Privacy Policy
Last updated: 31 July 2026
This policy explains how Flowion AB ("Flowion", "we", "us") collects, uses, and protects personal data in connection with the Flowion platform (the "Service") — the dashboard, API, and related infrastructure we operate for organizations that manage EV charging infrastructure.
Who we are#
Flowion AB is a company registered in Sweden under organization number 559453-0155. For the purposes of the EU General Data Protection Regulation (GDPR), Flowion AB is the data controller for the personal data described in this policy, except where we act as a data processor on behalf of our customers, as explained below.
You can reach us about any privacy matter at privacy@flowion.app.
Controller vs. processor: who this policy covers#
The Service is used by organizations ("Customers") to manage their own fleets of EV chargers, and by the individual people ("Users") those organizations authorize to sign in and operate the dashboard on their behalf.
- Where we are the controller: your account and identity data as a User — the information needed to authenticate you, know which organization(s) you belong to, and operate the Service securely (see "Account and identity data" below). This policy governs that processing directly.
- Where we are a processor: operational data a Customer stores or generates through the Service about its own charging infrastructure and the drivers who use it — for example charger configuration, connectivity status, and transaction/session records tied to an RFID tag or other identifier a Customer's own charging network uses. We process this data only on the Customer's documented instructions, under a data processing agreement with that Customer. If you are an EV driver whose data was processed through the Service, your relationship is with the Customer operating that charging network, not with Flowion directly — please contact them first.
What we collect#
Account and identity data#
When you sign in to the Service, authentication is handled by our identity provider, Zitadel. We receive and store:
- Your name and email address
- A unique identifier for your account
- Which organization(s) and role(s) you're associated with
We collect this when you're invited to an organization or sign in for the first time, and use it to authenticate you, enforce access control, and let you and your organization manage who has access to what.
Data you or your organization enter into the Service#
Configuration and records your organization creates while using the dashboard or API — organization and environment settings, charger registrations, and command history — so the Service can do what it's asked to do. This is processed as described in "Controller vs. processor" above.
Technical and log data#
Standard request logs (IP address, timestamp, requested path, user agent) generated by operating the Service, kept only as long as needed for security monitoring, debugging, and abuse prevention.
What we don't currently collect#
The Service does not currently use analytics, advertising, or marketing-tracking cookies, and does not process payment information. If that changes, we'll update this policy and, where required, ask for your consent before any non-essential cookie is set.
Why we process your data (legal basis)#
- Performance of a contract — to provide the Service to you and your organization (Art. 6(1)(b) GDPR).
- Legitimate interests — to keep the Service secure, prevent abuse, and improve reliability (Art. 6(1)(f) GDPR), balanced against your rights and interests.
- Legal obligation — where we're required to retain or disclose data by applicable law (Art. 6(1)(c) GDPR).
Who we share data with#
We share personal data only where necessary to run the Service:
- Zitadel, our identity provider, to authenticate sign-ins.
- Infrastructure providers we host the Service on, currently cloud infrastructure on Amazon Web Services.
- Your own organization's administrators, who can see which Users belong to their organization as part of normal account management.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
If any of these providers process data outside the European Economic Area, we rely on appropriate safeguards recognized under GDPR (such as the European Commission's Standard Contractual Clauses) to protect it.
How long we keep it#
We keep account and identity data for as long as your account or organization is active, and for a limited period afterward where needed to resolve disputes, enforce our agreements, or comply with legal obligations. Operational data processed on a Customer's behalf is retained according to that Customer's instructions and our agreement with them. You can ask us to delete your account data at any time, subject to the exceptions above.
Your rights#
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data, subject to legal or contractual limits
- Restrict or object to certain processing
- Data portability, where technically feasible
- Withdraw consent, where processing is based on consent
To exercise any of these rights, email privacy@flowion.app. If you're not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), or the supervisory authority in your own EU/EEA member state.
Security#
We protect personal data with TLS encryption in transit, authentication through Zitadel rather than shared secrets, and access to every organization's data authorized against real membership and role checks on every request, so one organization's data isn't reachable by another. See our Security page for more detail. No system is completely secure, and we continue to invest in these protections as the Service evolves.
Children's data#
The Service is intended for business use by adults acting on behalf of an organization. We don't knowingly collect personal data from children.
Changes to this policy#
We may update this policy as the Service or applicable law changes. We'll update the "Last updated" date above when we do, and for material changes we'll take reasonable steps to let affected Users know.
Contact us#
Flowion AB · Org. no. 559453-0155 · Sweden
Email: privacy@flowion.app