Legal

Privacy Policy

Last updated 21 August 2026

This Privacy Policy explains how Flow Room Music (“we”, “us”, “our”) collects, uses, discloses and stores personal data when you visit flowroommusic.com, create an account, start a trial or subscribe. It forms part of our contractual relationship with you, together with the Terms of Use.

01Data controller

The controller responsible for processing personal data under the EU General Data Protection Regulation (GDPR) is:

Flow Room Music
Nicosia, Republic of Cyprus
Operated by Constantinos Tsiolis (sole trader).

02Scope of this policy

This policy applies to personal data processed in connection with:

  • use of the public website and membership pages;
  • registration, authentication and account administration;
  • trial, subscription, billing and licence administration;
  • customer support communications.

Personal data means any information relating to an identified or identifiable natural person. Transmission of data over the internet is never completely secure; you transmit information at your own risk, without prejudice to our duty to implement appropriate security measures.

03Categories of personal data

Depending on how you interact with the service, we may process:

  • Identity and contact data — name, email address;
  • Account credentials — password (stored in hashed form; we cannot read it in clear text);
  • Subscription and billing status — membership state, renewal dates, invoice metadata. Payment card details are collected and processed by Stripe and are not stored on Flow Room Music servers;
  • Content you choose to upload — for example a photograph of your space, displayed only within your account;
  • Service preferences stored on your device — playlists, filters and downloads held in browser local storage where applicable;
  • Technical and log data — IP address, browser type and version, operating system, pages requested, date/time of access and similar server logs generated automatically by the hosting infrastructure.

We do not intentionally collect special-category data (including health data) and we do not request information about your clients. Please do not send us third-party client data.

04Purposes and legal bases (GDPR Art. 6)

PurposeExamplesLegal basis
Contract performance Creating and securing your account; providing library access; issuing licence documentation in your name; sending transactional notices (receipts, renewals, security alerts). Art. 6(1)(b) — performance of a contract
Payments and tax records Subscription status; invoices and accounting records via Stripe. Art. 6(1)(b) and Art. 6(1)(c) — legal obligation where tax law requires retention
Optional account content Studio photo upload displayed back to you. Art. 6(1)(a) — consent (withdrawable by deleting the content)
Security and service integrity Fraud prevention, abuse detection, diagnosing faults, maintaining availability. Art. 6(1)(f) — legitimate interests in a secure, reliable service
Legal claims and compliance Responding to lawful requests; establishing or defending legal claims. Art. 6(1)(c) and/or Art. 6(1)(f)
Advertising measurement Meta Pixel events (page view, start checkout, start trial) so we can see whether ads work. Loaded only after you tap Accept on the cookie bar. Art. 6(1)(a) — consent, withdrawable at any time via the Cookies control

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object as described in section 9.

05Cookies and local storage

If you tap Accept on the cookie bar, we load the Meta Pixel (Meta Platforms Ireland Limited) to measure advertising and to see whether a visit starts a free trial. That is optional. If you tap Reject, the Pixel is not loaded and the site, library and checkout still work. You can change this later with the Cookies control on the page.

Essential technology may include:

  • Browser local storage used by the member library to keep a session and remember playlists, filters and downloads on your device. This data remains on your device unless and until you clear it;
  • Your cookie choice stored locally (frm-ads-consent) so we do not ask again every visit;
  • Meta Pixel cookies (for example _fbp / _fbc) only after Accept — used by Meta to attribute ads, governed by Meta’s Privacy Policy;
  • Stripe cookies set during checkout for payment security and fraud prevention, governed by Stripe’s Privacy Policy;
  • Language preference stored locally so the site can remember your selected language.

You may configure your browser to block or delete cookies and stored data. Doing so may limit account or checkout functionality.

06Processors and disclosures

We do not sell or rent personal data. We share advertising measurement data with Meta only if you accept the cookie bar. Otherwise we disclose personal data only to service providers acting as processors (or independent controllers where the law so provides), under appropriate agreements, and only as needed to operate the service:

  • Stripe Payments Europe, Limited (and affiliates) — payment processing, invoicing, subscription management and, when enabled, tax calculation;
  • Google Firebase — authentication of member accounts;
  • Cloudflare, Inc. — website hosting, content delivery, security, and related workers that record membership status after payment confirmation;
  • Email service provider — delivery of transactional messages;
  • Meta Platforms Ireland Limited — Meta Pixel events if you Accept, so we can measure ads. Meta’s processing is described in Meta’s Privacy Policy.

We may also disclose data where required by applicable law, to protect our rights or users, or in connection with a reorganisation or transfer of the business, subject to appropriate safeguards.

07International transfers

Some providers operate infrastructure outside the European Economic Area (including the United States). Where personal data is transferred internationally, we rely on an adequacy decision where available, or on the European Commission’s Standard Contractual Clauses (or an equivalent approved transfer mechanism), together with any supplementary measures required.

08Retention

  • Account data — for the duration of the membership and up to 12 months thereafter (or sooner upon a valid deletion request, unless a longer period is required);
  • Invoices and payment records — for the period required by Cypriot tax and accounting law (currently typically six years);
  • Uploaded space photo — until you delete it or the account is closed;
  • Technical logs — for a short rolling period determined by the hosting provider (typically under 30 days), unless needed longer for security investigations.

09Your rights

Subject to the GDPR and applicable law, you may request:

  • access to your personal data;
  • rectification of inaccurate data;
  • erasure (“right to be forgotten”), where applicable;
  • restriction of processing;
  • objection to processing based on legitimate interests;
  • data portability, where applicable;
  • withdrawal of consent, without affecting the lawfulness of processing before withdrawal.

Requests may be sent to info@flowroommusic.com. We will respond within one month, subject to lawful extensions for complex requests. There is no fee unless a request is manifestly unfounded or excessive.

10Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction, including encrypted transport (HTTPS) and hashed password storage. No method of transmission or storage is completely secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and the competent supervisory authority as required by law.

11Children

The service is intended for professionals aged 18 or over. We do not knowingly collect personal data from children. If you believe we have received data from a minor, contact us and we will delete it where required.

12Changes to this policy

We may update this Privacy Policy to reflect changes in the service or in legal requirements. The “Last updated” date will be revised accordingly. Where a change is material, we will notify active members by email where reasonably practicable. Continued use of the service after the effective date constitutes acceptance of the updated policy, except where consent is required by law.

13Contact and complaints

For privacy requests or questions: info@flowroommusic.com.

You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy) or with your local supervisory authority in the EU/EEA. We would appreciate the opportunity to address your concern first.