Privacy policy

This statement was last updated on 9 August 2026 and describes how FlowCore processes your personal data. Questions? Mail info@flowcore.be.

1. Who is responsible for your data

FlowCore is the data controller.

  • Company: FlowCore, established in Pecq (Belgium)
  • Company number: BE 1036.070.163
  • Contact: info@flowcore.be

2. What data we process and why

We only process what a concrete purpose requires, each time on a clear legal basis.

  • Contact and quotes: name, e-mail address, phone number and the content of your message. Purpose: answering your question and preparing a quote. Basis: performance of, or steps prior to, a contract.
  • AI visibility scanner: the brand, domain, sector, region and any competitors you enter, plus your e-mail address. This data goes to external AI services to measure your visibility (see point 3) and we keep your e-mail address as a contact. Basis: performance of the service and, for keeping it as a lead, our legitimate interest.
  • Automation scan: the sector, tools and manual work you describe, plus your e-mail address. The free text goes to an external AI model to generate suggestions; do not enter the names of clients or staff here.
  • Customer account, tokens and subscription: name or company name, billing address, VAT number, e-mail address and the data needed for your token purchase or monitoring subscription. If you provide a VAT number, we verify it with the European Commission (VIES), because your invoice has to be legally correct. Basis: performance of the contract and legal obligations (accounting and VAT).
  • Monitoring: the domains, keywords and locations you enter yourself, and the results of the weekly scans that follow from them. Basis: performance of the contract.
  • Notifications: your preferences for alerts, the weekly summary and product news, and the notifications we keep for you in your account. You adjust those preferences yourself.
  • Newsletter: your e-mail address, if you subscribe. Basis: consent, which you can withdraw at any time.
  • Abuse protection: your IP address, to count how many scans start from one address per day and stop abuse. Basis: legitimate interest.
  • Technical data: IP address, device and browsing data, through necessary and (after consent) analytical cookies. We also record which pages are not found, with the referring page, your browser type and an encrypted session code, so we can repair broken links. Basis: legitimate interest for the necessary cookies and the error logs, consent for the analytical cookies.

3. What happens during a scan

A scan measures a website you enter yourself. To do that, your domain and your scan data leave our servers. This is exactly what happens.

Questions to AI models

We put real questions to external AI models (OpenAI, Anthropic, Google and Perplexity) to measure whether they know and recommend your brand. Those questions contain your brand, sector, region and the competitors you enter. They contain no data about your own customers or staff. Do not enter those in the free-text fields either.

Search, speed and map data

For positions in search results and AI overviews we use DataForSEO. For the loading speed of your pages we use Google PageSpeed Insights: your page addresses go to Google for that. For local visibility we use Google Places: your business name and a grid of coordinates around your location go to Google.

Scans with a real browser

Some scanners open your site in a real browser, because your cookie banner or your form cannot honestly be assessed any other way. That browser runs on our own infrastructure, not at an external scanning provider. A screenshot is taken as evidence for your report. Those images sit in protected storage that only you and we can reach, and they are deleted after 90 days at most. The report and the findings do stay.

Form monitoring

If you choose to have your contact form monitored, we fill that form in ourselves with a FlowCore e-mail address and submit it, to check that it still arrives. So you will occasionally receive a test message through your own form. We only do this for the site you enter yourself.

Sharing reports

You can share a report through a link with an unguessable code. Anyone holding that link can read that one report without logging in. So only share it with people who are allowed to see it.

4. Connections with your Google account

Google Search Console

If you have an account, you can connect your Google Search Console to your dashboard. That is optional and you can disconnect at any time.

We only request read access to your search performance (webmasters.readonly) and your e-mail address, so we can show which Google account is connected. We cannot change anything.

From the site you choose we retrieve clicks, impressions, CTR, average position, your main keywords and pages, countries, devices and sitemap status. We store that together with your Google e-mail address and an AES-256 encrypted access key, on servers within the EU. That key never leaves our server.

