GDPR & Consent Management
How Flowvenue collects, manages and respects user consent under GDPR and ePrivacy.
Last updated: June 2026 Version: 2026.06
Our Approach to GDPR Compliance
Flowvenue adopts a structured approach to compliance with the General Data Protection Regulation (GDPR) and the ePrivacy Directive. This page explains how we collect, manage, and respect user consent in accordance with these regulations.
Legal Basis for Processing
Necessary Cookies and Essential Services
Legal basis: Technical necessity for the provision of the service requested by the user under Article 6(1)(b) GDPR. We also apply security measures to protect the service.
Essential cookies and services required for the website to function do not require consent. These include:
- Session management
- Authentication
- Security measures
- Basic functionality
Statistics and Marketing Cookies
Legal basis: Article 6(1)(a) GDPR (expressed and informed consent) and Article 5(3) ePrivacy Directive.
All non-essential tracking requires expressed and informed consent before any processing occurs.
Consent Collection
How Consent Is Collected
When you first visit our website:
- Banner Display: A cookie banner appears with clear options
- Informed Choice: You can:
- Accept all cookies
- Reject all non-essential cookies
- Customize preferences category by category
- Explicit Action: Consent is only recorded when you take an explicit action (clicking "Accept", "Reject", or "Save" after customization)
- No Pre-Consent Tracking: No tracking scripts are loaded and no non-essential cookies are set before you provide consent
Granularity
Consent is collected per category:
- Necessary - Always active (no consent required)
- Preferences - Available for future use
- Statistics - Google Analytics 4
- Marketing - Meta Pixel
You can accept or reject each category independently.
Consent Trace (Consent Record)
When you provide consent, we record:
- Timestamp - Exact date and time of consent
- Categories - Which categories you accepted or rejected
- Policy Version - Version of the Cookie Policy you accepted
- Expiration - When the consent expires (6 months from consent)
- Source - How consent was provided (banner, preference center, etc.)
Note: For the website, the consent record is stored on the user's device and can be reset by clearing browser data; additional evidence may be collected in enterprise contexts or upon formal request.
This record enables us to demonstrate compliance and accountability.
Consent Application
Technical Implementation
Once consent is provided:
- Immediate Application: Consent preferences are applied immediately
- Conditional Loading: Tracking scripts are loaded only if consent was granted for the corresponding category
- Consent Mode: Google Consent Mode v2 is updated to reflect your choices
- No Retroactive Tracking: We do not attempt to track activity that occurred before consent
Verification
This behavior can be verified using browser technical tools. Non-essential cookies are only set after consent, and tracking scripts are only loaded after consent.
Consent Revocation
How to Revoke Consent
You can revoke or modify your consent at any time:
- Click "Cookie settings" in the footer of any page
- Modify your preferences in the preference center
- Click "Save"
- Changes are applied immediately
What Happens When You Revoke
When you revoke consent:
- Immediate Disabling: Tracking scripts are disabled and no further tracking calls are made
- Cookie Removal: First-party cookies are deleted (best-effort)
- Consent Mode Update: Google Consent Mode v2 is updated to "denied" for revoked categories
- No Further Tracking: No new tracking requests are made
Note: Third-party cookies (e.g., cookies set by Facebook) cannot be deleted directly by our website due to browser security restrictions. However, these cookies will no longer be used for tracking purposes once consent is revoked.
Consent Expiration
Automatic Expiration
Your consent expires automatically after 6 months (180 days) from the date you provided it.
What Happens on Expiration
When consent expires:
- Automatic Removal: The consent record saved on the device is automatically removed
- Banner Reappears: The cookie banner reappears on your next visit
- Tracking Stops: All tracking stops until you provide new consent
- Fresh Choice: You can make a new, informed choice about cookies
Why 6 Months?
The 6-month expiration period:
- Ensures your consent remains current
- Reflects changes in your preferences over time
- Aligns with best practices for consent management
- Is coherent with market practices and minimization principles
Policy Updates and Consent Renewal
When Policy Changes
If we make substantial changes to our Cookie Policy (e.g., adding new tracking technologies, changing purposes, or modifying legal basis):
- Policy Version Updated: The Cookie Policy version number is incremented
- Banner Reappears: The cookie banner reappears even if your previous consent has not expired
- New Consent Required: You must provide new consent for the updated policy
- Transparency: The updated policy is clearly marked with a new version number and date
What Constitutes a "Substantial Change"
Substantial changes that require new consent include:
- Adding new tracking technologies
- Changing the purpose of data processing
- Modifying the legal basis for processing
- Significant changes to how data is used
Minor changes (e.g., typo corrections, clarifications, contact information updates) may not require new consent, but the policy version will still be updated.
