JustFlows

Legal

Privacy Policy

Version 1.0 · Last updated 2026-08-20

This Privacy Policy explains how Noobbase holding BV collects, uses, stores, shares, and protects personal data when you visit our websites, create an account, use Justflows Cloud, the Marketplace, or otherwise interact with our Services. It also explains where responsibilities shift when you self-host the platform or operate sites for your own users.

This Privacy Policy is written in English. Any translation into another language is provided as a courtesy only. In the event of any conflict or inconsistency, the English version prevails.

This policy is intended to provide transparency under applicable privacy and data protection law, including the General Data Protection Regulation (GDPR) and Dutch implementation law. It is not a substitute for advice from qualified privacy counsel.

1. Overview

This Privacy Policy applies to personal data processed through justflows.com, related marketing sites, account systems, Justflows Cloud, the Marketplace, support channels, and other Services operated by Noobbase holding BV

The Justflows CMS platform (Community Edition) is open source software you may run on your own infrastructure. When you self-host, you are generally responsible for personal data processed on your instance unless you connect to our Services (accounts, Marketplace, updates, Cloud sync, support).

Depending on context, Justflows may act as a data controller for account, billing, website, marketing, and platform operations data, and as a data processor for personal data you control through Cloud-hosted sites or other processor arrangements.

2. Who is responsible for your data

For platform-level data — such as account registration, authentication, billing, product analytics, support, fraud prevention, security monitoring, and direct communications from Justflows — Noobbase holding BV is generally the data controller.

If you operate a website or application powered by Justflows (self-hosted or Cloud), you are generally the controller for personal data about your visitors, authors, customers, or end users. Justflows may act as processor when we host or process that data on your behalf under a DPA.

Marketplace publishers are controllers for data they collect through their listings, support channels, or publisher dashboards, subject to Marketplace terms.

Privacy questions about platform-level processing: privacy@justflows.com. Questions about data on a specific Justflows-powered site should usually be directed to that site operator first.

3. Categories of data we collect

The personal data we collect depends on how you interact with our Services and which features you use. We may collect data directly from you, automatically from your device or browser, from payment or identity providers, from support interactions, and from integrations you connect.

We do not intend to routinely collect special category data (such as health data or biometric data) unless clearly required by a service you use and supported by an appropriate legal basis.

  • Identity data: name, username, organisation name, job title, account identifiers.
  • Contact data: email address, phone number, billing address, support contact details.
  • Account and profile data: preferences, locale, roles, organisation membership, Marketplace publisher profile.
  • Billing and transaction data: subscription status, invoices, payout metadata, payment-related information from payment partners (we do not store full payment card numbers where a processor handles checkout).
  • Technical and device data: IP address, browser type, device identifiers, operating system, language, referring URLs, log data, and security signals.
  • Usage data: pages viewed, features used, session patterns, performance metrics, diagnostic events, and API usage metadata.
  • Communication data: emails, chat or ticket content, feedback, survey responses, and security notifications.
  • Compliance and risk data: verification results, fraud signals, abuse reports, and audit records where necessary.

4. Why we use personal data

We process personal data only where we have a lawful basis and for specified, legitimate purposes.

Depending on context, our lawful bases may include performance of a contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c)), legitimate interests (Article 6(1)(f)), consent (Article 6(1)(a)), and where necessary the establishment, exercise, or defence of legal claims.

  • To create, operate, maintain, and secure accounts and Services.
  • To provide Cloud hosting, Marketplace, updates, documentation, and related platform functionality.
  • To process subscriptions, invoices, payouts, and account administration.
  • To detect fraud, misuse, security threats, and policy violations.
  • To provide customer support, onboarding, and operational communications.
  • To improve service quality, performance, product design, and reliability.
  • To comply with legal, regulatory, tax, accounting, and law-enforcement obligations.
  • To send service notices and, where permitted and with appropriate consent where required, marketing communications.

5. Website, Cloud, self-hosted, and Marketplace roles

Website visitors: we may process technical and usage data to operate and secure our website, understand traffic, and improve content. Non-essential cookies or similar technologies should only be used with valid consent where required by law.

Account holders and Cloud customers: we process account and billing data to deliver contracted Services. For Cloud, we may process site content and visitor data on your instructions as processor under a DPA.

Self-hosters: unless you connect to Justflows Services, we generally do not access personal data on your instance. You are responsible for privacy notices, lawful bases, and rights handling for data on your installation.

Marketplace publishers and buyers: we process data needed to list, purchase, review, sign, and support extensions. Publishers remain responsible for data they collect through their software or support unless otherwise agreed in writing.

Developers using our API: we process credentials, usage logs, and related metadata to provide and secure API access.

6. Cookies and similar technologies

We and our partners may use cookies, pixels, local storage, and similar technologies to remember settings, keep you signed in, secure the platform, measure performance, understand usage, and support lawful marketing where permitted.

In the EU/EEA and UK, non-essential cookies or similar tracking technologies should generally only be activated after valid consent, with a meaningful way to manage preferences. A separate Cookie Policy may provide more detail when published.

You can control cookies through browser settings. Disabling essential cookies may affect sign-in, security, or core functionality.

7. When we share personal data

We do not sell personal data. We disclose personal data where necessary to operate Services, fulfil contracts, protect rights and security, or comply with law.

Recipients vary based on the Services you use and your configuration.

