Skip to content
BetterCMS
FeaturesSolutions
Join our Discord
FeaturesSolutions
Join our Discord

Legal

GDPR and Data Protection

Last updated: 27 July 2026

How we handle personal data, written for anyone running a privacy or vendor-security review. The Privacy Policy is the formal document; this is the detail behind it.

1. Who controls what

There are two different relationships here, and conflating them is the most common mistake in CMS privacy documentation:

  • Your account data: we are the controller. Your name, email, credentials and billing details.
  • Your content and your visitors' data: we are your processor. The pages, entries, media and above all the form submissions collected on the sites you publish. That data is yours. We process it only on your instructions. You are the controller, so you set the lawful basis, you inform your own visitors, and you answer their requests. We support you in doing so.

2. Where personal data is processed

  • Accounts and content: European Union (Finland)
  • Uploaded files and site assets: Cloudflare's global network
  • Transactional email: India
  • AI model inference: United States

Your account data and the content you create are stored and processed in the European Union. We are, however, an Indian company operating the service from India, and two further categories of processing sit outside the EU. Section 4 sets all of that out.

3. Sub-processors

Every third party that receives personal data, what it receives, the region it processes in, and a direct link to that provider's own GDPR or privacy terms. If your question is "our data is on Cloudflare, what are Cloudflare's commitments", the answer is one click away:

ProviderWhy we use themWhat they receiveRegionTheir terms
Hetzner Online GmbHHosting infrastructureData stored by the service, at restEuropean Union (Finland) Hetzner privacy & GDPR
Cloudflare, Inc.Content delivery, network and bot protection, file storageRequest traffic including IP addresses; uploaded filesGlobal network Cloudflare GDPR
Zoho Corporation (ZeptoMail)Transactional email: verification, password reset, invitations, notificationsRecipient email address and message contentIndia Zoho GDPR
Baseten Labs, Inc.AI model inferencePrompt content, which may include your contentUnited States Baseten privacy
Anthropic PBCAI model inferencePrompt content, which may include your contentUnited States Anthropic privacy & GDPR
Dodo PaymentsSubscription billing and payment processingBilling identity and payment details. Card data never reaches our systemsSee provider terms Dodo Payments privacy
GitHub, Inc. (Microsoft)Source-repository integration, only if you connect oneRepository contents and your GitHub account identityUnited States Microsoft/GitHub GDPR
Google LLCGoogle sign-in, and spreadsheet export only if you connect itYour Google account identity; exported form data if you enable that exportUnited States Google GDPR

If we add or replace a sub-processor that handles personal data, we will update this page. If you need advance notice of such changes as a contractual commitment, ask and we will put it in writing.

4. Where we are established, and international transfers

Flowtrix Private Limited is established in India, and the service is hosted in the European Union. Both facts matter, so we state them together rather than letting the EU hosting imply an EU company.

Because we offer this service to people in the EU, the GDPR applies to us under Article 3(2) even though we are established outside the Union, and we accept those obligations. As an Indian company we are also subject to India's Digital Personal Data Protection Act, 2023.

Personal data crosses borders in three ways, and we would rather name each than describe them vaguely:

  • Administration from India. Our team operates the service from India, so authorised staff can access systems holding personal data in order to run, support and secure it. Access is limited to what the role requires.
  • Transactional email is processed in India. Verification codes, password resets, invitations and form notifications contain the recipient's address and the message body.
  • AI inference is processed in the United States. When you use an AI feature, the prompt and the content it operates on go to a US model provider.

There is no European Commission adequacy decision for India, so where personal data moves from the EEA to us or to an Indian processor we rely on the appropriate Article 46 safeguards, primarily Standard Contractual Clauses, alongside the technical measures in section 6. For US providers we rely on the safeguards each provider offers, linked in the table above. If you need the specific mechanism for a named provider for your own records, ask and we will confirm it in writing rather than leave you to infer it.

EU representative: a controller outside the Union that offers services to people in the EU is generally required to designate a representative in the Union under Article 27. We have not yet appointed one. If you need to raise something and would prefer an EU point of contact, write to [email protected] and we will tell you where this stands.

5. AI features

When you use an AI feature, the relevant content leaves our infrastructure and goes to a third-party model provider to generate a response. Conversations are stored against your workspace so you can return to them, and are isolated to your workspace. Your content is not used to train AI models.

