Skip to content

Fluck for Business Privacy Policy

Effective 14 July 2026

Effective date: 14 July 2026

This Privacy Policy explains how Fluck AI LTD (company number 15723506), registered at Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, Essex, CO4 3ZQ, United Kingdom ("Fluck", "we", "us", "our") collects and processes personal data in connection with Fluck for Business (the "Business Portal" or "Service").

This is a business-to-business (B2B) service. It is intended for use by UK local businesses and their authorised team members. It is not directed at consumers or children.

If you are a consumer using the Fluck consumer app, a separate consumer privacy policy applies to you.


1. About Fluck for Business

Fluck for Business is a software-as-a-service (SaaS) platform that helps UK local businesses manage their customers and reputation. It provides:

  • review and reputation management,
  • digital loyalty (stamps, tiers and vouchers),
  • an omnichannel inbox (WhatsApp Business, Instagram, Facebook and Messenger, email, and web chat),
  • a knowledge base and AI assistant,
  • ticketing and service-level (SLA) management,
  • a customer CRM,
  • surplus and last-minute offers, and
  • discovery and listing to the Fluck consumer app.

2. Our dual role: controller and processor

Fluck acts in two distinct data protection roles depending on the data in question.

As a controller. We are the controller of the personal data of business account holders and their team members: the data you provide to open and run your account, billing information, and how you use the Service. This policy governs that controller processing.

As a processor. When your business connects channels and imports or receives customer information (for example, the content of customer conversations across WhatsApp, Instagram, Facebook, Messenger, email or web chat, loyalty records, CRM contacts, and review responses), we process that "Customer Data" on your behalf and on your instructions. For that processing your business is the controller and Fluck is the processor. The terms of that processing are set out in our Data Processing Agreement at dpa-bp.md, which forms part of your contract with us and is incorporated by reference into this policy.

Where this policy and the DPA differ in respect of Customer Data, the DPA prevails.


3. Who to contact

PurposeContact
General business and account querieshello@fluckai.com
Privacy, data protection and data-subject requestshello@fluckai.com
Contact formhttps://www.fluckai.com/contact
PostalFluck AI LTD, Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, Essex, CO4 3ZQ, United Kingdom

You can contact us by email at hello@fluckai.com or via the contact form at https://www.fluckai.com/contact. We have not appointed a statutory Data Protection Officer, but hello@fluckai.com reaches the team responsible for data protection.


4. What personal data we collect (as controller)

CategoryExamples
Business account databusiness name, trading name, company number, address, business type, logo and branding
Team-member account dataname, work email, phone number, job role, username, password (hashed), profile photo
Billing and transaction dataplan, subscription status, billing contact, partial card or payment-reference data held by our payment processor, invoices
Usage and product datafeatures used, settings, actions taken in the portal, in-product messages
Technical and device dataIP address, browser and device type, operating system, log data, cookie and similar identifiers (see our Cookie Policy at cookie.md)
Support and communications datamessages you send us, support tickets, survey and feedback responses

We also process, as a processor on your behalf, the Customer Data that flows through the channels and features your business enables. That processing is governed by the DPA. A short summary of the Meta-sourced element of that Customer Data is in Section 6.


5. Why we process your data and our lawful bases (UK GDPR / EU GDPR Article 6)

Purpose (controller processing)Lawful basis
Creating and administering your account and team membersPerformance of a contract (Art 6(1)(b))
Providing, maintaining and securing the ServicePerformance of a contract (Art 6(1)(b)); Legitimate interests (Art 6(1)(f)) in running a secure, reliable platform
Billing, invoicing and collecting paymentPerformance of a contract (Art 6(1)(b)); Legal obligation (Art 6(1)(c)) for tax and accounting
Product analytics, improvement and troubleshootingLegitimate interests (Art 6(1)(f)) in improving the Service, balanced against your rights
Service and security notificationsPerformance of a contract (Art 6(1)(b)); Legitimate interests (Art 6(1)(f))
Marketing to business contacts about our productsLegitimate interests (Art 6(1)(f)) or consent (Art 6(1)(a)) where required by PECR; you can opt out at any time
Meeting legal, regulatory and law-enforcement obligationsLegal obligation (Art 6(1)(c))
Establishing, exercising or defending legal claimsLegitimate interests (Art 6(1)(f))

Where we rely on legitimate interests, you can ask for details of our balancing assessment at hello@fluckai.com.


