Skip to main content

πŸ” Data Privacy and AI at flowit: Overview & Key Features

Updated over 5 months ago

At flowit, protecting your data and using Artificial Intelligence responsibly are top priorities. Here's an overview of our key features, when to use them, and why they matter. πŸš€


πŸ”’ Data Protection Policies

We strictly comply with the General Data Protection Regulation (GDPR) and adhere to even stricter European standards.

To ensure system security:

  • Regular penetration tests are conducted by external security experts.
    ​
    ​

  • Our last tests showed excellent results, validating our high security standards.
    ​


πŸ” Data Transmission and Storage

  • All data transfers are encrypted using ssL/TLS.
    ​
    ​

  • Data is stored on ISO-certified servers in Germany (Hetzner Cloud).
    ​
    ​

πŸ—‚οΈ Data Retention

  • We retain data for 5 years as legally required.
    ​
    ​

  • Deletions are logged for accountability.
    ​


πŸ›‘οΈ Security Features

  • GDPR-compliant architecture.
    ​
    ​

  • Role-based access control for data access.
    ​
    ​

  • Optional Single Sign-On (ssO) and Multi-Factor Authentication (MFA).
    ​
    ​

  • AI analysis is performed only on anonymized data.
    ​
    ​

  • Annual penetration tests with external providers ensure system safety.
    ​
    ​

πŸ‘ Why it matters: These features help you control who accesses your data while offering strong protective layers.


πŸ“ƒ ISO Certification

We are currently in the certification process and aim to achieve ISO 27001 and ISO 42001 certifications.


☁️ Hosting Partners

  • flowit: Data stored in ISO-certified German data centers (Hetzner Cloud).
    ​
    ​

  • monday.com: Hosted on Amazon Web Services (AWS) and Google Cloud Platform, both with industry-leading physical security measures.
    ​


πŸ€– AI Use in flowit

Our AI approach is human-centered and ethical.

  • AI supports users by analyzing data, making suggestions, and stimulating active thinking β€” but never makes autonomous decisions.
    ​
    ​

  • Analyses are based exclusively on anonymized data.
    ​
    ​

  • Texts are clustered into themes to preserve anonymity.
    ​
    ​

  • In teams smaller than 6, no individual statements are shown; instead, aggregation happens at a higher team level.
    ​
    ​

✨ Why it's useful: It promotes deeper thinking while preserving confidentiality.


πŸ” Who Has Access to Data?

Access is limited and always purpose-driven:

  • Project team: For collaboration and project success.
    ​
    ​

  • Customer Success Team: To ensure smooth processes, even during staff absences.
    ​
    ​

  • Product Team: For debugging, technical evaluations, and product development.
    ​

All access is strictly governed by our privacy policies.


🧠 Which AI Systems Are Used?

flowit uses custom-developed systems enhanced by psychological prompt engineering.

  • Models include OpenAI and other AI solutions.
    ​
    ​

  • Selection is based on:
    ​
    ​

    • Cost
      ​
      ​

    • Speed
      ​
      ​

    • Performance in flowit-specific metrics
      ​


πŸ” What Data is Processed?

  • Only anonymized text data and scale responses from surveys and reviews are used.
    ​
    ​

  • No additional personal information (e.g., role, age) is transmitted.
    ​
    ​

  • Data is not used for AI training.
    ​
    ​

  • Inputs are deleted after processing.
    ​
    ​

πŸ“Œ Good to know: Users can opt out of using AI features entirely (though single responses can’t currently be excluded).


❌ Data Training & Retention in AI Systems

  • Input from reviews and surveys is not used to train AI systems.
    ​
    ​

  • AI systems do not retain inputs; once processing is complete, all inputs are deleted.
    ​


πŸ§ͺ Quality Control & Bias Prevention

To ensure fair and accurate results, flowit employs several measures:

  • Input is sample-checked for quality and anonymity before processing.
    ​
    ​

  • Output is reviewed for relevance, accuracy, and potential bias.
    ​
    ​

  • Multi-layered, psychology-based prompts minimize distortions.
    ​
    ​

  • Systematic human quality checks validate results.
    ​
    ​

🎯 Why it matters: You get reliable, ethical, and well-calibrated insights β€” always.


πŸ”„ Updates & Maintenance

Maintenance

  • Maintenance work is performed outside of business hours.
    ​
    ​

  • It usually has no relevance for customers and typically goes unnoticed.
    ​
    ​

Updates

  • Major platform updates or new features are announced via newsletter or Messenger.
    ​
    ​

  • Smaller changes are summarized and presented once a month in the newsletter.

Did this answer your question?