Flowmingo Logo

Security and privacy

How we protect your data

Access, retention and privacy controls for your hiring team and candidates.

Checked 30 Sep 2026. Questions and subprocessor requests go to compliance@flowmingo.ai.

One candidate recordWho can open it
Video and audio answersYour organisation
The transcriptYour organisation
The evaluation and per-answer scoresYour organisation
CV and application detailsYour organisation
Their own submission, without the scoresThe candidate

A request for another company's record returns not found, not a permission error.

Access

Who can open a recording

Recruiter access is scoped to your organisation. Authorised providers and staff have limited operational access.

Every query filters by organisation
A request for a record that belongs to another company does not return a permission error. It returns a not-found, so the existence of the record is not disclosed either.
Inside Flowmingo, the minimum necessary
Role-based access for the CEO, the CTO, designated engineers and QA or support staff. Access is logged, and the log is reviewed quarterly.
Recruiter-only answer scores
Per-answer ratings and marked quotes belong to the recruiter report. Candidate-facing responses exclude these fields. How the score is produced.

How long each thing is kept

And what removes it. From our privacy policy, section 6.

On requestCandidate data owned by a recruiter, for as long as the recruiter requires it.Removed when the recruiter deletes it, or the account closes and sits inactive 2 years.
2 yearsReports and tests a candidate paid for.Removed when the candidate asks, or does not renew.
2 yearsRecruiter accounts, after closure.Removed when the period ends.
Up to 7 yearsBilling and payment records, which outlive the rest.Retention for legal obligations.
StatutoryOur own copy, kept only for security, QA and compliance.Removed on a validated data-subject request, or when the statutory period ends.

A candidate starts any of this by writing to compliance@flowmingo.ai. We act on our own copy and forward the request to the recruiter, escalating internally if they do not act.

How it is protected, and where it goes

Encryption
Encrypted in transit and at rest, with pseudonymisation of sensitive data.
Testing
Penetration testing and monitoring on a regular cycle.
If something goes wrong
Breach notification to the relevant authority within 72 hours where Article 33 requires it.
72h
International transfers
Data may be transferred outside the EEA. Our privacy policy explains the locations, Standard Contractual Clauses and Transfer Impact Assessments.
Who else touches it
Providers for cloud hosting, network security, AI processing, email, messaging, payments, monitoring and analytics, each contractually bound to GDPR obligations. The current list, and where each one is located, is available on request.

What a candidate can require of us

Ask for a human
AI-generated reports are used by recruiters, but final hiring decisions rest with people. Our privacy policy explains how candidates can request human intervention.
Put their own view, or contest it
We forward and track the request, and escalate internally where a recruiter does not respond.
Opt out of model improvement
Their data can be excluded from any use that improves our models, on request.

Getting this in writing

Read the privacy policy and DPA for the full terms and applicable exceptions.

Need a specific attestation, a subprocessor list or a signed answer about certifications? Write to compliance@flowmingo.ai.

Optional data contributions use a separate consent process. Withdrawal applies to future releases; see the privacy policy for limits.

Get in touch