Floral Privacy Policy

Version 2026-09-24.2

This policy explains how Floral handles personal data when you visit our website, contact us, use our applications or take part in a meeting processed through Floral. It covers what we collect, why we use it, who receives it, where it goes, how long it is kept and your choices and rights.

Private customer content is processed within the EEA under the DPA, with the service's EU locations described below. Limited account, authentication, billing and operational personal data, and separately sourced public business information, may be processed in the US.

1 Who we are and our responsibilities

Floral ApS, CVR 44598574, Vesterbrogade 29F, st., 1620 Copenhagen V, Denmark, provides Floral. You can contact us about this policy, privacy rights or a security concern at [email protected].

We act as a data controller when deciding how to handle our website, enquiries, sales and contractual contacts, marketing preferences, billing, statutory records and the limited records we need to protect our own legal rights. This policy explains that processing.

For personal data in a customer's workspace and processing carried out on its behalf, the customer normally acts as controller and Floral acts as processor under our Data Processing Agreement, or DPA. This includes meeting content, CRM records, connected sources, AI inputs and outputs and related service records. If our customer itself acts for another controller, Floral acts as its subprocessor. The relevant controller decides the purposes, lawful basis, users and retention instructions. Its privacy information also applies.

If your employer or another organisation gives you access, it administers your workspace and can manage users, permissions, sharing, connected systems, records and retention within the service's controls. Data shared with a workspace can remain available to the organisation after you leave. Contact its administrator about its practices. We can help identify the appropriate contact where possible without exposing another customer's information.

2 Personal data and where we obtain it

We collect information you provide through forms, account and billing flows, meetings, uploads, messages and support requests. We also receive information from the customer, its authorised users, selected integrations and public business sources. Our systems and service providers generate necessary technical and service records when the website or product is used.

CategoryExamples and sources
Identity and business contactsName, work email, employer, role, business contact information, organisation membership, permissions and account identifiers supplied by you, an administrator or an authorised identity provider.
Enquiries and contractual recordsYour messages, requested demo or service, correspondence, agreed orders, terms acceptance, privacy choices and the identity and authority of the organisation's representative.
BillingBilling contact and address, company and VAT details, subscriptions, invoices, transaction references and limited payment status. Our payment provider handles payment credentials through its secure payment flow; do not put payment-card details in workspace records or support messages.
Workspace and connected dataBusiness and CRM records, tasks, files, notes and the data made available through sources and integrations that the customer authorises. Calendar connections provide the permissions and event details needed for the selected calendar and meeting functions. Connecting a calendar does not give us general access to a mailbox.
Meeting and AI dataParticipant and speaker information, meeting details, temporary audio, transcripts, summaries, statements, prompts, responses, extracted information, embeddings and authorised actions. These can contain information about people mentioned in a meeting who do not use Floral. Inferences and summaries can also be personal data.
Technical and service recordsIP address, browser or device type, operating system, timestamps, account and organisation identifiers, authentication and security events, feature-use events, errors and delivery records. These records can identify a person even when they contain no meeting text.
Public business informationNecessary company names, public business websites, locations, register information and publicly listed business contacts obtained through authorised website imports, research and company-register sources. Public availability does not make personal data anonymous.

You choose whether to provide optional information. We identify information needed for a particular account, enquiry or transaction in that flow. Without required information, we may be unable to provide the requested function. Device permissions such as microphone or calendar access can be withdrawn in the relevant device or provider settings, which can prevent the associated feature working.

3 Why we process data and our lawful bases

The table below concerns processing for which Floral is controller. GDPR Article 6 bases do not replace the customer's responsibility to establish a lawful basis for workspace processing.

