FaciliFlow platform
Privacy notice
Last updated: 13 August 2026
This notice explains how personal data is handled across the FaciliFlow platform. The client organisation that invites you may provide additional instructions for its own workspace.
Who is responsible for your data?
When a client uses the FaciliFlow platform for its people, contracts, sites, maintenance, helpdesk, compliance, projects and asset evidence, that client normally decides why the information is used and acts as the data controller. FaciliFlow provides the platform and normally acts as the processor.
FaciliFlow is the controller for its own staff, supplier and business-contact information.
What we collect and why
We may process names, work email addresses, job roles, access assignments, project and site details, asset records, engineer comments, photographs and report history.
For account security and support, we record successful sign-in date and time, the FaciliFlow portal hostname used, and broad browser, operating-system and device categories. We do not retain IP addresses, precise location, full browser user-agent strings, device fingerprints, cookies or passwords in this login record.
We use this information to invite authorised users, control access, operate the modules assigned to each user, provide evidence-backed records and reports, keep an audit trail and support the service. We only ask for information that is relevant to those purposes.
Service providers
FaciliFlow uses carefully selected infrastructure providers, including Supabase for application data and authentication, Vercel for hosting and Resend for transactional email. Their access is limited to what is needed to provide the service and is governed by the relevant contractual and security arrangements.
Retention and your rights
Client organisations set the business retention period for their project records. We retain issued reports and audit history for as long as the client’s contract, legal or insurance requirements need them, then securely remove or anonymise them. Invitations and working drafts should be removed when no longer needed.
Successful-login security records expire after no more than 400 days. Access is restricted to authorised FaciliFlow administrators and managers within their assigned contract scope, or a client Workspace Admin viewing users in their own workspace.
You can ask the organisation that invited you to access, correct or delete your personal data, or to restrict how it is used. FaciliFlow will support the client with those requests where it acts as processor.
Security and contact
Access is role-based, client workspaces are isolated, and issued records retain an audit history. Do not upload unnecessary personal information or photographs of people into an asset record.
For privacy or data-protection questions, contact FaciliFlow through dan.evans@faciliflow.co.uk and include the client organisation and workspace involved.