1. Information We Collect
When you interact with our website (flowstateauto.com), run our diagnostic calculators, or engage FlowState for automation engineering services, we may collect the following categories of information:
- Contact & Identity Data: Name, work email address, company name, website domain, and phone number (if submitted via discovery scheduling).
- Operational Diagnostic Inputs: Monthly lead volume estimates, response turnaround latencies, team size, loaded wage estimates, and bottleneck descriptions provided in our interactive diagnostic suite.
- Technical & Telemetry Data: IP address, device type, browser specifications, operating system, and anonymous interaction timestamps to maintain site security, prevent rate-limit abuse, and debug frontend telemetry.
- Client System Credentials (Post-Contract Only): When engaged under a formal Statement of Work, API tokens, webhook secrets, and database credentials provided for automation staging are stored in isolated encrypted vaults (AES-256) and never stored in plain text.
2. AI & Foundation Model Data Processing Standards
Because FlowState engineers multi-agent systems and n8n workflows that leverage Large Language Models (LLMs) and Voice AI engines, we maintain strict architectural boundaries:
Zero Foundation Model Training
All interactions between FlowState automated pipelines and LLM providers (including OpenAI GPT-4o, Anthropic Claude 3.5 Sonnet, and Groq Llama 3) execute exclusively through commercial enterprise API endpoints. Under our provider agreements, inputs and outputs are not used to train, retrain, or improve foundation models.
- Ephemeral Processing: Inbound webhook payloads routed through LLMs for intent classification, lead scoring, or summarization are processed in memory and discarded immediately upon dispatch to your CRM or database.
- Voice AI Telemetry (VAPI): Audio streams processed via VAPI are transcribed in real time over TLS 1.3 WebSocket relays. Transcripts are synced directly to your designated CRM and not retained on public training queues.
- RAG Vector Embeddings: Knowledge base documents embedded into vector stores (pgvector, Qdrant) reside in self-hosted or tenant-isolated VPC clusters owned and controlled by you.
3. How We Use Collected Information
We process collected data exclusively for the following lawful business purposes:
- To evaluate your operational bottleneck parameters and calculate customized ROI diagnostics.
- To respond to your inquiries, deliver technical architecture reviews, and draft customized proposals.
- To engineer, test, monitor, and maintain production n8n workflows and API integrations.
- To enforce our terms, detect spam or unauthorized penetration attempts, and ensure high availability.
4. Data Storage, Security & Encryption
We implement industry-standard administrative, physical, and technical safeguards to protect your data against unauthorized access, loss, or alteration:
- Encryption in Transit: All data transmitted to and from our website, APIs, and webhooks is encrypted using Modern TLS (TLS 1.3 / HTTPS with HSTS).
- Encryption at Rest: Inbound inquiries and client data stored in Supabase PostgreSQL are encrypted using AES-256 at the storage layer.
- Infrastructure Isolation: Production n8n instances and worker nodes are deployed within isolated Docker containers with automated health monitoring and strict firewall rules.
- Least-Privilege Access: Only authorized engineering personnel have access to staging environments, enforced via multi-factor authentication (MFA).
5. Third-Party Service Providers (Sub-Processors)
We may share minimal data with trusted infrastructure providers solely to host, deliver, and monitor our services:
| Service Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Vercel | Edge Hosting & Serverless Compute | IP, HTTP Request Logs | United States / Global Edge |
| Supabase | Encrypted Database & Storage | Lead Form Submissions | United States (AWS) |
| Resend / Postmark | Transactional Email Dispatch | Email, Inbound Inquiry Payload | United States |
| OpenAI / Anthropic | LLM Qualification (API Tier) | Anonymized Inquiry Challenge | United States (ZDR) |
6. Cookies & Tracking Technologies
FlowState believes in a tracker-free web experience. We do not use third-party advertising cookies, cross-site trackers, or data-broker pixels (such as Meta Pixel or Google Ads tracking cookies).
We only use essential local session storage strictly required for user interface functionality (such as remembering your simulation parameters in the Workflow Simulator and diagnostic audit inputs during your browsing session).
7. Your Rights (GDPR, UK GDPR & CCPA/CPRA)
Depending on your geographic jurisdiction, you have the following rights regarding your personal information:
- Right of Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request immediate deletion of your contact data from our active records.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Non-Discrimination: We will never discriminate against you for exercising your privacy rights.
To exercise any of these rights, email us directly at sujal@flowstateauto.com. We fulfill verified requests within 30 days without charge.
8. Contact & Data Protection Officer
If you have questions, feedback, or security inquiries regarding this Privacy Policy or our AI data handling practices, contact our founder and lead systems architect directly:
Email: sujal@flowstateauto.com
Website: https://flowstateauto.com
Channel: youtube.com/@Sujal-flowstate
