Last updated: 8 July 2026
This Privacy Policy explains how FLO (“FLO”, “we”, “us”) collects and processes personal data when a company (our “Customer”) uses the FLO AI sales-assistant service, and when individuals interact with this website. We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and Romanian Law no. 190/2018 on measures implementing the GDPR.
1. Who we are
The data controller for this website and the operator of the FLO service is Neurony Solutions SRL, a company registered in Romania (Trade Register no. J2017002219402, sole registration code (CUI) RO 37108517), with its registered office at Str. Alexander von Humboldt nr. 18, camera 2, et. 2, Sector 3, Bucharest, Romania.
For any privacy question, or to exercise your rights, contact us at contact@neurony.ro. If we appoint a Data Protection Officer, their contact details will be published here.
2. Controller and processor roles
When we provide the FLO service to a Customer, the Customer decides why and how the personal data of its salespeople and its own clients is processed — the Customer is the controller and FLO acts as a processor on the Customer’s documented instructions, under a data-processing agreement. For this website, our own marketing, and account administration, FLO is the controller.
3. Personal data we process
Depending on how FLO is used, we process the following categories of personal data:
- Account & identity data — name, work email address, phone number and role, obtained when a user signs in with their company Google or Microsoft account.
- Calendar data — meeting times, titles and attendees, read from the connected Google Workspace or Microsoft 365 calendar.
- CRM data — client organisations, contacts, deals and interaction history, synchronised from the Customer’s Pipedrive or HubSpot account.
- Call data — audio recordings and transcripts of the briefing and debrief calls FLO places to, or receives from, a Customer’s salespeople, together with AI-generated summaries.
- Content data — documents a manager uploads about a client, notes, and emails read from or sent through the Customer’s connected mailbox.
- Technical data — limited log and security data needed to operate the service (see the Cookie Policy).
FLO is designed for business communications and is not intended to collect special categories of personal data (Article 9 GDPR). Please do not upload such data into the service.
4. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases (Article 6 GDPR):
- Providing the service — briefing and debriefing salespeople by phone, syncing calendars and CRM records, generating summaries and keeping the CRM updated: performance of a contract, or our and the Customer’s legitimate interest in running the service (Art. 6(1)(b) and (f)).
- Security, auditing and troubleshooting — keeping immutable activity logs and diagnosing problems: legitimate interest in a secure, reliable service (Art. 6(1)(f)).
- Website and enquiries — responding when you contact us or request a workspace: legitimate interest and steps prior to entering a contract (Art. 6(1)(b) and (f)).
- Legal compliance — meeting accounting, tax and other legal obligations (Art. 6(1)(c)).
5. Automated processing and AI
FLO uses artificial intelligence to draft call scripts, summarise conversations and emails, and distil “lessons learned”. These outputs assist people — salespeople and managers — and do not produce legal or similarly significant effects on any individual through solely automated means within the meaning of Article 22 GDPR. A human always remains in the loop.
6. Call recording
FLO’s calls with salespeople may be recorded and transcribed so the conversation can be summarised. Where FLO is deployed, the Customer is responsible for informing its salespeople and obtaining any consent required under applicable law before calls are recorded.
7. Recipients and sub-processors
We share personal data only as needed to run the service, with vetted service providers acting as our sub-processors, including:
- Google and Microsoft — sign-in and read-only calendar access.
- Pipedrive or HubSpot — the Customer’s chosen CRM.
- ElevenLabs — the voice technology that places and transcribes calls.
- Anthropic — the AI models (Claude) used to generate scripts and summaries.
- Our hosting and email providers — infrastructure on which the service runs.
We do not sell personal data. Each Customer’s data is kept logically isolated from every other Customer’s.
8. International transfers
Some sub-processors (for example, providers established in the United States) may process personal data outside the European Economic Area. Where they do, we rely on appropriate safeguards under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses. You may request a copy of the relevant safeguards using the contact details above.
9. Retention
We keep personal data only for as long as necessary for the purposes above and for the duration of the Customer’s subscription, after which it is deleted or anonymised within a reasonable period, unless a longer retention is required by law. When acting as a processor, we delete or return Customer data on termination in line with the data-processing agreement.
10. Security
We apply appropriate technical and organisational measures, including encryption of sensitive data at rest, access controls, tenant isolation, and immutable audit logging, to protect personal data against unauthorised access, loss or misuse.
11. Your rights
Subject to the GDPR, you have the right to access your personal data and to request rectification, erasure, restriction of or objection to processing, and data portability, and to withdraw any consent at any time. Where FLO processes data on behalf of a Customer, please direct your request to that Customer; we will assist them in responding.
To exercise your rights, contact us at contact@neurony.ro. You also have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania
anspdcp@dataprotection.ro · www.dataprotection.ro
12. Changes to this policy
We may update this Privacy Policy from time to time. The “last updated” date above shows when it was last revised. Material changes will be communicated through the service or this website.