7-day free trial — no credit card required
Reseller Flow
GDPR

GDPR

How we process personal data for customers and their contacts in the EEA, the UK, and Switzerland.

Effective: 2026-10-03 · Version: 2.0

This page explains how Reseller Flow meets the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss data protection law. Read it together with our Privacy Policy, which describes in detail what we collect and why.

1. Our role

  • Controller: for the personal data of people who create and use Reseller Flow accounts (account holders and team members), and for visitors to https://flow.inboxy.one.
  • Processor: for the personal data a workspace manages in Reseller Flow, such as its contacts, WhatsApp conversations, form answers, and appointments. The workspace is the controller of that data. We process it only on the workspace’s documented instructions, which are given through its use of the service and through our Terms of Service.

2. Legal bases (controller data)

  • Contract: to create your account and provide the service you signed up for.
  • Legitimate interests: to keep the service secure, prevent fraud and abuse, fix problems, and improve features, balanced against your rights.
  • Legal obligation: to keep invoices and respond to lawful requests.
  • Consent: for optional analytics and marketing cookies and for marketing emails. You can withdraw consent at any time.

3. Our commitments as a processor

  • We process workspace data only to provide the service, and never sell it or use it for our own marketing.
  • Everyone with access to workspace data is bound by confidentiality.
  • We protect data with encryption in transit (TLS), encryption of secrets and access tokens at rest, strict separation between workspaces, role-based permissions, two-factor authentication, audit logs, and backups.
  • We use only the subprocessors listed on our Subprocessors page, under written terms that protect personal data at least as well as we do. We update that page before adding a new subprocessor.
  • We help workspaces respond to their contacts’ requests (access, correction, deletion, export) and with data protection impact assessments where needed.
  • We notify the affected workspace without undue delay after becoming aware of a personal data breach.
  • When a workspace closes its account, we permanently delete its data within 30 days, except where the law requires us to keep it.

4. Your rights

You have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. To exercise these rights for your Reseller Flow account, email hello@clickcast.net. We reply within one month. If you are a contact of a business that uses Reseller Flow, please send your request to that business; we will help them respond. You can also complain to your local supervisory authority.

5. International transfers

Some subprocessors, such as Meta, OpenAI, and Google, process data in the United States and other countries. Where personal data leaves the EEA, the UK, or Switzerland, we rely on adequacy decisions (including the EU–US Data Privacy Framework where the recipient is certified) or on the European Commission’s Standard Contractual Clauses and the UK Addendum.

6. Data Processing Agreement

Workspaces that need a signed Data Processing Agreement (DPA) under Article 28 GDPR can request one at hello@clickcast.net.

7. Contact

For any data protection question, email hello@clickcast.net.