Skip to main content

Legal

Privacy Policy

How ArmoFlow Ltd collects, uses, shares, and protects personal data in connection with armoflow.com and FrostDesk.

Effective date: 1 June 2026 · Last updated: 1 June 2026

1. Who we are

ArmoFlow Ltd ("ArmoFlow," "we," "us," "our") is a company registered in England and Wales under company number 17081481, with its registered office at 167-169 Great Portland Street, London, England, W1W 5PF.

ArmoFlow is the data controller responsible for your personal data in connection with our website (armoflow.com) and our products, including FrostDesk (together, the "Services").

If you have any questions about this Privacy Policy or how we handle your personal data, contact us at hello@armoflow.com.

2. Scope of this Policy

This Privacy Policy explains how we collect, use, share, and protect personal data when you:

  • visit armoflow.com;
  • sign up for or use FrostDesk or any other ArmoFlow product;
  • communicate with us by email, form, or support channel.

It applies to two categories of people, and we're explicit about the difference because FrostDesk connects to WhatsApp and Gmail on behalf of our customers:

  • Customers: independent professionals (e.g. ski instructors, coaches, guides) who create an ArmoFlow account and use FrostDesk to manage their own communications and bookings.
  • End clients: the people who message, email, or book with our customers through channels FrostDesk connects to (e.g. a skier messaging their instructor on WhatsApp). We process this data as a processor acting on the instructions of our customer, who remains the data controller for their own clients' data. If you are an end client and have questions about how your data is used, please contact the professional or business you were communicating with directly; they can put you in touch with us if needed.

3. What personal data we collect

3.1 Data you provide directly

  • Account data: name, email address, phone number, business name, password (hashed).
  • Billing data: billing name and address, payment details (processed by our payment provider, Stripe — we do not store full card numbers).
  • Communications: messages you send us via email, contact forms, or support requests.

3.2 Data processed through the Services (on behalf of our customers)

When a customer connects WhatsApp Business and/or Gmail to FrostDesk, we process, on their instructions:

  • Message content and metadata from connected WhatsApp Business and Gmail accounts (text, timestamps, sender/recipient identifiers, attachments where applicable).
  • Contact information of the customer's end clients (names, phone numbers, email addresses) as it appears in those messages.
  • Booking and scheduling information entered or generated through the Service.
  • AI-generated outputs (e.g. suggested replies, summaries, categorisation) produced by processing the above through third-party AI providers, as described in Section 6.

3.3 Data collected automatically

  • Usage data and product analytics (pages visited, features used, session duration, device/browser type, approximate location from IP address) via PostHog and Google Analytics.
  • Error and performance logs via Sentry.
  • Cookies and similar technologies — see our separate Cookie Policy.

3.4 Special category / sensitive data

We do not intentionally collect special category data (e.g. health data, data concerning children) as a general matter, but because FrostDesk processes real client messages on behalf of our customers, such data may incidentally appear in message content (for example, a client mentioning a medical condition relevant to a ski lesson, or messages that reference minors booking lessons). We do not use this incidental content for any purpose beyond enabling the Service to function, and we contractually require customers to ensure they have a lawful basis for any such data they process through FrostDesk. If you are a customer and your work involves minors or health-related data, you remain responsible as controller for complying with applicable rules (e.g. parental consent) for that data.

4. How and why we use personal data (legal bases)

PurposeData usedLegal basis (UK/EU GDPR)
Create and administer your accountAccount dataPerformance of a contract (Art. 6(1)(b))
Provide the Service (unify WhatsApp/Gmail, AI-assisted replies, bookings)Connected account data, message contentPerformance of a contract (Art. 6(1)(b)); for end clients' data, processed under contract between us and the customer (Art. 28)
Process payments and manage subscriptionsBilling dataPerformance of a contract; legal obligation (invoicing/tax)
Provide customer supportCommunications, account dataLegitimate interests (Art. 6(1)(f)) — supporting our users
Improve and secure the Service, debug errorsUsage data, error logsLegitimate interests — product improvement and security
Website analyticsAnalytics/cookie dataConsent (Art. 6(1)(a)), obtained via our cookie banner
Marketing communications (if you opt in)Contact dataConsent
Comply with legal obligations (tax, accounting, regulator requests)Billing/account dataLegal obligation (Art. 6(1)(c))
Prevent fraud and abuseAccount/usage dataLegitimate interests

We never sell personal data.

