How your data is held
Where it lives, who can reach it, what happens if you leave, and the things CleanFlo does not do. Published before you sign up rather than after.
The short version. Your data is held in the EU, encrypted at rest, and separated from every other company's by the database itself rather than by the software remembering to be careful. There is no two-factor authentication and no audit log. Both halves of that are on this page because you need both to make a decision.
Where your data lives
Everything you put into CleanFlo (clients, sites, staff records, jobs, invoices, photographs, messages and health & safety records) is held in a database hosted in Ireland (eu-west-1), inside the EU. It is encrypted at rest with AES-256 and in transit over HTTPS.
A handful of suppliers necessarily touch some of it: the hosting provider, the payment processor, the email sender, and the push-notification services your own staff's phones require. Each one is named, along with exactly what it sees and the transfer safeguard that covers it, on the sub-processors page. We give 30 days' notice before adding to that list, and you can object.
How your company is separated from every other one
Every table is protected by row-level security keyed to your company. That means the separation is enforced by the database, not by the application remembering to filter: a query made from one account physically cannot return another company's rows, even if the software above it were to ask for them. It is the difference between a locked door and a sign asking people not to come in.
The read-only demo account works the same way in reverse: it refuses writes at the database, which is why nothing you press inside it can break anything.
Who inside your business can see what
There are three kinds of account, and each has a fixed set of screens:
- Owner: everything, including money, staff pay rates and settings.
- Supervisor: their round, meaning the jobs, the sites and the people on it.
- Cleaner: their own jobs, and nothing else. Not your client list, not your prices, not another cleaner's work.
Cleaners are added by a single-use invite link that they redeem to set their own password, so a password for your staff never passes through your hands or ours.
If you leave
You can export everything to CSV at any point, before or after cancelling: clients, sites, jobs, invoices, quotes and staff. Nothing is held in a format only we can read, and you do not need to ask us for it.
Cancelling pauses an account rather than deleting it, so the records are still there if you come back. If you want them erased instead, write to privacy@cleanflo.io and we will do it: there is no self-service delete button in Settings.
Telling us about a problem
If you think you have found a security problem, write to privacy@cleanflo.io with enough detail to reproduce it. We would rather hear about it than not. There is no bug bounty and we will not pretend otherwise, but we will tell you what we did about it.
Under the data processing agreement we notify you of a personal data breach affecting your data within 24 hours of becoming aware of it.
Related
- Data Processing Agreement: the Article 28 contract, in full.
- Sub-processors: everyone who touches your data.
- Privacy notice: what CleanFlo does with data about you.
- Terms: the agreement the above sits inside.