Back to Home
F1
FLOWOF1
Legal Document

Privacy Policy

How FLOWOF1 collects, uses, and protects your information

Publisher

O and P Advisory Services, LLC

Product

FLOWOF1 — Business Modeling & Workflow Analysis Platform

Last Updated

June 25, 2026

Effective Date:

The date on which LICENSEE completes electronic acceptance of the EULA ("I Agree" click-wrap or checkout completion), or the date of first access to the Platform, whichever is earlier.

Section 1 — Introduction

O and P Advisory Services, LLC ("FLOWOF1," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect information when you access and use the FLOWOF1 Business Modeling & Workflow Analysis Platform (the "Platform"). This Privacy Policy is incorporated by reference into our End User License Agreement ("EULA") and is an integral part of the agreement between you ("LICENSEE," "you," or "your") and us. In the event of any direct conflict between the EULA and this Privacy Policy with respect to the treatment of Licensee Data, the EULA shall control. Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the EULA.

Section 2 — Information We Collect

2.1 Account Registration Data

When you create a FLOWOF1 account, we collect information necessary to establish and manage your account, including: your full name, email address, company name, and role designation (admin, scheduler, operator, viewer). If you invite team members, we collect their email addresses for the purpose of issuing invitations. This information is provided voluntarily by you at registration and is required for the Platform to function.

2.2 Licensee Data

Licensee Data is the business and operational data that you and your Authorized Users input into the Platform in connection with your use of the Platform. This includes, without limitation: job schedules, workcenter configurations, product family definitions, changeover rules, shift calendars, scenario configurations, operational inputs, and any other data you submit to or through the Platform. As between you and FLOWOF1, you retain all right, title, and ownership interest in and to your Licensee Data. We process Licensee Data solely as described in Section 3 below and in accordance with the limited license granted in the EULA.

2.3 Technical Usage Data

We automatically collect certain technical and usage information when you interact with the Platform, including: IP address, browser type and version, device identifiers, operating system, referring URLs, timestamps of access, session duration, feature usage patterns, page interactions, and error logs. This data is collected through server logs, cookies, and similar technologies as described in Section 6 below.

2.4 Billing and Payment Data

When you purchase a subscription or Workcenter Bundle add-on, we collect billing-related information including your name, company, billing address, and subscription plan selections. Payment card information is processed exclusively by our payment processor, Stripe, and is not stored on our servers. We receive a tokenized reference from Stripe but do not see, store, or transmit your full payment card details.

2.5 Communications Data

If you contact us directly — via email, our contact page, or support channels — we collect the information you provide in those communications, including your name, email address, and the content of your message. We retain this information for the purpose of responding to your inquiry and maintaining a record of our communications.

Section 3 — How We Use Your Information

3.1 Providing the Platform

We use Account Registration Data, Licensee Data, and Technical Usage Data to: (a) operate, maintain, and improve the Platform; (b) authenticate users and manage sessions; (c) store and process your scheduling models, scenarios, and configurations; (d) generate Outputs based on your inputs; (e) provide customer support; and (f) communicate with you about your account, subscription, and the Platform.

3.2 Billing and Subscription Management

We use Billing and Payment Data to: (a) process subscription payments; (b) manage billing cycles and renewals; (c) handle cancellations and refunds as applicable under the EULA; (d) detect and prevent fraud; and (e) comply with applicable tax obligations.

3.3 Security and Compliance

We use Technical Usage Data and Account Registration Data to: (a) monitor and protect the security and integrity of the Platform; (b) detect, investigate, and respond to security incidents and unauthorized access; (c) enforce the EULA, including the Acceptable Use provisions in Section 5 thereof; (d) comply with legal obligations; and (e) maintain audit trails as required.

3.4 Aggregated Anonymous Data

Consistent with Section 6.5 of the EULA, we may collect, use, analyze, and disclose anonymized, aggregated, de-identified technical and usage data derived from your use of the Platform (including feature usage patterns, session frequency, performance metrics, error rates, and load data), provided that such data: (a) cannot reasonably be used, alone or in combination with other information, to identify you, any Authorized User, or any individual; and (b) does not incorporate or reveal any Licensee Data. We use such anonymized, aggregated data for platform improvement, product development, performance analysis, and statistical reporting.

3.5 Uses We Do Not Make

We do not: (a) sell Licensee Data or Account Registration Data to third parties; (b) use Licensee Data to train machine learning models, except as expressly provided in Section 6.5 of the EULA (Aggregated Anonymous Data); (c) use Licensee Data for advertising or marketing to third parties; or (d) share Licensee Data with third parties for their own independent commercial purposes. Our use of your data is limited to the purposes described in this Privacy Policy and the EULA.

