Privacy Policy
Last updated: 24 September 2026
1. Data Controller
The Data Controller is Flowvenue SRL, with registered office at Viale Giorgio Ribotta 11, 00144 Rome, Italy
(VAT no. IT18366041004, REA RM-1780474). Contact: info@flowvenue.com, certified email (PEC) flowvenue@pecimprese.it.
2. Purpose of Processing
Personal data collected through the website, conversational CRM services and the Flowvenue App on ChatGPT / OpenAI Apps (MCP Server) are processed for the following purposes:
- Provision of requested services (account management, CRM, customer support).
- AI-assisted features (conversational assistant, process automation and design).
- Delivery of the ChatGPT App / MCP Server: execution of authorized tools, OAuth authentication, scopes, rate limiting and security audit (see Sec. 7-ter).
- Service communications and improvement of user experience.
- Monitoring of inbound leads (including measurement of conversions from advertising campaigns and from the conversational demo on the website) in order to improve user experience and understand how visitors discover and use Flowvenue.
- Direct marketing activities (promotional communications) with specific, optional prior consent.
- Statistical analysis and profiling, if authorized
- Compliance with legal obligations.
Privacy consent and lead monitoring. When you accept this Privacy Policy (for example by starting the conversational demo on the homepage or submitting a lead form), that consent includes processing data needed to monitor inbound leads — including conversion events sent to advertising platforms (e.g. Meta, Google Ads, OpenAI Ads) — solely to improve user experience, campaign attribution and service quality. This purpose is distinct from optional consent to direct marketing communications and from marketing cookie preferences managed via the cookie banner (see the Cookie Policy).
3. Legal Basis
Processing is based on:
- Contract performance (Art. 6.1.b GDPR);
- Legal obligations (Art. 6.1.c GDPR);
- Data subject consent (Art. 6.1.a GDPR) for: (i) acceptance of this Privacy Policy, including monitoring of inbound leads for user-experience improvement; (ii) direct marketing and profiling, where requested with specific consent;
- Legitimate interest of the Controller (Art. 6.1.f GDPR), balanced with data subject rights, for security and service improvement purposes.
4. Types of Data
- Identifying and account data (name, surname, email, phone, company, role in the organization).
- Navigation and technical data (IP addresses, logs, cookies, user-agent) — details in the Cookie Policy.
- Data related to conversations and processes managed through the CRM platform (messages, business fields, workflow state).
- Data exchanged via the ChatGPT App / MCP Server: tool arguments (inputs), tool results (outputs), OAuth and audit metadata — see Sec. 7-ter.
- Files and attachments uploaded and linked to process instances, when provided by the user or organization.
- System integration credentials only when voluntarily configured by an organization administrator (stored encrypted; not returned in clear text in tool responses).
- Special categories of data (Art. 9 GDPR) only if voluntarily provided during service use and processed with enhanced protection measures.
5. Methods and Security
Data is processed using electronic tools and adequate technical-organizational measures (encryption, pseudonymization, access controls) in compliance with privacy by design and by default principles.
6. Retention
Data will be retained for a period not exceeding that necessary to achieve the purposes:
- Contractual data and organization business records: up to 10 years from relationship termination (civil and tax obligations), unless the customer organization applies shorter policies.
- MCP OAuth tokens / ChatGPT App connection sessions: until expiry, revocation or app disconnection.
- MCP tool-call audit logs (security metadata and tool outcome): typically up to 90 days, unless longer retention is required for security or legal obligations.
- Process attachments and files: for as long as they remain associated with the instance/organization and per the customer's policies.
- Marketing data: until consent withdrawal and in any case not beyond 24 months.
- Profiling data: maximum 12 months.
7. Communication and Transfers
Data may be communicated to:
- IT service providers, hosting, cloud providers (e.g. AWS).
- Identity and authentication providers (e.g. Auth0).
- Large language model (LLM) providers, where used with Flowvenue-managed credentials (e.g. Anthropic, OpenAI) — see Sec. 7-bis and DPA Annex 2.
