Skip to content

FlowPSA legal

Privacy Policy

Effective date and version: September 23, 2026 (2026-09-23)

Who we are and the scope of this notice

FlowDevs LLC, 612 Gumtree St NE, Saint Joseph, MN 56374, provides FlowPSA. Contact clientsupport@flowdevs.io for privacy, access, correction, or deletion requests. This notice covers the flowpsa.com website and information FlowDevs receives in providing FlowPSA services and evaluations. Our services are currently available only in the United States to eligible organizations, as described in the Terms of Service. U.S.-only availability does not mean every third-party provider processes data exclusively in the United States. FlowRMM is covered by the notice published at flowrmm.com.

We do not train on your data

FlowDevs does not use your data to train or fine-tune AI models. We do not sell your personal information or share it for cross-context behavioral advertising.

If you choose to connect an independent AI service or agent to FlowPSA over the Model Context Protocol, that service can receive the information its authorized tools return, including ticket content, contact details, time entries, and billing drafts. Its own terms, retention rules, and account settings govern its use of that information; our commitment does not change another provider’s policies. Review those settings before connecting a service. Automated processing needed to deliver a feature is different from training a model.

Information we process

Website and inquiries. Information you provide in an access request, walkthrough booking, or support request can include your name, contact details, company, role, team size, endpoint range, current tools, and message. Hosting and security systems may process IP addresses, browser details, request times, and error logs.

Service desk records. A FlowPSA deployment processes companies, sites, contacts, operator identities and roles, tickets and their timelines, customer communications, attachments, tasks, changes, projects, assets, time entries, agreements, invoices, approvals, and audit records. When connected to FlowRMM, it also references endpoint identifiers and the session and action evidence attached to tickets. Ticket content and attachments may contain personal or confidential information that your staff or your clients choose to include.

Client portal. Portal access uses signed, expiring links bound to a contact’s email and company. We process the contact details, requests, replies, files, and feedback that portal users submit.

Plans and payments. We process plan status, endpoint counts, and billing identifiers needed to manage a subscription. Payment providers process payment details under their own notices.

Why we use information and when people may access it

We use information to authenticate users, run the service desk features you configure, enforce role and approval boundaries, provide support, administer plans, diagnose failures, maintain security, prevent abuse, and meet legal obligations. Routine service operation involves automated processing. We do not browse customers’ tickets, files, or client communications out of curiosity or for advertising.

Authorized personnel may access the information reasonably necessary to provide support you request or authorize, operate and repair the service, investigate abuse or security incidents, protect people or the service, or comply with law. Access should be limited to the purpose and personnel who need it. Technical administrative access can exist; we do not claim that encryption makes all customer content inaccessible to us.

We may disclose information when legally required by a valid subpoena, court order, or other compulsory legal process, or when disclosure is otherwise permitted by law and reasonably necessary to address an emergency involving serious harm or protect legal rights. An informal government request does not automatically entitle the requester to customer data. We assess requests and limit disclosure to what is legally required or justified. Where legally permitted and appropriate, we will notify affected users.

Customer-deployed hosting and service providers

FlowPSA is deployed beside FlowRMM in the customer’s Azure environment. The customer administers that tenant and determines the use, access, and retention of data in the deployment. FlowDevs does not receive blanket tenant access because the customer installs FlowPSA. Customer-authorized support access and configured integrations can still disclose data to us or other providers.

Customer deployment is not a promise that no information ever leaves the tenant. Licensing, release and update checks, support, billing, configured mail gateways, and explicitly connected tools can exchange the information needed for those functions. The customer should review integration permissions and its own privacy obligations to its staff and clients. Direct a request about data held in a customer’s FlowPSA deployment to that organization first; we can help identify the appropriate contact where possible.

We use providers for hosting, storage, security, email and support, billing, and requested integrations. The marketing site is hosted through Lovable; configured inquiry routing and scheduling may use Microsoft Power Automate and Microsoft Bookings. Providers acting on our behalf may process information necessary for their service. Independently selected AI services and customer-configured integrations are also subject to their own policies. We may disclose necessary records to professional advisers or in a corporate transaction, subject to applicable confidentiality and legal obligations.

Cookies, storage, and retention

The website uses browser storage for preferences such as light or dark theme. The FlowPSA portal uses authentication cookies and browser storage for sign-in, security, preferences, and interface behavior. Hosting and security providers may use technical cookies or logs needed to deliver their services. We do not use customer service desk content for advertising profiles.

Operational, support, security, audit, time, and billing records are retained as needed for their purpose, configured retention, dispute resolution, and legal obligations. Retention varies by record type and by deployment; we do not promise a universal deletion deadline. Backups, fraud-prevention records, legal holds, posted invoices, and append-only audit records may persist after a deletion request. Such retained information remains subject to this notice and applicable law.

Your choices and requests

You can stop using the service, revoke connected tools, and request access to, correction of, or deletion of your personal information by emailing clientsupport@flowdevs.io. Identify the account or issue without sending passwords, tokens, or sensitive ticket content. We verify identity and authority before releasing data or deleting records. We respond within the time required by applicable law and explain any lawful exception or inability to verify a request. We do not discriminate against you for exercising an applicable privacy right.

Security and changes to this notice

We use safeguards designed to protect information, including Microsoft Entra sign-in, role-based access, server-enforced approvals, and signed portal links. No service can guarantee absolute security. Security for a customer deployment is shared among the customer, Microsoft, and FlowDevs according to what each controls; see the Terms of Service.

We will date changes to this notice and give appropriate notice of material changes. We will not silently repurpose previously collected data in a way that conflicts with the commitments under which it was collected. Where consent is required, we will obtain it before making that change.