6. Meta Platform Data (WhatsApp, Instagram, Facebook)

If your business connects WhatsApp Business, Instagram Messaging, Facebook or Messenger to the omnichannel inbox, Fluck accesses data from Meta's platforms through the Meta Graph API and related APIs. This includes message content, sender and recipient identifiers, conversation metadata, profile information made available by Meta, and account and page identifiers ("Platform Data").

We take the following commitments seriously and they apply whenever we handle Platform Data:

  • Purpose limitation. We access and use Platform Data only to provide the omnichannel messaging and related features your business has enabled, and only as necessary for those approved use cases. We do not use it for any unrelated purpose.
  • No sale, no licensing, no data brokers. We do not sell, license or purchase Platform Data. We do not transfer or share Platform Data with data brokers, advertising or monetisation networks, or any party that would use it to build or augment advertising profiles.
  • No unauthorised sharing. We share Platform Data only with the sub-processors listed in Section 8 that are necessary to deliver the Service, and only under contract and appropriate safeguards.
  • Retention and deletion. We retain Platform Data only for as long as it is needed to provide the enabled features. We delete Platform Data: on your request; when your business disconnects or removes the relevant integration; when a user or Meta requests deletion; when Meta access or permissions are revoked; or when it is no longer needed. Deletion routes are set out in our Data Deletion Policy at data-deletion.md.
  • Compliance with Meta terms. Our handling of Platform Data complies with the Meta Platform Terms, the Meta Developer Policies, and, for WhatsApp, the WhatsApp Business Messaging Policy and WhatsApp Business and Commerce Policies. Further platform-specific detail is in our Integrations & Meta Compliance Notice at integrations-compliance.md.
  • Opt-in and messaging rules. Your business is responsible for obtaining valid end-customer opt-in before messaging and for observing platform messaging rules (including the WhatsApp 24-hour customer service window and approved message templates). We provide tools to help you comply. See our Acceptable Use Policy at aup-bp.md and the Integrations Notice.

To request deletion of Platform Data or any personal data held about you, contact hello@fluckai.com or follow data-deletion.md.


7. Where your data comes from

We collect data directly from you when you register and use the Service. We also receive data from: your team members and your business administrator; our payment processor (billing status); connected platforms including Meta (as described in Section 6) when your business links them; and analytics and infrastructure providers that support the Service.


8. Sub-processors and recipients

We use trusted third parties to run the Service, including cloud hosting and storage, database and messaging infrastructure, email delivery, analytics, payment processing, and the Meta platforms for connected messaging channels. Each sub-processor is bound by contract to protect personal data and to process it only on our instructions.

A current list of sub-processors that handle Customer Data is maintained under the DPA at dpa-bp.md. We may also disclose data to professional advisers, to authorities where legally required, and to a successor entity in a merger, acquisition or reorganisation (subject to this policy).


9. International transfers

We are UK-based and prefer to store data in the UK or European Economic Area (EEA). Where personal data is transferred outside the UK or EEA (for example to a sub-processor, or through the Meta platforms), we put in place a lawful transfer mechanism, which will be the UK International Data Transfer Agreement (IDTA) or the UK Addendum, and the EU Standard Contractual Clauses (SCCs), together with any supplementary measures needed to protect the data. You can request details of the safeguards at hello@fluckai.com.


