1. Who operates PerfectFlow
PerfectFlow is a product of Code Flakes LLC ("CodeFlakes", "we"), which builds and operates it as a service for its clients. Where this policy says "your instance", it means the copy of PerfectFlow that CodeFlakes operates for your company.
Code Flakes LLC, a company incorporated in the State of Florida, United States.
Registered address: 4855 West Hillsboro Boulevard, Suite A3, Coconut Creek, FL 33073, United States.
Email: info@perfectflow.cloud
The appointment of a representative in the European Union under Article 27 of Regulation (EU) 2016/679 is under assessment. In the meantime, write to the address above for anything concerning your data.
2. Where your data lives
PerfectFlow is deployed in one of two modes, and your contract states which one is yours:
- Dedicated instance. Your company gets its own server and its own database. No other client shares either. This is the default.
- PerfectFlow Lite. Several companies are hosted on one server and one database. Each company's records carry their own identifier, and the system filters every query by it automatically, so each company reaches only its own data. Each also signs in through its own subdomain.
Either way, your company's data — including the social media accounts you connect and the posts you schedule — stays separate from every other client's.
That instance runs on DigitalOcean infrastructure: a dedicated server, a database cluster and private object storage. The region is chosen when you sign up and does not change afterwards:
- Clients in the European Economic Area: server, database and storage in Frankfurt (Germany), inside the EEA.
- All other clients: data centres in the United States.
Your contract states your instance's region, and you can ask us for it at any time. One instance's data is never replicated or copied into another instance's region.
The only exceptions are the social media integrations: CodeFlakes has a single application registered with Meta and a single application registered with TikTok, and every instance connects its accounts through them. Those applications are the channel through which the API calls are made; the data they return is still stored in each client's own instance.
3. Your account and business data
To set up your account and provide the service we store the contact details you give us: name, email address, phone number and your company details.
Inside PerfectFlow, your company enters its own operational data (customers, sales, inventory, finance and so on, depending on the modules you use). That data is yours: we store and process it solely so that the system works, and we do not use it for any other purpose.
Who is accountable for which data
There are two kinds of data, and they are not governed the same way:
- Your client account data — your name, your email address, your company details and billing. We are the controller of that data, and this policy is what covers it.
- The data your company enters into its instance — your customers, your contacts, your sales. You are the controller of that data and we act as your processor: we process it on your instructions and for nothing else. What we may and may not do with it is set out in the data processing agreement (DPA) we sign with you, not in this policy.
One practical consequence: if someone whose data sits in your instance wants to exercise their rights, the request is addressed to you, and we give you the tools and the assistance to answer it.
The legal basis for the data we control
This covers only your client account data, not what your company loads into its instance — you are the controller of that, and you set its basis.
| Purpose | Legal basis |
|---|---|
| Setting you up, delivering the service, invoicing you and handling your support | Performance of the contract (Art. 6(1)(b) GDPR) |
| Keeping accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Answering a demo or information request before you subscribe | Pre-contractual steps at the data subject's request (Art. 6(1)(b)) |
| Keeping the service secure and logging administrative access | Legitimate interests (Art. 6(1)(f)): operating the system securely and being able to show it |
| Telling you about material changes to these terms or to the subprocessors | Performance of the contract (Art. 6(1)(b)), and legal obligation where the GDPR itself requires the notice |
We do not process data we control on the basis of consent, so there is nothing to withdraw on that footing. If we ever did, it would be asked for separately and could be withdrawn at any time.
4. Social media module
The social media module lets you connect a supported social media account and, from PerfectFlow, view how the account and its content are performing, write and schedule posts, publish them, and — on Instagram — read and answer the conversations your customers start. Each network has its own subsection: everything the module stores for that network is set out there.
Instagram (Meta)
PerfectFlow lets you connect an Instagram professional account. What follows describes everything the module stores and processes for that connection.
When you connect an account
| Data | What it is used for |
|---|---|
| Instagram professional account identifier | Telling Meta's APIs which connected account an action refers to. |
| Username and display name | Showing you on screen which account is connected, so you don't publish to the wrong one. |
| Access token and token expiration information | Authorising calls to Meta's APIs on behalf of the connected business. The expiration information allows the connection to be maintained without asking you to authorise it again. |
| Account type | Knowing which operations the connected account supports. |
Tokens are refreshed automatically by a background process. Token renewal is performed only as permitted by Meta's APIs, in order to maintain the connection authorised by the account owner.
