Privacy Policy
Last updated: April 2026
Flowmatic ("we", "us", "our") is a sole trader business registered in Dublin, Ireland. We are committed to protecting the privacy of individuals who interact with our services and the services we provide on behalf of our clients.
This privacy policy explains what personal data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1. What data we collect
When you interact with a chat widget powered by Flowmatic on a client's website, we may collect the following information:
- Your name (if you provide it during the conversation)
- Your phone number (if you provide it during the conversation)
- The content of your chat conversation, including any details about services you enquire about
- The date and time of your enquiry
- The source of your enquiry (e.g. website)
We do not collect data automatically such as IP addresses, cookies, or device information through the chat widget. We do not use tracking cookies on flowmatic.ie.
2. How we use your data
We process your personal data for the following purposes:
- To respond to your enquiry in real time via the AI-powered chat widget
- To extract a summary of your enquiry and pass it to the relevant dental clinic so they can follow up with you
- To notify the clinic owner about your enquiry via email
- To log your enquiry in the clinic's lead management dashboard
3. Lawful basis for processing
We process your data under the following lawful bases as defined by Article 6 of the GDPR:
- Legitimate interest (Article 6(1)(f)) — The dental clinic has a legitimate interest in responding to patient enquiries and managing leads. We process data on their behalf to fulfil this interest.
- Consent (Article 6(1)(a)) — By using the chat widget and submitting your information, you consent to your data being processed as described in this policy. You may withdraw consent at any time by contacting us.
4. Who we share your data with
Your data may be shared with the following parties, solely for the purposes described above:
- The dental clinic whose website you used to make your enquiry — they receive your name, phone number, service interest, and a summary of your conversation
- OpenAI — your conversation is processed by OpenAI's API (gpt-4o-mini) to generate responses and extract lead details. OpenAI's data usage policy applies to this processing. OpenAI does not use API data to train its models.
- Google (Google Sheets, Google Workspace) — lead data is stored in Google Sheets and email notifications are sent via Google Workspace
- Make.com — used to automate the transfer of lead data from the chat widget to Google Sheets and email
- Netlify — hosts the website and serverless functions that process chat data
We do not sell your personal data to any third party. We do not share your data with any party not listed above.
5. Where your data is stored
Your data may be processed and stored on servers located in the European Economic Area (EEA), the United States, or other jurisdictions where our service providers operate. Where data is transferred outside the EEA, we rely on the service providers' compliance with appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. How long we keep your data
Lead data is retained for as long as the dental clinic requires it to manage their patient enquiries. Typically, this is no longer than 12 months from the date of the enquiry, unless the clinic has an ongoing relationship with you as a patient. You may request deletion of your data at any time.
7. Your rights under GDPR
Under the GDPR, you have the following rights in relation to your personal data:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate data.
- Right to erasure — You can ask us to delete your data ("right to be forgotten").
- Right to restrict processing — You can ask us to limit how we use your data.
- Right to data portability — You can request your data in a structured, commonly used format.
- Right to object — You can object to the processing of your data based on legitimate interest.
- Right to withdraw consent — Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at hello@flowmatic.ie.
8. Data controller and data processor
When Flowmatic provides services to a dental clinic, the dental clinic is the data controller (they determine why and how patient data is processed) and Flowmatic is the data processor (we process data on their behalf according to their instructions).
For data collected through flowmatic.ie directly (e.g. the demo chat widget), Flowmatic is the data controller.
9. AI-powered chat
The chat widget on this website and on our clients' websites is powered by artificial intelligence (OpenAI gpt-4o-mini). The AI acts as a virtual receptionist and does not provide medical advice, diagnoses, or treatment recommendations. All responses are for informational and scheduling purposes only. A human member of the dental clinic team may follow up with you after your enquiry.
10. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- API keys stored as server-side environment variables (never exposed to browsers)
- Webhook authentication tokens to prevent unauthorised data submissions
- HTTPS encryption on all data in transit
- Rate limiting and anti-spam protections on the chat widget
- Security headers (Content Security Policy, HSTS, X-Frame-Options)
- Password-protected access to client dashboards
11. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Data Protection Commission (DPC), Ireland's supervisory authority:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28
Website: www.dataprotection.ie
Phone: +353 1 765 0100 / +353 57 868 4800
12. Changes to this policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.
13. Contact
If you have any questions about this privacy policy or how we handle your data, contact us at:
Flowmatic
Dublin, Ireland
Email: hello@flowmatic.ie