Skip to content

Legal

Privacy Policy

How VAULT DESK, SINGLE MEMBER P.C. handles personal data in CRM FLOW: yours as a subscriber, and that of the clients or patients you record in the app.

Last updated:

Who we are

CRM FLOW (crmflow.io) is a software service operated by VAULT DESK, SINGLE MEMBER P.C., registered at Archaiou Theatrou 59, 136 75 Athens, Greece, company number 163840403000. Where this policy says “we” or “CRM FLOW”, it means that company, acting as data controller under the General Data Protection Regulation (GDPR, EU 2016/679).

For any data protection matter — a question, a request or a complaint — write to info@crmflow.io. Data subject requests are handled by our team at that address.

Our two roles

The GDPR distinguishes two roles. CRM FLOW holds both, over different data — and the distinction determines who you address for what.

  • Controller for your own data as a subscriber: account, business details, subscription, correspondence with us, technical logs. Here we decide the purposes and means of processing.
  • Processor for everything you enter into the app about your own clients or patients. There, you are the controller; we process that data only on your instructions, in order to run the service.

The terms of that processing on your behalf (Article 28 GDPR) are set out in the “Processing data on your behalf” section of the Terms of Service and form the data processing agreement between us — there is no separate document to sign.

Data we collect about you

Account

  • Full name or display name, username, business name, role within the team.
  • The language and the edition (trade) you selected.
  • Your password is stored only as a cryptographic hash. We do not know it and cannot recover it.

Signing in with Google (optional)

If you choose “Continue with Google”, we receive your Google account identifier, email address and name, so that your account can be created or matched. We gain access to no other data in your Google account.

Subscription and payments

Payments are handled by Polar, acting as Merchant of Record: it collects the payment details, issues the invoices and remits the taxes. Card details never reach our servers. From Polar we receive the status of your subscription — edition, plan, dates, whether a charge succeeded — and the billing details you gave them.

Usage and technical logs

Our servers record IP address, browser type and version, and the time and type of each request. These logs serve security, debugging and abuse handling — not profiling.

Correspondence

Whatever you send us by email: we keep it as long as needed to answer you and to document the case.

Data you record about your clients

The app exists so you can keep the record of your work. What you write there belongs to you and stays yours.

  • Client or patient details: name, phone, email, address, tax number and other billing details.
  • Appointments, jobs, visit history, notes, photos and files you upload.
  • Charges, payments and balances per client.
  • Depending on the edition: dental chart and clinical notes (DentalPro), session notes (PhysioPro), case details and deadlines (LawPro), clients’ tax data (TaxPro), job sheets, measurements and installer declarations (PlumbPro, ElectroPro).
  • Your staff accounts and their access rights.

Some of this is special category data under Article 9 GDPR — health data in DentalPro and PhysioPro — or covered by professional secrecy (LawPro, TaxPro). We use none of it for any purpose of our own: we do not read it, analyse it or sell it, and we do not train artificial intelligence models on it. Our staff access it only when you ask for support, and only as far as needed to resolve the problem.

Voice dictation

When you use dictation, the audio clip is sent to our server and from there to ElevenLabs (Scribe) for transcription. The text comes back and is saved to the record; we do not retain the audio. Voice navigation commands use the browser’s own Web Speech API — in Chrome, that means the audio is processed by Google under Google’s own policy.

SMS reminders

If you enable SMS reminders, the client’s number and the message text are passed to the SMS provider we use, solely in order to send the message. In-app and email reminders do not pass through any third party.

  • Performance of a contract (Art. 6(1)(b)): creating and running your account, providing the service, billing, support.
  • Legitimate interests (Art. 6(1)(f)): platform security, abuse prevention, server logs, aggregate statistics and improving the service.
  • Legal obligation (Art. 6(1)(c)): tax and accounting records.
  • Consent (Art. 6(1)(a)): only where we ask for it explicitly, e.g. for product emails. You can withdraw it at any time, without affecting the lawfulness of earlier processing.

For your clients’ data, the legal basis is determined by you as controller — usually your contract with them, your legal record-keeping duty or, for health data, Article 9(2)(h) GDPR.

Cookies and local storage

We use no advertising cookies and no third-party tracking cookies. That is why you will not see a consent banner: the ones we do use are strictly necessary for the service to work and require no consent.