5. Who we share data with

We share personal data only as necessary with the following categories of recipients, all bound by data processing agreements where they act as processors:

RecipientRolePurpose
WhatsApp Business API (Meta)Processor / platformDelivers and receives WhatsApp messages connected to FrostDesk
Google (Gmail API)Processor / platformDelivers and receives Gmail messages connected to FrostDesk
AI service providers (e.g. Anthropic, OpenAI)Sub-processorGenerates AI-assisted replies, summaries, and categorisation from message content
StripeProcessorPayment processing and subscription billing
VercelProcessor (hosting)Hosts and serves our web application
SupabaseProcessor (hosting/database)Database and backend infrastructure
RailwayProcessor (hosting)Backend service hosting
PostHogProcessorProduct analytics
Google AnalyticsProcessorWebsite analytics
SentryProcessorError monitoring and debugging
ResendProcessorProcesses submissions from website contact forms

We may also disclose personal data: to comply with a legal obligation, court order, or regulatory request; to protect the rights, property, or safety of ArmoFlow, our users, or others; or in connection with a merger, acquisition, or sale of assets (with notice to affected users where required by law).

6. AI processing

Where FrostDesk uses AI to draft replies, summarise threads, or categorise messages, relevant message content is sent to our AI service provider(s) to generate that output. We select providers that contractually commit not to use customer data to train their general-purpose models, and we require confidentiality and data protection commitments consistent with UK/EU GDPR. Customers can review which AI features are active on their account in the FrostDesk settings.

7. International data transfers

Some of our processors (including AI providers, hosting, and analytics providers) may process data outside the UK/EEA, including in the United States. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum / EU Standard Contractual Clauses, or transfers to jurisdictions covered by an adequacy decision. You can request more information about these safeguards by contacting hello@armoflow.com.

8. Data retention

We retain personal data only as long as necessary for the purposes described in this Policy:

  • Account data: for the duration of your account, plus up to 12 months after closure for legal/accounting purposes.
  • Message/booking data processed via FrostDesk: retained per the customer's account settings and our standard retention schedule; deleted or anonymised within 90 days of account closure unless a longer period is required by law.
  • Billing records: retained for 7 years to meet UK tax and accounting obligations.
  • Analytics and log data: retained for up to 26 months then deleted or aggregated.

9. Your rights

If you are located in the UK or EEA, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten"), subject to legal exceptions;
  • Restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
  • Data portability for data you provided to us under a contract or consent;
  • Withdraw consent at any time, where processing is based on consent (this does not affect processing carried out before withdrawal);
  • Lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO), ico.org.uk.

To exercise these rights, contact hello@armoflow.com. We will respond within one month, as required by UK/EU GDPR. If your request relates to data we process on behalf of an ArmoFlow customer (i.e. you are an end client), we may need to direct your request to that customer, who is the data controller.

10. Data protection complaints procedure

We maintain an internal procedure for receiving, logging, and responding to data protection complaints, in line with UK regulatory requirements. To submit a complaint, email hello@armoflow.com with the subject line "Data Protection Complaint." We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days; if we need longer, we will explain why.

11. Security

We implement technical and organisational measures to protect personal data, described in full in our Security Policy, including encryption in transit, access controls, and monitoring. No system is completely secure, and we encourage you to use a strong, unique password and enable any available account security features.

12. Children's data

Our Services are intended for business use by professionals aged 18 and over. We do not knowingly collect personal data directly from children. As noted in Section 3.4, client message content processed via FrostDesk may incidentally reference minors (e.g. a parent booking a lesson for their child); customers are responsible for ensuring lawful handling of such data.

13. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify customers by email or in-product notice before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

14. Contact us

Data Controller: ArmoFlow Ltd
Email: hello@armoflow.com
Registered address: 167-169 Great Portland Street, London, England, W1W 5PF

If you are unhappy with our response, you can complain to the ICO at ico.org.uk or by calling 0303 123 1113.