10. How long we keep data

We keep controller personal data only for as long as necessary for the purposes in this policy:

  • account and team-member data: for the life of your account and then deleted or anonymised within a reasonable period after closure;
  • billing and tax records: for as long as required by UK tax and accounting law (generally six years);
  • usage, log and technical data: for a limited period for security and troubleshooting;
  • marketing data: until you opt out or the data is no longer needed.

Customer Data and Platform Data are retained and deleted as described in the DPA and in Section 6, and following data-deletion.md.


11. How we protect your data

We use appropriate technical and organisational measures, including encryption of data in transit and at rest, access controls and least-privilege permissions, network protections, logging and monitoring, and staff confidentiality obligations. No system is completely secure, but we work to protect personal data against unauthorised access, loss or misuse, and we operate a process to detect, investigate and, where required, report personal data breaches to the relevant authority and affected individuals.


12. Your rights (UK GDPR / EU GDPR)

Where we are the controller, you have the right to: access your data; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; object to processing based on legitimate interests or to direct marketing; data portability; and, where we rely on consent, to withdraw that consent at any time (without affecting prior processing).

To exercise any right, contact hello@fluckai.com. We will respond within one month, and we may need to verify your identity. There is normally no charge.

Where Fluck processes Customer Data as a processor, requests from individuals should be directed to the relevant business (the controller); we will assist that business to respond as required by the DPA. If Meta communicates a data-subject or deletion request to us, we will action it and notify the affected business client.


13. California privacy rights (CCPA / CPRA)

If you are a California resident interacting with us in a business capacity, you have rights to know, access, correct and delete personal information, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not sell, license or transfer Platform Data to advertising networks or data brokers. We do not use or disclose sensitive personal information beyond the purposes permitted by law. To exercise your rights, contact hello@fluckai.com.


14. Children

The Service is a B2B product for business users who must be 18 or over. We do not knowingly collect personal data from children through the Business Portal. Any personal data of minors that appears within Customer Data is the responsibility of your business as controller and must be handled lawfully.


15. AI assistant

The Service includes an AI assistant that helps draft replies, summarise conversations and surface knowledge-base answers. The assistant is assistive only: its output is intended to be human-reviewable before it is sent, and your team remains in control. We do not use your Customer Data (including message content and Platform Data) to train general or third-party AI models without a lawful basis and, where required, your instruction or consent under the DPA. Where we use AI providers as sub-processors, they are contractually bound not to use your data to train their models except as permitted.

AI-assisted review replies. To help businesses reply to customer reviews, review text together with the reviewer's name and the business name is sent to Anthropic (Claude API, United States) to generate a suggested draft reply. Every draft is reviewed and approved by a person before use; no reply is published by automated means alone. Anthropic acts as our sub-processor and does not use the data to train its models. This US transfer is safeguarded by Standard Contractual Clauses (with the UK Addendum/IDTA as applicable).


16. Marketing and communications

We may send business contacts information about our products and updates, relying on legitimate interests or consent as required by PECR. You can opt out at any time using the unsubscribe link or by emailing hello@fluckai.com. Service and security messages are not marketing and will still be sent while your account is active.


17. Cookies and similar technologies

Our website, the Business Portal and our app SDKs use cookies and similar technologies. See our Cookie Policy at cookie.md for details and for how to manage your choices.


18. How to complain

If you have a concern, please contact hello@fluckai.com first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO), www.ico.org.uk, helpline 0303 123 1113. In the EEA, you may complain to your local data protection authority.


19. Changes to this policy

We may update this policy from time to time. If we make material changes we will notify you through the Service or by email, and we will update the effective date above. Continued use of the Service after changes take effect means you accept the updated policy.


This Privacy Policy should be read together with our Terms of Service (terms-bp.md), Acceptable Use Policy (aup-bp.md), Data Processing Agreement (dpa-bp.md), Integrations & Meta Compliance Notice (integrations-compliance.md), Data Deletion Policy (data-deletion.md) and Cookie Policy (cookie.md).