Privacy policy
Last updated: 26 September 2026 · Versione italiana
1. Who we are
FloQ is a service of LOGIN SRL (“SoftwareX”), Via Legnano 26, 63821 Porto Sant'Elpidio (FM), VAT IT02573380447. Privacy questions: privacy@software-x.it.
This policy (Articles 13 and 14 of the EU General Data Protection Regulation, “GDPR”) covers:
- your FloQ account data (name, email, sign-ins), for which SoftwareX is the controller;
- your team’s content (connected mailboxes, chat, codes), for which the company or professional who created the team is the controller, and SoftwareX processes it on their behalf as a processor (Art. 28 GDPR).
2. What we process, why and for how long
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, password (stored only as a hash), optional profile picture | Create and run your account | Contract (Art. 6.1.b) | While the account exists, then 30 days |
| Connected devices, date and time of sign-ins (IP addresses are used in memory only, to limit attempts) | Account security, new sign-in alerts | Legitimate interest in security (Art. 6.1.f) | 12 months |
| Verification codes sent by email | Address confirmation, two-step sign-in, password reset | Contract | 15 minutes |
| Identifier of the Microsoft or Google account used to sign in | Sign in with Microsoft or Google | Contract | While linked to the account |
| Push notification tokens | Send the notifications you chose | Contract | While the device stays connected |
| Team activity log | Security and accountability within the team | Legitimate interest | 24 months |
| Connected AI assistants (app, team, permissions, last use) and the log of what they read (tool used and target, never the content) | Running the connection, showing it to you and to the team’s owners | Contract and legitimate interest in security | Connection: until you revoke it or it goes unused for 60 days; log: 90 days |
For team content FloQ stores: email metadata (sender, recipients, subject, date, folder, status and a 200-character preview), chat messages and attachments, mailbox credentials and 2FA secrets (encrypted). Full email bodies and email attachments are never written to our disks: they are read from the mail provider when someone opens the message and kept in memory for at most 15 minutes.
3. Google and Microsoft mailboxes and sign-in
You can connect a Gmail or Google Workspace mailbox, or a Microsoft 365 / Outlook mailbox, by signing in with that account instead of typing its password. You can also sign in to FloQ with your Google or Microsoft account.
What FloQ accesses.
- Signing in to FloQ (
openid,email,profile): your email address, name and an account identifier, to recognise you when you sign in. - Google mailbox (
https://mail.google.com/) or Microsoft mailbox (IMAP.AccessAsUser.All,SMTP.Send): reading folders and messages over IMAP and sending over SMTP on your behalf. This is the only permission Google and Microsoft offer for using a mailbox over IMAP and SMTP.
How FloQ uses it. Only to provide the features you see in the app: showing folders and messages to you and to the team members you chose to share the mailbox with, searching, sending the emails you write, carrying out your actions (mark as read, move, archive, delete) and notifying you of new messages. A personal mailbox is visible only to you.
What FloQ does not do. It does not sell this data, use it for advertising, profiling or market research, use it to train artificial intelligence or machine learning models, or share it with anyone other than the technical providers listed below as needed to run the service, or as required by law. No one at SoftwareX reads your email, except with your explicit consent for a problem you ask us to solve, for security reasons, or to comply with the law.
Protection and retention. The token issued by Google or Microsoft is encrypted (AES-256-GCM) with a key of its own for each team. Message metadata is kept while the mailbox is connected; full bodies are never stored on disk. When you disconnect the mailbox from FloQ, its token and all its data are deleted from the database immediately and from backups within 30 days. You can also revoke access at any time at myaccount.google.com/permissions or myapps.microsoft.com.
Limited Use. FloQ’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. AI assistants
You can connect FloQ to an AI assistant of your choice (for example Claude or ChatGPT) through the MCP protocol, if your team’s owners allow it. The assistant has access, in one team, to what you see: the mail of the mailboxes you can access and the channels and direct messages you can read. It is read-only by default; only if the team’s owners allow it and you agree, can it also answer mail, send mail and write in the chat on your behalf. It cannot see 2FA codes. How it works.
When the assistant reads a mail or a message, that content is sent, at your request, to the service you connected. From then on that provider handles it under its own terms and privacy policy, which SoftwareX does not control: check your assistant’s settings, including whether conversations are used to train models. The assistant’s provider is not one of our providers: you choose it.
Gmail mailboxes connected with Google are never available to assistants: data received from Google APIs is not transferred to third-party artificial intelligence services. You get an email at every new connection; you can revoke it at any time from Profile → AI assistants, and the team’s owners can switch assistants off for everyone.
5. Recipients
Data is stored on servers in the European Union. These providers process it only as needed to run the service:
| Provider | Service | Data |
|---|---|---|
| OVH SAS (France) | Server: database, sync, backups | All service data |
| Cloudflare, Inc. (USA) | Network to the server; storage of chat attachments and encrypted backup copies | Traffic in transit, chat attachments, encrypted backups |
| Resend, Inc. (USA) | System emails (codes, invitations, alerts) | Name, email and content of the system email |
| Apple Inc. (USA) | Push notifications on iPhone, iPad and Mac | Device token, notification title and preview |
| Google LLC (USA) | Push notifications on Android (Firebase Cloud Messaging) | Device token, notification title and preview |
Transfers to US providers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses. As mail providers, Google, Microsoft and the others are not our providers: you or your team choose them, and FloQ connects to them on your behalf. FloQ uses no third-party analytics or tracking.
6. Security
Encrypted connections; argon2 password hashing; mailbox credentials, tokens and 2FA secrets encrypted with a per-team key; two-step sign-in by email code; alerts on every new sign-in; sessions revocable per device; encrypted nightly backups; an updated, automatically monitored server.
7. Your rights
You can ask to access, correct, delete, restrict or port your data, and object to processing (Articles 15–22 GDPR), by writing to privacy@software-x.it. You can delete your account at any time from the app or on the Delete your account page. For a team’s content, also contact the company that runs it; SoftwareX helps it respond. You can lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or your local authority.
8. Changes
We announce important changes in the app or by email before they apply. The date at the top shows the latest version.