Privacy Policy
Effective Date: 4th August 2026. Last updated: 4th August 2026
Fluir ("Fluir", "we", "us", "our") operates the Fluir platform. This Privacy Policy explains how we collect, use, share, and protect data when you use Fluir, in accordance with applicable Indian law, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023, to the extent in force.
Personal Data VS Customer Data
This policy distinguishes between two categories of information:
Personal Data: Information that identifies you as an individual, such as your name, work email, IP address, and login information.
Customer Data : The content your organization creates or uploads within Fluir, such as projects, whiteboards, notes, and client records. Customer Data may itself contain personal data about your own clients or team, which you are responsible for having a lawful basis to upload.
Where this policy refers to "personal data," it means data in the first category; references to "Customer Data" mean the second, unless the context makes clear both are intended.
Information We Collect
a. Information you provide
Account information: Name, work email, organization name, role.
Billing information: Billing name, address, and GSTIN (for invoicing); payment card and bank details are collected and stored directly by Razorpay, not by Fluir.
Customer Data: Client records, project data, whiteboard content, notes, and files entered into the platform.
b. Information collected automatically
Usage data: Pages visited, features used, session duration, and device/browser information.
Log and diagnostic data: IP address, timestamps, and error logs, used for security and reliability.
Analytics data: Product usage patterns collected through analytics tooling (for example, product analytics and error-monitoring providers), used to understand how the Service is used and to identify and fix issues.
c. Information from third-party sign-in
If you sign in using a third-party authentication provider (for example, Google), we receive basic account information — such as your name, email address, and profile identifier — necessary to authenticate and create your account.
d. Information from AI features
Inputs and prompts you provide to Notes.AI and related AI features, and the outputs generated in response.
Legal Basis for Processing
Depending on the context, we process personal data on one or more of the following bases:
To perform our contract with you (providing the Service you have subscribed to);
With your consent, where consent is the applicable basis under law;
To comply with a legal obligation (for example, tax and accounting records);
For our legitimate operational purposes, such as securing the Service and preventing fraud or abuse, where permitted by applicable law and not overridden by your rights.
How we use information
To provide, operate, and maintain the Service, including the Client Book, Whiteboard, Project Manager, Dashboard, and Notes.AI.
To authenticate you, including via third-party sign-in providers.
To process subscription payments and send invoices, via Razorpay.
To send account-related communications, including invoices, password resets, team invitations, and service notices, and, where you have not opted out, product updates.
To monitor, secure, and improve the Service, including diagnosing technical issues through analytics and error-monitoring tools.
To comply with legal obligations, including tax and accounting requirements.
AI Processing
Where you use Notes.AI or other AI-assisted features, the following applies:
Your prompts and relevant context may be transmitted securely to third-party AI infrastructure providers in order to generate a response.
These providers process that information solely to return the requested output to Fluir and, under our agreements with them, are not permitted to use it for unrelated purposes such as training their own models, except where a provider's terms expressly state otherwise, in which case we select providers and configurations that disable such use where available.
You should not enter into AI features any information you are not authorized to share, including third-party confidential information beyond what is reasonably necessary for the task.
AI-generated outputs may be inaccurate or incomplete and should be reviewed before you rely on them, consistent with our Terms of Service.
Sharing of Information
We do not sell or rent personal information to advertisers or data brokers. We share information only as follows:
With Razorpay, to process payments and subscriptions.
With infrastructure, hosting, and analytics providers, and AI infrastructure providers, strictly to operate and improve the Service.
With professional advisors (legal, accounting) where necessary.
Where required by law, regulation, or valid legal process, or to protect our legal rights.
In connection with a merger, acquisition, or sale of assets, in which case Customer Data will transfer subject to equivalent confidentiality obligations.
Fluir relies on a limited, vetted set of subprocessors across categories such as hosting and infrastructure, authentication, analytics and error monitoring, AI processing, transactional email delivery, and payment processing. We do not currently publish a standing subprocessor list; one is available on request at admin@thefluir.com, and we intend to publish a formal list as the Service scales.
Internal Access to Customer Data
Access to Customer Data by Fluir personnel and contractors is restricted to those who require it to provide, maintain, or support the Service, and all such personnel are subject to confidentiality obligations. Fluir personnel do not access Customer Data to browse or review it outside of legitimate support, security, or engineering purposes.
