Product Privacy Notice
For users of the Flowscape smart office application
Last updated: 19 August 2026
Introduction
This notice explains how Flowscape AB (“Flowscape”, “we”, “us”) handles personal data in the Flowscape smart office application and related services (the “Service”), which you use to book desks, meeting rooms and other spaces, manage visitors, find your way around the office (wayfinding), locate colleagues (colleague finder) and report issues. It tells you what personal data is processed through the Service, why, who it is shared with, and the rights you have.
1. Who is responsible for your personal data
The Service is provided to you by your employer or the organization that gave you access (your “Organization”). Under data protection law there are two roles that matter here:
- Your Organization is the data controller. It decides which personal data is processed in the Service, for what purposes, and on what legal basis. Your use of the Service is part of the working relationship between you and your Organization.
- Flowscape is the data processor. We process personal data on your Organization's behalf and on its documented instructions, under a written Data Processing Agreement. We do not use your personal data for our own independent purposes.
What this means in practice: your Organization is your first point of contact for questions about why your data is used and for exercising most of your rights (see section 8). We will support your Organization in responding to you. This notice is provided by Flowscape so that you can see, in one place, what personal data is processed through the Service and how we protect it.
2. What personal data is processed
Depending on which features your Organization has enabled and how you use the Service, the following categories of personal data may be processed:
- Identity and contact details - Your name, profile picture, work phone number, work email address, company name, office address and department.
- Vehicle information - Car registration number (where you use parking or vehicle related features).
- Device and network information - MAC address and IP address of the device you use to access the service.
- Bookings and meetings - Desk, meeting room and space bookings that you make (user, space, time span). Meeting details, such as the subject, description, organizer and attendees, are read from your connected calendar (Microsoft Exchange or Google) and shown to you in the app only. Flowscape does not store this meeting information.
- Presence and office activity - When you dock your laptop at a space (user, space, time span), whether a booked space was used (time span), and the times you have been logged into the system.
- Usage and feedback - Application usage associated with a pseudonymised user identifier, including features used, actions performed and timestamps, together with your responses to in-app surveys and other product feedback.
Where the Service records how the application is used, your identity is replaced with a pseudonymised (hashed) user identifier before the usage data is analyzed. This reduces the data, but it is still personal data under the GDPR, because it can be linked back to you, and it is treated accordingly.
3. Why the data is processed
Personal data is processed through the Service, on your Organizations instructions, in order to:
- provide the smart office features, including desk, meeting room and space booking, presence and space usage, visitor management, wayfinding, colleague finder and issue reporting;
- show you contextual in-app guidance and invite you to take part in in-app surveys;
- analyze how the application is used so that the Service can be maintained, improved and made more reliable for your Organization;
- provide user support and resolve technical issues; and
- meet the contractual and legal obligations that apply to the Service.
The purposes and the legal basis for processing your personal data are determined by your Organization as controller. If you would like to know which legal basis your Organization relies on, please contact them directly (see section 8).
4. Who your data is shared with
We use a small number of carefully selected service providers (“sub-processors”) to help deliver the Service. Each of them is bound by a written agreement that imposes the same data protection obligations that apply to us, and each processes personal data only to provide the service described below:
- Microsoft (Azure) - Hosting of the application and personal data. - Netherlands (EU)
- EastCoast Solutions - Hosting of the Visitor Management solution, plus research, development and fault finding. - Sweden and France (EU)
- Zendesk - Management of support tickets. - Germany (EU)
- Jobshark - Fault finding and issue resolution. - Bulgaria (EU)
- PostHog - Product analytics, analysis of application usage, in-app guidance and surveys. - Germany (EU)
- Amplitude - Product analytics, analysis of application usage, in-app guidance and surveys. - Germany (EU)
Your Organization is informed of the sub-processors we use and of any intended changes, and can object to changes, in line with our Data Processing Agreement. We do not sell your personal data, and we do not share it with third parties for their own marketing.
5. Where your data is processed
The personal data processed through the Service is stored and processed within the EU/EEA, as shown in the table above. Some of our providers are companies with a parent outside the EU/EEA, but the data itself is hosted on servers located in the EU/EEA. We do not transfer personal data outside the EU/EEA without your Organization's approval, and, where any such transfer were to take place, it would be protected by an appropriate safeguard under the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses.
6. How long the data is kept
Your personal data is processed for as long as your Organization's agreement with Flowscape is in force. If you are removed from the system by your Organization, your personal data is no longer processed by us and is deleted or returned to your Organization, unless we are required by law to keep it for longer. Support tickets and similar operational records may be retained for a limited period so that we can manage and evidence the support we have provided.
Usage data is kept for a maximum of two years, after which it is deleted.
7. How your data is protected
We apply appropriate technical and organizational measures to keep personal data secure, including:
- pseudonymisation and encryption of personal data;
- separation of your identity from historical activity data: bookings, presence and similar historical records are held in a separate data store in which your activity is linked only by a reference identifier, not by your direct contact details. If your personal data is deleted, the link between you and that historical data is removed;
- measures to ensure the ongoing confidentiality, integrity, availability and resilience of our systems;
- the ability to restore access to personal data after a physical or technical incident;
- access limited to trained, authorized personnel on a need-to-know basis and bound by confidentiality. Usage and analytics data that contains personal data is further restricted by role-based access controls, so that only a limited number of authorized people within your Organization can access it; and
- regular testing and evaluation of the effectiveness of these measures.
If a personal data breach affecting your data occurs, we notify your Organization without undue delay so that it can meet its own obligations, including, where required, informing you and the supervisory authority.
8. Your rights
Under the GDPR you have the right to request access to your personal data, and to ask for it to be corrected, erased or restricted, to object to certain processing, and to receive your data in a portable form. You also have the right to lodge a complaint with a supervisory authority.
Because your Organization is the controller, please direct requests to exercise these rights to your Organization in the first instance. If you contact us directly, we will forward your request to your Organization and assist them in responding. You can also contact us using the details in section 10 with any question about how the Service handles your data.
You may lodge a complaint with your local data protection authority. In Sweden this is the Swedish Authority for Privacy Protection (IMY), www.imy.se.
9. Children
The Service is a workplace tool intended for use by employees, contractors and visitors of our customer organizations. It is not directed at children and is not intended to process the personal data of children.
10. Changes and how to contact us
We may update this notice from time to time, for example if we add or change a sub-processor or a feature. When we make material changes we will update the date at the top and inform your Organization.
Controller (your data protection rights): your employer or the organization that gave you access to the Service. Please use the internal contact your Organization has provided.
Processor: Flowscape AB, org. no. 556866-9625, Sveavägen 64, 111 34 Stockholm, Sweden.
Privacy contact / Data Protection Officer:
- Mohammed El Shobaki, mohammed.el.shobaki@flowscapesolutions.com
- privacy@flowscapesolutions.com