Where your data actually sits.

Last updated: 31 August 2026

This page is meant to be readable by the person who has to sign off on it, not only by a lawyer. If something here is unclear, that is a bug and we would like to hear about it.

Two different jobs

Flora handles two kinds of personal data, and the law treats them differently.

Your account. Your email address, your plan, your settings. For this, Serendipiware Ltd is the controller. We decided to collect it and we decide what happens to it, so this page explains it.

Your submissions. The names, messages and anything else the people who fill in your forms send you. For this, you are the controller and Flora is the processor. We hold that data on your instructions and do nothing else with it. Your own privacy notice is what covers those people, not this page. Our obligations to you are set out in our data processing agreement, which is included on the Business plan and available on request.

This distinction matters. It means we never read, analyse, sell, or train anything on your submissions, because we have no legal basis to and no wish to.

Who we are

Flora is a product of Serendipiware Ltd, a company registered in England & Wales, company number 17232380, registered office Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom.

For anything involving personal data, write to [email protected]. A person reads it.

What we collect, and why

WhatWhyLegal basis
Your email addressTo create your account and send you a login codePerformance of a contract
Your plan and settingsTo run the service you signed up forPerformance of a contract
Submission contentsTo store and show them to youProcessed on your instructions as processor
The hostname a submission came fromTo let you restrict which sites may use your formLegitimate interest in preventing abuse
Billing detailsTo take payment, when billing is switched onPerformance of a contract, and legal obligation for tax records

We do not collect: passwords (there are none, you sign in with a code sent to your address), submitter IP addresses, user agents, device fingerprints, or any behavioural profile of anyone.

Where it sits

WhatWhereWho
Submission contents and account dataParis, France (eu-west-3)Supabase
The endpoint that receives submissionsAmsterdam, NetherlandsRailway
The dashboard and DNSEU edgeCloudflare
Notification and login emailsFranceBrevo (Sendinblue)
Payments, once billing is switched onIreland and the EUStripe

Each of these is a subprocessor. If that list changes, we will say so on this page before the change takes effect, and Business customers get notice directly.

We do not use a US processor for the storage of submissions. If you need this in a signed document naming each of the above, that is what the data processing agreement is for.

How long we keep things

Submissions are deleted automatically according to your plan and your own per-form setting, whichever is shorter:

  • Free: 7 days
  • Solo: up to 1 year
  • Business: kept for as long as the plan is active

A scheduled job runs daily and removes anything past its date. You can also delete any submission, any form, or your whole account at any time, and that deletes rows rather than hiding them.

Account data is kept while your account exists. Deleting your account removes your profile, every form and every submission attached to it, in one operation and immediately.

Billing records are kept for as long as tax law requires us to, which is currently six years. This is the one thing we cannot delete on request.

Cookies and analytics

Flora sets one cookie, which holds your login session. It is necessary for the service to work and there is no version of the product without it.

We use Cloudflare Web Analytics to count page views. It sets no cookies, stores no identifier for you, and does not follow you to other sites. There is no advertising, no tracking pixel, and no analytics of any kind on the endpoint that receives your submissions.

Your rights

Under the UK GDPR and the EU GDPR you can ask us to:

  • give you a copy of your personal data
  • correct anything wrong
  • delete your account and everything in it
  • restrict or object to how we use it
  • give you your data in a portable format

Most of these you can do yourself from the dashboard, immediately, without asking anyone. For the rest, write to [email protected] and we will answer within one month.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office in the UK (ico.org.uk), or to the supervisory authority in your own country if you are in the EU or EEA.

Note that if your complaint is about a submission someone made through a form built by one of our customers, the customer is the controller of that data and you should contact them. We will help them answer you.

Automated decision-making

There is none. Nothing about you is decided by an algorithm, and your submissions are not fed into any machine learning system, ours or anyone else's.

Security

Data is encrypted in transit with TLS 1.3 and encrypted at rest on disk. Access to submission data is restricted per account at the database level, so one account cannot read another's rows even if the application had a bug. The service key that can write submissions lives only on the ingest server and is never sent to a browser.

If we ever become aware of a breach affecting personal data, we will notify the relevant supervisory authority within 72 hours and tell affected customers without undue delay.

Changes to this page

If we change anything material here we will update the date at the top and, for anything that affects how your data is handled, tell you before it takes effect rather than after.