Scope
This policy explains how Fliplet handles personal data, when we act as a controller or processor, and the rights available to you.
Last updated:
This privacy policy explains how Weboo Online Limited, trading as Fliplet ("Fliplet", "we", "us" or "our"), collects, uses, stores and shares personal data when you use our websites, products and services.
Fliplet provides a no-code and low-code platform that enables customers to create, manage and publish mobile and web applications. Depending on how you interact with Fliplet, we may act as a data controller or a data processor.
This policy should be read together with our Terms of Service, Data Processing Addendum, Sub-processors page and any other privacy notice or agreement provided to you or your organization.
1. Who we are
Weboo Online Limited is a company registered in England and Wales under company number 06974225.
Registered office: 14a Sydenham Road, Croydon, England, CR0 2EE.
Trading name: Fliplet.
Privacy contact: support@fliplet.com.
Subprocessor queries: hello@fliplet.com.
2. Scope of this policy
This policy applies to personal data processed through:
- our website at https://fliplet.com and related Fliplet websites;
- Fliplet Studio, Fliplet Viewer and other Fliplet products;
- support, sales, marketing, customer success and account-management interactions;
- forms, demos, webinars, events, downloads and other communications with Fliplet.
This policy does not apply to third-party websites, services or applications that are not controlled by Fliplet. It also does not replace a privacy notice provided by a Fliplet customer for an application they create using Fliplet.
If you use an application created by one of our customers, that customer is normally responsible for telling you how your personal data is used in that application.
3. When Fliplet is a controller and when Fliplet is a processor
Fliplet acts as a data controller when we decide why and how personal data is processed. This includes, for example, when we process personal data for account management, website analytics, sales, billing, marketing, security, customer support and our own business operations.
Fliplet acts as a data processor when we process customer personal data on behalf of a customer through the Fliplet platform. In those circumstances, the customer is normally the controller and Fliplet processes the data in accordance with the customer's instructions, the applicable agreement and our Data Processing Addendum.
4. Personal data we collect
We may collect and process the following categories of personal data.
Identity data: name, username, job title, employer, account identifiers and similar information.
Contact data: business email address, phone number, postal address, billing address and communication details.
Account data: login details, organization, role, permissions, account settings, product plan, workspace details and support history.
Customer content and app data: content, files, forms, datasets, app configuration, user records and other information uploaded, created or processed through Fliplet by customers and their authorized users.
Usage data: information about how you use our websites, products and services, including pages viewed, features used, actions taken, session activity, clicks, timestamps and interactions.
Technical data: IP address, browser type and version, device identifiers, operating system, time zone, approximate location, diagnostic data, log data and security events.
Financial and transaction data: billing details, payment status, invoices, products or services purchased, subscription details and payment-related records. Payment card details are normally processed by our payment provider and not stored directly by Fliplet.
Marketing and communications data: marketing preferences, event registrations, email engagement, survey responses, feedback and communication history.
AI input and output data: where you or your organization use AI-powered features, this may include prompts, instructions, uploaded content, generated output and related metadata needed to provide the feature.
Special category data: Fliplet does not intentionally collect special category data for its own website, sales or account-management purposes. However, customers may configure Fliplet applications to collect or process special category data, such as health data or other sensitive information. Where that happens, Fliplet processes that data as a processor on behalf of the customer and in accordance with the applicable customer agreement.
5. How we collect personal data
We collect personal data in the following ways:
- directly from you when you create an account, request a demo, contact us, use our products, attend an event, complete a form, subscribe to communications or provide feedback;
- automatically when you use our websites, products or services, including through cookies, server logs and similar technologies;
- from your organization, where your employer or another organization creates an account for you or invites you to use Fliplet;
- from customers and users who upload data into Fliplet applications;
- from third parties such as analytics providers, advertising networks, CRM tools, payment providers, app stores, communication tools and publicly available sources.