Section 4 — Legal Bases for Processing

4.1 General

FLOWOF1 processes personal data under applicable legal frameworks. For individuals in the European Economic Area, the United Kingdom, or Switzerland (the "EEA"), we process personal data under the EU General Data Protection Regulation (GDPR) based on the following legal bases: (a) performance of a contract — processing necessary to provide the Platform services under the EULA; (b) compliance with legal obligations — processing required to meet our legal and regulatory duties; (c) legitimate interests — processing for security, fraud prevention, and platform improvement, balanced against your privacy rights; and (d) consent — where you have provided explicit consent for specific processing activities.

4.2 California Consumer Privacy Act (CCPA/CPRA)

For California residents, we process personal information as a "service provider" or "processor" on behalf of our business customers, consistent with the business-to-business and employee data exemptions under the CCPA as amended by the CPRA, where applicable. We do not sell personal information as defined by the CCPA. Licensee Data that you input into the Platform is processed on behalf of the business entity that licensed the Platform, and that entity is the "business" responsible for providing privacy notices to its employees and end users. We process such data only as instructed by the business and in accordance with this Privacy Policy and the EULA.

Section 5 — How We Share Your Information

5.1 Sub-Processors and Service Providers

We engage a limited number of trusted third-party service providers and sub-processors to deliver the Platform. These providers process data on our behalf under contractual obligations that are no less protective than the commitments in this Privacy Policy. Our current sub-processors are listed in Section 9 below. We do not authorize any sub-processor to use your data for its own purposes.

5.2 Legal and Regulatory Disclosures

We may disclose Account Registration Data, Technical Usage Data, or other information if required to do so by law, regulation, court order, subpoena, or other governmental authority, or in response to a lawful request from law enforcement. We may also disclose information to protect our rights, property, safety, or the rights, property, or safety of others, including to prevent fraud or enforce the terms of the EULA.

5.3 Business Transfers

In the event of a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, we may transfer Account Registration Data, Technical Usage Data, and billing information to the acquiring entity. We will provide notice of such transfer and any choices you may have, where required by applicable law. Licensee Data remains subject to the terms of the EULA and the acquiring entity must honor those terms.

5.4 What We Do Not Share

We do not share Licensee Data with third parties for their own independent commercial purposes. We do not sell personal information to data brokers or advertising networks. We do not share your data for cross-context behavioral advertising. Sub-processor access is strictly limited to what is necessary to provide the contracted service.

Section 6 — Cookies and Tracking Technologies

6.1 Types of Cookies We Use

The Platform uses cookies and similar tracking technologies (including web beacons and pixels) for the following purposes: (a) Essential cookies — required for the Platform to function, including authentication, session management, and security. These cannot be disabled. (b) Preference cookies — remember your settings and preferences, such as theme selection and language. (c) Analytics cookies — help us understand how users interact with the Platform so we can improve performance and usability. (d) Security cookies — detect and prevent fraud, abuse, and unauthorized access.

6.2 Third-Party Cookies

Certain third-party services we engage may set their own cookies when you interact with the Platform. These include: Stripe (payment processing — sets cookies on checkout pages), and Google Fonts (web typography — may set cookies when fonts are loaded). These third parties manage their own cookies in accordance with their respective privacy policies.

6.3 Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. Please note that some parts of the Platform may not function properly if you disable essential cookies. We do not use cookies for cross-site tracking, behavioral advertising, or building advertising profiles of individual users.

Section 7 — Data Retention

7.1 Persistent Storage Model

Consistent with Section 6.3 of the EULA, the Platform is a cloud-hosted, persistent storage service. Licensee Data — including job schedules, scenarios, workcenter configurations, and operational inputs — is stored securely in our database and is not purged upon logout or session termination. This allows you to access, modify, and manage your manufacturing schedules and models across multiple sessions. We maintain Licensee Data for the duration of your Subscription Term, unless you request earlier deletion in accordance with Section 8 below.

7.2 Post-Termination Retention

Upon termination or expiration of your subscription, consistent with Section 12.4 of the EULA, we retain Licensee Data for a period of ninety (90) days to allow you to export your data. During this post-termination retention period, you may submit a written request for an export of your Licensee Data. After the 90-day period, all Licensee Data — including jobs, schedules, workcenters, scenarios, and Outputs — is permanently and irreversibly deleted.

7.3 Account and Billing Data

We retain Account Registration Data and Billing and Payment Data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. Billing records may be retained for up to seven (7) years to comply with tax and financial record-keeping requirements.

7.4 Technical Usage Data

We retain server logs and Technical Usage Data for a period of up to twelve (12) months, after which such data is automatically purged or anonymized. Aggregated, de-identified data may be retained indefinitely, as it can no longer be used to identify you or any individual.

