Flow2FA legal
Privacy Policy
- Last Revised:
- 7 August 2026
- Effective Date:
- 7 August 2026
This Privacy Policy describes how Flowstates Inc, doing business as Flow2FA ("Flow2FA," "we," "us," or "our"), located at 330 Madison Avenue, 27th Floor, New York, NY 10017, United States (SR: 20223077628, EIN: 88-3465626), collects, uses, discloses, stores, transfers and protects Personal Data in connection with flow2fa.com and the Flow2FA business-to-business OTP / two-factor-authentication delivery platform (the "Flow2FA Services").
1.Contact Details
Controller / Business:
Flowstates Inc, doing business as Flow2FA
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Privacy Contact / Data Protection Officer: dataprotectionofficer@flowstates.net
Legal Contact: legal@flowstates.net
For privacy rights requests, data protection questions, complaints, or Colombian consultas or reclamos, please contact us using the privacy email address above, or via our contact page.
2.Scope of This Privacy Policy
This Privacy Policy applies to Personal Data we process when:
- you visit flow2fa.com;
- you create or use a Flow2FA account;
- you communicate with us, including through our contact form or AI assistant;
- you receive customer support;
- you interact with our cookies or similar technologies (see our Cookie Policy);
- you are a business customer, supplier, partner, or representative of one; or
- your Personal Data is processed through the Flow2FA Services on behalf of one of our Customers, for example as an OTP or verification message recipient.
This Privacy Policy does not replace any Data Processing Agreement, Customer agreement, or platform-specific terms that apply to our Customers. See our Website Terms of Use and Cookie and Browser Storage Policy for related terms.
3.Our Role: Controller, Processor, Service Provider, or Encargado
Flow2FA may process Personal Data in different roles depending on the context.
3.1 Where Flow2FA Acts as Controller
Flow2FA acts as a controller when we determine the purposes and means of processing Personal Data, including account registration information, billing information, website and contact-form data, AI assistant chat data, support records, business contact data, and security logs processed for our own business purposes.
3.2 Where Flow2FA Acts as Processor or Service Provider
Flow2FA acts as a processor, service provider, or contractor when it processes Personal Data on behalf of our Customers through the Flow2FA Services — for example, when routing and delivering OTP and verification messages over WhatsApp, SMS, or email. In that context, the Customer determines the purposes and means of processing, and Flow2FA processes the data only on the Customer's documented instructions, under the applicable Data Processing Agreement, Website Terms of Use, and applicable law.
3.3 Colombian Law Roles
For purposes of Colombian data protection law, Flow2FA may act as a Responsable del Tratamiento when it determines the purposes and means of processing, or as an Encargado del Tratamiento when it processes Personal Data on behalf of a Customer.
4.Key Definitions
- Customer — a business or organization that registers for or uses the Flow2FA Services to authenticate or verify its own end users.
- End User — an individual whose phone number, WhatsApp identifier, or email address is used by a Flow2FA Customer to receive an OTP or verification message through the Flow2FA Services.
- OTP / Verification Message — a one-time passcode, authentication code, or related verification communication sent by or on behalf of a Customer through the Flow2FA Services.
- Personal Data or Personal Information — information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an identified or identifiable person, household, or device.
- Processing — any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, deletion, or analysis.
- Sensitive Personal Data — Personal Data treated as sensitive under applicable law, which may include health data, biometric data, precise geolocation, government identifiers, account login credentials, racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, sexual orientation, children's data, or other protected categories.
- Data Processing Agreement or DPA — the agreement governing Flow2FA's processing of Personal Data on behalf of a Customer.