6. How we use personal data
We use personal data for the following purposes:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and manage user accounts | Identity, contact, account and technical data | Performance of a contract; legitimate interests |
| Provide Fliplet products and services | Account data, customer content, app data, technical data and usage data | Performance of a contract; legitimate interests; processor activities carried out under customer instructions |
| Provide support and customer success | Identity, contact, account, support and technical data | Performance of a contract; legitimate interests |
| Process billing and payments | Identity, contact, financial and transaction data | Performance of a contract; legal obligation; legitimate interests |
| Protect security and prevent misuse | Account, technical, usage, log and security data | Legitimate interests; legal obligation |
| Monitor, maintain and improve our services | Technical data, usage data, support data and aggregated data | Legitimate interests |
| Provide AI-powered features | AI input and output data, customer content where submitted to AI features, usage data and technical data | Performance of a contract; legitimate interests; processor activities carried out under customer instructions |
| Send service communications | Identity, contact, account and transaction data | Performance of a contract; legitimate interests; legal obligation |
| Send marketing communications | Identity, contact, usage and marketing data | Consent where required; legitimate interests where permitted by law |
| Manage events, webinars and demos | Identity, contact, marketing and communications data | Consent; performance of a contract; legitimate interests |
| Comply with legal and regulatory obligations | Any relevant personal data | Legal obligation; legitimate interests |
| Manage business operations, professional advice and corporate transactions | Identity, contact, account, transaction and business records | Legitimate interests; legal obligation |
We may also use aggregated or anonymized information for analytics, benchmarking, reporting, product improvement and business planning. Where data is truly anonymized, it is no longer personal data.
7. AI-powered features
Fliplet may provide AI-powered features and integrations that allow customers and users to generate, summarize, classify, translate, analyze or transform content.
Where AI-powered features are used, data submitted to those features may be processed by Fliplet and relevant AI subprocessors, including providers listed on our Sub-processors page. This may include prompts, uploaded content, customer content, generated responses and technical metadata needed to provide, secure and monitor the feature.
Fliplet does not permit its subprocessors to use customer personal data for their own independent purposes. Where AI providers are used, they are engaged under contractual terms intended to restrict processing to the provision of the relevant services to Fliplet.
You and your organization are responsible for deciding what information is submitted to AI-powered features. Unless your agreement with Fliplet specifically permits it and appropriate controls are in place, you should not submit special category data, confidential client data or highly sensitive information to AI-powered features.
For OpenAI API services, Fliplet has entered into a Business Associate and Healthcare Addendum with OpenAI and has Zero Data Retention agreed for the relevant OpenAI API organization. This enables use for HIPAA-related workloads only where Fliplet and the customer use eligible OpenAI API services, eligible HIPAA endpoints and the applicable OpenAI HIPAA implementation guidance. This does not apply to all OpenAI services, all OpenAI features, ChatGPT consumer or team products, third-party services, web search, or any non-eligible endpoint or feature.
Different AI features and providers may have different retention, logging and availability controls. Where a customer has specific requirements, such as zero data retention, modified abuse monitoring, data residency or HIPAA-related controls, those requirements should be agreed with Fliplet in writing before the feature is used for regulated or sensitive workloads.
8. Cookies and similar technologies
We use cookies and similar technologies to operate our websites and products, keep users signed in, remember preferences, understand how our services are used, provide support, measure marketing activity and improve our services.
The types of cookies and similar technologies we may use include:
- strictly necessary cookies, which are required for security, authentication, session management and core product functionality;
- analytics and performance cookies, which help us understand traffic, usage and product performance;
- functionality cookies, which remember preferences and improve user experience;
- support and messaging cookies, which help us provide in-product and website support;
- advertising and marketing cookies, which help us measure campaigns and provide relevant communications where permitted.
Examples of tools that may use cookies or similar technologies include Google Analytics, Google Tag Manager, HubSpot, PostHog, Segment, Userpilot, and Fliplet authentication cookies.
Where required by law, non-essential cookies will only be used with your consent. You can manage cookies through our cookie banner or preference tool, and you can also control cookies through your browser settings.
If you disable some cookies, parts of our websites or products may not work as intended.
9. Marketing communications
We may send marketing communications where you have requested information, registered for an event, used our services, downloaded content, or where otherwise permitted by law.
You can opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us.
We will not sell your personal data. We will not share your personal data with third parties for their own direct marketing unless we have your consent or another lawful basis to do so.
Service, security, billing and account communications are not marketing communications and may still be sent where necessary.