For each post
Posts can be published immediately or scheduled: a scheduled post is published later by a background job in PerfectFlow, without anyone having to be present.
- The text of the post.
- The image or video files you attach.
- The date it is scheduled for.
- The identifier Meta returns when the post is created.
- The permalink to the published post.
- The status of the post and, if it failed, the error message returned by the API.
Instagram insights and analytics
When you connect an Instagram professional account and enable analytics, PerfectFlow may retrieve account and media performance information made available by Meta's APIs, including metrics such as reach, views, engagement and other aggregate performance metrics. What is actually available depends on what Meta exposes for that account and that piece of content.
PerfectFlow stores a daily snapshot of the connected account's counters and, for each post, the performance figures Meta returns, so that the dashboard can show how they change over time rather than only today's number.
These figures are aggregate counts. The module does not download the follower list, and it does not read the text of comments — only how many there are.
The purpose is limited to displaying analytics inside PerfectFlow and showing account and content performance to authorized PerfectFlow users of the connected business. Insights are not used for advertising, for profiling individuals, for sale of data, or for training artificial intelligence models.
Instagram direct messages
If you use PerfectFlow's Instagram Inbox, PerfectFlow receives information made available through Meta's messaging APIs and webhooks in order to display and manage conversations with your professional Instagram account. This covers conversations that people start with the connected business; PerfectFlow is not a tool for messaging Instagram users who have not written to you.
For each conversation, the data may include:
- The Instagram-scoped sender identifier, and the sender or display information Meta makes available.
- The conversation identifier and the message identifier.
- The message text or content, and any attachments or media associated with it.
- The timestamp of each message, and message status information.
PerfectFlow processes this information so authorized users of your company can view customer conversations and respond to them from within PerfectFlow. PerfectFlow sends replies only when permitted by Meta's applicable messaging rules and messaging windows.
Instagram message data is not used for advertising, profiling, sale, or artificial intelligence model training. It is your operational data: your company is its controller and Code Flakes hosts it as processor, like everything else in your instance.
TikTok
You can connect a TikTok account to schedule and publish videos to it from PerfectFlow.
When you connect an account
| Data | What it is used for |
|---|---|
open_id (the account identifier) |
Telling TikTok's API which account to publish to. |
| Display name and profile picture | Showing you on screen which account is connected, so you don't publish to the wrong one. |
| Access token, which lasts 24 hours, and its expiry date | Authorising calls to TikTok's API on your behalf. The expiry date allows the token to be refreshed before it lapses. |
| Refresh token, which lasts 365 days | Renewing the access token without asking you for permission again. |
| The permissions you granted | Knowing what PerfectFlow may do with the account. We store the granted permissions rather than the requested ones, because they determine whether your video is published on its own or left in drafts. |
Both tokens are stored encrypted in the database. Renewal is a background process that only exchanges one token for another, requesting no additional data. Unlike Meta, with TikTok that renewal is daily, because the access token lasts 24 hours.
For each post
- The text and the video file you attach.
- The date it is scheduled for.
- The
publish_idTikTok returns. - The status of the post and, if it failed, the error message returned by the API.
How the video reaches TikTok
You upload the video file to PerfectFlow and it is stored in private object storage. To publish, PerfectFlow hands TikTok a signed URL that expires after 30 minutes, and TikTok downloads the video from there itself. Once that window passes the URL stops working. The file is never public.
Where the video ends up: drafts or published
There are two possible destinations, and they change what you have to do:
- With the
video.uploadpermission, the video is left in your TikTok account's drafts and you publish it yourself from the TikTok app. - With the
video.publishpermission, the video is published directly.
PerfectFlow uses whichever your account granted.
WhatsApp Business
Separately from Instagram, you can connect a WhatsApp Business account, which does messaging only: nothing is published to WhatsApp. When you do, the module stores the conversation and the messages exchanged — sender identifier and display information, message text and attachments, timestamps, and whether the thread has been answered or archived — so authorized users of your company can reply from PerfectFlow.
This is a separate integration with its own authorisation, and it is not enabled unless you connect the account.
Where all of this is stored
Image and video files are stored in private, S3-compatible object storage. Every other field is stored in your instance's database.
