← BookflowR

Privacy Policy

Last updated: 16/09/2026

BookflowR (operated by BK Modules LLC) is committed to protecting your privacy. This Policy explains what personal data we collect, why we collect it, how we protect it, and what your rights are, in accordance with Regulation (EU) 2016/679 (GDPR), and where applicable, the California Consumer Privacy Act (CCPA/CPRA). This Policy constitutes a legally binding document between you and BK Modules LLC.

1. Data controller

BK Modules LLC, a limited liability company organized under the laws of the State of New Mexico (United States), with registered address at 102 Gold Ave SW Albuquerque - NM - 87102, telephone +1 (813) 214-0078, is the controller of personal data collected through https://bookflowr.com/.

For any privacy or data protection question, contact us at bookflowr@bookflowr.com. Users located in the European Economic Area (EEA) may direct requests to the same email; we will respond within a maximum of 30 days.

2. Data we collect

  • Account data: name, email, hashed password (bcrypt), preferred language, and business details if you register as a professional.
  • Billing data: legal name, tax ID, billing address, and payment method, processed through Stripe (PCI-DSS Level 1 certified; we do not store full card numbers).
  • Usage and technical data: IP addresses, session identifiers, browser type, operating system, pages visited, access timestamps, and in-platform events.
  • Communications: support messages, survey responses, and any information you voluntarily share.
  • End-customer data of the business: when you use BookflowR to manage your own customers (bookings, notifications, history), BK Modules LLC acts as a data processor; you are the data controller.

3. Purposes and legal bases (GDPR)

  • Service provision (art. 6.1.b — contract performance): creating and managing your account, providing panel access, processing bookings and subscriptions.
  • Billing and tax compliance (art. 6.1.c — legal obligation): issuing and retaining invoices, responding to authority requests.
  • Security and fraud prevention (art. 6.1.f — legitimate interest): event logging, abuse detection, access audits, and service integrity.
  • Essential operational communications (art. 6.1.b — contract performance): account verification, system alerts, and billing notices.
  • Marketing and newsletter (art. 6.1.a — consent): only if you expressly opt in; you may withdraw consent at any time.
  • Service improvement and aggregate analytics (art. 6.1.f — legitimate interest): anonymized usage statistics to improve the platform.

4. Retention periods

We retain your account data while it remains active. After closure, identifying data is deleted or anonymized within thirty (30) days, except data we must retain by law:

  • Invoices and tax records: minimum 6 years (EU accounting/tax obligation).
  • Security and audit logs: up to 12 months.
  • Support communications: up to 3 years from last contact.

Technical and statistical records (visits to your website, sent notices, assistant conversations) are kept between three (3) and thirteen (13) months depending on their type and are then deleted or anonymously aggregated.

5. Processors and recipients

We rely on providers acting as data processors under contract (art. 28 GDPR):

  • Stripe, Inc. (United States), with Stripe Payments Europe Ltd. (Ireland, EU) for EEA users — payment processing and billing.
  • Cloud infrastructure providers — hosting and databases, preferably within the EU.
  • Transactional email providers — system email delivery.
  • Meta Platforms Inc. (WhatsApp Cloud API) and Telegram — only if the business enables these notification channels.
  • Google LLC — embedded maps and, if the business enables it, analytics (GA4) and tags (GTM).

BK Modules LLC does not sell or share personal data with third parties for their own commercial purposes.

6. International transfers

BK Modules LLC is established in the United States. Data is transferred to and processed in the US and, where applicable, within the EU. To ensure the lawfulness of transfers from the EEA, we rely on the following mechanisms:

  • EU-US Data Privacy Framework (DPF, July 2023): for providers certified under the DPF.
  • EU Standard Contractual Clauses (SCCs) approved by the European Commission: for providers not covered by the DPF.
  • European Commission adequacy decisions: where applicable to the recipient country.

7. Your rights (GDPR — EEA users)

If you are in the European Economic Area, you may exercise the following rights at any time:

  • Access: obtain confirmation of whether we process your data and receive a copy.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): request deletion of your data when no longer necessary or when you withdraw consent.
  • Objection: object to processing based on legitimate interest.
  • Restriction: request suspension of processing under certain circumstances.
  • Portability: receive your data in a structured, commonly used format.
  • Not to be subject to solely automated decisions with legal or similarly significant effects.

Write to bookflowr@bookflowr.com indicating your name, account email, and your specific request. We will respond within 30 days. If you believe we have not handled your request properly, you may lodge a complaint with the supervisory authority in your country (in Spain, the AEPD — www.aepd.es).

8. Additional rights — California residents (CCPA/CPRA)

If you reside in California (USA), the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:

  • Right to know what personal information we have collected, the purpose of collection, and to whom it has been disclosed.
  • Right to delete your personal information, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right not to be discriminated against for exercising your rights.
  • Right to opt out of the sale or sharing of personal information: BK Modules LLC does not sell personal data.

To exercise these rights, contact us at bookflowr@bookflowr.com.

9. Minors

The Service is intended exclusively for individuals over 18 years of age. We do not knowingly collect personal data from individuals under 18 years old. If you believe a minor has provided us with data without parental or guardian consent, contact us at bookflowr@bookflowr.com and we will promptly delete such data.

10. Automated decisions and profiling

We do not make decisions with significant legal effects based solely on automated processing. Fraud detection and validation mechanisms are used only as decision-support tools, always under the supervision of qualified human staff.

11. Changes to this policy

We may update this Policy to reflect legal, regulatory, or service changes. Substantial changes will be notified by email or via a panel notice at least fifteen (15) days in advance. The date at the top of this page indicates the last published update. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

Privacy policy Cookie policy Terms and conditions Legal notice Data processing agreement