5.Personal Data We Process as Controller
The table below describes the main categories of Personal Data we process as controller through flow2fa.com and our own business operations. Unlike a marketing platform, our website does not run advertising pixels, analytics cookies, or a payment checkout — the categories below reflect what the site actually collects.
| Category | Examples | Source | Purpose | Retention Criteria |
|---|---|---|---|---|
| Contact-form submissions | Name, work email, company, phone, topic, message, page path the form was submitted from | You, via the contact form | Respond to enquiries, qualify leads, provide sales and support information | Retained in our database for as long as needed to respond to and document the enquiry, and thereafter as required for record-keeping or legal purposes |
| AI assistant chat data | A random session identifier for your assistant conversation — stored persistently in your browser's localStorage only where you have accepted optional assistant-continuity storage, and otherwise a temporary identifier held in page memory only — together with chat messages you send, the page path where the chat session started, and your browser user agent | You, via the AI assistant widget; your browser | Operate the assistant, restore your earlier conversation where you have accepted optional assistant-continuity storage, generate relevant replies, and troubleshoot | Conversations and their messages are kept in our live database for 30 days from the last message in that conversation, then deleted automatically. You can delete the current conversation at any time from the assistant panel. We do not retain raw chat text for analytics or for training AI models |
| AI assistant model processing | The text of your assistant conversation, sent as prompts and conversation context | You, via the assistant, transmitted through the Lovable AI Gateway to the configured Google Gemini model | Generate an AI-drafted reply to your message | Retained by the model provider only as needed to process and return the response; see Section 21 (AI Assistant Disclosure) |
| Account and business contact data | Name, work email, company, role, phone | You, your employer, account administrators | Create and manage Customer accounts, provision API/SMPP access, communicate about the service | For the duration of the business relationship and a defined period after account closure |
| Hosting, security, and server logs | IP address, request metadata, timestamps, error and access logs | Automatically, through hosting and infrastructure providers | Operate, secure, and troubleshoot the website and platform; detect and prevent abuse | For a defined period necessary for security, troubleshooting, and abuse prevention, or longer where needed for an investigation or legal claim |
6.Personal Data We Process on Behalf of Customers
Customers use the Flow2FA Services to deliver one-time passcodes and verification messages to their own End Users over WhatsApp, SMS, and email, using their own vendors and SMPP binds, Flow2FA-supplied routes, or both. In this context the Customer is generally the controller (or Responsable del Tratamiento), and Flow2FA is generally the processor, service provider, or Encargado del Tratamiento.
| Data Type | Examples | Processing Purpose |
|---|---|---|
| End User contact identifiers | Phone numbers, WhatsApp identifiers, email addresses | Delivering OTP and verification messages to the correct destination |
| OTP / verification content | One-time passcodes, verification codes, message templates | Generating, transmitting, and validating authentication codes |
| Account, API, and routing configuration | Customer account data, API keys, SMPP bind credentials, routing and fallback rules | Provisioning and operating the Customer's authentication traffic |
| Request and session identifiers | OTP IDs, request IDs, SMPP session data | Tracking a request through generation, delivery, and validation |
| Delivery and verification metadata | Timestamps, delivery status, verification outcome, retry and fallback attempts | Routing, fallback logic, delivery monitoring, and troubleshooting |
| Vendor, route, and carrier logs | Vendor/route identifiers, mobile-operator or carrier data, billing and traffic logs | Routing traffic, billing, reconciliation, and compliance with carrier requirements |
| Security signals | IP address, device data, or risk indicators, only where supplied by the Customer or generated for service security | Fraud prevention, abuse detection, and service integrity |
Flow2FA processes End User Personal Data only to provide the Flow2FA Services, comply with Customer instructions, maintain security and service integrity, prevent abuse, comply with law, and perform related activities described in the applicable DPA. Flow2FA is a business-to-business authentication delivery platform — it is not a marketing campaign platform, and Flow2FA does not guarantee delivery of any message.
7.Customer Responsibilities
Because the Flow2FA Services are used to deliver OTP and verification messages, Customers must comply with all applicable privacy, telecommunications, consumer protection, and anti-spam laws. Customers are responsible for:
- providing lawful notices to End Users regarding authentication messages;
- obtaining and documenting any legally required consents or authorizations;
- determining the lawful basis for processing End User Personal Data;
- ensuring messages sent through the Flow2FA Services are lawful and non-deceptive;
- maintaining accurate End User contact data;
- ensuring that End User data submitted to Flow2FA may lawfully be processed; and
- properly configuring their own vendors, SMPP binds, or Flow2FA-supplied routes.
Flow2FA may suspend, restrict, or terminate access to the Services where we believe it is necessary to protect End Users, prevent abuse, preserve service integrity, comply with law, respond to carrier or regulator requirements, or enforce our Website Terms of Use.