  • Session cookie — keeps you signed in. Expires on sign-out or when the session ends.
  • XSRF-TOKEN — protection against cross-site request forgery.
  • cf_trade — remembers the trade you selected on the public pages, so your next visit opens the right edition. Lasts 180 days and holds no personal data.

In your browser’s local storage we also keep the trade selection and the voice mode setting. Chairside scratch notes live in sessionStorage: they are erased when the tab closes and explicitly on sign-out, so the next person at a shared computer does not find them.

Traffic statistics

On the public pages we use Piqo, a cookieless analytics tool that builds no profiles and does not follow visitors from site to site. We see totals — page views, referrers, country — not people. No analytics tool runs inside the application.

Where data is hosted and how it is protected

The application, the database and the files you upload are hosted on Amazon Web Services (AWS) infrastructure within the European Union.

  • Encryption in transit (TLS) and at rest.
  • Passwords stored only as cryptographic hashes.
  • Role-based access control, so each of your staff sees only what their role allows.
  • CSRF protection and session cookies with security flags.
  • Regular backups, so your data does not depend on a single machine.

No service is invulnerable. If a breach affecting your data occurs, we will inform you without undue delay and with the details you need in order to meet your own notification duties (Articles 33 and 34 GDPR).

Who else processes data

We do not sell data and we do not share it for advertising. We share it only with partners necessary to run the service, each bound by a processing agreement and a duty of confidentiality:

  • Amazon Web Services — hosting and backups (European Union).
  • Polar — payments, subscriptions and invoicing, as Merchant of Record.
  • ElevenLabs — speech-to-text for dictation.
  • Google — only if you use Google sign-in or voice commands in a Chrome browser.
  • SMS provider — sending reminders, if you enable them.
  • Piqo — cookieless statistics for the public pages.

An up-to-date list of sub-processors, with each one’s details and role, is available on request at info@crmflow.io. Data is disclosed to public authorities only where required by law or court order.

Transfers outside the EEA

Application data stays within the European Union. Some of the partners above (Polar, ElevenLabs, Google) may process data outside the European Economic Area. Where they do, the transfer relies on a European Commission adequacy decision or on the Standard Contractual Clauses, together with the supplementary technical measures those require.

How long we keep data

  • Account data: for as long as your subscription lasts.
  • Your clients’ data: for as long as you keep the account. After it ends or is deleted, the data stays available for export for 30 days and is then permanently deleted from live systems — and from backups at their next rotation.
  • Invoices and tax records: for as long as tax law requires, as a rule five years.
  • Server logs: up to 12 months.
  • Support correspondence: up to 24 months after the case is closed.

Your rights

As a data subject you have the right to:

  • Access — find out what data we hold about you and receive a copy.
  • Rectification — correct inaccurate or incomplete details.
  • Erasure — ask for your data to be deleted, where no lawful ground to keep it remains.
  • Restriction of processing and objection to it.
  • Portability — receive your data in a structured, commonly used format. Export is also available inside the app.
  • Withdrawal of consent, where processing is based on it.

Exercise these rights at info@crmflow.io. We answer within one month; if the request is complex, that period may be extended by two months and we will tell you. The service takes no decisions based solely on automated processing that produce legal effects for you.

If you are a client or patient of a professional who uses CRM FLOW, your request goes to them — they are the controller of your data. We will assist them in answering you.

Right to complain

If you believe we process your data unlawfully, you may complain to the Hellenic Data Protection Authority (1-3 Kifissias Ave., 115 23 Athens, Greece, www.dpa.gr) or to the supervisory authority in your country of residence. We would of course be glad to have the chance to put it right first.

Minors

The service is aimed at professionals and is not intended for use by minors; we do not knowingly create accounts for people under 18. Records of minor clients or patients that you enter are a different matter: there, informing them and obtaining parental consent is your responsibility as controller.

Changes to this policy

If something material changes — a new sub-processor, a new purpose of processing — we will update this page and the date at the top of it. For significant changes we will also notify you by email or in-app, at least 30 days before they take effect.

Contact

VAULT DESK, SINGLE MEMBER P.C. · Archaiou Theatrou 59, 136 75 Athens, Greece · Company no. 163840403000 · info@crmflow.io