Flowenica
Privacy notice
Version: flowenica-privacy-v6-2026-09-21
Status: Public notice
Effective from: 21 September 2026
Controller and contacts
Morrone Marco, Via Antonio Gramsci 1, 10072 Caselle Torinese (TO), Italia. Privacy: privacy@flowenica.com. Support: support@flowenica.com. The controller is reached by email only.
Who you deal with
With Flowenica you deal only with an artificial intelligence system. Every message, reply and action is handled by AI: no person will write to you, call you or reply to you. The owner can check a reply before it is sent, but does not write it and never contacts you.
Data processed
Identity and contact data voluntarily provided, company, request, selected offer and budget, messages sent with the “Write to us” form (optional name, email and text), consents and the versions of the documents accepted, language, a fingerprint of the IP address kept with the consent, computed with a secret key that stays on our server and without which the address cannot be derived from the fingerprint (fingerprints recorded before 21 September 2026 were computed without a key), security events and necessary technical data. If you receive a direct Flowenica response, the link may contain a random identifier that records the date of the first visit, the date of the last visit and the number of visits to the website. We do not ask for phone numbers: a number sent anyway is discarded without being stored. We do not request special-category data.
Purposes and legal bases
Managing and verifying requests, responding and taking requested pre-contractual steps; replying to messages sent with the “Write to us” form; measuring a direct response's effectiveness through the visits its link records, based on legitimate interests (Article 6(1)(f) GDPR), as explained in the section “Links in a direct response”; an anonymous count of the pages visited, which processes no personal data; security and abuse prevention based on legitimate interests; promotional communications only with consent; legal obligations where applicable.
Links in a direct response
When we reply to a request you published, the link in the reply may contain a random identifier tied to that reply, and so to you: the visits it records (date of the first visit, date of the last visit, number of visits) are personal data. Legal basis: the controller's legitimate interest (Article 6(1)(f) GDPR) in knowing whether a reply sent to your public request was opened, to assess how effective the replies are. The processing is limited to dates and a count, uses no cookie, IP address or browser data, builds no profile and is kept for the period stated under “Retention”; for this reason we consider that it does not override your interests and rights. You may object at any time (Article 21 GDPR) by writing to privacy@flowenica.com: we delete the recorded visits and the link stops recording them.
Emails and replies to published requests
If you write to us directly, we keep your message, our reply and the conversation they belong to. If we reply to a request you published on a public platform, the address we write to comes from that post or from the public profile linked to it (Article 14 GDPR): we process the address, the published text and our reply for the legitimate interest in offering a service relevant to the request (Article 6(1)(f) GDPR). You may object at any time by writing to privacy@flowenica.com: we delete the reply and do not contact you again. If you are already a customer we may write to you about services similar to those provided, and every message says how to object.
Source of data not collected from you
When we reply to a published request, the email address and the text of the request come from the public platform where you published it or from the public profile linked to it. We do not buy contact lists and we do not collect addresses from third parties.
Mandatory and optional data
Name, company, email, request, privacy acknowledgement and contact permission are necessary to manage the request; the “Write to us” form needs only email, message and privacy acknowledgement. Marketing is optional. Missing necessary data prevents submission.
Recipients and processors
The controller and strictly necessary cloud, network protection, hosting, email and AI providers. Providers act under their applicable roles and agreements.
International transfers
Some providers may process data outside the EEA. Where applicable, transfers rely on adequacy decisions, the Data Privacy Framework, standard contractual clauses and supplementary measures declared by providers.
Retention
Unverified requests: up to 30 days from receipt. Verified requests: up to 365 days from verification. Technical events: up to 90 days. Verification emails: the text, with the link, is deleted 7 days after sending and the record of the sending (recipient and date) after 90 days; the link is not kept after it is sent or after it expires. Analysis email prepared by the AI system for a verified request: 24 months from sending. Marketing consent: valid for 24 months unless renewed; the proof of consent is kept 24 months after it ends. Privacy requests (access, deletion and similar): once carried out we keep only a fingerprint of the address, computed with the same secret key, the type and the dates, for 24 months; fingerprints recorded before 21 September 2026 were computed without a key and are deleted. Objection to communications: the address is kept without a time limit, only to keep honouring it. Customers: invoices and contracts for 10 years as required by law; operational notes 24 months from the end of the relationship. “Write to us” messages: 24 months from receipt. Visits recorded by a reply's link: deleted 12 months after the last visit; the link records visits for 12 months after it was sent. Anonymous page counts: 24 months. Emails you send us, our replies and their conversation: 24 months from the last message of the exchange. Replies to published requests and their record: 12 months from sending. Messages sent to customers about similar services and their campaigns: 24 months from sending, as the proof of what was sent. Drafts never sent: 90 days. Order confirmation emails and the related business correspondence: 10 years (Article 2220 of the Italian Civil Code). Copies of a request in other records (demand register, contacts, drafts) follow the request: when it is deleted they are deleted or anonymised. Deletion runs every day and we keep a record of it. Legal duties, disputes or earlier deletion may apply.
Automated decisions
Flowenica's AI system classifies and prioritises requests and prepares the replies, but it does not conclude contracts, enable payments or produce legal or similarly significant effects: those always require a separate offer and your explicit acceptance.
Rights
You may request access, correction, deletion, restriction, objection, portability where applicable, and withdrawal of consent at privacy@flowenica.com. You may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the competent authority in your EU Member State.
Security and breaches
We apply encryption, access control, rate limiting, event logging and incident procedures. No system removes all risk; breaches are assessed and notified under applicable law.
Updates
Material changes produce a new version. The version and fingerprint of the document accepted are retained with each request as documentary evidence.