On this page
1. Who we are
Leegwater GmbH ("Flok", "we", "our") provides a SaaS platform for clubs and associations. Our registered office is in Jona, Switzerland. For the purposes of the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG), Flok acts as a data processor for the member data your organisation ("Customer") stores in Flok, and as a data controller for the account data of the administrators who sign in to Flok.
2. Data we collect
Account data (admin users)
- Name, email address, hashed password, preferred language.
- Session and authentication logs, including IP address and user-agent.
- Billing details when a paid plan is purchased.
Customer data (data your organisation puts into Flok)
- Member records: name, contact details, membership status, custom fields you define.
- Invoices, payments, events, tickets, newsletters and audit logs.
- Files you upload, such as logos and attachments.
Technical data
- Product analytics (aggregated page views, feature usage) without third-party ad trackers.
- Diagnostic logs from our servers, kept only as long as needed for troubleshooting.
3. How we use data
- Provide, secure and improve the Flok service.
- Send transactional emails (invoices, event tickets, password resets).
- Provide customer support that you or your organisation request.
- Detect abuse, fraud and technical issues.
- Comply with legal obligations (tax, accounting, lawful requests).
We do not sell personal data, and we do not use member data to train third-party AI models.
4. Legal bases (GDPR Art. 6)
| Processing | Legal basis |
|---|---|
| Providing the service to admins & the Customer | Contract (Art. 6(1)(b)) |
| Sending service and security notifications | Legitimate interests (Art. 6(1)(f)) |
| Processing member data on behalf of a Customer | Customer's chosen basis under a Data Processing Agreement |
| Billing, tax and accounting records | Legal obligation (Art. 6(1)(c)) |
| Optional marketing communications | Consent (Art. 6(1)(a)) |
5. Sharing & subprocessors
We share data only with vetted providers under signed data processing agreements. Categories include cloud hosting (EU/Swiss data centres), transactional email delivery, payment processing (Stripe / Payrexx when enabled by the Customer) and error monitoring. A current list of subprocessors is available on request.
6. Retention
- Account data: while the account is active and up to 90 days after closure.
- Member data processed for a Customer: kept as long as the Customer decides, then deleted or returned on request within 30 days of contract termination.
- Invoicing records: retained for 10 years to meet Swiss accounting law.
- Server logs: rotated within 30 days.
7. Your rights
Under GDPR and nDSG you may request access, rectification, deletion, restriction, portability, or object to processing. Members should contact their club administrator first, because the club is the controller of that data. For account data held by Flok, write to privacy@getflok.app. You also have the right to lodge a complaint with a supervisory authority.
8. Security
- TLS 1.2+ for all data in transit.
- Encryption at rest at the storage layer.
- Role-based access control and row-level security in the database.
- Least-privilege access for engineers, audit-logged.
- Regular backups with tested restore procedures.
9. International transfers
Our primary hosting region is the EU with Swiss failover. Where a subprocessor requires transfers outside the EEA/Switzerland, we rely on Standard Contractual Clauses, the Swiss addendum and additional safeguards.
10. Children
Flok is not directed at children under 16. Clubs that manage junior members do so under their own consent framework and remain the controller of that data.
11. Changes to this policy
We will notify admins by email of material changes at least 30 days in advance. Minor clarifications will be posted here with an updated "Last updated" date.
12. Contact
Leegwater GmbH · Jona, Switzerland · privacy@getflok.app · Contact form.