PurposeLawful basis and limits
Operate and protect our website and business relationshipOur legitimate interests under Article 6(1)(f) in providing a functioning website, communicating with business representatives, administering the relationship and preventing misuse. We use the information necessary for those purposes and consider the effects on individuals.
Respond to enquiries and arrange a demo or purchaseOur legitimate interests in responding to the request and communicating with the organisation. Article 6(1)(b) applies where necessary to take requested steps or perform a contract with you personally, such as a sole trader. An employee's organisation having a contract is not itself a contract with that employee.
Invoicing and statutory accountingArticle 6(1)(c) for Danish accounting and tax obligations. Necessary business-contact administration also relies on legitimate interests, or contract where you personally are the contracting party.
Optional website analytics and electronic marketingYour consent under Article 6(1)(a) where requested. Non-essential device storage or access also requires the applicable cookie consent. We do not make optional marketing or analytics consent a condition of buying the service.
Handle privacy requests and regulatory obligationsArticle 6(1)(c) to meet applicable data-protection and other legal duties.
Establish or defend a specific legal claim and retain necessary evidenceOur legitimate interests in protecting legal rights, or a legal obligation where one applies. This does not give us a general right to retain or reuse customer meeting content after the DPA requires deletion.

You can object to processing based on legitimate interests. We then assess the request under the GDPR. You can withdraw consent at any time without affecting the lawfulness of earlier processing. Marketing messages provide an unsubscribe route, and you can also contact [email protected]. Necessary security, billing and contractual messages continue where required for the service or law.

We do not sell personal data or use private customer content for advertising. We do not make solely automated decisions about you that produce legal or similarly significant effects as part of our own controller processing.

4 Meetings transcripts summaries and AI

The customer chooses the meetings and sources it is authorised to process, subject to permissions and supported settings. It must give participants appropriate information and obtain consent where the applicable law requires consent. A user accepting Floral's Terms, or inviting a bot, is not consent from everyone in the meeting.

Transcripts, summaries and related records support the customer's authorised features, including search and AI chat. The customer controls their retention under the DPA. Audio is temporary transcription material.

AI providers process content only for requested features under the DPA. Neither Floral nor its providers use customer content, including de-identified or aggregated derivatives, to train or fine-tune models. Outputs and transcripts can be inaccurate. Users must check relevant sources and apply human review before consequential use.

The standard service is for ordinary business information. Intentional processing of restricted categories, such as health or criminal-offence data, CPR numbers or HR personnel-case files, requires a suitable written arrangement under the Terms and DPA. Accidentally submitted data remains protected and should be reported through a secure route for lawful handling.

5 Who receives personal data

Access is limited to authorised Floral personnel, the customer's authorised users and recipients, and providers needed for the relevant service. Our personnel work in Denmark and are subject to confidentiality. Workspace access and sharing depend on the customer's permissions and instructions.

Our product providers supply hosting and storage, identity, AI and meeting processing, document extraction, email delivery, service analytics, support, diagnostics, billing and permitted public-information research. The Trust Portal provider list describes their roles and locations. The accepted DPA's Annex C controls permitted processing; a listed provider receives data only where needed for an authorised feature.

For our own business administration, we use hosting, communication, document and contract-management, payment, accounting and professional-advisory providers. They receive only information needed for their role. Relevant providers act under processing obligations or, for their own regulated or professional functions, as independent controllers.

An authorised customer connection, external AI client, API, export or sharing action may disclose data to a destination chosen by the customer. That destination's terms and privacy practices apply to its own handling. We remain responsible for Floral's implementation and the providers we appoint.

We may disclose necessary information to regulators, courts or other lawful recipients where legally required, or to advisers for a specific legal matter. We assess requests, limit disclosure and provide notice where permitted.

6 Processing locations and international transfers

Private customer content is processed within the EEA by Floral and its appointed providers under the DPA. Annex C identifies their roles, locations and limits, including EU AI, storage and Mailgun processing. Floral personnel access customer data from Denmark.

Limited account, authentication, billing, delivery and operational data can be processed in the US. This can include work names and emails, account identifiers, IP addresses, login events and subscription records.

Invitation emails sent or forwarded to Floral, including attachments, pass through Mailgun's EU region. Mailgun keeps messages and related delivery records for no more than three days.

Public-web collection and company research may process public business information in the US through providers listed in DPA Annex C. They do not receive private customer content.

Transfers outside the EEA must have a valid GDPR Chapter V basis. This may be an applicable adequacy decision, including the EU-US Data Privacy Framework where the specific recipient has active, relevant certification, or the European Commission's Standard Contractual Clauses with any necessary assessment and supplementary safeguards. We do not treat policy acknowledgement as a substitute for those safeguards. You may request information about the applicable arrangement and a copy of relevant safeguards at [email protected], with lawful redactions to protect others' information and security.