Practically: do not paste anything into the AI assistant that you would not want processed by those providers.

6. Security

Stated as what the controls achieve. We do not publish our internal architecture, because a detailed description of how a system is built is more useful to an attacker than to a customer. What we will confirm:

  • Tenant isolation is enforced below the application. Your workspace's records are separated from every other workspace at the storage layer, not only by application code, so a mistake in application logic still cannot return another customer's data.
  • Passwords are stored as slow salted hashes and are never recoverable, by us or by anyone who obtained the stored values. Two-factor authentication and passkeys are available on every account.
  • API keys are stored only as hashes. We cannot show you an existing key, only issue a replacement.
  • Credentials you supply for your own third-party providers are encrypted at rest with AES-256-GCM.
  • Transport: HTTPS everywhere, HSTS, and a strict set of security response headers including a frame-embedding denial.
  • Uploads are validated against an allow-list and by inspecting the file's actual contents, not the type it claims. Formats that can carry script are rejected.
  • Features that fetch a URL you supply refuse internal, private and cloud-metadata destinations, and re-check on every redirect, so they cannot be used to reach systems that are not publicly reachable.
  • Rate limiting and bot protection on authentication, public forms and resource-consuming endpoints.
  • Audit logging of administrative and security-relevant actions.
  • Least-privilege access internally, and role-based permissions with per-site scoping available to you for your own team.

If your review needs more depth than this, we will complete a security questionnaire or answer specific questions under NDA. We are happy to be specific privately; we are not willing to publish a blueprint.

7. If there is a breach

If a personal data breach affects your data we will notify you without undue delay once we have established what happened, and in any case in time to support your own Article 33 obligations where we act as your processor. We will tell you what was affected, what we know about the cause, and what we are doing about it, including where the answer is embarrassing for us.

8. Retention

DataKept for
Account data (profile, credentials)For the life of the account
Content you create: pages, entries, mediaFor the life of the account, or until you delete it
Server access logs (include IP address)Being fixed, see note ⚠️
Site analytics (pseudonymised; no IP stored)Being fixed, see note ⚠️
Form submissionsUntil you delete them ⚠️
AI assistant conversationsUntil you delete them ⚠️
Billing and accounting recordsAs required by law after the account closes

The rows marked ⚠️ are an honest gap: those stores have no automatic expiry yet, so they grow until deleted. We are setting defined periods. Until then, if you want any of that data removed sooner, ask and we will remove it.

9. Your rights, and how to exercise them

You can access, rectify, erase, restrict and port your personal data, and object to certain processing. You can correct your profile in your account settings, and export or delete individual projects from inside the product.

For a full export, or deletion of your entire account, email [email protected] and we will carry it out manually. There is no self-service button for this yet, and we would rather say so than imply a capability that does not exist. We respond within one month, as the GDPR requires. You may also complain to your local data protection authority.

Requests from your site's visitors

If one of your visitors asks you to produce or delete their form submission, you can do that yourself from your project's form submissions. Where you need our help, for example to confirm deletion across backups, contact us and we will act on your instruction as your processor.

10. Data processing agreement

Because we act as your processor for the content and form data you collect, a data processing agreement is appropriate for business customers. We do not yet publish a standard DPA. If you need one, contact us. We will provide one and will not treat it as an unusual request.

11. Certifications

We hold no ISO 27001 or SOC 2 certification today, and we would rather state that than let section 6 imply otherwise. The controls described there are real; they are simply not third-party audited yet.

12. Related documents

Privacy Policy, which includes our cookie disclosure, and Terms of Service.

13. How to contact us

This service is operated by Flowtrix Private Limited, 2nd Stage, 13th Cross Road, Indiranagar, Binnamangala, Bengaluru, Karnataka 560038, India. GSTIN 29AAGCF9453R1ZL.

Flowtrix Private Limited is the data controller for your account data. For any privacy request, access, export, correction or deletion, contact [email protected]. We answer within one month.

More legal documents

  • Privacy Policy
  • GDPR
  • Terms of Service
  • Back to home
BetterCMS

The Content Operating System for teams building modern websites with AI.

System status

Company

FeaturesSolutionsContact usDemo
Email usJoin our discordLinkedInXInstagram
Privacy PolicyTerms & ConditionGDPR Compliant

Built withlovein Bengaluru, IndiaIndian flag