Privacy Policy

Welcome to Bestflow!

We care deeply about keeping your information safe and sound. We want you to feel confident knowing that when you visit our website, use our services, or interact with our team, we handle your data responsibly, transparently, and in strict compliance with applicable laws—including the EU General Data Protection Regulation (EU GDPR), the UK GDPR, and the UK Privacy and Electronic Communications Regulations (PECR).

We will never sell, rent, or trade your personal information with third parties. This policy explains what information we collect, how we collect and secure it, our legal grounds for processing it, and your rights regarding your data.

1. Legal Grounds for Processing Personal Data

We process personal data only when we have a valid legal basis under Article 6 of the GDPR and UK GDPR:

  • Legitimate Interest (Art. 6(1)(f)): We process limited business contact information for Business-to-Business (B2B) communications and direct outreach targeting business professionals who may benefit from our Google Workspace development and productivity automation services. We perform Legitimate Interest Assessments (LIAs) to ensure our commercial interests do not override your privacy rights.
  • Consent (Art. 6(1)(a)): When you voluntarily submit information to us through a contact form, leave a comment, or explicitly opt-in to communications.
  • Contractual Necessity (Art. 6(1)(b)): When processing is required to deliver requested services, manage accounts, or execute agreements with our clients and partners.

2. Information We Collect and How We Collect It

A. Information You Provide directly to Us

We collect information that you actively share with us when you:

  • Fill out a contact or inquiry form on our website.
  • Book or schedule a consultation via our discovery call scheduling webapp.
  • Leave a comment on our posts or articles.
  • Become a Bestflow client or partner.

This information typically includes your name, business email address, company name, phone number, and any details included in your inquiry.

B. B2B Prospecting and Direct Outreach Data

To introduce our Google Workspace automation solutions to relevant organizations, we process limited professional contact data.

  • Source of B2B Data: If we did not receive your contact details directly from you, your business contact information was sourced from publicly available online business channels (such as public domain records, company websites, or professional networks like LinkedIn) combined with algorithmically inferred and technically validated data using standard domain metrics and proprietary verification methods.
  • Categories of Data Processed: Full name, professional job title/role, company name, business domain, business email address, and indicators of company technology usage (such as Google Workspace adoption).

3. How We Use Your Information

We use your data solely for clear, legitimate business purposes:

  • Responding to your inquiries, support requests, and messages.
  • Organize, prepare for, and conduct discovery calls and technical consultations you request.
  • Delivering our development, integration, and automation services to clients.
  • Conducting targeted, relevant B2B direct communications to introduce our services to business decision-makers.
  • Fulfilling client contracts, accounting obligations, and system administration requirements.

We do not use automated decision-making or profiling tools that produce legal effects for you, nor do we add cold outreach leads to public marketing newsletters or third-party mailing lists.

4. Direct Marketing & Your Right to Opt-Out

If you receive a direct B2B message from us regarding Google Workspace automation services, you have an absolute right to object and opt-out at any time.

  • Easy Opt-Out: You can opt-out instantly by replying with “STOP” to any email you receive from us, by clicking an unsubscribe link where provided, or by contacting us directly.
  • Prompt Processing: Upon receiving an opt-out request, your email address is permanently added to an internal suppression list to ensure you are never contacted again.

5. Cookies and Web Tracking

Cookies are small text files placed on your computer or mobile device when you visit a website.

At Bestflow, we only use essential cookies that are strictly necessary for our website to function properly.

  • We do not use third-party advertising, remarketing, or behavioral tracking cookies.
  • Browsing our site without logging in generally does not set any non-essential cookies.
  • Because essential cookies are mandatory for site navigation and security, they cannot be individually disabled through our site, though you can manage cookie settings in your browser.

6. Embedded Content from Other Websites

Articles or posts on our site may occasionally include embedded content (e.g., videos, images, or articles from platforms like YouTube). Embedded content from other websites behaves in the exact same way as if you visited the other website directly.

These third-party websites may collect data about you, use their own cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, especially if you have an account and are logged in to that external website.

7. Data Hosting, Infrastructure, and Security

We take the security of your business and personal information extremely seriously.

Secure Cloud Infrastructure

  • Google Cloud SQL: Our operational databases containing B2B contact and service data are hosted on secure Google Cloud SQL servers located within the European Economic Area (EEA, region: europe-west4, Frankfurt).
  • Google Workspace Environment: Our daily communication and client management operations are executed within the highly protected Google Workspace infrastructure, benefiting from enterprise-grade security protocols, digital signatures, and SSL/TLS encryption for all data in transit.

Access Control & Credentials Security

  • In-House Processing: All lead processing, data validation, and communications are conducted strictly in-house. We do not sell, share, or lease personal data to external lead aggregators or marketing agencies.
  • Subcontractor Protocols: If sharing contact information with a subcontractor is necessary to fulfill a specific client service, we always seek explicit permission first.
  • Password Managers: When accessing client or partner systems, we strictly utilize secure password manager tools to access accounts without storing or exposing plaintext passwords.

8. Data Processors and Service Providers

To operate our business, we rely on trusted infrastructure providers acting as Data Processors bound by GDPR-compliant agreements:

Service ProviderRole / PurposeLocation & Safeguards
Google Cloud (Google Ireland Ltd.)Database Hosting (Google Cloud SQL)Hosted within the EEA (europe-west4). Full GDPR compliance.
Google Workspace (Google Ireland Ltd.)Business Email & Document ManagementHosted within the EEA / Adequacy decisions / Standard Contractual Clauses (SCCs).

9. Data Retention

  • Outreach Data: Business contact data collected for outreach is retained for up to 12 months from the initial verification or last interaction. If no engagement occurs within this window, the lead record is removed.
  • Suppression Data: If you opt out of communications, a minimal record of your email address is maintained indefinitely on our suppression list solely to prevent future outreach.
  • Client Data: Client records and transaction history are retained for the duration of our business relationship plus statutory accounting and tax compliance periods.

10. Your Data Protection Rights

Under EU GDPR and UK GDPR, you hold full control over your personal information and can exercise the following rights:

  1. Right of Access (Art. 15): Request a copy of the personal data we hold about you and details regarding its source.
  2. Right to Rectification (Art. 16): Request correction of any inaccurate or incomplete data.
  3. Right to Erasure (Art. 17): Request the deletion of your personal data (“Right to be Forgotten”).
  4. Right to Object (Art. 21): Object at any time to direct marketing or processing based on Legitimate Interest.
  5. Right to Restrict Processing (Art. 18): Request that we temporarily suspend processing your data.
  6. Right to Data Portability (Art. 20): Request your data in a structured, commonly used, and machine-readable format.

To exercise any of these rights, please contact us by submitting a request through our contact form. We will fulfill legitimate requests within 30 days without fee.

You also have the right to lodge a complaint with a supervisory authority, such as the Information Commissioner’s Office (ICO) in the UK or the National Authority for Data Protection and Freedom of Information (NAIH) in Hungary.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect operational, legal, or regulatory updates. When changes occur, we will update the “Last Updated” date at the bottom of this document. For major revisions affecting your privacy rights, we will provide noticeable notice on our site or reach out via email.

12. How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please reach out to us:

  • Contact Form: https://bestflow.io/contact/

Last updated: August 10, 2026