Accountability and Evidence
Demonstrating Compliance
We maintain evidence and documentation to demonstrate compliance with GDPR and ePrivacy requirements:
- Consent Traces: Timestamped records of when and how consent was provided (stored on user's device for the website)
- Policy Versions: Tracking of which policy version was accepted for each browser/device (for the website)
- Technical Evidence: Ability to verify that tracking only occurs after consent
- Documentation: Internal documentation of our consent management processes
Consent Trace Details
Each consent record (trace) includes:
- When consent was given
- What categories were accepted
- Which policy version was in effect
- How consent was provided (banner, preference center, etc.)
- When consent expires
This trace enables us to demonstrate accountability to:
- Data protection authorities
- Enterprise clients (under appropriate agreements)
- Auditors
- Regulators
AI-assisted processing (LLM) — reference
Flowvenue may process personal data or customer content through large language models (LLMs) in several modes:
- Platform-managed LLM — inference via Flowvenue-approved providers (default OpenAI GPT-5.6 Luna; Anthropic models where enabled), with contractual and technical measures described in Information Security and Security measures — §1.5.
- Bring Your Own Key (BYOK) — inference using Customer-supplied API credentials (including dedicated cloud or private/on‑premise endpoints). The Customer’s LLM provider for that path is outside Flowvenue’s sub-processor list for inference; Customer keys are stored encrypted (AES-256-GCM). See Terms of Service Section 10.
- External LLM via MCP Server — the Customer connects an external LLM client (e.g. Claude, ChatGPT) to Flowvenue’s inbound MCP Server; LLM inference runs on the Customer’s chosen environment, while Flowvenue hosts MCP tools subject to OAuth, scopes, and audit controls.
Provider-specific documentation (security, privacy, GDPR, residency, retention) remains authoritative for each vendor—for example Anthropic Trust Center, OpenAI Trust portal, and OpenAI data controls. This GDPR page does not replace provider documentation or your own legal assessment.
Your Rights Under GDPR
In addition to consent management, you have the following rights under GDPR:
Right of Access (Article 15)
You can request information about what personal data we process about you.
Right to Rectification (Article 16)
You can request correction of inaccurate personal data.
Right to Erasure (Article 17)
You can request deletion of your personal data in certain circumstances.
Right to Restrict Processing (Article 18)
You can request restriction of processing in certain circumstances.
Right to Data Portability (Article 20)
You can request your data in a structured, machine-readable format.
Right to Object (Article 21)
You can object to processing based on legitimate interests.
Right to Withdraw Consent (Article 7(3))
You can withdraw consent at any time (as described in the "Consent Revocation" section above).
How to Exercise Your Rights
To exercise your rights, contact us:
- Email: info@flowvenue.com
- PEC: flowvenue@pecimprese.it
We will respond to your request within one month (or two months for complex requests), as required by GDPR.
Privacy by Design
Built-In Privacy Protections
Our consent management system is designed with privacy by design principles:
- Default Denied: No tracking before consent
- Granular Control: Category-by-category consent
- Easy Revocation: One-click access to modify preferences
- Automatic Expiration: Consent expires after 6 months
- Transparency: Clear information about what cookies do
Technical Safeguards
Technical measures ensure that consent is respected:
- Scripts are conditionally loaded based on consent
- Consent state is checked before any tracking occurs
- Revocation immediately disables tracking
- No workarounds or "soft consent" mechanisms
Compliance with ePrivacy Directive
Article 5(3) ePrivacy Directive
The ePrivacy Directive requires consent before storing or accessing information on a user's device (cookies and similar tracking technologies).
Our compliance:
- ✅ Consent is obtained before any non-essential cookies are set
- ✅ Consent is obtained before any non-essential tracking scripts are loaded
- ✅ Consent is expressed and informed
- ✅ Consent can be withdrawn at any time
Integration with GDPR
The ePrivacy Directive works in conjunction with GDPR:
- Legal basis: Consent under ePrivacy Directive aligns with Article 6(1)(a) GDPR
- Requirements: Both require expressed, informed, and freely given consent
- Enforcement: Violations can result in penalties under both frameworks
Contact
For questions about GDPR compliance or consent management:
- Privacy email: info@flowvenue.com
- PEC: flowvenue@pecimprese.it
You also have the right to file a complaint with your local data protection authority if you believe that the processing of your data violates GDPR or the ePrivacy Directive. In Italy: Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).
Note: This page provides a high-level overview of our GDPR and consent management approach. Detailed technical documentation is available upon formal request for authorized parties (auditors, regulators, enterprise clients under NDA).