- OpenAI / ChatGPT, when the user connects the Flowvenue App: the conversation and tool invocations transit through the user's ChatGPT environment under OpenAI's terms; Flowvenue receives only authorized tool calls (Sec. 7-ter).
- Third-party systems already configured and authorized by the organization in Flowvenue (email, WhatsApp/Meta, Salesforce, OpenAPI or a customer-chosen remote MCP endpoint), only when an invoked tool requires that outbound connector.
- Administrators of the user's Flowvenue organization, within assigned roles and permissions.
- External consultants and professionals (legal, tax, technical).
- Public authorities in cases provided by law.
- Any transfers to non-EU countries will only be made to subjects with EU Commission adequacy decisions or through Standard Contractual Clauses (Arts. 44-49 GDPR).
7-bis. Artificial intelligence and language models (LLM)
Flowvenue uses large language models (LLMs) for conversational features, process design, translation assist, and similar use cases. Depending on the organization's configuration and subscribed plan, LLM inference may occur through one or more of the following paths:
- Flowvenue-managed LLM — inference via approved providers (default OpenAI GPT-5.6 Luna; alternative OpenAI or Anthropic models among supported options, where enabled). Content required for inference may be transmitted to such vendors as sub-processors, under their respective terms (including, where applicable, prohibition on using API/Enterprise content to train models). Sub-processor list: DPA Annex 2.
- Bring Your Own Key (BYOK) — if the organization configures its own credentials (OpenAI, Anthropic, or a compatible endpoint, including dedicated cloud or private/on‑premise LLM infrastructure), inference runs with the organization's chosen provider, which is not a Flowvenue sub-processor for that inference path. Organization keys are stored encrypted (AES-256-GCM).
- External LLM clients via MCP Server — the organization may connect external LLM clients (e.g. Claude, ChatGPT, Gemini, Copilot with MCP support) to Flowvenue's MCP Server. LLM inference runs on the organization's chosen environment; Flowvenue hosts MCP tools with authorization (OAuth 2.0 with PKCE), scopes, rate limiting, and audit of tool calls. Any outbound connectors used through those tools (email, WhatsApp/Meta, Salesforce, OpenAPI, or a customer-chosen remote MCP endpoint) run only against integrations the organization has already configured and authorized in Flowvenue; Flowvenue does not operate as an unofficial scrape or social-network data collector.
For business customers, further contractual detail is in the Data Processing Agreement (Section 5), Terms of Service (Section 10), and the Information Security compliance documentation.
LLM-generated responses may contain inaccuracies; for critical information (personal data, amounts, configurations), always verify status in the platform's deterministic backend (processes, data objects, instances).
7-ter. ChatGPT App (OpenAI Apps) and MCP Server — tool inputs and outputs
This section explicitly describes processing related to the Flowvenue application available on ChatGPT / OpenAI Apps and to the remote MCP Server used by authorized external LLM clients. It reflects the current inputs and outputs of the MCP tools exposed by the server (read/write of processes and instances, search, operational dashboards, process design, marketing templates, organization-configured outbound connectors, attachment uploads, issue reporting, etc.).
Data collected and processed (tool inputs)
When you connect Flowvenue to ChatGPT (or another MCP client) via OAuth 2.0 with PKCE, Flowvenue may receive and process:
- Authentication identity and connection context (Flowvenue user identifier, account email, organization, roles/permissions, OAuth metadata, enabled capabilities/scopes).
- MCP tool arguments sent by the model/client to perform the requested operation (e.g. search queries, process/instance IDs, CRM field values, process drafts, aggregation parameters, file/attachment references, email/WhatsApp template parameters).
- Operational content already stored in the Flowvenue organization as needed to execute the tool (process records, leads/contacts and other business objects configured by the organization, templates, workflow state, knowledge base, attached documents).
- System integration credentials only when an organization administrator voluntarily configures them in Flowvenue (e.g. Salesforce, OpenAPI, SMTP); such secrets are stored encrypted and are not returned in clear text in tool responses.
- Files uploaded by the user and linked to process instances, when required by the tool.
- Technical security and audit metadata (timestamps, tool name, outcome, sanitized errors, rate limiting) — not used for advertising profiling.