8.Sensitive Personal Data
Flow2FA does not require Customers to submit Sensitive Personal Data through the Flow2FA Services. Customers must not submit Sensitive Personal Data, protected health information, children's data, biometric data, government identifiers, or other regulated data through the Services unless:
- the Customer has obtained all legally required consent or authorization;
- such processing is permitted under the applicable agreement with Flow2FA; and
- Flow2FA has confirmed that the relevant Services are configured to support that processing.
The Flow2FA Services are not intended for the processing of Protected Health Information under HIPAA unless Flow2FA and the Customer have entered into a separate agreement addressing that processing. Where we process Sensitive Personal Data as controller, we do so only where permitted by applicable law and, where required, with explicit consent.
9.Children's Privacy
The Flow2FA Services are intended for business customers and are not directed to children or minors under 18. We do not knowingly collect Personal Data from children under 13 through our website or AI assistant. Customers must not use the Flow2FA Services to deliver messages to children or minors unless they have obtained all legally required consents and authorizations.
If you believe a child has provided Personal Data to us, please contact dataprotectionofficer@flowstates.net.
12.Subprocessors and Service Providers
We use third-party subprocessors, service providers, and vendors to help provide, secure, maintain, and improve the Flow2FA Services. These currently include our database and backend infrastructure provider (Supabase) and the AI infrastructure used by our assistant (the Lovable AI Gateway and the underlying Google Gemini model). Customers may also route traffic through their own vendors and SMPP binds, which are not Flow2FA subprocessors.
Our subprocessors are required to process Personal Data under contract and only for the purposes authorized by Flow2FA or our Customers, using appropriate confidentiality, security, and privacy safeguards. Where required by our DPA, we provide Customers with notice of new subprocessors and an opportunity to object.
13.International Transfers
Flow2FA is based in the United States, and Personal Data we process — whether as controller or processor — may be processed in the United States and in other countries where our subprocessors operate. Where we transfer Personal Data from the EEA, UK, Switzerland, Colombia, or another jurisdiction that restricts international transfers, we use appropriate safeguards where required, such as:
- Standard Contractual Clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- applicable adequacy decisions;
- data processing or transmission agreements; or
- another lawful transfer mechanism recognized under applicable law.
You may contact us at dataprotectionofficer@flowstates.net for more information about the transfer safeguards we use.
14.Data Retention
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Because exact retention periods depend on the type of record and applicable legal requirements, we describe the criteria we apply below rather than fixed periods.
| Data Category | Retention Criteria |
|---|---|
| Contact-form submissions | For as long as needed to respond to and document the enquiry, and thereafter as required for record-keeping |
| AI assistant chat sessions, messages, page path, and user agent (server-side) | Deleted automatically 30 days after the last message in that conversation (a rolling window that restarts each time you send a message). You can also delete the current conversation yourself at any time from the assistant panel, which removes the conversation and all of its messages. We do not retain raw chat text for analytics or AI training |
| Browser storage on your device (consent record and optional assistant-continuity identifier) | The consent record expires after 180 days and is then renewed by asking again; the optional assistant-continuity identifier is kept only until consent expires, is withdrawn, you clear site data, or the value is replaced. Where you have not accepted optional storage, the assistant identifier exists in page memory only and is discarded on reload. See our Cookie and Similar Technologies Policy |
| Account and business relationship data | For the duration of the business relationship plus a defined period required for accounting, tax, and legal purposes |
| End User data processed on behalf of Customers | As instructed by the Customer and under the applicable DPA, and no longer than needed to provide the Services |
| Delivery, verification, vendor, route, and carrier logs | For a defined period necessary for billing, reconciliation, compliance, and abuse prevention, or longer where needed for a dispute, investigation, or legal claim |
| Hosting, security, and server logs | For a defined period necessary for security and troubleshooting, or longer where needed for an investigation or legal claim |
| Legal and compliance records | As long as necessary to demonstrate compliance and support an audit or dispute |
15.Security
We use administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, including access controls, encryption in transit, and database-level access restrictions on our backend infrastructure. No security measure is perfect, and we cannot guarantee absolute security. If we become aware of a security incident affecting Personal Data, we will take reasonable steps to investigate and notify affected parties as required by applicable law.
