Privacy and data handling
What the Exchange API processes, where it lives, how long it is kept, and on what legal basis. The binding corporate policy is at get-flowie.com/legal/privacy; this page describes the API specifically.
What the API processes
Documents you send or receive, and the identifiers needed to route them: company names, registration and VAT numbers, Peppol participant identifiers, addresses, invoice line items and amounts, and the lifecycle events attached to each document. Invoices are commercial records, so they routinely contain personal data — a named contact, an individual trader, a consumer buyer.
Where it is stored
EU-hosted. A document transmitted to a national platform is additionally processed by that platform under its own rules: the French PPF, Italian SDI, Saudi Fatoora and others each impose their own retention and access regimes, documented per country under /compliance/.
Retention
Retention is driven by statutory invoice-archival obligations, which vary by country and commonly run six to ten years. Sandbox data is different: sandbox organizations and their documents are synthetic, are never transmitted to a real network, and are purged on a rolling basis. Do not put real personal data in the sandbox.
Roles and legal basis
For documents processed on your behalf you are the data controller and Flowie is the processor, acting on your documented instructions. Processing is generally necessary for the performance of a contract and for compliance with the legal obligation to issue and archive invoices.
Your rights
Access, rectification, erasure, restriction, portability and objection, exercised through the controller. Where Flowie is the controller, write to [email protected]. Note that erasure interacts with statutory archival duties: an invoice a tax authority requires you to retain cannot simply be deleted on request.
Security and agent credentials
ISO 27001:2022 certified. Encryption in transit and at rest, full audit trails on every document and lifecycle transition, and scoped credentials. An AI agent never needs a copy of your API key: you mint a short-lived, single-use handoff token instead, and the agent redeems it for its own scoped credential. See share access with an agent.