Last updated: 5 August 2026
Site Flow, operated by Other World Media Ltd (“we”, “us”, “our”), is the data controller for personal data processed through this platform. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Registered office: 48 West George Street, Glasgow, G2 1BP. ICO registration: ICO:00014390343. You can reach us about privacy at privacy@siteflow.app.
We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, we anonymise personal data rather than deleting records to preserve audit trail integrity. Anonymised data is retained indefinitely as it can no longer identify you.
Under UK GDPR, you have the following rights:
To exercise any of these rights, visit your Profile page where you can download your data or delete your account.
We use the following types of cookies:
We do not use third-party advertising or tracking cookies.
We do not sell your personal data. We may share data with your organisation's administrators who manage user accounts, and with law enforcement where required by law. We also use the following third-party sub-processors to provide the service. Each is bound by a data processing agreement (DPA) and processes data only on our instructions:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Application hosting, PostgreSQL database and Redis (cache / rate-limiting / realtime) | US / EU region — configurable |
| Cloudflare (R2 & CDN) | File and document (attachment) storage and CDN delivery | Cloudflare, Inc. — region-configurable |
| Resend | Transactional email (verification, password reset, notifications) | United States |
| Stripe | Subscription billing and payment processing | United States / EU |
| Sentry | Error monitoring and diagnostics | United States |
| Xero (only if you connect it) | Accounting / invoice synchronisation | New Zealand / international |
| Google (only if you connect it) | Calendar synchronisation and optional Google sign-in | United States |
This list is current as of the date above and may change as the service evolves; an up-to-date register is available on request.
Some of our sub-processors are located outside the United Kingdom. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — namely the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and/or reliance on a UK adequacy decision where one applies to the destination country. You can request details of the safeguards applying to a specific transfer using the contact details below.
We implement appropriate technical and organisational measures including password hashing, HTTPS encryption, encryption of sensitive tokens at rest, role-based access controls, and audit logging.
For privacy-related enquiries, contact us at privacy@siteflow.app.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.