Privacy Policy
Last updated: 10 September 2026
This policy explains how OC Flow Media processes personal data relating to website visitors, subscribers, professional contacts, clients and participants in Audit services. It applies to the website and the channels and tools used to provide our services.
1. Data controller
The controller is OC Flow Media Sociedad Limitada, a single-member company (OC Flow Media), tax ID B93819423, with registered office at C/ Pau Casals, 3 (Edificio CINC), 17001 Girona, Spain. Commercial Registry of Girona, sheet GI-79762, entry 1.
Contact for enquiries and data subject rights: legal@ocflowmedia.com.
2. Audience and processing roles
The website and services are intended for businesses and professionals and are not directed at children.
OC Flow Media acts as controller for its contacts, subscribers, clients, billing, communications and commercial management. When it processes personal data on a client's instructions during an Audit, it may act as processor; that relationship will be governed by the relevant contract.
3. Data we may process
Identification and contact details; role, company, sector and country; the content of enquiries and communications; enquiry source; contractual, financial and billing information; relationship history and communication preferences.
During an Audit we may also process documents, processes, communications, operational data, source code, system information and professional data relating to the client's staff, contractors, customers or suppliers, within the agreed scope.
After participants have been informed, we may process voice, images, recordings, transcripts, summaries and notes from meetings held through Zoom, Google Meet or Plaud.
We also process technical data such as IP address, device, browser, security logs, pages visited, traffic source and cookie identifiers as described in the Cookie Policy.
We do not request special-category data, credentials or bulk personal data. If they are required for a project, they must be identified and expressly governed; if received unnecessarily, they may be deleted or minimised.
4. Purposes and legal bases
Handling enquiries, Audit requests and pre-contractual communications: taking steps requested by the data subject before entering into a contract.
Preparing and delivering the Audit and other agreed services, including meetings, documentation, deliverables and support: performance of a contract. Recordings are made after prior notice and, when required, with the relevant consent or authorisation.
Managing professional relationships by email, telephone or WhatsApp Business: pre-contractual steps, performance of a contract or legitimate interests in maintaining the professional relationship, depending on context.
Sending the newsletter: consent, which may be withdrawn at any time through the unsubscribe link or by contacting legal@ocflowmedia.com.
Billing, accounting and official requests: compliance with legal obligations.
Protecting the website, preventing abuse and retaining technical logs: proportionate legitimate interests in system security.
Measuring website and campaign use: consent for analytics or marketing cookies.
Using artificial intelligence tools to analyse information, transcribe, summarise, classify or support deliverable preparation: pre-contractual steps, performance of a contract or documented client instructions, as applicable.
5. Sources of data
We obtain data directly from the individual, their employer, the client commissioning the Audit, communications and meetings, public professional sources, or systems and documents the client chooses to make available.
When a client provides data about other people, it must be authorised to do so and meet its transparency obligations. OC Flow Media will follow contractual instructions and the obligations corresponding to its role.
6. Providers and recipients
We may use technology providers only to the extent necessary for the purposes described. These include: Vercel for website hosting; Google Workspace, Gmail, Drive, Meet and Gemini; Make and Pipedrive for automation and CRM; MailerLite for newsletters; Jotform for Audit forms; Zoom and Plaud for meetings, recording, transcription and AI features; OpenAI Business/API and Anthropic Claude Team/API for AI assistance; Notion, Internxt, Apple iCloud, Supabase and GitHub for documentation, storage, development and management; Hostinger for the infrastructure hosting n8n; and WhatsApp Business for professional communications.
Telegram and Slack are used on a limited basis for internal communications and notifications. We aim not to send unnecessary client documentation through these channels.
For measurement and marketing, and only with the relevant consent, we may use Google Analytics, Google Tag Manager, Google Ads, Metricool and LinkedIn Insight. Google Ads may be used to measure conversions, build audiences and run remarketing when campaigns are activated.
Providers may act as processors, subprocessors or independent controllers depending on the service and terms. OC Flow Media will put required processing terms in place and maintain an internal register. We may also disclose data to professional advisers, financial institutions and authorities when necessary or legally required.
7. International transfers
Some providers or subprocessors may process data outside the European Economic Area. Where GDPR applies, transfers will rely on an adequacy decision, the EU-US Data Privacy Framework for eligible recipients, standard contractual clauses or another valid safeguard, together with supplementary measures where required.
We select European regions when available, but location and subprocessors may vary by product and configuration. The provider's current contractual documentation determines the applicable safeguard.
8. Artificial intelligence and automated decisions
We may use OpenAI, Anthropic Claude, Google Gemini, Plaud, Zoom AI Companion and AI features embedded in other tools to support analysis, transcription, summarisation, classification and material preparation.
We apply data minimisation and, where reasonably possible, separate identifying details from analysed content. We do not use these tools to make solely automated decisions producing legal or similarly significant effects on individuals. Relevant outputs are reviewed by people.
9. Retention periods
Contacts and prospects without a contract: up to 12 months after the last meaningful professional interaction. A new interaction restarts the period where a genuine pre-contractual purpose remains.
Newsletter: while the subscription remains active. After unsubscribing, we retain only the minimum information needed to evidence the request, honour suppression and address potential liability for the applicable period.
Operational client data: during the relationship and for up to 12 months after the last professional interaction, unless the contract requires earlier return or deletion. Unnecessary working copies are then deleted, returned or anonymised.
Recordings and transcripts: during an active commercial opportunity or relationship and for up to 12 months after the last professional interaction. Full recordings and transcripts are then deleted; minimal professional notes may be kept where a legitimate purpose remains. A non-recorded meeting option is available.
Contracts, invoices, books, correspondence and supporting records: for the applicable statutory periods; commercial documentation is generally retained for six years and tax rights generally expire after four years, subject to special periods.
Security logs: for the configured period needed to protect systems, normally no more than 12 months unless an incident occurs. Cookies: for the periods stated in the Cookie Policy.
Where needed to comply with an obligation or defend a claim, necessary data may be restricted from ordinary use until the relevant period expires.
10. Your rights
You may request access, rectification, erasure, objection, restriction and portability and withdraw consent without affecting earlier processing. Email legal@ocflowmedia.com and identify the right you wish to exercise.
We will request additional identity information only where we have reasonable doubts and will respond within statutory time limits. Erasure may be limited where data must be restricted for legal obligations or the establishment, exercise or defence of claims.
You may also lodge a complaint with the Spanish Data Protection Agency at www.aepd.es.
11. Security and access
We apply risk-appropriate technical and organisational measures, including access control, individual accounts where available, authentication, encryption offered by the systems, permission management and provider review. Access is limited to Andrea, Laura and authorised people who need the information for their work and are bound by confidentiality.
No system can guarantee absolute security. We will handle incidents under applicable law and notify authorities or affected people where required.
12. Changes to this policy
We will update this policy when processing, providers or legal requirements change. The current version date appears at the top. Where a change affects existing consent, we will ask for a new choice when required.