16.Your Rights
Depending on your location and the applicable law, you may have rights to access, correct, delete, restrict, or object to our processing of your Personal Data, to receive a copy of your data in a portable format, or to withdraw consent where processing is based on consent. You may exercise these rights by contacting dataprotectionofficer@flowstates.net. Where Flow2FA processes your Personal Data as a processor on behalf of a Customer, we may direct your request to that Customer, who is generally best placed to respond.
17.GDPR, EEA, UK, and Swiss Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
- access the Personal Data we hold about you;
- rectify inaccurate or incomplete Personal Data;
- erase your Personal Data in certain circumstances;
- restrict or object to processing in certain circumstances;
- request data portability; and
- lodge a complaint with your local data protection supervisory authority.
Where we rely on legitimate interests to process your data as controller, you have the right to object at any time. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
For cookies and similar technologies, you can withdraw consent as easily as you gave it by using "Cookie settings" in the website footer. Changing that setting stops any further persistent storage on your device and removes the optional assistant-continuity identifier immediately, so earlier conversations are no longer restored in your browser. It does not by itself delete assistant messages already stored on our servers. You can delete those yourself using "Delete this conversation" in the assistant panel, which permanently removes that conversation and all of its messages from our live database; in any event, each conversation is deleted automatically 30 days after its last message. Other requests to access or delete server-side data are handled as privacy-rights requests under this Privacy Policy, using the contact details above.
18.U.S. State Privacy Rights
Residents of certain U.S. states — including California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws — may have rights to know what Personal Information we collect about them, to access or delete that information, to correct inaccuracies, to opt out of the sale or sharing of Personal Information or its use for targeted advertising, and to be free from discrimination for exercising these rights.
Flow2FA does not sell Personal Information for money, and the current version of flow2fa.com does not use Personal Information for targeted advertising or cross-context behavioral advertising. You may exercise your state privacy rights by contacting dataprotectionofficer@flowstates.net. The full California Privacy Notice below describes our practices and your rights in more detail; other state residents may exercise comparable rights using the same contact channel.
19.California Privacy Notice
This section supplements the rest of this Privacy Policy and applies to California residents, as required by the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
19.1 Notice at Collection
We collect the categories of Personal Information described in Sections 5 and 6 of this Privacy Policy, including identifiers (such as name, email, and phone number), internet or electronic activity information (such as chat messages, session identifiers, and page paths), and commercial information (such as contact-form and account data), for the business and commercial purposes described in this Privacy Policy.
19.2 Sources of Personal Information
- directly from you, such as through our contact form or AI assistant;
- automatically, through your use of our website;
- from your employer or the business you represent, where you are a Customer's representative; and
- from Customers, where Personal Information is processed on their behalf through the Flow2FA Services.
19.3 Purposes for Collection
- operating and securing our website and the Flow2FA Services;
- responding to enquiries and providing customer support;
- operating the AI assistant and improving its responses;
- delivering OTP and verification messages on behalf of Customers;
- billing, account administration, and business relationship management;
- fraud, abuse, and security incident prevention; and
- complying with legal obligations.
19.4 Disclosures for a Business Purpose
We disclose the categories of Personal Information described in Section 11 (How We Share Personal Data) to service providers and contractors for the business purposes described in this Privacy Policy, under written contracts that restrict their use of the information.
19.5 Sale or Sharing of Personal Information
Flow2FA does not sell Personal Information for money. The current version of flow2fa.com does not use Personal Information for cross-context behavioral advertising, and we do not use analytics or advertising cookies that would constitute "sharing" under the CCPA. If this changes, we will update this Privacy Policy and provide the required notice and opt-out mechanism.
19.6 Your California Rights
- Right to know / access the specific pieces and categories of Personal Information we have collected;
- Right to delete Personal Information we have collected, subject to certain exceptions;
- Right to correct inaccurate Personal Information;
- Right to opt out of the sale or sharing of Personal Information (not currently applicable, as described above);
- Right to limit use of Sensitive Personal Information (not applicable, as we do not collect Sensitive Personal Information through the website); and
- Right to non-discrimination for exercising any of these rights.