Flowvenue does not receive the full ChatGPT chat log: it operates only on the snippets, tool arguments and resources that the client/model explicitly sends.
Tool outputs (data returned)
MCP tools return only data needed to fulfill the authenticated user's request, typically:
- Connection metadata and the catalog of authorized capabilities/processes.
- Read results: lists, searches, instance aggregations, runtime state, field contracts, knowledge, authorized attachments, operational snapshots (home, backlog, briefing, insights).
- Write confirmations: instance create/update, workflow advancement, process configuration/design, test/sandbox outcomes.
- Where the organization has enabled already-configured outbound connectors: outcomes of actions toward email, WhatsApp/Meta, Salesforce, OpenAPI or a customer-chosen remote MCP endpoint.
Outputs may include personal data present in the organization's records (e.g. name, email, phone of leads/customers) when those fields are part of the requested result. They do not include authentication secrets, unnecessary internal debug payloads, or data from other organizations.
App / MCP-specific purposes
- Deliver ChatGPT App / MCP Server functions requested by the authenticated user within their organization.
- Apply authorization, scopes, rate limiting and security controls.
- Retain tool-call audit logs for security, support and compliance.
- Not use MCP call contents to train Flowvenue proprietary models, nor for advertising or marketing profiling toward third parties.
Recipients (ChatGPT App / MCP)
- Flowvenue infrastructure (AWS hosting) and identity provider (Auth0) for the account.
- OpenAI / ChatGPT as the client chosen by the user (conversation processing under OpenAI's terms; Flowvenue receives authorized tool invocations).
- Sub-processors listed in DPA Annex 2, where applicable.
- Third-party systems only if the organization has already configured and authorized an outbound connector in Flowvenue and the invoked tool requires it.
- Administrators of the user's Flowvenue organization, within assigned roles.
User controls
- Disconnect the Flowvenue app from ChatGPT (ChatGPT Apps/Plugins settings) and/or revoke OAuth consent / tokens from the Flowvenue platform.
- Organization administrators can restrict roles, MCP capabilities and outbound integrations.
- Exercise GDPR rights (access, rectification, erasure, restriction, objection, portability) by contacting info@flowvenue.com (see also Sec. 8).
- Do not send to MCP tools categories of data prohibited by OpenAI Apps guidelines (e.g. PHI health data, PCI payment data, government identifiers, clear-text passwords/OTPs), except where strictly necessary and lawful for a business process configured by the organization with an adequate legal basis.
8-bis. Use of Google APIs
Flowvenue uses Google APIs (such as Google Calendar, Gmail or other Google services authorised by the user) solely to provide the functionalities explicitly requested by the user within the conversational CRM platform.
Data obtained through Google APIs:
- are used only to deliver the functionalities requested by the user;
- are not used for advertising purposes;
- are not shared with third parties other than those strictly necessary for the provision of the service;
- are not sold or used for marketing or external profiling purposes.
Processing of data from Google APIs is carried out in compliance with the Google API Services User Data Policy, including the Limited Use provisions.
The user may revoke access to their Google data at any time directly from their Google account settings or by contacting the Data Controller.
8. Data Subject Rights
Users have the right to:
- Access, rectify and delete their data (Arts. 15-17 GDPR).
- Restrict or object to processing (Arts. 18-21 GDPR).
- Request data portability (Art. 20 GDPR).
- Withdraw consent at any time, without prejudice to the lawfulness of processing based on consent given before withdrawal.
- Disconnect the Flowvenue App from ChatGPT and revoke MCP OAuth tokens (controls described in Sec. 7-ter).
- Lodge a complaint with the Data Protection Authority (www.garanteprivacy.it)
9. Profiling
Flowvenue uses conversational CRM systems that may include profiling processes to improve interaction and provide personalized responses. Such processing occurs only with explicit consent and ensuring the user the possibility to request human intervention.
Marketing and profiling activities do not use in any way data from Google services.
10. DPO
Flowvenue has appointed a Data Protection Officer (DPO), contactable at: info@flowvenue.com
11. Updates
This Privacy Policy may be updated at any time to adapt to regulatory changes or services offered. Updated versions will be published on this page with revision date.