GDPR & Consent Management

How Flowvenue collects, manages and respects user consent under GDPR and ePrivacy.

Last updated: June 2026 Version: 2026.06


Our Approach to GDPR Compliance

Flowvenue adopts a structured approach to compliance with the General Data Protection Regulation (GDPR) and the ePrivacy Directive. This page explains how we collect, manage, and respect user consent in accordance with these regulations.


Legal Basis for Processing

Necessary Cookies and Essential Services

Legal basis: Technical necessity for the provision of the service requested by the user under Article 6(1)(b) GDPR. We also apply security measures to protect the service.

Essential cookies and services required for the website to function do not require consent. These include:

Statistics and Marketing Cookies

Legal basis: Article 6(1)(a) GDPR (expressed and informed consent) and Article 5(3) ePrivacy Directive.

All non-essential tracking requires expressed and informed consent before any processing occurs.


Consent Collection

How Consent Is Collected

When you first visit our website:

  1. Banner Display: A cookie banner appears with clear options
  2. Informed Choice: You can:
    • Accept all cookies
    • Reject all non-essential cookies
    • Customize preferences category by category
  3. Explicit Action: Consent is only recorded when you take an explicit action (clicking "Accept", "Reject", or "Save" after customization)
  4. No Pre-Consent Tracking: No tracking scripts are loaded and no non-essential cookies are set before you provide consent

Granularity

Consent is collected per category:

You can accept or reject each category independently.

Consent Trace (Consent Record)

When you provide consent, we record:

Note: For the website, the consent record is stored on the user's device and can be reset by clearing browser data; additional evidence may be collected in enterprise contexts or upon formal request.

This record enables us to demonstrate compliance and accountability.


Consent Application

Technical Implementation

Once consent is provided:

  1. Immediate Application: Consent preferences are applied immediately
  2. Conditional Loading: Tracking scripts are loaded only if consent was granted for the corresponding category
  3. Consent Mode: Google Consent Mode v2 is updated to reflect your choices
  4. No Retroactive Tracking: We do not attempt to track activity that occurred before consent

Verification

This behavior can be verified using browser technical tools. Non-essential cookies are only set after consent, and tracking scripts are only loaded after consent.


Consent Revocation

How to Revoke Consent

You can revoke or modify your consent at any time:

  1. Click "Cookie settings" in the footer of any page
  2. Modify your preferences in the preference center
  3. Click "Save"
  4. Changes are applied immediately

What Happens When You Revoke

When you revoke consent:

  1. Immediate Disabling: Tracking scripts are disabled and no further tracking calls are made
  2. Cookie Removal: First-party cookies are deleted (best-effort)
  3. Consent Mode Update: Google Consent Mode v2 is updated to "denied" for revoked categories
  4. No Further Tracking: No new tracking requests are made

Note: Third-party cookies (e.g., cookies set by Facebook) cannot be deleted directly by our website due to browser security restrictions. However, these cookies will no longer be used for tracking purposes once consent is revoked.


Consent Expiration

Automatic Expiration

Your consent expires automatically after 6 months (180 days) from the date you provided it.

What Happens on Expiration

When consent expires:

  1. Automatic Removal: The consent record saved on the device is automatically removed
  2. Banner Reappears: The cookie banner reappears on your next visit
  3. Tracking Stops: All tracking stops until you provide new consent
  4. Fresh Choice: You can make a new, informed choice about cookies

Why 6 Months?

The 6-month expiration period:


Policy Updates and Consent Renewal

When Policy Changes

If we make substantial changes to our Cookie Policy (e.g., adding new tracking technologies, changing purposes, or modifying legal basis):

  1. Policy Version Updated: The Cookie Policy version number is incremented
  2. Banner Reappears: The cookie banner reappears even if your previous consent has not expired
  3. New Consent Required: You must provide new consent for the updated policy
  4. Transparency: The updated policy is clearly marked with a new version number and date

What Constitutes a "Substantial Change"

Substantial changes that require new consent include:

Minor changes (e.g., typo corrections, clarifications, contact information updates) may not require new consent, but the policy version will still be updated.


Accountability and Evidence

Demonstrating Compliance

We maintain evidence and documentation to demonstrate compliance with GDPR and ePrivacy requirements:

Consent Trace Details

Each consent record (trace) includes:

This trace enables us to demonstrate accountability to:


AI-assisted processing (LLM) — reference

Flowvenue may process personal data or customer content through large language models (LLMs) in several modes:

  1. Platform-managed LLM — inference via Flowvenue-approved providers (default OpenAI GPT-5.6 Luna; Anthropic models where enabled), with contractual and technical measures described in Information Security and Security measures — §1.5.
  2. Bring Your Own Key (BYOK) — inference using Customer-supplied API credentials (including dedicated cloud or private/on‑premise endpoints). The Customer’s LLM provider for that path is outside Flowvenue’s sub-processor list for inference; Customer keys are stored encrypted (AES-256-GCM). See Terms of Service Section 10.
  3. External LLM via MCP Server — the Customer connects an external LLM client (e.g. Claude, ChatGPT) to Flowvenue’s inbound MCP Server; LLM inference runs on the Customer’s chosen environment, while Flowvenue hosts MCP tools subject to OAuth, scopes, and audit controls.

Provider-specific documentation (security, privacy, GDPR, residency, retention) remains authoritative for each vendor—for example Anthropic Trust Center, OpenAI Trust portal, and OpenAI data controls. This GDPR page does not replace provider documentation or your own legal assessment.


Your Rights Under GDPR

In addition to consent management, you have the following rights under GDPR:

Right of Access (Article 15)

You can request information about what personal data we process about you.

Right to Rectification (Article 16)

You can request correction of inaccurate personal data.

Right to Erasure (Article 17)

You can request deletion of your personal data in certain circumstances.

Right to Restrict Processing (Article 18)

You can request restriction of processing in certain circumstances.

Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format.

Right to Object (Article 21)

You can object to processing based on legitimate interests.

Right to Withdraw Consent (Article 7(3))

You can withdraw consent at any time (as described in the "Consent Revocation" section above).

How to Exercise Your Rights

To exercise your rights, contact us:

We will respond to your request within one month (or two months for complex requests), as required by GDPR.


Privacy by Design

Built-In Privacy Protections

Our consent management system is designed with privacy by design principles:

Technical Safeguards

Technical measures ensure that consent is respected:


Compliance with ePrivacy Directive

Article 5(3) ePrivacy Directive

The ePrivacy Directive requires consent before storing or accessing information on a user's device (cookies and similar tracking technologies).

Our compliance:

Integration with GDPR

The ePrivacy Directive works in conjunction with GDPR:


Contact

For questions about GDPR compliance or consent management:

You also have the right to file a complaint with your local data protection authority if you believe that the processing of your data violates GDPR or the ePrivacy Directive. In Italy: Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).


Note: This page provides a high-level overview of our GDPR and consent management approach. Detailed technical documentation is available upon formal request for authorized parties (auditors, regulators, enterprise clients under NDA).