Effective Date: November 1, 2025
This Privacy Policy explains how Princep Pte. Ltd. ("Flowmingo"), registered at 966 Hougang Ave 9 #12-596, Singapore 530966, collects, processes, and protects personal data in compliance with the EU General Data Protection Regulation (GDPR).
• For candidate data provided to recruiters (such as CVs, pre-screening responses, interview responses, videos, and other related materials), Flowmingo acts both as a processor (on behalf of recruiters) and as a controller of its own copy of that data which it retains for platform operation and compliance purposes.
○ In its processor role, Flowmingo processes candidate data strictly on recruiter instructions.
○ In its controller role, Flowmingo may retain and process its own copy of candidate data for limited and clearly defined purposes (e.g., platform security, quality assurance, legal compliance) and will honor candidate requests under GDPR for that copy.
○ Where recruiters are the controllers (e.g., evaluation reports generated for recruiters), Flowmingo will forward Data Subject Access Requests (DSARs) and enforce follow-up through internal escalation if recruiters fail to act.
• In limited cases where Flowmingo and recruiters may jointly determine specific purposes, such as co-developing interview models, the parties may act as joint controllers. Where this applies, Flowmingo will ensure that the essence of the arrangement under Art. 26 GDPR is accessible to candidates upon request. In most other cases, Flowmingo's roles as controller (for its own copy of data) and processor (for recruiter-owned data) are clearly separated as described above.
• For candidate-paid services (evaluation reports or assessment tests purchased directly by candidates), Flowmingo acts as a controller.
• For recruiter account and billing data, Flowmingo acts as a controller to manage accounts, billing, and service provision.
• DCP controller split (important). For recruiter‑run interviews, Flowmingo generally processes candidate data on behalf of the recruiting organization to provide the recruitment service (i.e., as a processor, where applicable). By contrast, if a candidate opts in to the DCP, Flowmingo processes the DCP dataset for a separate, consent‑based controller purpose with separate access controls. Recruiters cannot view who opted in. Recruiter deletion/DSAR instructions do not automatically delete DCP datasets unless the candidate also withdraws (and vice versa).
This is optional and separate from recruitment. Flowmingo may offer candidates an optional "Data Contribution Program" ("DCP"). If a candidate opts in, Flowmingo (as an independent controller for DCP purposes) will create a de‑identified / pseudonymised dataset derived from the candidate's interview responses and may share that dataset with trusted organizations that use data to develop and evaluate AI systems. Opting in is not required to complete an interview or to be considered for a role, and the hiring company is not shown whether a candidate opts in.
DCP processing is based on consent. Where required by law (e.g., higher‑risk categories), we rely on explicit consent. Refusal or withdrawal does not affect the candidate's job application.
DCP datasets may be shared with trusted organizations globally. We require contractual restrictions designed to prevent attempts to identify individuals, prohibit using the data to make decisions about any individual (e.g., employment/credit/insurance/housing), and restrict onward transfer/resale except with Flowmingo's written authorization. International transfers are handled using appropriate safeguards where required (e.g., contractual clauses and security measures).
"De‑identified / pseudonymised" means we take reasonable steps to remove or reduce direct identifiers (e.g., names, emails, phone numbers, addresses, government IDs) and limit linkability. De‑identification reduces risk but may not eliminate it completely, especially for audio (and video, if enabled). We apply technical and organizational safeguards and exclude certain content from DCP releases (including direct identifiers and categories of sensitive information) unless we obtain explicit consent and can justify inclusion.
| Processing Activity | Legal Basis |
|---|---|
| Candidate account creation & services | Contract (6(1)(b)) |
| Candidate-paid evaluation reports/tests | Contract (6(1)(b)) |
| Recruiter account management | Contract (6(1)(b)) |
| Recruiter AI evaluation features | Legitimate interest (6(1)(f)) with published LIA summaries |
| Recruiter billing & payment processing | Legal obligation (6(1)(c)) |
| Platform security, QA, AI improvement | Legitimate interest (6(1)(f)) with published LIA summaries |
| Marketing & non-essential cookies | Consent (6(1)(a)) |
| Optional Data Contribution Program (DCP): creation and sharing of de‑identified / pseudonymised datasets | Consent (Art. 6(1)(a)); explicit consent where required |
• AI-generated reports may be used by recruiters, but final hiring decisions rest with humans.
○ Request human intervention by contacting Flowmingo at compliance@flowmingo.ai. Flowmingo will escalate internally if recruiters fail to respond to forwarded DSARs.
○ Express their views or contest automated assessments (requests will be forwarded and tracked).
○ Opt-out of AI model improvement uses.
• Personal data may be transferred outside the EEA (e.g., GCP, Cloudflare, Stripe, HitPay).
• Transfers rely on Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs).
• Flowmingo publishes summaries of TIAs and safeguards.
• Supplementary safeguards include encryption in transit and at rest, access minimisation, and regional split-processing.
• Recruiter-owned candidate data: Flowmingo acts as a processor. Data is retained as long as required by the recruiter (controller) and will be deleted when instructed by the recruiter or when the recruiter account is closed and inactive for more than 2 years. Flowmingo's controller copy of candidate data (limited to security, QA, and compliance purposes) will be deleted in accordance with statutory obligations or upon validated data subject request.
• Candidate-paid reports/tests: retained for 2 years by default, unless renewed or deleted at the candidate's request.
• Recruiter accounts: retained for 2 years post-closure.
• Billing/payment records: retained up to 7 years (legal obligation).
• Flowmingo uses trusted service providers for hosting, payment, and analytics.
• Current examples: GCP, Cloudflare, Stripe, HitPay, Google Analytics.
• Flowmingo ensures subprocessors are bound by contractual agreements that require GDPR compliance. Material changes will be communicated where appropriate, and clients may raise objections consistent with Art. 28.
• Encryption and pseudonymisation of sensitive data.
• Role-based access limited to minimum necessary (CEO, CTO, designated engineers, QA/support).
• Access is logged and reviewed quarterly.
• Regular penetration testing and monitoring.
• Breach notifications to authorities within 72 hours where required (Art. 33).
• De‑identification standard (summary). For DCP releases, we maintain a documented de‑identification standard (risk‑based), including: (i) removal/suppression of direct identifiers from transcripts where feasible; (ii) exclusion rules for sensitive content; (iii) QA sampling; and (iv) contractual restrictions for recipients (including prohibitions on re‑identification and onward resale). A short summary may be provided on request.
• Flowmingo services are not directed at children under 16.
• While we do not actively collect age information at signup, users are required to confirm eligibility through acceptance of the Terms of Service, which include an age restriction clause. For higher-risk services, Flowmingo may apply additional verification measures to comply with Art. 8 GDPR.
• This Policy may be updated.
• Material changes will be notified via email or in-app.
• Flowmingo will maintain an archive of prior versions for accountability (Art. 5(2)).
For any privacy inquiries or to exercise GDPR rights:
• Email: compliance@flowmingo.ai
• Address: 966 Hougang Ave 9 #12-596, Singapore 530966