The short version
- For residents’ reports, your city decides how data is used. We process it only on the city’s instructions.
- We never sell personal data or use it for advertising.
- Customer data stays in the region the customer chooses — the EU or the US.
- This website sets no cookies. It remembers your language and theme in your browser only.
Who we are
CivicFlow is provided by CivicFlow Technologies S.L., a Spanish limited company registered in Madrid and founded in 2025, with its registered office at Patio Studio, 7 Calle del Almendro, 28005 Madrid, Spain. CivicFlow Technologies S.L. is the controller for the personal data described in this policy, except where we act as a processor for a city. In this policy, “CivicFlow”, “we” and “us” mean CivicFlow Technologies S.L.
Our role: processor and controller
We handle personal data in two different roles:
- As a processor for our customers — municipalities and public bodies. When residents report an issue to a city that uses CivicFlow, the city is the controller of that data. We process it only on the city’s documented instructions under a data processing agreement (DPA). If you are a resident, please contact your city about your data; we will help them respond.
- As a controller for visitors to this website, people who contact us or book a demo, and the account and billing data of our customers’ staff.
Data we collect
- Contact and demo requests: name, work email, organization, city, size and your message.
- Customer accounts: staff names, work emails, roles, sign-in events and product settings.
- Usage data: feature usage, device and browser type, and error reports from the product, used to keep it reliable.
- Billing: billing contact, invoicing address, VAT number and payment status. Card numbers are handled by our payment provider and never reach our systems.
- Candidates: the information you send when you apply for a role.
We do not collect special categories of data for our own purposes. Website server logs (IP address, time, requested page) are kept for 14 days to protect the service.
Purposes and legal bases
We only use personal data for the purposes below, each with a legal basis under the GDPR.
| Purpose | Data | Legal basis |
|---|---|---|
| Provide and support the CivicFlow service | Account, usage and support data | Contract (Art. 6(1)(b)) |
| Answer enquiries and demo requests | Contact details and message | Legitimate interests (Art. 6(1)(f)) |
| Invoicing, tax and accounting | Billing contact and invoices | Legal obligation (Art. 6(1)(c)) |
| Security, fraud prevention and reliability | Logs, sign-in events, device data | Legitimate interests (Art. 6(1)(f)) |
| Product updates and event invitations | Name and work email | Consent (Art. 6(1)(a)); unsubscribe at any time |
| Recruitment | Application and interview notes | Steps before a contract (Art. 6(1)(b)) |
Resident data
Reports submitted to a city may contain a resident’s name, contact details, location, photos and messages. The city decides what is collected, how long it is kept and who can see it. We use resident data only to provide the service to that city — never for our own purposes, never to train AI models shared with other customers, and never for marketing.
Public status pages and open data exports are anonymized automatically: names, contact details and photos of people are removed, and locations are rounded.
Retention
- Customer data is kept for the duration of the contract and deleted within 30 days after the end of the export period, unless the customer’s retention policy deletes it sooner.
- Backups are encrypted and expire after 35 days.
- Enquiries and demo requests are deleted 24 months after our last contact.
- Invoices and accounting records are kept for 6 years, as required by Spanish commercial law.
- Candidate data is deleted 6 months after the hiring decision, unless you agree to a longer period.
Sharing and subprocessors
We share personal data only with subprocessors that help us run the service — cloud hosting, backups, transactional email and SMS, monitoring and support tooling — under written agreements with equivalent protections. The current list, with each subprocessor’s purpose and location, is on our Security page. Customers are notified 30 days before a new subprocessor is added.
We disclose data to authorities only when legally required, and we tell the affected customer unless the law forbids it.
International transfers
EU customers’ data is stored and processed in the European Union — hosted in Frankfurt, with encrypted backups in a second EU region in Amsterdam. These hosting regions are data-center locations and are separate from our Madrid headquarters. Customers outside Europe can choose to be hosted in the United States. Where a subprocessor accesses data from outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (SCCs), together with encryption and access controls. Enterprise customers can restrict all access to EU-based staff.
Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256), with per-region keys rotated automatically. Access is role-based, protected by single sign-on and hardware keys, and recorded in audit logs. An independent firm penetration-tests the platform every year, and ISO/IEC 27001 certification is in progress. Read more on our Security page.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing, including for direct marketing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting earlier processing.
We answer requests within one month. You can also complain to a supervisory authority. Our lead authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD); you can also contact the authority in the EU country where you live. If your data was submitted to a city, contact the city first; we will support them.
Cookies and local storage
This website sets no cookies and uses no analytics or advertising trackers. It stores two preferences in your browser’s local storage, only after you choose them:
cf-lang— the language you selected (English or Spanish).cf-theme— the theme you selected (light or dark).
These values never leave your device. You can remove them by clearing your browser’s site data. The CivicFlow product uses strictly necessary session cookies to keep you signed in.
Children
Our website and products are intended for professionals and are not directed at children. Cities may allow residents of any age to submit reports; in that case the city is responsible for meeting the applicable rules for children’s data.
Changes to this policy
We will update this policy when our practices change. The date at the top shows the latest version. For material changes, we notify customers’ admins at least 30 days in advance.
Contact and Data Protection Officer
For privacy questions or to exercise your rights, write to privacy@civicflow.site. Our Data Protection Officer can be reached at the same address, or by post at CivicFlow Technologies S.L., attn. Data Protection Officer, Patio Studio, 7 Calle del Almendro, 28005 Madrid, Spain. You can also use our contact page.