Flowvent

Legal & Compliance

Privacy Policy

Effective October 1, 2026

This Privacy Policy ("Policy") explains how Flowvent ("we", "us", or "our") collects, processes, shares, and safeguards personal information across our web platform (including flowvent.app and associated tenant subdomains) and our native mobile applications, including Flowvent Track (event ticketing, attendee safety, and live tracking) and Flowvent Bio Check-in (enterprise biometric attendance, facial verification, and workplace management).

1. Who controls your data

Flowvent powers event registration, attendance tracking, and workplace management. Legal roles vary depending on whether you are interacting with an event workspace or a workplace attendance organization:

  • Event Workspaces (Conferences, Camps, Gatherings): When an organization or event host uses Flowvent to manage registrations and entry check-ins, that host organization is the independent Data Controller for all attendee, child, and guardian details. Flowvent acts as aData Processor processing that data strictly on the host's documented instructions.
  • Workplace Attendance (Flowvent Bio Check-in): An organization (your employer or contractor) creates a workspace and registers staff. In data protection terms:
    • Your Employer/Organization is the Data Controller for attendance, shift records, work hours, payroll compensation settings, and internal staff notes. It determines why attendance records are kept and how long they are maintained under employment law.
    • Flowvent acts as the Data Controller for your direct platform account credentials, enrolled biometric face embeddings, consent audit logs, and hardware device public keys, and as a Data Processor for the organizational attendance ledger.
  • Platform Account Holders: Flowvent serves as an independent Data Controller for direct account credentials of event organizers, officials, administrators, and visitors to our public marketing surfaces.

2. What we collect

We collect only the minimum personal data strictly necessary to deliver event ticketing, safe attendance, and biometric check-in workflows:

CategoryData ElementsStorage & Protection
Account CredentialsFull name, email address, mobile number (optional), salted password hash.PostgreSQL database; passwords hashed with modern algorithms, never plain text.
Biometric Face VectorA 512-dimension mathematical vector ("embedding") produced by our self-hosted AuraFace model. We never store your photo as your biometric template.Self-hosted PostgreSQL (pgvector extension). Never exposed via public API endpoints.
Biometric Consent LogConsent version agreed to, timestamp, IP address, device platform.PostgreSQL compliance audit ledger.
Hardware Fingerprint KeysCryptographic public key tied to device secure hardware (WebAuthn/FIDO). Your raw fingerprint never leaves your device.Public verification key stored in PostgreSQL. Biometric matching is handled locally by iOS/Android OS.
Check-in EvidenceSnapshot captured at clock-in, GPS geofence coordinate verification, timestamp.Private object storage (encrypted). Auto-deleted after 30 days or immediately upon consent withdrawal.
Enrollment PhotoInitial photo taken during face enrollment.Purged within seconds in-memory/temp storage immediately after generating the vector embedding.
Attendance & Check-insCheck-in/out timestamps, entry gate, official operator, geofence match status.PostgreSQL chronological ledger.
Payroll & Banking (Optional)Salary amount and payout bank account details (only for organizations with Payroll enabled).Verified via Paystack account-lookup; encrypted database storage.
Event RegistrationsAttendee names, custom organizer form fields, squad/room grouping, emergency contacts.Encrypted PostgreSQL tenancy database.
Payment MetadataTransaction reference, settlement amount, currency, timestamp.Processed via Paystack PCI-DSS gateway. Flowvent never stores credit card numbers.

3. Mobile Application: Flowvent Track

The Flowvent Track mobile application provides real-time event check-in, ticket verification, and attendee safety for conferences, youth camps, and summits. To perform these native functions, the app may request the following operating system permissions:

A. Camera Access (QR Scanning)

Permission: CAMERA. Used exclusively by authorized event officials and guardians to scan ticket barcodes and attendee QR codes for rapid, touchless verification.

Data Protection: The camera feed is analyzed in real time on-device. We do not photograph, record, store, or transmit raw camera video during ticket QR scanning.

B. Precise & Approximate Location (Geofencing & Safe Zones)

Permission: ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION (when in use). Used to center venue maps, display authorized attendee location markers on official event dashboards, and configure virtual geofences ("Safe Zones") around event perimeters.

Data Protection: Location is queried only during active tracking sessions authorized by the event organizer and registered guardian. Location data is never used for advertising or cross-app tracking.

C. Push Notifications

Permission: POST_NOTIFICATIONS. Delivers instant event announcements, check-in verification receipts, boundary exit alerts, emergency SOS alerts, and schedule changes.

