This statement was last updated on 9 August 2026 and describes how FlowCore processes your personal data. Questions? Mail info@flowcore.be.
FlowCore is the data controller.
We only process what a concrete purpose requires, each time on a clear legal basis.
A scan measures a website you enter yourself. To do that, your domain and your scan data leave our servers. This is exactly what happens.
We put real questions to external AI models (OpenAI, Anthropic, Google and Perplexity) to measure whether they know and recommend your brand. Those questions contain your brand, sector, region and the competitors you enter. They contain no data about your own customers or staff. Do not enter those in the free-text fields either.
For positions in search results and AI overviews we use DataForSEO. For the loading speed of your pages we use Google PageSpeed Insights: your page addresses go to Google for that. For local visibility we use Google Places: your business name and a grid of coordinates around your location go to Google.
Some scanners open your site in a real browser, because your cookie banner or your form cannot honestly be assessed any other way. That browser runs on our own infrastructure, not at an external scanning provider. A screenshot is taken as evidence for your report. Those images sit in protected storage that only you and we can reach, and they are deleted after 90 days at most. The report and the findings do stay.
If you choose to have your contact form monitored, we fill that form in ourselves with a FlowCore e-mail address and submit it, to check that it still arrives. So you will occasionally receive a test message through your own form. We only do this for the site you enter yourself.
You can share a report through a link with an unguessable code. Anyone holding that link can read that one report without logging in. So only share it with people who are allowed to see it.
If you have an account, you can connect your Google Search Console to your dashboard. That is optional and you can disconnect at any time.
We only request read access to your search performance (webmasters.readonly) and your e-mail address, so we can show which Google account is connected. We cannot change anything.
From the site you choose we retrieve clicks, impressions, CTR, average position, your main keywords and pages, countries, devices and sitemap status. We store that together with your Google e-mail address and an AES-256 encrypted access key, on servers within the EU. That key never leaves our server.
We use this data solely to display it in your own dashboard, in line with the Google API Services User Data Policy including the Limited Use requirements. We do not sell it, do not share it with third parties and do not use it for advertising or AI training.
If you disconnect, we revoke the access at Google and delete the data. If you delete your account, everything goes with it.
If we track your Google Business Profile, you connect that profile to your dashboard yourself, with your own Google login. That connection is optional too and you can end it at any time.
We retrieve your profile data (name, address, phone number, categories, opening hours and website), your reviews with the replies to them, and the figures Google provides about your profile: views, searches, phone calls and direction requests.
We keep that profile data and those reviews for 30 calendar days at most, and only to make your dashboard faster. That is what Google's policy for business profiles allows. After that we retrieve them from Google again or they disappear. Your access key is stored AES-256 encrypted on servers within the EU, for as long as the connection exists.
For business profiles Google offers only one level of access (business.manage). We use that access to read your profile and your reviews and show them in your dashboard and your report. We change nothing on your profile and publish no replies, unless you expressly instruct us to. If we do make a change at your request, we tell you within 48 hours.
If you disconnect, we revoke the access at Google and delete the retrieved profile data and reviews. If you delete your account, everything goes with it.
If you have an account, you can connect your Google Analytics property (GA4) to your dashboard. That is optional and you can disconnect at any time.
We only request read access to your measurement data (analytics.readonly) and your e-mail address, so we can show which Google account is connected. We cannot change anything.
From the property you choose we retrieve aggregated figures: sessions, users and new users, page views, engagement rate, average session duration and key events, per day, per channel and per page. We also read your property's settings (data retention, defined key events, data streams and any Google Ads link), so we can tell you whether your measurement is set up correctly. We never request data about individual visitors.
We store the daily figures together with your Google e-mail address, the selected property and an AES-256 encrypted access key, on servers within the EU. That key never leaves our server.
We use this data solely to show it to you in your own dashboard and reports: your traffic overview, the evolution over time, an alert when your traffic drops, and the weight of a finding (an error on a busy page matters more). This follows the Google API Services User Data Policy including the Limited Use requirements. We do not sell it, do not share it with third parties, and do not use it for advertising or AI training.
One limit worth knowing: Google Analytics only counts visitors who consented to analytics cookies. Every figure in this part of your dashboard therefore undercounts your real traffic, and the stricter your cookie banner, the bigger that gap.
If you disconnect, we revoke access at Google and delete the stored figures. If you delete your account, everything goes with it.
These connections fall under the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
We place necessary cookies to make the site work (your language choice, for example) and, only after your consent, analytical cookies from Google Analytics and Microsoft Clarity to measure how the site is used. You can change your choice at any time through the cookie settings at the bottom of the site. Without consent, no analytical cookies are loaded.
Both only measure our public pages. The customer console, the admin and a stored scan report stay out of it: the link to such a report contains the key that opens the report, and we do not pass that on to third parties. We do not allow Google Analytics to use advertising storage or ad personalisation, not even if you accept the marketing category.
Microsoft Clarity goes further than numbers: it records your visit, which shows us where visitors get stuck. That recording covers your mouse movements, clicks and scrolling. What you type, e-mail addresses and numbers are made unreadable on your own device before anything is sent. Clarity only runs on our public pages: nothing is recorded in the customer console or the admin. The data goes to Microsoft (see point 7).
Our forms are protected by Cloudflare Turnstile. It checks that a submission comes from a human and processes your IP address and some technical browser data to do so. It does not track you across other websites and places no advertising cookies.
We never sell your data. We do rely on carefully chosen service providers who process data on our behalf, each with the necessary safeguards:
The scans that use a real browser run on our own protected infrastructure. No external scanning provider is involved.
We also pass on data where the law requires it: your VAT number goes to the European Commission's verification service (VIES) so your invoice is drawn up correctly, and your invoice data goes to our accountant and, on request, to the tax authorities.
Some of these services (including the AI models, Resend, Cloudflare, Google and Microsoft) are based in the United States. Where data is processed outside the European Economic Area, that happens on the basis of appropriate safeguards: the EU-US Data Privacy Framework and/or the European Commission's standard contractual clauses.
You have the right of access, rectification, erasure, restriction and portability of your data at any time, and you can object to certain processing or withdraw your consent.
If you have an account you do not need to ask us: you can download all your data yourself and permanently delete your account yourself, under the privacy settings in your account. Your e-mail preferences for alerts, the weekly summary and product news are there too.
If you prefer to ask us, or if you have no account, send your request to info@flowcore.be; we respond within the statutory period. If you disagree with how we handle your data, you can lodge a complaint with the Belgian Data Protection Authority (www.dataprotectionauthority.be).
We take no decisions about you based solely on automated processing with legal or similarly significant effects. A scan score is a measurement of a website, not an assessment of a person.
Our services are aimed at businesses. We do not knowingly collect data from minors.
We take technical and organisational measures to protect your data, including encrypted connections, encrypted storage of access keys and per-user access control. Should a data breach nonetheless occur with a risk to your rights, we report it within 72 hours to the Data Protection Authority and, where required, to you.
We update this statement when our services or the regulations change. The date at the top shows the last change.