Automation runs directly inside the AI platforms your business already uses: Claude, ChatGPT, and Gemini. This page covers how data is handled, what controls govern it, and where to go for more detail, whether you're working with FlowMate directly, through a platform partner, or connecting it to tools like HubSpot, Slack, or Intercom.
GDPR: FlowMate GmbH is a German company and processes personal data in accordance with GDPR.
SOC 2 Type II: in progress, targeted for Q1 2027.
No model training: your automation data is never used to train third-party AI models, beyond what's required to run the specific flow you've configured.
Flow data is processed in transit to run the automation you've configured, but isn't persisted afterward. The exception is activity logs, which record what ran and when, kept for 30 days to operate and troubleshoot the service, then automatically deleted.
FlowMate works with a small number of sub-processors to run the service. The complete, current list is in our Data Processing Agreement.
You control how much autonomy an automation has:
Runs without manual review of each action.
Runs with visibility into each action as it happens.
Requires explicit approval before execution.
This means the level of human oversight on any given flow is a setting you choose, not something fixed in advance.
The platform is built on a component-based architecture with a single, authenticated entry point for all external traffic, network segmentation between internal services, mandatory multi-factor authentication and role-based access internally, and encryption in transit and at rest. For the full technical detail, see the Security page.
Since FlowMate operates inside Claude, ChatGPT, and Gemini, it's worth being precise about where each provider's responsibility ends and FlowMate's begins:
When FlowMate is used through one of these platforms, the platform provider (Anthropic, OpenAI, or Google) processes the prompts, context, and outputs of that session under its own privacy terms.
The automation layer runs on top of this and receives only the data needed to execute the configured flow. It doesn't have broader access to conversations or accounts beyond that.
For businesses and platforms that connect FlowMate to third-party tools (HubSpot, Slack, Intercom, and others):
Only the OAuth scopes required to run the specific automations set up are requested, not broad account access by default.
Access can be reviewed and revoked at any time.
This section is also what's shared when an app platform, such as HubSpot or Slack, reviews FlowMate as part of its own app approval process.
Workspace-level permissions: admins manage who can create, edit, or run automations within their account.
Visibility: activity logs let admins see what automations have run and what they did.
Flow-level control: the Automated / Assisted / Supervised setting above gives admins a direct lever over how much autonomy any single automation has.
For formal vendor assessments, app reviews, or anything not covered here, we're glad to walk through it directly.
Book a Security Review© 2026 FlowMate GmbH, Cologne. All rights reserved.