you (Note: Flozi does not currently use your personal data for automated decision-making in this way).
- The right to lodge a complaint with a supervisory authority.
To exercise any of these rights, please contact us at hello@flozi.io. We will respond to your request in accordance with applicable law.
- Data Security
We are committed to protecting the security of your Personal Data. We implement industry-standard technical and organizational measures designed to protect your data from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data both at rest (when stored) and in transit (when being transferred).
- Regular security audits and vulnerability assessments.
- Strict access controls and monitoring of internal systems.
- Secure handling of credentials and tokens.
While we strive to use commercially acceptable means to protect your Personal Data, no method of transmission over the Internet or method of electronic storage is 100% secure.
- International Data Transfers
Your Personal Data may be transferred to, and processed in, countries outside of your country of residence, including to the United States, where our service providers or infrastructure may be located.
When transferring data outside of the European Economic Area (EEA) or other regions with similar data protection requirements, we ensure that appropriate safeguards are in place to provide a similar level of protection. These safeguards may include:
- Transferring data to countries that have been deemed to provide an adequate level of data protection by the European Commission or relevant authorities.
- Using Standard Contractual Clauses (SCCs) approved by the European Commission or relevant authorities, which contractually oblige recipients to protect your data.
- Where applicable, relying on the service provider's Binding Corporate Rules or adherence to frameworks designed to ensure adequate protection.
- Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our services. Please refer to our separate Cookie Policy for detailed information on how we use cookies, what types of cookies we use, and how you can manage your preferences. We use cookies for session management and analytics (such as Google Analytics).
- Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the new Privacy Policy on this page, and where appropriate, by email or through a prominent notice within the Flozi App before the changes become effective.
This Privacy Policy is intended to provide transparency regarding our data processing activities and our commitment to protecting your privacy in a manner consistent with general data protection principles reflected in laws such as the EU GDPR and the California CCPA. If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at hello@flozi.io.
Join the Founder’s Club
$9/mo
annually
Perfect if you’re just getting started with Flozi. You get full access to the editor, SEO features, and Notion-to-Webflow sync.