Cookies and Browser Storage
Fluir uses cookies and similar technologies, which fall into the following categories:
Necessary — required to keep you logged in and to operate core functionality; these cannot be disabled without affecting the Service.
Functional — remember preferences and settings to improve your experience.
Analytics — help us understand usage patterns and improve the Service.
In addition to cookies, Fluir may use browser-based storage mechanisms such as Local Storage or IndexedDB to store session state and preferences on your device; these are not traditional cookies but serve a similar purpose. You can control cookies through your browser settings; disabling non-necessary cookies may affect some functionality but will not prevent core use of the Service.
Email Communication
We send transactional emails necessary to operate your account including invoices, password resets, and team invitations which cannot be opted out of while your account is active. We may also send product updates and other non-essential communications, which you may opt out of at any time via the unsubscribe link or by contacting admin@thefluir.com.
Data Retention
We retain account information and Customer Data for as long as your subscription is active, and generally for up to 30 days following account termination to allow for recovery, unless you request earlier deletion or longer retention is required by law (for example, tax and accounting records, which we retain for the statutory period). You may request deletion of your organization's data at any time by contacting admin@thefluir.com
Account Deletion
When you or your organization request account deletion: your account and access become inactive immediately; Customer Data is retained for up to 30 days to allow for recovery in case of error; and, after that period, the data is permanently deleted from our active systems, subject to Section 12 below on backup copies and any legal retention requirements.
Confidential Information
In the course of using Fluir, you may upload confidential materials belonging to you or your clients, including campaign strategy, pricing, and contractual information ("Confidential Information"). Fluir will use reasonable care to protect the confidentiality of Confidential Information and will not disclose it to third parties except as necessary to provide the Service (including to the sub-processors described in Section 14 and our Privacy Policy), as required by law, or with your consent.
Back up Copies
Like most SaaS providers, we maintain encrypted backups of our systems for disaster-recovery purposes. Following deletion from our active systems, residual copies of your data may remain in encrypted backups for a limited period before those backups are themselves automatically rotated out and deleted.
Data Security
We use industry-standard administrative, technical, and organizational safeguards designed to protect information during transmission and storage, including TLS encryption in transit, encrypted storage where appropriate, access controls based on least-privilege principles, and monitoring and audit logging of access to production systems. No system is completely secure, and we cannot guarantee absolute security. We do not represent that we hold any particular security certification (such as SOC 2 or ISO 27001) unless expressly stated in writing.
Incident Response
If we become aware of a data breach affecting personal data, we will take appropriate steps to investigate and contain the incident and will notify affected customers and, where required, relevant regulators, consistent with applicable law.
Data Location and International Transfers
Fluir's infrastructure may involve service providers located outside India. Where personal data is transferred internationally, we take reasonable steps — including contractual and organizational safeguards with the recipient — to ensure it receives a comparable level of protection, consistent with applicable Indian data protection law.
Your Rights
Subject to applicable law, you may:
Access, correct, or update your personal information.
Request a copy of your personal information, where applicable.
Request deletion of your personal information, subject to legal retention requirements.
Object to certain processing, where applicable law provides for this right.
Withdraw consent for optional processing, where consent is the basis for processing.
Raise a grievance with our Grievance Officer (see Section 19).
We aim to respond to rights requests within a reasonable period, and in any event within any timeline required by applicable law.
Children's Data
Fluir is a B2B product intended for business use by adults acting on behalf of their organizations. It is not directed at, and we do not knowingly collect personal data from, individuals under 18 years of age.
Law Enforcements and Legal Requests
We may disclose information, including personal data, where we believe in good faith that disclosure is required by law, regulation, or valid legal process, or where necessary to protect the rights, property, or safety of Fluir, our customers, or others.
Grievance Officer
In accordance with applicable Indian law, the Grievance Officer for Fluir can be contacted at:
Name: Karan Anil Jethmalani
Email: Karan@thefluir.com
Address: Office No. 03-135, Wework Futura, Kirtane Baugh, Magarpatta, Pune. 411028
Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or email. The "Last Updated" date at the top of this policy indicates when it was last revised.
Contact
Questions about this polcy can be directed to admin@thefluir.com.