5. What we do not do
To be explicit, the social media module does not:
- Sell information obtained through Meta APIs.
- Use Instagram message content or insights for advertising.
- Use Instagram data to train artificial intelligence models.
- Build advertising profiles of Instagram users.
- Access information or permissions that the connected business has not authorized.
- Use customer conversations for purposes unrelated to providing the PerfectFlow service.
Two limits worth stating plainly, because they are easy to assume the other way round: the module does not download your follower list — only aggregate counts — and it does not read the text of comments on your posts, only how many there are. Comment management is not part of this integration.
For TikTok, which is a separate integration, the module only publishes:
- We do not read your existing videos.
- We do not read your follower list.
- We do not read your TikTok messages.
- We do not use TikTok data for advertising or to train AI models.
- We do not share TikTok data with third parties.
Nothing described in this policy is used for advertising, profiling of individuals, artificial intelligence model training, or sold or transferred to third parties for their independent marketing or commercial purposes. Transfers that are necessary to deliver the service — to Meta in order to publish what you asked to publish, or to the infrastructure providers listed below — are a different thing, and they are described in section 6.
6. Who it is shared with
We do not sell data and we do not pass it to third parties for commercial purposes. Data leaves your instance only in these cases:
- Meta Platforms (Instagram): provides authentication and authorized Instagram account information, analytics and messaging data through its APIs and webhooks. Meta also receives the content and messages that authorized PerfectFlow users choose to publish or send through Instagram.
- TikTok: it receives the video's text and the temporary signed URL it downloads the file from, and returns the
publish_idand the status of the post. - When a competent authority legally requires it of us.
The social media module may communicate with Meta platforms, including Instagram and WhatsApp Business, and with TikTok when the corresponding integration is enabled.
Service providers and subprocessors
To run the service we rely on the following providers, which process data on our behalf as subprocessors, under a data processing agreement, and cannot use it for their own purposes:
| Provider | What for | Where |
|---|---|---|
| DigitalOcean | Servers, database and file storage | Your instance's region (EU or US) |
| Cloudflare | DNS and network security | Global network |
| Calendly | Booking the demo meetings requested from this site | United States |
Third-party platforms you connect
These are different: they are platforms your business connects to PerfectFlow, under your own account and your own relationship with them. They come in only if you turn on the matching channel, and until you do they process none of your data:
| Provider | What for | Where the data is |
|---|---|---|
| Meta (WhatsApp Business) | Exchanging messages with your contacts over WhatsApp — always your own account | Ireland and the United States |
| Meta (Instagram) | Account connection, analytics, publishing the content you schedule, and the conversations of the connected professional account | Ireland and the United States |
| TikTok | Publishing the videos you schedule | Ireland and the United States |
| Your outbound email provider | Delivering all mail that leaves the system: notices to your users — password resets, invitations — and communications to your contacts. The account is always yours | Depends on the provider you contract |
| Stripe | Charging your own customers — the account is always yours | Ireland and the United States |
Automations run on software we self-host on your own instance's server, with its own database. There is no central engine shared between clients. That software's vendor does not access your data; the messages those automations send do go out through the channels in the table above.
Each subprocessor in the first table accesses only what it needs to deliver its service, is bound by a data processing agreement, and cannot use the data for its own purposes. If we add or replace one, we tell you thirty days in advance and you may object.
Third-party platforms such as Meta process information according to their own applicable privacy terms and platform agreements, in addition to the actions initiated by authorized PerfectFlow users. Those are your accounts and your relationship with those platforms; we connect to them on your instruction.
The full, current list — with the detail of what each provider processes and which of them are your own accounts — is on the subprocessors page.
International transfers
Code Flakes LLC is based in the United States. Even where a European client's instance is hosted inside the EEA, the processor is a US company, and that is the flow the processing agreement covers.
The people who operate those instances access them from Venezuela. They are partners and staff of the company itself, not a contracted firm, so that access is not in itself a transfer to a third party. We state it for transparency. Support runs on the server itself: no copies are downloaded to local machines.
The applicable Chapter V mechanism is determined in each client's data processing agreement, as is that of providers headquartered outside the EEA. We invoke no adequacy framework and no certification.
7. How long it is kept
- Access and refresh tokens: kept while the account is connected. Disconnecting it from PerfectFlow deletes them.
