Trust · Compliance

Compliance

Where your data lives, who touches it, what we hold and what we refuse to. Everything a security or procurement review asks for, in one place.

Last updated: September 18, 2026

Running a vendor review? Ask AI to check it for you.
At a glance

The short answers.

Stored in the EU by default

Customer data is processed and stored in Cloudflare’s Western Europe region by default. Exclusive residency can be pinned in writing on Enterprise.

DPA §11.1

We are your processor

You are the controller of the personal data you put into Flowdrive. We process it only on your documented instructions.

DPA §2

Breach notice within 72 hours

We notify you without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach.

DPA §13

Never used to train AI

We do not sell personal data, share it for advertising, or use customer data or content to train AI or machine learning models.

DPA §8

SCCs for any transfer out

Where data is processed outside the EEA, UK or Switzerland we rely on EU Standard Contractual Clauses, the UK IDTA, and Swiss equivalents.

DPA §11.2

Deleted on termination

Customer data is removed from active systems within 30–90 days of termination, with backups ageing out on their own cycle. Earlier deletion on request.

DPA §14
Documents

The paperwork, up front.

Nothing here needs a sales call to read. The signed versions are the part that does.

Data Processing Agreement

The full DPA, including technical and organisational measures (Annex A) and the subprocessor register (Annex B).

Read the DPA →

Privacy Policy

What we collect about you as a Flowdrive customer, why, and how long we keep it.

Read the policy →

Terms of Service

The commercial agreement that governs your use of Flowdrive.

Read the terms →

Signed DPA & security questionnaires

On Enterprise we countersign a DPA on our template or yours and complete your vendor and security questionnaires ourselves.

See Enterprise →
Data residency

Where your data lives.

Flowdrive runs on Cloudflare. Uploads, storage and delivery are configured to Cloudflare's Western Europe region by default, so assets are served from the EU without you configuring anything.

Default: EU

Customer data is processed and stored in Cloudflare’s Western Europe (EU) region by default, on every plan including the free tier.

Pinned: Enterprise

Our standard DPA does not guarantee exclusive residency in a named jurisdiction. If your policy requires that commitment in writing, it is part of Enterprise.

When data does leave the EEA

Some subprocessors operate outside the EEA. Where that happens we rely on EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss equivalent safeguards, alongside encryption and access controls. Where the SCCs and our DPA conflict, the SCCs win.

Subprocessors

Everyone who touches your data.

The full list. Each one has signed a data protection agreement, maintains GDPR-level safeguards, and may only process data for the stated purpose.

ProviderPurposeRegion
CloudflareInfrastructure, CDN, object storage EU
StripePayments and invoicing US / EU
PostHogProduct analytics EU
SendPulseTransactional email EU / US
QencodeVideo transcoding Only when you use this featureGlobal

Change notice

We give customers reasonable advance notice of material subprocessor changes — typically at least 30 days. You can object for legitimate data-protection reasons by emailing [email protected]; if we cannot resolve it, you may terminate the affected services without penalty for the unused portion of the term.

Data we handle

What we hold, and what we don’t.

We hold

  • Account details: name, email, user IDs, hashed passwords
  • Files you or your end users upload, and their metadata
  • Access, activity and error logs, including IP and browser information
  • Billing records: name, billing address, payment status, transaction IDs

We don’t

  • Card numbers — Stripe handles payment details, we never see them
  • Personal data sold or shared with advertisers, ever
  • Training data — your content never reaches an AI or ML model
  • Customer content used for product development beyond running the service
Security

The safeguards we run.

Our technical and organisational measures, as committed in Annex A of the DPA.

  • TLS encryption in transit
  • AES-256 encryption at rest
  • MFA for all internal systems
  • Role-based access control
  • Secure API authentication
  • WAF + DDoS protection via Cloudflare
  • Continuous monitoring and logging
  • Vulnerability scanning and patching
  • Incident response procedures
  • Regular backup and restore testing
  • Production/staging separation

You can request reasonable information to demonstrate compliance once a year, and we may satisfy that with third-party security reports where available.

In the middle of a vendor review?

Send us the questionnaire. On Enterprise we countersign a DPA on your template, complete your security forms, pin EU residency in writing, and give you a named contact with a response commitment — plus annual invoicing instead of a card.

Anything urgent, email [email protected].

Take control of your file hosting on Webflow.

Ask about Flowdrive on
© 2026 Flowdrive