Where your data actually sits.
Last updated: 31 August 2026
This page is meant to be readable by the person who has to sign off on it, not only by a lawyer. If something here is unclear, that is a bug and we would like to hear about it.
Two different jobs
Flora handles two kinds of personal data, and the law treats them differently.
Your account. Your email address, your plan, your settings. For this, Serendipiware Ltd is the controller. We decided to collect it and we decide what happens to it, so this page explains it.
Your submissions. The names, messages and anything else the people who fill in your forms send you. For this, you are the controller and Flora is the processor. We hold that data on your instructions and do nothing else with it. Your own privacy notice is what covers those people, not this page. Our obligations to you are set out in our data processing agreement, which is included on the Business plan and available on request.
This distinction matters. It means we never read, analyse, sell, or train anything on your submissions, because we have no legal basis to and no wish to.
Who we are
Flora is a product of Serendipiware Ltd, a company registered in England & Wales, company number 17232380, registered office Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom.
For anything involving personal data, write to [email protected]. A person reads it.
What we collect, and why
| What | Why | Legal basis |
|---|---|---|
| Your email address | To create your account and send you a login code | Performance of a contract |
| Your plan and settings | To run the service you signed up for | Performance of a contract |
| Submission contents | To store and show them to you | Processed on your instructions as processor |
| The hostname a submission came from | To let you restrict which sites may use your form | Legitimate interest in preventing abuse |
| Billing details | To take payment, when billing is switched on | Performance of a contract, and legal obligation for tax records |
We do not collect: passwords (there are none, you sign in with a code sent to your address), submitter IP addresses, user agents, device fingerprints, or any behavioural profile of anyone.
Where it sits
| What | Where | Who |
|---|---|---|
| Submission contents and account data | Paris, France (eu-west-3) | Supabase |
| The endpoint that receives submissions | Amsterdam, Netherlands | Railway |
| The dashboard and DNS | EU edge | Cloudflare |
| Notification and login emails | France | Brevo (Sendinblue) |
| Payments, once billing is switched on | Ireland and the EU | Stripe |
Each of these is a subprocessor. If that list changes, we will say so on this page before the change takes effect, and Business customers get notice directly.
We do not use a US processor for the storage of submissions. If you need this in a signed document naming each of the above, that is what the data processing agreement is for.
How long we keep things
Submissions are deleted automatically according to your plan and your own per-form setting, whichever is shorter:
- Free: 7 days
- Solo: up to 1 year
- Business: kept for as long as the plan is active
A scheduled job runs daily and removes anything past its date. You can also delete any submission, any form, or your whole account at any time, and that deletes rows rather than hiding them.
Account data is kept while your account exists. Deleting your account removes your profile, every form and every submission attached to it, in one operation and immediately.
Billing records are kept for as long as tax law requires us to, which is currently six years. This is the one thing we cannot delete on request.
Cookies and analytics
Flora sets one cookie, which holds your login session. It is necessary for the service to work and there is no version of the product without it.
We use Cloudflare Web Analytics to count page views. It sets no cookies, stores no identifier for you, and does not follow you to other sites. There is no advertising, no tracking pixel, and no analytics of any kind on the endpoint that receives your submissions.
Your rights
Under the UK GDPR and the EU GDPR you can ask us to:
- give you a copy of your personal data
- correct anything wrong
- delete your account and everything in it
- restrict or object to how we use it
- give you your data in a portable format
Most of these you can do yourself from the dashboard, immediately, without asking anyone. For the rest, write to [email protected] and we will answer within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office in the UK (ico.org.uk), or to the supervisory authority in your own country if you are in the EU or EEA.
Note that if your complaint is about a submission someone made through a form built by one of our customers, the customer is the controller of that data and you should contact them. We will help them answer you.
Automated decision-making
There is none. Nothing about you is decided by an algorithm, and your submissions are not fed into any machine learning system, ours or anyone else's.
Security
Data is encrypted in transit with TLS 1.3 and encrypted at rest on disk. Access to submission data is restricted per account at the database level, so one account cannot read another's rows even if the application had a bug. The service key that can write submissions lives only on the ingest server and is never sent to a browser.
If we ever become aware of a breach affecting personal data, we will notify the relevant supervisory authority within 72 hours and tell affected customers without undue delay.
Changes to this page
If we change anything material here we will update the date at the top and, for anything that affects how your data is handled, tell you before it takes effect rather than after.