We use this data solely to display it in your own dashboard, in line with the Google API Services User Data Policy including the Limited Use requirements. We do not sell it, do not share it with third parties and do not use it for advertising or AI training.

If you disconnect, we revoke the access at Google and delete the data. If you delete your account, everything goes with it.

Google Business Profile

If we track your Google Business Profile, you connect that profile to your dashboard yourself, with your own Google login. That connection is optional too and you can end it at any time.

We retrieve your profile data (name, address, phone number, categories, opening hours and website), your reviews with the replies to them, and the figures Google provides about your profile: views, searches, phone calls and direction requests.

We keep that profile data and those reviews for 30 calendar days at most, and only to make your dashboard faster. That is what Google's policy for business profiles allows. After that we retrieve them from Google again or they disappear. Your access key is stored AES-256 encrypted on servers within the EU, for as long as the connection exists.

For business profiles Google offers only one level of access (business.manage). We use that access to read your profile and your reviews and show them in your dashboard and your report. We change nothing on your profile and publish no replies, unless you expressly instruct us to. If we do make a change at your request, we tell you within 48 hours.

If you disconnect, we revoke the access at Google and delete the retrieved profile data and reviews. If you delete your account, everything goes with it.

Google Analytics

If you have an account, you can connect your Google Analytics property (GA4) to your dashboard. That is optional and you can disconnect at any time.

We only request read access to your measurement data (analytics.readonly) and your e-mail address, so we can show which Google account is connected. We cannot change anything.

From the property you choose we retrieve aggregated figures: sessions, users and new users, page views, engagement rate, average session duration and key events, per day, per channel and per page. We also read your property's settings (data retention, defined key events, data streams and any Google Ads link), so we can tell you whether your measurement is set up correctly. We never request data about individual visitors.

We store the daily figures together with your Google e-mail address, the selected property and an AES-256 encrypted access key, on servers within the EU. That key never leaves our server.

We use this data solely to show it to you in your own dashboard and reports: your traffic overview, the evolution over time, an alert when your traffic drops, and the weight of a finding (an error on a busy page matters more). This follows the Google API Services User Data Policy including the Limited Use requirements. We do not sell it, do not share it with third parties, and do not use it for advertising or AI training.

One limit worth knowing: Google Analytics only counts visitors who consented to analytics cookies. Every figure in this part of your dashboard therefore undercounts your real traffic, and the stricter your cookie banner, the bigger that gap.

If you disconnect, we revoke access at Google and delete the stored figures. If you delete your account, everything goes with it.

What we do not do with your Google data

These connections fall under the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use your Google data only for the features you see yourself in your dashboard and your report.
  • We do not sell it and do not pass it to advertising networks, data brokers, credit assessment services or targeted advertising services.
  • We do not use it to train or improve AI models, including the models the scanner queries. Your Google data is never put into a question to an AI model.
  • Nobody at FlowCore reads your Google data, except when you expressly ask us to (for support, for example), when it is necessary to guarantee security or fix an error, or when the law obliges us to.
  • You can disconnect at any time from your account, and withdraw your permission directly at Google through myaccount.google.com/permissions. If you ask us to disassociate you, we do so within seven business days.

5. Cookies, analytics and spam protection

We place necessary cookies to make the site work (your language choice, for example) and, only after your consent, analytical cookies from Google Analytics and Microsoft Clarity to measure how the site is used. You can change your choice at any time through the cookie settings at the bottom of the site. Without consent, no analytical cookies are loaded.

Both only measure our public pages. The customer console, the admin and a stored scan report stay out of it: the link to such a report contains the key that opens the report, and we do not pass that on to third parties. We do not allow Google Analytics to use advertising storage or ad personalisation, not even if you accept the marketing category.

Microsoft Clarity goes further than numbers: it records your visit, which shows us where visitors get stuck. That recording covers your mouse movements, clicks and scrolling. What you type, e-mail addresses and numbers are made unreadable on your own device before anything is sent. Clarity only runs on our public pages: nothing is recorded in the customer console or the admin. The data goes to Microsoft (see point 7).