19.7 How to Exercise Your Rights
You may submit a request to know, access, delete, or correct your Personal Information by emailing dataprotectionofficer@flowstates.net or using our contact page. We will need to verify your identity before completing certain requests. Authorized agents may submit requests on your behalf; we may require proof of authorization and may ask you to verify your identity directly with us unless an exception applies.
19.8 Response Timelines
We will respond to California privacy requests within the period required by law. For requests to know, access, delete, or correct, we generally confirm receipt within 10 business days and respond within 45 calendar days, unless an extension is permitted by law.
20.Colombian Privacy Notice
This section applies to Personal Data processing subject to Colombian data protection law, including Law 1581 of 2012 and its implementing regulations.
20.1 Responsible Entity
Responsable del Tratamiento:
Flowstates Inc, doing business as Flow2FA
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Email: dataprotectionofficer@flowstates.net
20.2 Purposes of Processing
- providing and operating the Flow2FA Services;
- managing accounts and business relationships;
- delivering OTP and verification messages over WhatsApp, SMS, and email;
- providing customer support, including through our AI assistant;
- billing, accounting, and tax compliance;
- fraud, abuse, and security incident prevention;
- compliance with legal, regulatory, judicial, or contractual obligations; and
- responding to consultas, reclamos, complaints, and other rights requests.
20.3 Authorization
Where required by Colombian law, we will request prior, express, and informed authorization for the processing of Personal Data. Authorization may be obtained in writing, electronically, orally, by affirmative conduct, or by another mechanism that allows later consultation of the authorization. When requesting authorization, we will inform data subjects of the Personal Data to be collected, the purposes of processing, their rights, our identity and contact details, the optional nature of providing Sensitive Personal Data or children's data where applicable, and how to access this Privacy Policy.
20.4 Sensitive Data
The provision of Sensitive Personal Data is optional unless an exception applies under law. We will not condition any activity on the provision of Sensitive Personal Data unless legally permitted, and we will obtain express consent where required.
20.5 Children and Adolescents
Processing Personal Data of children and adolescents is restricted. Where such processing is permitted, it must respect the superior interests of the child or adolescent and their fundamental rights.
20.6 Colombian Data Subject Rights
- know, update, and rectify their Personal Data;
- request proof of the authorization granted for processing, unless an exception applies;
- be informed, upon request, about how their Personal Data has been used;
- file complaints with the Superintendencia de Industria y Comercio after completing the applicable consulta or reclamo process with us;
- revoke authorization and/or request deletion of Personal Data where applicable;
- access their Personal Data free of charge; and
- exercise any other right provided under Colombian law.
20.7 Procedure for Consultas and Reclamos
Privacy / Data Protection Office: dataprotectionofficer@flowstates.net
Requests should include:
- the data subject's full name;
- identification information sufficient to verify identity;
- contact details for response;
- a clear description of the request, consulta, or reclamo;
- supporting documents, where applicable; and
- if submitted by a representative, proof of authority to act.
Consultas will be answered within 10 business days from receipt. If we cannot respond within that period, we will explain the reason for the delay and provide a response within the additional period permitted by law. Reclamos will be handled within 15 business days from receipt of a complete claim; if incomplete, we may request additional information, and we will similarly explain any necessary delay. A data subject may file a complaint with the Superintendencia de Industria y Comercio only after first completing the applicable consulta or reclamo process with us.
20.8 International Transfers and Transmissions From Colombia
Personal Data subject to Colombian law may be transferred or transmitted outside Colombia, including to the United States and other countries where Flow2FA or its subprocessors operate. Where required, we will use contractual safeguards, transmission agreements, transfer mechanisms, authorization, or other measures required under Colombian data protection law.
20.9 Effective Date and Database Validity
This Colombian Personal Data processing notice is effective as of the "Effective Date" shown at the top of this page. Our databases will remain valid for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, compliance, dispute resolution, or legitimate business purposes.
21.AI Assistant Disclosure
Please read before using the assistant
The Flow2FA website includes an AI assistant that answers questions about our OTP delivery platform. Replies are generated automatically by an AI model and may be inaccurate, incomplete, or out of date — always verify anything important with our team via /contact.