7 Retention and deletion

We keep personal data only as long as needed for the relevant purpose and applicable legal obligations. We consider the data's sensitivity, the active relationship or request, lawful instructions and whether the purpose can be met with less information.

RecordsPeriod or retention criteria
Workspace data including transcripts and summariesFor the customer's active lawful purpose until deletion or a shorter supported instruction. The customer should review its need regularly. The DPA's end-of-service schedule applies when service ends.
Temporary processing and diagnosticsAudio and provider copies: up to seven days. Routine diagnostics: up to 30 days. Security records: up to 90 days. See DPA Annex D for the full schedule.
Customer-content support messagesFor the active case and no more than 30 days after closure.
Own enquiries and business contactsWhile handling the enquiry and maintaining a relevant business relationship. We remove or minimise information when follow-up ends or a contact becomes obsolete, except for necessary contract, accounting or specific claim evidence.
Accounting materialFive years from the end of the financial year to which it relates, or another period specifically required by applicable law. It does not include a general archive of customer workspace content.
Marketing and privacy choicesWhile the relevant preference remains applicable. We may retain a minimal suppression or consent record where necessary to respect your choice or demonstrate compliance.
Specific legal claimsOnly the records necessary for the identified claim and its applicable limitation, proceeding or legally required retention period, with restricted access.

At service end, the customer may request return, deletion or both. The DPA sets a 30-day export window, a 30-day retrieval window and up to 90 days for restricted backups after active deletion. A deletion-only instruction requires active deletion within 30 days.

Removing your membership does not necessarily delete the organisation's records. Copies lawfully exported to recipients or held in a customer's separate systems follow those recipients' responsibilities. Contact the relevant controller about them.

8 Cookies and similar technologies

The website and web application use cookies or similar storage for functions such as authentication, security and preferences. The website also remembers your analytics choice. The signed-in app uses PostHog storage for feature flags and usage analytics, as described in our Cookie Policy.

On floral.so, optional analytics starts only if you allow it in Cookie settings. You can decline or withdraw there. The website choice does not control the signed-in app's usage analytics. Workspace-related service records are processed under the customer's instructions and DPA.

Service analytics excludes meeting text, customer prose and private form values. Our Cookie Policy lists the technologies, providers, purposes and lifetimes.

9 Security

We apply technical and organisational measures appropriate to the processing risk, including access restrictions, confidentiality, encryption in transit and at rest, tenant authorisation, controlled changes and procedures for incidents, recovery and deletion. The DPA describes our contractual security measures.

Use your assigned account, protect your device and credentials, review sharing and promptly report suspected misuse. Ask us for a secure transfer route if a support case requires sensitive material.

10 Your rights and how to exercise them

Depending on the circumstances, you can request access to your personal data and information about its use, correction, erasure, restriction, and a portable copy where the GDPR's conditions apply. You can object to processing based on legitimate interests and to direct marketing, and withdraw consent where consent is used. These rights are subject to the GDPR's conditions and lawful exceptions.

Contact [email protected] for Floral's controller processing. We normally respond within one month of receiving a request. Where the GDPR permits a necessary extension of up to two further months, we tell you within the first month and explain why. We may request proportionate information to verify identity or clarify the request. We do not require unnecessary identity documents. Requests are normally free of charge, subject to the GDPR's rules for manifestly unfounded or excessive requests.

For customer-controlled workspace data, contact the organisation responsible for the meeting or workspace. If you contact Floral, we help route the request and assist the controller under the DPA. We do not disclose customer records or make the customer's substantive decision without authority or a legal requirement.

You can complain to the Danish Data Protection Agency, Datatilsynet, through datatilsynet.dk, or to a competent supervisory authority in the country where you live or work or where the alleged infringement occurred. You do not have to contact us before exercising that right.

11 Children and changes to this policy

Floral is a business service for adult users and is not directed at children. Customers must not intentionally use the standard service for children's case files or unsupported sensitive uses. If you believe a child has provided information improperly, contact the responsible organisation or [email protected] so the situation can be assessed and the data handled lawfully.

We update this policy when our practices or legal requirements change and identify the version. We provide appropriate advance information about material changes, for example by email or an in-product notice. A revised policy does not itself change an accepted DPA, authorise new purposes or replace any consent or contractual acceptance required for a change.