- Connected account data and posts: kept in your instance until you request their deletion or the instance is decommissioned.
- Image and video files: kept alongside the post they belong to and deleted with it.
- Instagram messages: retained in the customer's PerfectFlow instance while necessary to provide the Instagram Inbox feature, until deleted by the customer, pursuant to a deletion request, or when the instance is decommissioned.
- Instagram insights: retained as necessary to provide analytics and historical reporting — the daily snapshots are what make a trend possible at all — until deleted by the customer, pursuant to a deletion request, or when the instance is decommissioned.
Outside the social media module:
- Your client account data — contact and billing — is kept while the subscription is active and, afterwards, for the tax and commercial limitation period that obliges us to retain accounting records.
- The data your company loads into its instance is yours to keep: you set the periods, as controller. Once the contract ends we hold the instance for thirty (30) days so you can export it, and after that we delete the instance, its database and its files, backups included, unless you tell us otherwise in writing.
- Backups are taken daily and overwritten on the rotation cycle set out in your contract, so a deleted record also disappears from the backups once that cycle completes.
You can request deletion at any time by following the data deletion instructions.
8. Security
Access to PerfectFlow and communications with third-party APIs are encrypted in transit using HTTPS. Authentication tokens used for supported third-party integrations are encrypted at rest. Each instance is isolated from the others as described in section 2, and administrative access is limited to the CodeFlakes staff who operate the service.
No system is infallible. If we detect a security breach affecting your instance's data, we will tell you without undue delay and in accordance with applicable legal and contractual requirements, by email at your account's contact address, with the information you need to meet your own notification obligations.
9. Your control over this data
Concretely, this is what you can do:
- Disconnect the account from PerfectFlow's social media module. Doing so deletes the authentication tokens, and PerfectFlow can no longer access Instagram analytics, publish content, receive new Instagram messages, or send replies on behalf of the connected account.
- Revoke access from Meta, in your Instagram account settings, under the apps and websites connected to your account. This takes effect immediately, independently of PerfectFlow.
- Revoke access from TikTok, in your account settings, under connected apps. This also takes effect immediately.
- Request deletion of your data by writing to info@perfectflow.cloud. The details are on the data deletion page.
- Ask us for a copy or a correction of the data we hold about you, at the same address.
If the General Data Protection Regulation applies to you
For the data we control — your client account data — you can exercise the rights of access, rectification, erasure, restriction, objection and portability. Write to info@perfectflow.cloud and we will answer within one month at the latest.
If you believe we have not handled your request properly, you have the right to lodge a complaint with the data protection supervisory authority in your country.
For the data your company enters into its instance, those rights are exercised against you, as their controller. We assist you in answering them under the terms of the data processing agreement: export, correction and deletion of the records you tell us to act on.
10. This website
The public PerfectFlow website at perfectflow.cloud does not use Google Analytics, nor any other analytics, and sets no tracking cookies. Some customer landing pages may use Google Analytics 4, but only when that customer explicitly enables the analytics feature — that is a different site, under that customer's own property. This section is about this website. The only thing stored in your browser is a local flag (pf_cookies) remembering that you dismissed the cookie notice, so it isn't shown again. That flag never leaves your browser.
This site has no contact form. There are three ways to reach us, each with its own consequence:
- Emailing us at info@perfectflow.cloud. We use those details solely to reply to you.
- Booking a demo, which opens Calendly. What you type there — name, email and the slot you pick — is collected by Calendly and reaches us so we can prepare the meeting.
- Messaging us on WhatsApp, which opens the WhatsApp app with our number. That conversation is governed by WhatsApp's own terms.
The pages on this site load a typeface from Google Fonts servers. To serve it, Google receives your browser's IP address. No cookie is set that way and we receive nothing back about your visit.
11. Minors
PerfectFlow is a management tool for businesses. It is not directed at minors and we do not knowingly collect data from people under 18.
12. Changes to this policy
If we change what the system does with data, we update this page and the last-updated date shown above. Significant changes are also announced by email to active clients.
13. Contact
Code Flakes LLC — PerfectFlow
4855 West Hillsboro Boulevard, Suite A3, Coconut Creek, FL 33073, United States
Email: info@perfectflow.cloud
For data deletion, follow the data deletion instructions.