Last updated: September 9, 2026
Privacy Policy
This Privacy Policy explains how Parallax One (SASU, France), the operator of Flotr, processes personal data when you visit our website, create an account, or use our services. We process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable French data protection law.
Data controller
The data controller is Parallax One, a SASU registered in France, operating the Flotr service at https://flotr.app.
For privacy-related requests, contact us at hello@flotr.app. For general inquiries, use hello@flotr.app.
Personal data we collect
Depending on how you use Flotr, we may process the following categories of data:
- Account data: name, email address, profile information, and authentication identifiers.
- Workspace data: organization name, team membership, roles, permissions, and workspace settings you configure.
- Operational data: operations, checklists, comments, files, approvals, and other content you or your organization submit to the service.
- Usage and technical data: IP address, browser type, device information, log data, and product usage events needed to operate and secure the service.
- Billing data: subscription status and billing contact details. Payment card details are processed by our payment provider and are not stored by us.
- Support and communications: messages you send to us, feedback, and records of support interactions.
How we use personal data
We use personal data for the following purposes:
- Providing, maintaining, and improving the Flotr service.
- Creating and managing user accounts and workspace memberships.
- Authenticating users and securing access to the platform.
- Processing subscriptions and managing customer relationships.
- Responding to support requests and communicating about the service.
- Monitoring performance, preventing abuse, and protecting the security of our systems.
- Complying with legal obligations and enforcing our Terms of Service.
Legal bases for processing
Where GDPR applies, we rely on one or more of the following legal bases: performance of a contract (providing the service you requested), legitimate interests (securing and improving the service, preventing fraud, and supporting customers, balanced against your rights), consent (where required, such as optional marketing communications), and legal obligation (where applicable).
Sharing and subprocessors
We do not sell personal data. We share data only with service providers that help us operate Flotr, such as hosting, database, authentication, email delivery, payment processing, and infrastructure providers. These providers act as processors or independent controllers under contractual safeguards appropriate to their role.
We may also disclose data when required by law, to protect our rights or the safety of users, or in connection with a merger, acquisition, or asset sale, subject to appropriate protections.
International transfers
We aim to host and process customer data within the European Economic Area where feasible. If personal data is transferred outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms required by GDPR.
Retention
We retain personal data for as long as needed to provide the service, fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce agreements. Workspace content is retained according to your organization's use of the service and applicable contractual terms.
Your rights
If GDPR applies to you, you may have the right to access, rectify, erase, restrict, or object to certain processing of your personal data, and to data portability where applicable. When processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
You may lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority. To exercise your rights, contact hello@flotr.app. We may need to verify your identity before responding.
Security
We implement technical and organizational measures designed to protect personal data, including access controls, encryption in transit, workspace-scoped data access, and operational logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children
Flotr is a business service not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated through the service or by email where appropriate.