Legal
Privacy policy
How FlowSentinel collects, uses and protects personal data. This policy was last updated on 9 September 2026.
1. Introduction
1.1 We are committed to safeguarding the privacy of everyone who visits our marketing site, uses the FlowSentinel console or connects a HubSpot portal to the Application. This policy explains how we handle personal data.
1.2 FlowSentinel is a security governance integration for HubSpot. It reads user, team, permission and object metadata from connected HubSpot portals so that administrators can monitor access, detect drift and manage provisioning. We do not use that data for any purpose other than providing and improving the Application.
1.3 By using the Application and agreeing to this policy, you consent to our use of cookies in accordance with the terms of this policy.
2. Data we process
2.1 We may process the following categories of personal data:
- Account data
- Your name and email address, collected when you sign in or are invited to an organisation. This is used to operate the console, maintain security and communicate with you.
- Usage data
- Your IP address, browser type and version, operating system, referral source, length of visit, page views and navigation paths. This is collected through analytics and error tracking to monitor and improve the Application.
- HubSpot metadata
- Names, email addresses, roles, team memberships, permission sets and object ownership information retrieved from connected HubSpot portals. This is Customer Data that we process only on behalf of the organisation that connected the portal.
- Correspondence data
- Information contained in support requests or other communications you send us, including message content and metadata.
2.2 The legal basis for processing account, usage and correspondence data is our legitimate interest in administering the Application and our business. The legal basis for processing HubSpot metadata is the performance of our contract with the Customer.
3. HubSpot data and Customer responsibility
3.1 When a Customer connects a HubSpot portal, the Application retrieves metadata needed to provide the Services. This includes user profiles, team assignments, permission settings, property definitions and object ownership. It does not include the free-text contents of emails, notes or call transcripts unless those are required for a specific feature and explicitly requested by the Customer.
3.2 The Customer is the Controller of personal data held in its HubSpot portals. We act as a Processor in respect of that data. The Customer must ensure it has a lawful basis for us to access and process the data on its behalf.
3.3 HubSpot OAuth tokens are stored in encrypted form and are never exposed to end users of the Application.
4. Automated decision-making
4.1 We do not make automated decisions that produce legal or similarly significant effects about individuals.
4.2 The Application uses rules and thresholds to flag security and hygiene findings (for example, a user who is a member of multiple teams, or a permission that has drifted from a baseline). These are advisory alerts for administrators. Any action taken in response remains a human decision made by the Customer.
6. International transfers of your personal data
6.1 The Application is hosted in the United Kingdom, the European Union and the United States through our cloud infrastructure providers. The European Commission has made adequacy decisions with respect to the data protection laws of the United Kingdom and the United States.
6.2 Where personal data is transferred outside the European Economic Area and no adequacy decision applies, we use appropriate safeguards, such as standard data protection clauses adopted or approved by the European Commission.
7. Retaining and deleting personal data
7.1 Personal data is kept only for as long as necessary for the purpose for which it was processed.
7.2 Account and usage data is retained for two years following your last interaction with the Application, after which it is deleted or anonymised.
7.3 HubSpot metadata retrieved from connected portals is retained while the portal remains connected and the Customer maintains an active subscription. When a portal is disconnected or a subscription ends, we delete the associated Customer Data within 90 days, except where we are required by law to retain it.
7.4 Audit logs and security records may be retained for longer where necessary to comply with legal obligations, defend legal claims or maintain the integrity of the Application.
8. Security
8.1 We implement appropriate technical and organisational measures to protect personal data, including encryption of credentials at rest, role-based access controls, row-level security in the database and regular review of access permissions.
8.2 On becoming aware of a personal data breach affecting Customer Data, we will notify the Customer without undue delay and co-operate with the Customer to address the breach.
9. Your rights
9.1 You have the following rights under data protection law in relation to personal data we hold about you:
- the right to access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to object to processing;
- the right to data portability;
- the right to complain to a supervisory authority; and
- the right to withdraw consent.
9.2 If you wish to exercise any of these rights, please contact us using the details below. We may need to verify your identity before fulfilling your request.
9.3 If you consider that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with the Information Commissioner's Office or the supervisory authority in your country of residence, place of work or place of the alleged infringement.
10. Third-party websites
The Application includes links to, and integrates with, HubSpot and other third-party websites. We have no control over, and are not responsible for, the privacy policies and practices of third parties. Your use of HubSpot is governed by HubSpot's own privacy policy and terms of service.
11. Personal data of children
11.1 The Application is intended for use by organisations and persons over the age of 18.
11.2 If we have reason to believe that we hold personal data of a person under that age in our databases, we will delete that personal data.
13. Updating information
Please let us know if the personal information that we hold about you needs to be corrected or updated. You can update some account details from within the Application, or contact us using the details below.
14. Acting as a data processor
14.1 In respect of HubSpot metadata retrieved on behalf of a Customer, we act as a data processor. Our legal obligations as a processor are set out in our terms of service and any data processing addendum agreed with the Customer.
14.2 This privacy policy applies to personal data for which we act as controller (such as marketing site visitors and registered console users). It does not override the processing instructions we receive from Customers in their capacity as controllers.
15. Our details
15.1 This Application is owned and operated by Six & Flow Ltd, a company registered in England and Wales under number 09465254, whose registered office is at Second Floor, Barton Arcade, Deansgate, Manchester, M3 2BH.
15.2 You can contact us:
- by post, using the address above;
- using the support page; or
- by email, using privacy@sixandflow.com.
15.3 We are registered as a data controller with the UK Information Commissioner's Office. Our registration number is ZA179703.
15.4 Our data protection officer can be contacted at privacy@sixandflow.com.