Privacy Policy
How we collect, use, and protect your data. Last updated: February 2026.
1. Introduction
Flow Myna Ltd ("Flow Myna," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered process mining platform.
Flow Myna is a company registered in the United Kingdom. We comply with the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU General Data Protection Regulation (EU GDPR).
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and authentication credentials through our identity provider (WorkOS). We may also collect your company name, job title, and profile picture if you choose to provide them.
Process Data
When you upload data for process mining analysis, we store and process this data on your behalf. This may include event logs, timestamps, activity names, case identifiers, and any additional attributes you choose to include. This data remains your property and is processed solely to provide our services to you.
Usage Information
We automatically collect information about how you interact with our website and platform, including pages visited, features used, AI copilot conversations, and performance metrics. This helps us improve our services and provide better support. We use our own first-party analytics (Flow Myna) and Plausible Analytics on our website - we do not use third-party tracking cookies.
Technical Information
We collect device information, browser type, IP address, and other technical data necessary for security, fraud prevention, and service optimization. We also record your IP address when you accept our Terms of Service for legal audit purposes.
3. How We Use Your Information
We process your information for the following purposes and legal bases under UK GDPR:
- Contract performance: To provide, maintain, and improve our process mining platform; to process and analyse your uploaded data; to generate insights and visualisations
- Contract performance: To respond to your inquiries and provide customer support
- Legitimate interests: To send you service updates and important notifications (our interest: keeping you informed about service changes)
- Legitimate interests: To detect, prevent, and address technical issues and security threats (our interest: protecting our systems and users)
- Legal obligation: To comply with applicable laws, regulations, and legal requests
- Consent: To send marketing communications (where you have opted in)
You may object to processing based on legitimate interests by contacting us. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
4. AI and Data Processing
Our platform uses artificial intelligence to analyze your process data. This includes:
- Automated Data Mapping: AI agents analyze your uploaded files to understand data structure and create appropriate mappings
- AI Copilot: Natural language processing to understand your questions and generate relevant filters, charts, and insights
- Insight Generation: Automated analysis to identify bottlenecks, anomalies, and optimization opportunities
We use third-party AI providers (including OpenAI and Anthropic) to power these features. Data sent to these providers is processed in accordance with their privacy policies and our data processing agreements with them. We do not use your data to train AI models.
5. Data Storage and Security
Your data is stored securely using industry-standard encryption at rest and in transit. We use trusted infrastructure providers including:
- Railway for application hosting and database services
- AWS S3 for file storage
- WorkOS for authentication and identity management
We implement appropriate technical and organizational measures to protect against unauthorized access, alteration, disclosure, or destruction of your data.
6. Data Sharing
We do not sell your personal information or process data. We may share information with:
- Service Providers: Third parties who assist in operating our platform (hosting, analytics, AI processing)
- Workspace Members: Other members of your workspace can access shared datasets and projects
- Legal Requirements: When required by law or to protect our rights and safety
7. Your Rights (UK/EU)
Under UK GDPR and EU GDPR (where applicable), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your personal data ("right to be forgotten")
- Restrict processing of your data
- Object to processing based on legitimate interests
- Data portability - receive your data in a structured, machine-readable format
- Withdraw consent at any time (where processing is based on consent)
- Not be subject to decisions based solely on automated processing that significantly affect you
Flow Myna does not make automated decisions that produce legal or similarly significant effects on individuals. Our AI features generate insights and recommendations for human review—final decisions remain with you and your organisation.
To exercise these rights, contact us at privacy@flowmyna.com. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.
8. Your Rights (California)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions
- Right to Correct: You may request correction of inaccurate personal information
- Right to Opt-Out: You may opt out of the "sale" or "sharing" of personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
We do not sell or share your personal information as defined under CCPA/CPRA. We do not intentionally collect or process Sensitive Personal Information as defined under CPRA (such as Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, or health information). If your uploaded process data contains such information, you are responsible for ensuring appropriate legal basis and safeguards.
To exercise your California privacy rights, contact us at privacy@flowmyna.com or submit a request through your account settings. We will verify your identity before processing requests.
9. Data Retention
We retain your information for the following periods:
- Account information: Retained while your account is active and for 30 days after account closure to allow for reactivation
- Process data: Retained until you delete it or close your account, then deleted within 30 days
- Usage and technical data: Retained for up to 12 months for service improvement and security purposes
- Legal and compliance records: Retained for up to 7 years where required by law (e.g., financial records, terms acceptance logs)
- Backup data: Removed from backup systems within 90 days of deletion from primary systems
Upon request, we will provide written confirmation that your data has been deleted.
10. International Transfers
Your data is primarily stored in the EU (Amsterdam, Netherlands). Some data may be transferred to the United States for processing by our AI service providers (OpenAI, Anthropic). When we transfer data outside the UK/EEA, we ensure appropriate safeguards are in place:
- UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses
- EU Standard Contractual Clauses (2021 version) for EU data subjects
- Data processing agreements with all sub-processors
You may request a copy of the safeguards we use by contacting privacy@flowmyna.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, or wish to exercise your privacy rights, please contact us at:
Flow Myna Ltd
38 Malvern Road, Cambridge, CB1 9LD, United Kingdom
Email: privacy@flowmyna.com
Company Number: 16428866