Legal
Privacy Policy
How Floxa Ltd collects, uses and protects personal data when you use Floxa or visit our website, and how to exercise your rights.
Last updated: 2 September 2026
This policy explains how Floxa Ltd ("Floxa", "we", "us") collects, uses and protects personal data when you visit floxa.co.uk or use the Floxa service. Floxa is registered in England and Wales under company number 16971343, with its registered office at Office 439, Unit 5, 399-405 Oxford Street, Mayfair, London, England, W1C 2BU. For the purposes of UK data protection law, Floxa is the controller of the personal data described in this policy.
Contact us about anything in this policy at support@floxa.co.uk.
1. Two kinds of data — our role differs
Floxa is a business management service. It holds two distinct kinds of personal data, and our legal role is different for each:
- Your account and billing data — data about you as a Floxa user (registration details, subscription records, and so on). For this data Floxa is the controller, and this policy describes how we handle it.
- Customer Data — the records your business stores in Floxa about its own staff, clients, suppliers and jobs. For this data your business is the controller and Floxa is a processor, acting on your instructions under our Data Processing Agreement. If you are a member of staff or a client of a business that uses Floxa and you have questions about data held about you, please contact that business — we will redirect any request we receive to them.
2. The personal data we collect
- Account data — your name, email address, password (stored as a secure hash, never in plain text) and optional profile photo. If you sign in with Google, we receive your name, email address and profile photo from your Google account instead of a password.
- Organisation data — the business details you give us when setting up your organisation, such as its name, logo and settings.
- Billing data — your subscription plan, billing history and payment status. Payments are processed by Stripe; we never see or store your full card number.
- Usage and security data — sign-in events, session records and technical logs (such as IP addresses and browser type) generated when you use the service, used to keep accounts secure and the service running.
- Correspondence — messages you send us, for example support requests.
3. How we use it, and our lawful bases
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Providing the Floxa service — creating and operating your account and organisation | Performance of a contract |
| Billing and subscription management, including collecting payment through Stripe | Performance of a contract; legal obligation (tax and accounting records) |
| Service emails — invoices you send, timesheets, password resets, sign-in links, invitations, a welcome email when you finish setting up, and important service notices | Performance of a contract |
| Keeping the service secure — authentication, session management, fraud and abuse prevention, security logging | Legitimate interests (protecting the service and its users) |
| Improving the service — diagnosing faults and understanding how features perform | Legitimate interests (running and improving our business) |
| Complying with law and responding to lawful requests | Legal obligation |
Product emails. We may occasionally email you about new Floxa features, tips and free resources, and short feedback polls. If you subscribed on our website we rely on your consent, confirmed by clicking the link we email you. If you are a customer we rely on the "soft opt-in" under PECR: we told you about these emails when you set up your account and gave you the chance to refuse. Either way, every message includes a working unsubscribe link, you can change what you receive under Settings → Notifications, and we keep a record of when and how you subscribed or opted out. Service emails about your account are not affected by these choices.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we never sell personal data.
4. Cookies
Floxa sets strictly necessary cookies — the session and security cookies our authentication system needs to keep you signed in and protect your account, and a cookie that remembers your cookie preference itself. Because these are essential to provide the service you have asked for, UK law (PECR) does not require consent for them.
We may also use analytics cookies to understand how visitors use Floxa, but only with your permission. On your first visit you will be asked to accept, reject, or choose which optional cookies to allow. You can change your mind at any time using the "Cookie preferences" link in the footer, which reopens the same choices. Analytics cookies are not set until you allow them.
We do not use advertising or tracking cookies, and the emails we send contain no tracking pixels or rewritten tracking links.
5. Who we share personal data with
- Service providers (sub-processors) — the companies that host and power Floxa, listed with locations and purposes at floxa.co.uk/legal/subprocessors. Each is bound by a written data protection agreement.
- Stripe — for payments, acting as an independent controller for payment processing, fraud prevention and its own regulatory compliance.
- Google — if you choose to sign in with Google, acting as an independent controller for your Google account.
- Professional advisers and authorities — where necessary for legal, accounting or insurance purposes, or where the law requires disclosure.
- A buyer or successor — if Floxa is involved in a merger, acquisition or asset sale, in which case we will notify you before your personal data becomes subject to a different privacy policy.
6. Where data is stored and international transfers
Floxa's data is stored in the United Kingdom and the European Union — our database runs in London, uploaded files are held under EU jurisdiction, and email is sent from the EU. Where a service provider processes personal data outside the UK or EEA (for example in the United States), the transfer is protected by a lawful transfer mechanism — the UK Extension to the EU–US Data Privacy Framework and/or Standard Contractual Clauses with the UK International Data Transfer Addendum — as described on our sub-processor page.
7. How we protect it
All connections to Floxa are encrypted in transit with TLS, and data is encrypted at rest. Particularly sensitive fields (such as saved bank details) are additionally encrypted at the application layer with AES-256-GCM, with the key held separately from the database. Every organisation's data is isolated by enforced database row-level security in addition to application-level checks, uploaded files are served only through authenticated, organisation-scoped access — never public links — and our isolation and encryption controls are verified by an automated security test suite. The full set of measures is described in Annex 2 of our Data Processing Agreement.
8. How long we keep it
- Account and organisation data — for as long as your account is active, then deleted from our production systems within 90 days of closure.
- Billing and transaction records — kept for six years after the end of the relevant financial year, as UK tax law requires.
- Backups — encrypted backups expire on a fixed rotation of no more than 35 days; deleted data leaves backups as that rotation completes.
- Correspondence and security logs — for as long as reasonably necessary for support, security and evidencing compliance, then deleted.
9. Your rights
Under UK data protection law you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected (you can edit most account details directly in settings);
- Erasure — ask us to delete your personal data;
- Restriction and objection — limit or object to certain processing, including any processing based on legitimate interests;
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format.
To exercise any of these rights — including requesting deletion of your account or an export of your data — email support@floxa.co.uk from the email address on your account. We will respond within one month, as the law requires, and action account deletion within 30 days of verifying the request. Note that where your request concerns Customer Data controlled by a business that uses Floxa (section 1), we will pass your request to that business rather than acting on it ourselves, and that we must retain billing records required by tax law even after an account is deleted.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or 0303 123 1113 — though we would appreciate the chance to resolve your concern first.
10. Children
Floxa is a business tool and is not intended for, or directed at, children. We do not knowingly collect personal data from anyone under 16; if you believe we have, contact us and we will delete it.
11. Changes to this policy
When we make material changes to this policy we will notify account owners by email and update the date at the top of this page. The current version is always published at floxa.co.uk/legal/privacy.