Privacy Policy
This policy explains what personal data GG Flows collects, why we collect it, how we use and protect it, and the rights you have over it. It is written for a UK small-business audience — plain English, but legally binding.
1. Scope
This policy covers our two product lines:
- Flow & overlay build service — we build branded Klaviyo email/SMS marketing flows and StreamLabs/OBS live-draw overlay scenes for prize-competition operators.
- Served Social — our software product that generates on-brand social posts, reels, marketing emails and SMS content and delivers them to the client as a download pack. Where a client connects their own GoHighLevel account, it can also create those posts in that account's Social Planner at the client's request.
It applies to our clients (the businesses that buy our services), people who contact us or request access, and visitors to www.ggflows.com.
2. The personal data we collect
From client businesses and their staff
- Account & contact details — business name, contact name, email address, phone number, and login credentials (passwords are stored only as a secure one-way hash).
- Brand & competition data — your competition website URL(s) and publicly available information scraped from them (competition names, prices, ticket counts, end dates, published winners), plus the brand assets you upload (logos, mascot images, product photos, example posts and ad copy).
- Connected-account access — Klaviyo API keys/account access (flow-build clients) and, where a Served Social client chooses to connect one, a GoHighLevel private-integration token and Location ID (stored encrypted). These are credentials we hold to act on your instructions. We do not hold logins, passwords or OAuth tokens for Facebook, Instagram or any other social network.
- Billing data — subscription status and the details needed to take payment. Card details are handled by our payment processor (see section 5) and are not stored on our servers.
- Usage & technical data — log data, IP address, device/browser information, and records of how you use the product, used to run, secure and improve the service.
- Consent records — the date and time you accepted these policies at sign-up.
End-customer data inside your Klaviyo account
When we build flows for you, we access the contact data held inside your own Klaviyo account (your subscribers). We do not own or export this data — see section 6.
3. How we use your data, and our legal basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Providing the service you signed up for (generating content, delivering your pack, creating posts in a GoHighLevel account you have connected and confirmed, building flows/overlays) | Performance of a contract |
| Taking payment and managing your subscription | Performance of a contract |
| Securing the service, preventing abuse, keeping logs | Legitimate interests |
| Improving and supporting the product | Legitimate interests |
| Service and account emails (e.g. welcome, password reset, important notices) | Performance of a contract / legitimate interests |
| Optional marketing emails from GG Flows about our own product | Consent (you can opt out at any time) |
| Meeting legal, tax and accounting obligations | Legal obligation |
4. How AI generation uses your assets
Served Social uses AI to generate content. We handle your uploaded assets carefully and by category:
- Style references — used only as a visual style guide for AI image generation; they are not reproduced directly in output.
- Brand marks (logos, frames, watermarks) — used only to composite onto generated images. They are not sent to the AI model as generation input.
- Text/ad references — used only as tone reference for caption generation; they are not reproduced verbatim.
Logos and text-heavy assets are explicitly excluded from image-generation prompts, and every image request applies a negative prompt excluding text, typography and logos. We do not use your data to train third-party AI models, and our AI subprocessors (see section 5) act on our instructions under their own commitments not to train their base models on API content.
5. Who we share data with (subprocessors)
We use a small number of trusted providers to run the service. We share only what each needs to do its job:
| Provider | Purpose |
|---|---|
| Anthropic (Claude API) | Generating post/email/SMS copy from your brand profile |
| Google Cloud / Vertex AI (Gemini) | Generating images from brand-derived prompts |
| HighLevel (GoHighLevel) | Only if you connect your own GoHighLevel account: we upload the images you approved to your media library and create the approved posts in your Social Planner. Your captions and images are sent to HighLevel to do this. |
| Klaviyo | Your own email/SMS marketing platform (your account — we access it on your behalf) |
| Stripe | Payment processing (card data is handled directly by Stripe) |
| Railway | Application hosting |
| Cloudflare | DNS, CDN and security |
| Resend | Sending our own service emails |
Some of these providers are located outside the UK. Where personal data is transferred internationally, we rely on the UK's adequacy regulations or on standard contractual clauses / the UK International Data Transfer Addendum to keep it protected. We do not sell your personal data.
6. When we are a data processor
For the end-customer data held inside your Klaviyo account, you remain the data controller and GG Flows acts only as your data processor: we access and process that data solely to build and configure the flows you have asked for, on your documented instructions, and we do not use it for any other purpose. A Data Processing Agreement (DPA) is available on request for clients who grant us Klaviyo access.
7. How long we keep it
- Generated media (posts, images, reels, videos) is automatically purged from the product after 7 days.
- Account and brand data (your profile, uploaded brand assets, connected-account tokens) is kept while your account is active and deleted within 30 days of account closure, unless we must keep some records longer to meet a legal obligation.
- Trial accounts that lapse without subscribing are removed automatically after a short grace period.
- Billing and tax records are kept for as long as UK law requires (generally 6 years).
8. How we protect your data
We use encryption in transit (HTTPS), hashed passwords, access controls, and reputable infrastructure providers. Connected-account credentials (Klaviyo, GoHighLevel) are encrypted at rest, are never displayed back to you or to us once saved, and are held only to perform the actions you have authorised. You can disconnect and delete a GoHighLevel token from your Brand page at any time. No online service can be guaranteed 100% secure, but we take reasonable and appropriate technical and organisational measures to protect your data.
9. Your rights
Under UK GDPR you have the right to access, correct, delete or restrict the use of your personal data, to object to certain processing, to data portability, and to withdraw consent where we rely on it. To exercise any of these, email us at [email protected] and we will respond within one month. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to put things right first.
10. Cookies
We use only the cookies necessary to run the service — chiefly to keep you signed in and to keep the service secure. We do not use advertising or third-party tracking cookies.
11. Children
Served Social and our flow/overlay services are business tools intended for use by people aged 18 or over. They are not directed at children and we do not knowingly collect data from anyone under 18.
12. Changes to this policy
We may update this policy from time to time. The version number and "last updated" date at the top show the current version, and we will notify clients of material changes by email or in-product.
13. Contact
Questions about this policy or your data? Email [email protected] or write to G Green Holdings Ltd at the registered office above.