Privacy

What we hold, why we hold it, who else sees it, and how long it stays.

Last updated 21 September 2026

Two different roles

For information about the business using flow — the account, its staff, what it pays us — Skynat Labs is the responsible party under POPIA and the controller under the GDPR.

For information a business records about its own customers, the business is the responsible party or controller, and we are its operator under POPIA and its processor under the GDPR. We act on that business's instructions and do not use its customer data for anything else.

What we hold, and why

Account information: the name and email of each person with a login, so they can sign in and be attributed for what they do.

Business records: whatever the business chooses to record — customers, documents, money, stock, jobs.

Operational records: sign-in attempts, an audit trail of who changed what, server errors with names and identifiers stripped out, and timing samples that carry no content at all. These exist so we can tell a business what happened on its account and so that a fault is visible before a customer has to report it.

The AI assistant

When the assistant is used, the relevant part of the workspace's own records is sent to a model provider to produce an answer. Which provider can be chosen per workspace in settings.

What is sent is what the question needs, not the whole workspace. We do not use a business's records to train a model, and we do not permit our providers to.

Who else sees it

Sub-processors, and only for the job they do: hosting, the database, email delivery, file storage, payment processing, and the model provider in use. Each is bound to the same obligations we owe you.

Nobody else. We do not sell personal information and we do not share it for anyone else's marketing.

Where it is kept

Currently in a single region. If you need your records kept in a specific jurisdiction, ask before signing up — we would rather say no than say yes and be wrong.

How long

For as long as the workspace is open. After closure, most of it is removed after a grace period. Invoices and tax records are kept for the period the law where you trade requires, because both POPIA and the GDPR allow keeping what a law requires and the tax authority requires these.

Your rights

You can ask what we hold about you, ask for it to be corrected, ask for a copy, and ask for it to be deleted. Deletion is not absolute — what the law requires kept stays, and you are entitled to be told exactly which parts and why.

A business using flow can answer most of these for its own customers from inside the product, which is where such a request usually belongs.

If you are unhappy with how we have handled a request, you can complain to the Information Regulator in South Africa or to your own supervisory authority.

Security

Access to a workspace is checked on every request against a real membership, not against the address in the browser. Passwords are hashed, credentials stored in the database are encrypted, and sign-in is throttled against guessing.

We hold no independent security certification yet. SOC 2 is in progress and this paragraph will say so plainly until it is finished.