Our forms are protected by Cloudflare Turnstile. It checks that a submission comes from a human and processes your IP address and some technical browser data to do so. It does not track you across other websites and places no advertising cookies.

6. Who we share data with (processors)

We never sell your data. We do rely on carefully chosen service providers who process data on our behalf, each with the necessary safeguards:

  • Supabase - database, authentication and storage (servers in the EU).
  • Netlify - hosting of the website and server functions.
  • Mollie - payments (EU).
  • Billit - invoicing (Belgium).
  • Resend - sending transactional e-mails.
  • MailerLite - newsletter management (EU).
  • OpenAI, Anthropic, Google and Perplexity - the AI models the scanner queries.
  • DataForSEO - measurement data on AI and search results.
  • Google - PageSpeed Insights (loading speed), Places (local visibility), and Search Console and Analytics (your own connections).
  • Cloudflare - spam protection for the forms.
  • Google Analytics - website statistics (only after consent).
  • Microsoft Clarity - session recordings and heatmaps of the public pages (only after consent).

The scans that use a real browser run on our own protected infrastructure. No external scanning provider is involved.

We also pass on data where the law requires it: your VAT number goes to the European Commission's verification service (VIES) so your invoice is drawn up correctly, and your invoice data goes to our accountant and, on request, to the tax authorities.

7. Transfers outside the EU

Some of these services (including the AI models, Resend, Cloudflare, Google and Microsoft) are based in the United States. Where data is processed outside the European Economic Area, that happens on the basis of appropriate safeguards: the EU-US Data Privacy Framework and/or the European Commission's standard contractual clauses.

8. How long we keep data

  • Account, scan and monitoring data: as long as your account exists. If you delete your account, we erase everything immediately, with the exception of the invoices.
  • Invoices: 7 years, as the law requires. If you delete your account, the invoices remain, no longer linked to you.
  • Data from your Google connections: the Search Console figures stay for as long as the connection exists, so you can follow your progress. Profile data and reviews from your Google Business Profile are kept for 30 days at most. The daily figures from Google Analytics are likewise kept for as long as the connection exists.
  • Screenshots from the browser scans: 90 days at most. The report itself stays.
  • Website statistics in Google Analytics: Google keeps user-level and event-level data for 14 months. The aggregated reports, such as visitor numbers per page and per source, remain available after that.
  • Session recordings in Microsoft Clarity: Microsoft keeps a recording for 30 days. Recordings we mark as favourites and a random sample are kept for up to 9 months; heatmap data likewise up to 9 months.
  • Leads from the scanner and the newsletter: until you unsubscribe or ask for deletion.
  • Support requests: up to 2 years after your request is closed. A request that is still open is not deleted.
  • Support mail delivery log: 90 days at most. It records which address a mail went to, never what it said.
  • Contact messages: up to 2 years after the last contact.
  • Technical logs and abuse counters: 30 days at most.

9. Your rights

You have the right of access, rectification, erasure, restriction and portability of your data at any time, and you can object to certain processing or withdraw your consent.

If you have an account you do not need to ask us: you can download all your data yourself and permanently delete your account yourself, under the privacy settings in your account. Your e-mail preferences for alerts, the weekly summary and product news are there too.

If you prefer to ask us, or if you have no account, send your request to info@flowcore.be; we respond within the statutory period. If you disagree with how we handle your data, you can lodge a complaint with the Belgian Data Protection Authority (www.dataprotectionauthority.be).

We take no decisions about you based solely on automated processing with legal or similarly significant effects. A scan score is a measurement of a website, not an assessment of a person.

Our services are aimed at businesses. We do not knowingly collect data from minors.

10. Security and data breaches

We take technical and organisational measures to protect your data, including encrypted connections, encrypted storage of access keys and per-user access control. Should a data breach nonetheless occur with a risk to your rights, we report it within 72 hours to the Data Protection Authority and, where required, to you.

11. Changes

We update this statement when our services or the regulations change. The date at the top shows the last change.