10. When we share personal data
We may share personal data with:
- hosting, infrastructure and storage providers;
- payment and billing providers;
- customer support and communications providers;
- analytics, monitoring and error-tracking providers;
- CRM, sales, marketing and event-management providers;
- AI service providers where AI-powered features are used;
- app store, build, notification and distribution providers;
- professional advisors, auditors, insurers and legal advisors;
- regulators, law enforcement agencies, courts or public authorities where required or permitted by law;
- third parties involved in a business sale, merger, acquisition, restructuring or similar transaction.
We maintain a public Sub-processors page at https://fliplet.com/subprocessors/ which lists key third-party processors and subprocessors used to provide and support Fliplet services.
Where we act as a processor for a customer, subprocessors are engaged in accordance with our Data Processing Addendum or the relevant customer agreement.
11. International data transfers
Some personal data may be processed outside the United Kingdom, European Economic Area or the country where you are located. This may happen because Fliplet, our customers, users or service providers operate internationally.
Where personal data is transferred internationally, we use appropriate safeguards where required by law. These may include:
- adequacy decisions;
- the European Commission's Standard Contractual Clauses;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- transfer risk assessments and supplementary measures where appropriate.
Further information about relevant subprocessors and processing locations is available on our Sub-processors page.
12. Security
We use appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
These measures include access controls, encryption, logging, monitoring, staff confidentiality obligations, supplier due diligence and security processes appropriate to the nature of the data and services involved.
Security is also a shared responsibility. Customers are responsible for configuring their Fliplet applications appropriately, managing user access, setting permissions, applying security rules, maintaining backups where appropriate and ensuring their use of Fliplet complies with applicable law.
If you believe personal data has been misused, lost or accessed without authorization, contact us at support@fliplet.com.
13. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
Retention periods depend on the type of data, the purpose of processing, contractual requirements, legal obligations, security needs and whether the data is processed by Fliplet as controller or processor.
For example:
- account and customer relationship records are retained while the account or relationship is active and for a reasonable period afterwards;
- billing, tax and accounting records are retained for the period required by law;
- support and communication records are retained for customer service, audit and dispute-resolution purposes;
- security logs are retained for security, fraud prevention and incident investigation;
- marketing records are retained until you opt out or the data is no longer needed;
- customer application data is retained in accordance with the customer agreement, product configuration and Data Processing Addendum.
Where Fliplet processes customer personal data as a processor, deletion or return of that data following termination is handled under the applicable customer agreement and Data Processing Addendum. Unless a different agreement applies, customer personal data may be made available for export and deleted in line with the DPA and any legal retention requirements.
We may anonymize personal data so it can no longer be associated with an individual. We may use anonymized data indefinitely.
14. Your rights
Depending on where you are located and the nature of the processing, you may have rights to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- request portability of personal data;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
To exercise your rights, contact support@fliplet.com.
If your request relates to personal data processed by Fliplet on behalf of one of our customers, we may refer the request to that customer or ask you to contact them directly.
You also have the right to complain to the UK Information Commissioner's Office at https://ico.org.uk/. If you are located outside the UK, you may also have the right to complain to your local supervisory authority.
15. Children's data
Fliplet's websites and products are not intended for children under 16, and we do not knowingly collect personal data from children for our own purposes.
Customers may choose to use Fliplet applications in contexts involving children. Where they do so, the customer is responsible for ensuring that their use of Fliplet complies with applicable law and that appropriate notices, consents and safeguards are in place.
16. Third-party links and integrations
Our websites and products may contain links to third-party websites, plug-ins, integrations, app stores or services. Those third parties may process personal data under their own privacy notices.
We are not responsible for the privacy practices of third-party websites or services that are not controlled by Fliplet.
17. Changes to this policy
We may update this policy from time to time. The updated version will be posted on our website with a new "last updated" date.
Where required by law or contract, we will provide additional notice of material changes.
18. Contact us
For privacy questions or to exercise your rights, contact:
Weboo Online Limited trading as Fliplet
Registered office: 14a Sydenham Road, Croydon, England, CR0 2EE
Email: support@fliplet.com
Subprocessor queries: hello@fliplet.com
Contact
Notices to Fliplet can be sent to support@fliplet.com.