Cumplimiento GDPR - Guía de Protección de Datos

20 min de lectura

GDPR Compliance Guide

Version 2.0 | Last Updated: January 2025

Complete guide to General Data Protection Regulation (GDPR) compliance when using ClientFlow for your business operations in the European Union.

Executive Summary

ClientFlow is designed for full GDPR compliance. As a data processor, we provide the technical and organizational measures required by GDPR while you (the data controller) maintain responsibility for lawful processing of your clients' data.

GDPR RoleEntityResponsibility
Data ControllerYou (ClientFlow User)Lawful basis, consent, data subject rights
Data ProcessorClientFlowSecurity, DPA, sub-processors, breach notification

Data Subject Rights

Your clients have rights under GDPR. ClientFlow provides tools to fulfill these:

RightClientFlow Feature
Right to Access (Art. 15)Export client data to JSON/CSV
Right to Rectification (Art. 16)Edit client records anytime
Right to Erasure (Art. 17)Delete client with 30-day soft delete
Right to Portability (Art. 20)Export in machine-readable format
Right to Object (Art. 21)Unsubscribe from marketing/reminders

Lawful Bases for Processing

Contract Performance (Art. 6(1)(b))

Processing client data is necessary for service delivery (appointments, payments, reminders).

Legitimate Interest (Art. 6(1)(f))

Analytics and business operations where interests don't override client rights.

Marketing communications require explicit opt-in consent.

Data Processing Agreement (DPA)

ClientFlow provides a DPA as required by GDPR Article 28.

  • Availability: All paid tiers (Starter, PRO, Team)
  • Request: Email dpa@clientflow.center
  • Format: DocuSign electronic signature
  • Contents: Processing scope, security measures, sub-processors, breach notification

Data Location

Data TypeLocationProvider
DatabaseFrankfurt, Germany (EU)Hetzner
File StorageEU RegionsCloudflare R2
BackupsFrankfurt + Helsinki (EU)Hetzner
Key Point: All primary data is stored within the EU. No personal data is transferred to the USA without Standard Contractual Clauses.

Sub-Processors

ClientFlow uses the following sub-processors:

  • Hetzner (Germany): Infrastructure hosting
  • Cloudflare (EU): CDN and file storage
  • iyzico (Turkey): Payment processing
  • Resend (USA): Email delivery (SCCs in place)

Breach Notification

In case of a data breach:

  1. <24 hours: ClientFlow notifies you
  2. <72 hours: You notify supervisory authority (if required)
  3. Without undue delay: You notify affected individuals (if high risk)

Data Retention

Data TypeRetention Period
Active client recordsUntil you delete
Deleted client records30 days (soft delete), then purged
Payment records7 years (tax requirement)
Audit logs2 years

Contact

Data Protection Officer: dpo@clientflow.center

DPA Requests: dpa@clientflow.center


Read time: ~15 minutes | Audience: Data Controllers, Compliance Officers

Was this helpful?