Last updated 12 September 2026
Privacy policy
SPGFlow is a UK-based software platform. This notice explains how we handle personal data when businesses apply for early access, use SPGFlow or connect supported communications channels.
Data we process
- Business account, user and contact details.
- Early-access application details, including business profile, team size, current software, product interests and feedback preferences.
- Customer enquiries, messages, attachments and conversation timestamps.
- Identifiers for authorised messaging accounts, phone numbers, Facebook Pages and Instagram business accounts.
- Security, authentication, audit and service diagnostic information.
Early-access applications
We use beta and waiting-list application details to assess suitability, plan product development, contact applicants about access and understand demand by business type and country. Applying does not create an SPGFlow account or require payment.
How we use data
We use personal data to provide and secure SPGFlow; receive and display authorised business communications; let approved staff respond to, assign and track enquiries; maintain customer and workflow records; provide support; prevent misuse; and meet legal obligations. We do not sell Platform Data or use connected communications data for unrelated advertising.
Roles and lawful basis
For data a business customer imports or receives through SPGFlow, that customer normally acts as controller and SPGFlow acts as processor under the customer’s instructions. For account administration, security, early-access applications and our own commercial records, SPGFlow acts as controller. Processing is based as applicable on contract, legitimate interests, legal obligations and consent.
Sharing and international transfers
We disclose data only to authorised users, communications platforms where required to provide connected channels, infrastructure and support suppliers working under contract, professional advisers, or authorities where legally required. Where data is transferred internationally, we use applicable contractual and legal safeguards.
Security and retention
SPGFlow separates customer tenants, restricts access by role, validates webhook authenticity and encrypts stored connection credentials. We retain business data while an account is active and as needed for the service, security, backups and legal obligations. Data is deleted or anonymised when no longer required, subject to agreed retention periods and backup cycles.
Your choices and rights
Business administrators control connected assets and staff access. Individuals may have rights to access, correct, erase, restrict or object to processing, and to data portability or withdrawal of consent. Requests concerning a business customer’s records should normally be directed to that business first.
Contact
For privacy questions or rights requests, email [email protected]. You may also complain to the UK Information Commissioner’s Office.