Privacy Policy
Last updated: September 4, 2026
Flux Technologies ("Flux", "we", "us") builds a customer messaging platform that unifies WhatsApp, Instagram and Facebook Messenger conversations into a single inbox and connects them to configurable sales pipelines.
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it. It applies to our website, our marketing communications and the Flux application (together, the "Services").
This document is a general template provided for informational purposes. Review it with qualified legal counsel and adapt it to your jurisdiction and actual data practices before publishing it as your production policy.
1. Our two roles: controller and processor
Flux acts as a data controller for the personal data of our own customers — the businesses and individuals who visit our website, create an account, subscribe to a plan or contact support. We decide why and how that data is processed.
Flux acts as a data processor (a "service provider" under some laws) for the personal data our customers upload to, or receive through, the platform — most importantly the contact details and message content of the end users who message our customers. Our customer is the controller of that data; we only process it on their documented instructions under our Data Processing Agreement.
2. Personal data we collect
Depending on how you interact with Flux, we may collect the following categories of data:
- Account data — name, business name, work email, phone number, password hash, role, workspace and team membership.
- Billing data — billing address, tax identifiers, plan and subscription history, and the last four digits and brand of your payment card. Full card numbers are handled by our payment processor and never stored on our servers.
- Channel connection data — the WhatsApp Business Account, phone number, Instagram Professional account or Facebook Page you connect, along with the access tokens and permissions you grant us through Meta.
- Customer content — messages, attachments, media, voice notes, contact names, phone numbers, profile pictures, labels, notes, custom fields, pipeline stages and deal values that flow through your workspace. This is the data we process on your behalf.
- Usage and device data — IP address, browser and device type, operating system, language, pages viewed, features used, timestamps, referring URLs and diagnostic logs.
- Support data — the content of tickets, emails, chats and calls you exchange with our team.
- Marketing data — the information you submit in demo requests, newsletter forms and event sign-ups, plus your communication preferences.
3. How we use personal data
We use personal data to:
- Provide, operate, maintain and secure the Services, including delivering and receiving messages across connected channels.
- Create and administer accounts, workspaces, seats, roles and permissions.
- Process payments, prevent fraud, manage subscriptions and issue invoices.
- Provide customer support and respond to your requests.
- Monitor performance, debug errors, analyse aggregate usage and improve our features.
- Send service communications such as security alerts, billing notices and product changes.
- Send marketing communications where permitted by law, always with an unsubscribe link.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell personal data, and we do not use the content of your customers’ messages to train general-purpose advertising or foundation models. Where AI features are enabled in your workspace, they run on request, are scoped to your workspace, and providers are contractually barred from using your data to train their models.
4. Legal bases for processing
Where the EU or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Services you subscribed to); legitimate interests (to secure, improve and promote our platform, balanced against your rights); consent (for optional cookies and certain marketing, which you may withdraw at any time); and legal obligation (for tax, accounting and lawful requests).
5. WhatsApp, Instagram and Messenger data
Flux is a WhatsApp Business Solution Provider and integrates with the Meta platforms through their official APIs. When you connect a channel, Meta shares limited data with us so we can deliver the Services: your business account identifiers, connected phone numbers or pages, message payloads, delivery and read receipts, and quality or rate-limit signals.
We use platform data only to provide and improve the Services for you. We do not use it for advertising, we do not sell it, and we do not transfer it except to the subprocessors listed below or where you direct us to. Our use of information received from Meta APIs follows the Meta Platform Terms, the WhatsApp Business Messaging Policy and the applicable developer policies.
You are responsible for having a lawful basis to message your own contacts, for honouring opt-outs, and for the content of the templates and campaigns you send.
7. International transfers
Flux operates globally, so your data may be processed in countries other than the one you live in, including the United States. When we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on an adequacy decision where one exists, or otherwise on the European Commission’s Standard Contractual Clauses together with supplementary technical and organisational safeguards.
Customers on eligible plans may request that their workspace data be hosted in a specific region. We sign a Data Processing Agreement, including the Standard Contractual Clauses, with any customer who requests one.
8. Data retention
We keep account and billing records for as long as your account is active and for up to seven years afterwards, where required by tax and accounting law.
Customer content is retained for as long as your workspace exists. When you delete a conversation, contact or record, it is removed from the interface immediately and purged from active systems within 30 days. Encrypted backups are rotated out within 90 days.
When you close your account, we delete or anonymise your workspace data within 90 days, except where a longer period is required by law or to resolve a dispute. You can export your contacts and conversations at any time before closing.
9. How we protect data
We encrypt data in transit with TLS 1.2 or higher and at rest with AES-256. Access to production systems is limited to authorised personnel, protected by single sign-on and multi-factor authentication, and logged. We apply least-privilege access controls, review them periodically, run automated vulnerability scanning and commission independent penetration tests.
No system can be guaranteed perfectly secure. If a personal data breach affects you, we will notify the relevant supervisory authority and, where the law requires it, affected users without undue delay.
10. Your privacy rights
Subject to your jurisdiction, you may have the right to access your personal data, correct inaccurate data, delete it, restrict or object to its processing, receive it in a portable format, withdraw consent, and lodge a complaint with your data protection authority. Residents of California may additionally request disclosure of the categories of data collected and shared, and may opt out of any "sale" or "sharing" — Flux does not sell or share personal data as those terms are defined.
To exercise a right, email privacy@flux.app from the address associated with your account. We respond within 30 days, and we will not discriminate against you for exercising your rights. If your request concerns data that a Flux customer controls (for example, a business that you messaged on WhatsApp), we will refer you to that business, which is the controller of that data.
12. Children
Flux is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Third-party links and integrations
The Services may link to or integrate with third-party products such as Meta, payment providers, CRMs, e-commerce platforms and automation tools. Those third parties operate under their own privacy policies, and we are not responsible for their practices. Review them before connecting an integration.
14. Changes to this Policy
We may update this Policy to reflect changes to the Services or the law. When we make a material change we will update the date at the top, and notify you by email or an in-app notice at least 15 days before it takes effect. Continuing to use the Services after the effective date means you accept the updated Policy.
15. Contact us
For any privacy question, request or complaint — including to reach our Data Protection Officer — write to us. We reply to every privacy request.
Flux Technologies · Data Protection Officer · 1 Market Street, Suite 400, San Francisco, CA 94105, USA