When you use the assistant, we store your conversation — including the messages you send and receive, a random session identifier for that conversation, the page path where the session started, and your browser's user agent — in our backend database. Storing that identifier persistently in your browser is optional and controlled through your cookie and storage preferences, which you can open at any time from "Cookie settings" in the footer: where you have accepted assistant continuity, it is kept in localStorage so the conversation can resume across pages, reloads and later visits; where you have not, it is held in page memory only and discarded when the page is reloaded or closed. Either way, it is sent with your messages so we can group the server-side conversation records. Your messages, together with the assistant's prior replies, are transmitted through the Lovable AI Gateway to the configured Google Gemini model so that a reply can be generated.
Do not submit OTP codes, passwords, API keys, SMPP credentials, or other secrets, sensitive personal data, or confidential business information through the public assistant. The assistant is intended for general product and documentation questions only.
22.Marketing Communications
We may send account-related, transactional, service, and support communications to our Customers and business contacts as part of operating the Flow2FA Services. Where we send any promotional communications, we will do so only where permitted by law and will provide an opt-out mechanism. You may object to any such communications at any time by contacting dataprotectionofficer@flowstates.net. We may continue to send non-promotional communications, including transactional, account, security, billing, and legal messages.
23.Messaging Opt-Outs
If you receive an OTP or verification message sent by a Flow2FA Customer through the Flow2FA Services, the Customer is generally responsible for that message and for honouring your preferences. If you contact Flow2FA about a message you received, we may forward your request to the relevant Customer or help process the request as required by law, contract, or carrier rules. Because OTP and verification messages are transactional and typically required to complete authentication, an opt-out request may mean the Customer can no longer authenticate you through that channel.
24.Do Not Track and Opt-Out Preference Signals
Some browsers provide "Do Not Track" settings. Because there is no uniform industry standard for responding to Do Not Track signals, and because our website does not currently use advertising or analytics cookies, we do not respond differently to Do Not Track signals at this time. Where required by law, including California law, we will honour recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of any future sale or sharing of Personal Information for the relevant browser, device, or account.
25.Automated Decision-Making and Profiling
We do not use Personal Data for automated decision-making that produces legal or similarly significant effects without appropriate notice and lawful basis. Our AI assistant generates conversational replies only and does not make decisions about you. Where the Flow2FA Services include risk signals or delivery-monitoring logic used to route, retry, or fall back a message between channels, this operational logic is used to improve delivery reliability and does not constitute profiling that produces legal or similarly significant effects on End Users.
26.Legal Requests and Compliance
We may disclose Personal Data where we believe disclosure is necessary or appropriate to:
- comply with applicable law;
- respond to subpoenas, court orders, warrants, lawful government requests, or legal process;
- cooperate with regulators or law enforcement;
- protect the rights, property, or safety of Flow2FA, Customers, End Users, or others;
- investigate fraud, abuse, security incidents, or unlawful activity;
- enforce our agreements and policies; or
- preserve evidence or defend legal claims.
27.Business Transfers
If Flow2FA is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, Personal Data may be disclosed or transferred as part of that transaction, subject to appropriate safeguards and applicable law.
28.Third-Party Websites and Services
Our website and Services may link to third-party websites, platforms, or integrations, including channel providers such as WhatsApp, mobile carriers, and Customer-supplied vendors. We are not responsible for the privacy practices of third parties, and their own privacy policies govern their collection and use of Personal Data.
29.Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last Revised" date at the top of this page indicates when it was last updated. Where required by law, we will provide additional notice or obtain consent for material changes. See also our Website Terms of Use and Ethics Policy for related commitments.
30.Contact Us
For questions, privacy rights requests, complaints, Colombian consultas or reclamos, California privacy requests, GDPR requests, or other data protection concerns, please contact:
Flowstates Inc, doing business as Flow2FA
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Privacy Contact / Data Protection Officer: dataprotectionofficer@flowstates.net
Legal: legal@flowstates.net
Or use our contact page.
This Privacy Policy is governed by the laws of the State of New York, United States.