7.5 Immediate Deletion

You may request immediate deletion of your Licensee Data at any time, even before the end of your Subscription Term or the 90-day post-termination retention period, by submitting a written request as described in Section 8 below. Upon verification of your identity and authority, we will initiate deletion of your Licensee Data within a reasonable period, not to exceed thirty (30) days.

Section 8 — Your Privacy Rights

8.1 Access and Export

You may request access to and a copy of the personal data we hold about you, and you may request an export of your Licensee Data, by submitting a written request to us at the contact information in Section 11. We will respond to verified requests within thirty (30) days. We may need to verify your identity before fulfilling your request.

8.2 Correction

You may correct or update your Account Registration Data at any time through your account settings within the Platform. If you believe we hold inaccurate personal data about you, you may request correction by contacting us.

8.3 Deletion

You may request deletion of your personal data and Licensee Data. Please note that certain data may be retained where required by law, to comply with legal obligations, to protect our rights, or to enforce the EULA. Upon termination of your subscription, Licensee Data is retained for 90 days and then permanently deleted, as described in Section 7.2 above. You may request immediate deletion at any time per Section 7.5.

8.4 Restriction and Objection

Depending on your jurisdiction, you may have the right to: (a) restrict the processing of your personal data under certain circumstances; (b) object to the processing of your personal data for direct marketing or other legitimate-interest-based processing; (c) data portability — receive your personal data in a structured, machine-readable format and transmit it to another controller; and (d) withdraw consent at any time where we process data based on your consent, without affecting the lawfulness of processing before withdrawal.

8.5 Exercising Your Rights

To exercise any of the rights described in this Section 8, please contact us using the information in Section 11 below. We will respond to your request within the timeframe required by applicable law (generally within 30 days). If we decline to act on your request, we will inform you of the reasons and your right to lodge a complaint with the relevant supervisory authority. For EEA residents, you may lodge a complaint with your local data protection authority. For California residents, you may exercise your rights through the Attorney General's office.

Section 9 — Sub-Processors

FLOWOF1 uses the following third-party sub-processors to deliver the Platform. Each sub-processor is bound by contractual obligations to protect data in a manner consistent with this Privacy Policy and applicable law. We review this list regularly and will provide notice of material changes. If you wish to be notified of new sub-processors before they are engaged, please contact us at the email address in Section 11.

SubprocessorPurposeLocation
Base44 / Wix CloudApplication hosting, database, and runtime infrastructureUnited States
StripePayment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
Google FontsWeb typography (Inter font family)United States

Section 10 — Data Security

Consistent with Section 6.7 of the EULA, we implement commercially reasonable technical, administrative, and organizational security measures designed to protect your data from unauthorized access, disclosure, alteration, or destruction. These measures include: TLS 1.2+ encryption in transit; AES-256 encryption at rest; role-based access control (RBAC) enforced at the database and API layer; multi-tenant data isolation at the query level; secure session management with automatic expiration; enterprise-grade HTTP security headers on all API responses; continuous monitoring for anomalous activity; and regular dependency scanning and vulnerability detection. Despite these measures, no system or security measure is completely secure or impenetrable. We do not guarantee the absolute security of the Platform or any data transmitted to or through it. For more details, please see our Security page.

Section 11 — International Data Transfers

11.1 Cross-Border Processing

The Platform and its sub-processors are primarily located in the United States. If you access the Platform from outside the United States, your data will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Platform, you consent to the transfer and processing of your data in the United States and other jurisdictions where our sub-processors operate, subject to the protections described in this Privacy Policy and the EULA.

11.2 GDPR Data Transfers

For personal data originating from the EEA, we rely on Standard Contractual Clauses (SCCs) or other valid transfer mechanisms approved by the European Commission to ensure appropriate safeguards for cross-border data transfers to our sub-processors. We assess sub-processor adequacy and transfer mechanisms on an ongoing basis.

Section 12 — Children's Privacy

The Platform is a business-to-business tool designed for use by commercial organizations. It is not intended for use by individuals under the age of eighteen (18). We do not knowingly collect personal information from children under 16 (or the applicable age of consent in the relevant jurisdiction). If we become aware that we have collected personal data from a child, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, please contact us using the information below.

Section 13 — Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will provide notice of material changes by: (a) posting the updated Privacy Policy on this page with a revised "Last Updated" date; (b) sending an email notification to the address on file; or (c) displaying a prominent in-Platform notification at least fourteen (14) calendar days before the changes take effect. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the updated terms, your sole remedy is to cancel your subscription in accordance with Section 3.6 of the EULA. We encourage you to review this page periodically.

Section 14 — Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact us at:

O and P Advisory Services, LLC

privacyflowof1@oandpadvisoryservices.com

Contact information fields are confirmed and published on the FLOWOF1 platform.

© 2026 O and P Advisory Services, LLC — All Rights Reserved.

FLOWOF1 Privacy Policy — Version 2026-06-25 — Last Updated: June 25, 2026