  • Infrastructure, hosting, storage, monitoring, email, support, and security vendors.
  • Payment processors, banking partners, tax providers, and identity or fraud screening providers.
  • Analytics, communications, and product tooling providers acting under contract.
  • Professional advisers, auditors, insurers, and legal counsel where reasonably necessary.
  • Courts, regulators, supervisory authorities, or law enforcement where legally required or necessary to protect rights, safety, and the platform.
  • Corporate transaction participants in connection with merger, financing, acquisition, or reorganisation, subject to appropriate safeguards.

8. International data transfers

Personal data may be processed in countries other than where it was collected, including countries with different data protection standards.

Where personal data is transferred from the EEA, UK, or another jurisdiction with transfer restrictions, we intend to rely on an appropriate mechanism such as an adequacy decision, EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, binding corporate rules where available, or another recognised legal basis, together with supplementary safeguards where appropriate.

Cloud customers and self-hosters who transfer data internationally remain responsible for lawful transfer mechanisms for data they control.

9. Data retention

We retain personal data only as long as necessary for the purposes described in this policy, including to provide Services, comply with legal obligations, resolve disputes, maintain security records, enforce agreements, and support legitimate business operations.

Retention periods depend on data type, processing role, legal and tax requirements, sensitivity, and whether deletion or anonymisation is possible without undermining required operational or compliance functions.

When data is no longer required, we seek to delete, anonymise, or securely isolate it in accordance with our retention standards. Backups and logs may be retained for a limited period for security and disaster recovery.

10. Security measures

We maintain technical, organisational, and administrative safeguards designed to protect personal data against unauthorised access, misuse, disclosure, alteration, and loss. These may include encryption, access controls, logging, authentication safeguards, backup processes, staff access restrictions, and incident management procedures.

No internet-based service is completely secure. You are responsible for protecting your account credentials, devices, and security practices on self-hosted installations.

Report suspected security incidents affecting our Services to security@justflows.com.

11. Privacy rights and choices

Depending on your location and applicable law, you may have rights relating to access, correction, deletion, restriction, objection, portability, consent withdrawal, and complaint submission.

For individuals in the EU/EEA and UK, these may include the rights under GDPR and UK GDPR, including access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and rights relating to automated decision-making where applicable.

If Justflows is controller for the relevant data, contact privacy@justflows.com to exercise applicable rights. We may need to verify your identity. If another party controls the data (for example a site operator), we may direct you to them while assisting as required under processor obligations.

We aim to respond within one month unless an extension is permitted by law.

  • Access personal data we hold about you, subject to applicable exceptions.
  • Correct inaccurate or incomplete personal data.
  • Request deletion where a valid legal basis exists.
  • Object to or restrict certain processing where the law allows.
  • Request portability of certain data in a structured, commonly used format where applicable.
  • Withdraw consent where processing depends on consent.
  • Opt out of direct marketing using unsubscribe links or by contacting us.

12. Additional EU and EEA disclosures

Where EU data protection law applies, we intend to follow the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.

Where required, we maintain records of processing activities, implement appropriate controller-processor terms, support data protection impact assessments for high-risk processing, and apply privacy by design and by default in product and operational decisions.

You may lodge a complaint with a supervisory authority. In the Netherlands, this may be the Autoriteit Persoonsgegevens (AP). In other EU/EEA countries, contact the competent authority in your member state.

13. Marketing communications

We may send product updates, event invitations, or marketing emails where permitted by law and, where required, based on your consent or an applicable soft opt-in rule.

You can opt out of marketing at any time using the unsubscribe link in an email or by contacting privacy@justflows.com. Service-related transactional or security messages may still be sent where necessary.

14. Children's privacy

Our Services are not directed to children and are intended for users who meet the minimum age required under applicable law (see our Terms and Conditions).

If we become aware that we have collected personal data from a child in violation of applicable law, we will seek to delete that information or take appropriate remedial action.

15. Third-party links and self-hosted sites

Our website may contain links to third-party websites or services not controlled by Justflows. Their privacy practices are governed by their own policies.

Many Justflows-powered sites are operated independently by third parties. We cannot provide help or information about personal data on those sites. Contact the site operator or author directly for site-specific privacy requests.

Aggregated or anonymised statistics about platform usage (for example download counts or popular extensions) may be published without identifying individuals.

16. Automated processing

We may use automated tools to detect abuse, fraud, security threats, or spam. Significant decisions with legal or similarly significant effects are not intended to be based solely on automated processing without appropriate safeguards or human review where required by law.

If we introduce AI-assisted review workflows for support, Marketplace, or security, we will describe them in updates to this policy and apply appropriate human oversight.

17. Changes to this policy

We may update this Privacy Policy to reflect product changes, legal developments, or operational improvements.

Material changes will be posted with an updated date and, where required, notified by email or in-product notice. Continued use after the effective date may constitute acknowledgment where permitted by law.

18. Contact and complaints

Noobbase holding BV

[Registered address]

The Netherlands

Privacy: privacy@justflows.com

Legal: legal@justflows.com

Security: security@justflows.com

KvK: [KvK number]

For data on a specific Justflows-powered website, contact that site's operator first where appropriate. For platform-level requests, contact privacy@justflows.com.

Practical note

Before public launch, replace placeholder company details, confirm subprocessors and retention schedules, publish a Cookie Policy if you use non-essential cookies, and align Cloud customer terms with a Data Processing Agreement (DPA). Have this policy reviewed by qualified privacy counsel.