SPGFlow

Last updated 12 September 2026

Privacy policy

SPGFlow is a UK-based software platform. This notice explains how we handle personal data when businesses apply for early access, use SPGFlow or connect supported communications channels.

Data we process

Early-access applications

We use beta and waiting-list application details to assess suitability, plan product development, contact applicants about access and understand demand by business type and country. Applying does not create an SPGFlow account or require payment.

How we use data

We use personal data to provide and secure SPGFlow; receive and display authorised business communications; let approved staff respond to, assign and track enquiries; maintain customer and workflow records; provide support; prevent misuse; and meet legal obligations. We do not sell Platform Data or use connected communications data for unrelated advertising.

Roles and lawful basis

For data a business customer imports or receives through SPGFlow, that customer normally acts as controller and SPGFlow acts as processor under the customer’s instructions. For account administration, security, early-access applications and our own commercial records, SPGFlow acts as controller. Processing is based as applicable on contract, legitimate interests, legal obligations and consent.

Sharing and international transfers

We disclose data only to authorised users, communications platforms where required to provide connected channels, infrastructure and support suppliers working under contract, professional advisers, or authorities where legally required. Where data is transferred internationally, we use applicable contractual and legal safeguards.

Security and retention

SPGFlow separates customer tenants, restricts access by role, validates webhook authenticity and encrypts stored connection credentials. We retain business data while an account is active and as needed for the service, security, backups and legal obligations. Data is deleted or anonymised when no longer required, subject to agreed retention periods and backup cycles.

Your choices and rights

Business administrators control connected assets and staff access. Individuals may have rights to access, correct, erase, restrict or object to processing, and to data portability or withdrawal of consent. Requests concerning a business customer’s records should normally be directed to that business first.

Contact

For privacy questions or rights requests, email [email protected]. You may also complain to the UK Information Commissioner’s Office.