They operate in the EU
All data is stored and processed in European data centres.
We take the same approach with digital colleagues. During onboarding, we gradually increase their autonomy under the supervision of your team and ours.
All data is stored and processed in European data centres.
Your data is not used to train AI models. We put that in the contract.
Every organisation receives a technically isolated environment and its own knowledge layer.
Access is role- and task-based: no more than the agreed process requires.
Actions and exceptions are recorded, so you can always see what happened.
If you stop using Flowstead, you take all the data and knowledge your organisation has built with you.
Your private environment on European cloud infrastructure.
Dedicated hardware running everything, including the AI models.
From 2 August 2026.
From 15 August 2026.
Within the EU, encrypted in transit and at rest. We document the chosen region and infrastructure before starting, both technically and contractually.
No. Not by Flowstead and, through our agreements with suppliers, not by model providers either. This is included in our data processing agreements.
That depends on the process, required quality and chosen deployment. We document the specific models and endpoints for each environment. In Flowstead Dedicated, models run on dedicated hardware without a public model API.
We connect with common ERP, email and accounting systems such as AFAS, Exact Online, SAP and Microsoft 365. Before starting, we determine exactly which secure connections your process needs.
Only authorised Flowstead engineers have access for management and support. Access is role-based, limited and logged.
Yes. It sets out roles, security arrangements, sub-processors, retention periods and how incidents are handled.
We return all data created during the engagement in a standard format. We then delete the environment according to the agreed procedure and confirm its removal.
The Dutch Cybersecurity Act comes into force on 15 August 2026 and implements NIS2. You must determine whether the law applies to your organisation. Flowstead supports supplier assessments with EU data location, limited access, logging and documented processing agreements.
The application determines the risk category and obligations. We assess this per process, build in human oversight and logging, and provide the required transparency. Flowstead does not build digital colleagues for recruiting, selecting or assessing employees.
To deliver our service we work with a small number of parties that process personal data in doing so. We have a data processing agreement with each of them. We keep this list current.
| Party | For what | Established in | Storage |
|---|---|---|---|
| Google Cloud | Infrastructure the Flowstead platform and the digital colleagues run on | United States | Western Europe |
| Vercel | Hosting of flowstead.ai and the website server logs | United States | European Union |
| Formspree | Handling of messages sent through the forms on our website | United States | United States |
| Google Workspace | Email, calendar, documents and booking introductions | United States | European Union |
For parties outside the European Union we have concluded the European Commission's standard contractual clauses. Which language model we use per digital colleague and where it runs is set out per customer in the data processing agreement.
Privacy policy
What we process about visitors, prospects and applicants, and why.
Read the policyResponsible disclosure
How to report a vulnerability to us and what you can expect from us.
Read the policyData processing agreement
The terms covering the data we process for you as a processor. Available on request.
Request the documentWe are happy to discuss your technical and contractual questions.
Found a vulnerability in our systems? Read our responsible disclosure policy