4. Mobile Application & Suite: Flowvent Bio Check-in

Flowvent Bio Check-in provides enterprise workplace attendance verification, ensuring reliable, fraud-resistant clock-ins through facial verification, hardware fingerprint keys, and GPS geofence checks.

Core Biometric Privacy Principles

  • Explicit, Informed Consent: Biometric facial enrollment is strictly optional and requires your unambiguous affirmative consent before the camera is activated. You can withdraw your consent at any time directly in the app.
  • Mathematical Embeddings Only (No Photos Stored as Biometrics): Our self-hosted AuraFace model converts your face into an anonymous 512-dimension numerical vector. We never store your enrollment photo as your biometric template.
  • Self-Hosted Processing (Zero External AI Sharing): Face embedding and matching run exclusively on our own self-hosted, dedicated servers. We do not transmit your face imagery or biometric vectors to OpenAI, Google Cloud Vision, AWS Rekognition, or any external third-party AI provider.
  • Hardware Fingerprint Protection: Fingerprint authentication leverages the operating system's hardware security module (Apple Secure Enclave / Android Keystore). Your physical fingerprint template never leaves your device and is never transmitted to Flowvent.
  • 30-Day Auto-Purge of Evidence Photos: Verification snapshots captured during clock-in are stored in private, encrypted object storage and are automatically and permanently deleted after 30 days, or immediately if you revoke biometric consent.
  • Immediate Deletion of Enrollment Photos: The temporary photograph captured during the enrollment step is wiped from memory and temporary disk within seconds of vector generation.
  • Geofence Fix, Not Continuous Tracking: GPS coordinates are inspected momentarily at the instant of check-in solely to verify on-premise physical presence within your employer's designated geofence. The app does not track your background location while off-duty.

5. How we use your data & legal bases

We process collected data under the following legitimate legal and contractual grounds:

  • Biometric Processing (Face Embeddings & Verification): Processed solely upon your explicit consent (GDPR Art. 9(2)(a), NDPR). Consent may be freely revoked at any time.
  • Attendance & Verification Records: Processed to perform the contractual attendance and workforce service ordered by your employer or event organizer (contractual necessity / legitimate organizational interest).
  • Payroll & Compensation Transfers: Processed for organizations that activate the Payroll feature, to calculate compensation, disburse funds via Paystack, and fulfill statutory tax documentation.
  • Event Ticketing & Access Control: Processed to issue digital tickets, enforce capacity limits, and facilitate automated house, squad, and dorm room sorting.
  • Transactional Communications: To transmit login OTPs, ticket receipts, check-in confirmations, and account recovery links via automated email or push notification.
  • Platform Security & Fraud Prevention: To detect malicious access attempts, prevent buddy-punching, and maintain database integrity.

We never sell, rent, monetize, or trade personal data or biometric information to data brokers, marketing agencies, or advertisers.

6. Subprocessors & data sharing

We share the minimum necessary personal data with vetted third-party subprocessors operating under strict data protection and confidentiality contracts:

SubprocessorPurposeData Processed
PaystackMerchant card payments & payroll disbursementsPayout bank account details, transaction references (PCI-DSS Level 1 compliant).
ResendTransactional email deliveryRecipient email address, ticket confirmations, password reset and deletion OTP codes.
Google FCM & Apple APNsPush notifications & check-in alertsDevice push token and notification headers (no personal biometric payload).
Backblaze B2Encrypted off-site disaster recovery backupsClient-side encrypted database and evidence snapshots.
Google Maps PlatformMap visualization & geocodingGeographic coordinates for event perimeters and safe zone setup.

Zero Biometric Sharing: We do not send your face photo, face embedding, or fingerprint key to any third party. Face matching runs strictly on our self-hosted infrastructure.

7. Data retention schedules

We retain personal data strictly according to defined schedules aligned with operational needs and legal requirements:

Data RecordRetention PeriodAction at Expiry
Face Vector EmbeddingActive until consent withdrawal or user account deletion.Immediately deleted from database (pgvector).
Enrollment PhotographA few seconds (only duration of vector extraction).Permanently wiped from memory and temporary disk.
Check-in Evidence Photo30 calendar days (or immediate upon consent withdrawal).Automated cryptographic deletion from private storage.
Biometric Consent AuditRetained as a legal compliance record.Records fact/timestamp of grant and revocation (no biometric data).
Workplace Attendance & PayrollMaintained by employer per labor and fiscal requirements.Upon account deletion, all identifying personal ties are severed/anonymized.
Event RegistrationsDuration of event lifecycle plus organizer archiving window.Deleted or anonymized at organizer request or workspace closure.

