1. Who we are
This Privacy Policy explains how Igor Kozhevin (Partita IVA #04727640163) ("FlowKnot", "we", "us", "our") collects, uses, and protects personal data of visitors to flowknot.eu and of individuals who contact us in connection with our management and financial consulting services.
The Data Controller / Titolare del trattamento is:
Data Controller
Igor Kozhevin
Legal form: Private Entrepreneur
Registered office: Via San Michele 12, Foresto Sparso, 24060, BG, Italy
VAT / Tax ID / Company number: Partita IVA #04727640163
Tax code / Codice Fiscale: KZHGRI72E05Z135S
Email: flow@flowknot.eu
Website: https://flowknot.eu
If you have any questions about this Policy or about how we handle your personal data, please contact us at flow@flowknot.eu.
2. Scope of this Policy
This Policy applies to personal data processed through:
- The flowknot.eu website and its pages (Home, Approach, Services, Who We Work With, About, Insights, Contact);
- The contact form on the Contact page;
- Any direct email correspondence with flow@flowknot.eu that results from a website visit or business inquiry.
This Policy does not cover the practices of third-party websites we may link to, or of clients' or partners' own systems, which are governed by their own privacy notices.
3. What personal data we collect
3.1 Data you provide directly
When you submit our Contact form, we collect the information you enter into the form fields, which typically includes:
- Name
- Email address
- Company name (where provided)
- The content of your message/inquiry
We also use a hidden "honeypot" field purely to detect and block automated spam submissions; this field is not intended to capture data from human visitors and any value automatically inserted by a bot is not processed for any purpose other than spam filtering.
Submitted form data is transmitted from our web server by email (SMTP) to our business mailbox (flow@flowknot.eu) and is not stored in a separate website database. It is retained in our mailbox in line with Section 7 below.
If you correspond with us directly by email (rather than via the form), we collect whatever personal data is contained in that correspondence (e.g., your name, email address, job title, company, and the content of your messages and any attachments).
3.2 Data collected automatically
Like most websites, our hosting infrastructure automatically logs limited technical information when you visit flowknot.eu, such as:
- IP address
- Browser type and version, device/operating system information
- Pages visited, referring page, and timestamps
- Basic error/server logs (e.g., for security and troubleshooting)
This information is generated and retained by our hosting provider's standard web-server logs and is used only for security, abuse prevention, and diagnosing technical issues. We do not currently use this data to build individual visitor profiles.
3.3 Cookies and similar technologies
flowknot.eu is built as a static informational site. At present we do not knowingly deploy analytics, advertising, or third-party tracking cookies. If this changes — for example, if we add a web analytics tool (such as Google Analytics or a privacy-focused alternative), a chat widget, or marketing pixels — we will update this Policy and, where required by the ePrivacy Directive/GDPR, implement a cookie consent banner allowing you to accept or reject non-essential cookies before they are set.
Any strictly necessary cookies (e.g., needed to load the page or remember basic technical settings) do not require consent under applicable law but are listed here for transparency: None.
4. How and why we use your data (purposes and legal basis)
We process personal data only where we have a valid legal basis under Article 6 of the General Data Protection Regulation (GDPR):
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Responding to inquiries submitted via the Contact form or by email | Name, email, company, message content | Art. 6(1)(b) — steps taken at your request prior to entering into a contract; or Art. 6(1)(f) — our legitimate interest in responding to business inquiries |
| Assessing and pursuing a potential consulting engagement | Name, email, company, message content, subsequent correspondence | Art. 6(1)(b) — pre-contractual steps at your request |
| Performing a consulting engagement once contracted | Contact and engagement-related data as agreed with the client | Art. 6(1)(b) — performance of a contract |
| Website security, fraud/spam prevention, troubleshooting | IP address, technical/server log data, honeypot field | Art. 6(1)(f) — legitimate interest in keeping our website secure and functioning |
| Compliance with legal, tax, and accounting obligations | Client/engagement records as required by Italian and EU law | Art. 6(1)(c) — legal obligation |
| Any future email newsletter or marketing communication (only if introduced) | Name, email | Art. 6(1)(a) — your consent, given via opt-in |
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you, and we do not sell personal data to third parties.
5. Who we share your data with
We do not sell or rent personal data. We may share personal data with:
- Hosting and infrastructure providers — our website and mailbox are hosted with Hetzner Online GmbH (Germany), which processes data on our behalf as a processor under a data processing agreement, in accordance with Article 28 GDPR.
- Professional advisers (e.g., accountants, lawyers) where necessary for our legitimate business or legal purposes.
- Public authorities where required by applicable law (e.g., tax authorities, law enforcement, courts).
- Successors in the event of a business transfer, restructuring, or sale, subject to appropriate safeguards.
We do not currently use any third-party CRM, email-marketing platform, or analytics provider.
6. International data transfers
Our website hosting and email infrastructure (Hetzner) are located in Germany, within the European Union/European Economic Area. We do not currently transfer personal data outside the EU/EEA. If this changes in the future (for example, by using a non-EU-based service provider), we will ensure an appropriate transfer mechanism is in place — such as an adequacy decision or Standard Contractual Clauses under Article 46 GDPR — and will update this Policy accordingly.
7. How long we keep your data
- Contact form / inquiry correspondence: retained for as long as necessary to respond to and follow up on your inquiry, and thereafter for up to 24 months from the last contact, unless a business relationship develops (in which case client-engagement retention rules apply) or you ask us to delete it sooner.
- Client engagement records: retained for the duration of the engagement plus any period required by Italian civil, tax, and accounting law (generally up to 10 years for accounting/tax documentation).
- Technical/server logs: retained for a limited period (typically 90 days, per our hosting provider's default log-retention settings) for security purposes, then automatically deleted or anonymised.
When personal data is no longer needed for the purposes above, we securely delete or anonymise it.
8. Your rights under GDPR
If you are located in the EU/EEA (or otherwise protected by GDPR), you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erase your data ("right to be forgotten") in certain circumstances (Art. 17);
- Restrict processing in certain circumstances (Art. 18);
- Data portability — receive your data in a structured, commonly used, machine-readable format (Art. 20);
- Object to processing based on our legitimate interests, including direct marketing (Art. 21);
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal (Art. 7(3));
- Lodge a complaint with a supervisory authority, in particular in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.
To exercise any of these rights, contact us at flow@flowknot.eu. We will respond within one month, as required by GDPR (extendable by two further months for complex requests, with notice to you).
Lead supervisory authority: as we are established in Italy, our lead supervisory authority is the Italian Data Protection Authority — Garante per la Protezione dei Dati Personali, Piazza Venezia 11, 00187 Rome, Italy. Website: www.garanteprivacy.it.
You may also contact the data protection authority in your own EU/EEA country of residence.
9. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure, including secure (SMTP/TLS) transmission of contact-form submissions, access controls on our mailbox and hosting environment, and use of a reputable EU-based hosting provider. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to keep your data appropriately protected and to review these measures periodically.
10. Children's data
Our website and services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
11. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the tools we use on the website, or legal requirements. The "Last updated" date at the top of this page indicates when it was last revised. We encourage you to review this Policy periodically. Material changes affecting how we use previously collected data will be communicated where appropriate.
12. Contact us
For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact:
Contact
FLOWKNOT
Igor Kozhevin
Email: flow@flowknot.eu
Registered office: Via San Michele 12, Foresto Sparso, 24060, BG, Italy