8. Account deletion & consent withdrawal

In full compliance with Apple App Store (Guideline 5.1.1) and Google Play Developer policies, Flowvent provides direct, autonomous mechanisms for users to manage their data:

A. In-App Biometric Consent Revocation

You may withdraw your biometric consent at any time inside the Flowvent Bio Check-in app. Revoking consent immediately and permanently purges your face vector embedding and any associated check-in evidence photos. Your account and past attendance records remain intact, and you may re-enroll in the future if desired.

B. In-App Self-Service Account Deletion

You can permanently delete your Flowvent account directly inside our mobile applications without contacting an administrator:

  • Flowvent Bio Check-in: Navigate to Settings → Delete my account. To safeguard against accidental or unauthorized deletion, the app sends a secure one-time verification code (OTP) to your registered email.
  • Flowvent Track: Navigate to Profile → Account Settings → Delete Account.

What Happens Upon Deletion: Your name, email, phone number, password, face embedding, device keys, and push tokens are permanently erased or pseudonymized. Your employer's attendance/payroll ledger remains intact for statutory accounting, but with all personal links to your identity irreversibly removed.

C. Web Deletion Requests

If you no longer have the app installed, you may submit a verified deletion request by emailing support@flowvent.app or flowventadmin@gmail.com with the subject "Account and Data Deletion Request" from your registered account email.

9. Children's privacy & minor records

Workplace Suite: Flowvent Bio Check-in is dedicated workplace software for verified personnel and employees. It is not directed at minors, and we do not knowingly enroll or process biometrics of children under 18.

Event Ticketing & Youth Camps: Certain events hosted on Flowvent (such as youth camps, religious retreats, and school competitions) involve minors. Registration of minors is restricted strictly to verified parents, legal guardians, or educational institutions holding documented parental consent. Real-time safety tracking in Flowvent Track is accessible solely by authenticated guardians of that specific child and authorized event officials.

10. Cookies & local storage

Our web platform employs strictly necessary cookies and encrypted HTTP sessions partitioned by organization subdomain. We do not use tracking cookies or third-party behavioral advertising pixels.

Our mobile applications utilize secure operating system keychains (via expo-secure-store and native keystores) strictly to maintain authenticated session tokens, encrypted preferences, and biometric cryptographic keypairs.

11. Your legal rights

Under applicable data protection legislation (including NDPR, UK/EU GDPR, and statutory privacy regulations), you possess the rights to:

  • Request access to and a copy of personal information processed concerning you;
  • Demand rectification of inaccurate, outdated, or incomplete data;
  • Request permanent erasure of your personal data ("right to be forgotten");
  • Revoke consent for biometric data processing at any time without penalty;
  • Demand restriction of or object to specific processing operations;
  • Request data portability in a structured, machine-readable format.

For workplace attendance records controlled by your employer, your employer is the primary Data Controller. Flowvent actively assists employers in fulfilling all data subject rights promptly.

12. Security safeguards

We implement comprehensive technical and administrative defenses to safeguard your personal and biometric data:

  • All web and API data transmissions are encrypted using modern Transport Layer Security (TLS 1.2/1.3);
  • Passwords and session tokens are salted and cryptographically hashed;
  • Biometric face embeddings are stored in isolated vector tables accessible only by internal verification logic;
  • Evidence photos are held in private object buckets reachable exclusively via short-lived, signed URLs;
  • System access adheres to strict least-privilege role-based access control (RBAC);
  • Off-site database backups are encrypted prior to network transit.

13. Changes to this Policy

We may update this Policy periodically to reflect technological advancements, product expansions, or regulatory changes. When updates occur, we revise the "Effective Date" at the top of this page. For any material modifications affecting biometric data handling, we will notify registered users via in-app notification or email and seek fresh consent where required by law.

14. Contact us

For questions, privacy inquiries, data subject requests, or biometric concerns, contact our Data Protection Office:

Flowvent Data Protection Office

Primary Email: support@flowvent.app

Compliance Alternate: flowventadmin@gmail.com

Platform Website: https://flowvent.app

This Policy applies to Flowvent, Flowvent Track, and Flowvent Bio Check-in.

← Back to Flowvent