Privacy Policy
Effective September 18, 2026 · Version 1 · Print
This policy explains what personal information Kapeedias Tech Group Inc. ("we", "us") collects through the FlowLogicx platform at https://app.flowlogicx.com, why we collect it, who we share it with, where it is kept and how you can reach us about it. We are a British Columbia business and we follow the Personal Information Protection Act (British Columbia), the Personal Information Protection and Electronic Documents Act (Canada) where it applies, and Canada's anti-spam legislation.
1. What this policy covers
This policy covers the FlowLogicx platform (the sign-in pages, the operations backend and the pages linked from its footer) and the FlowLogicx marketing website at https://flowlogicx.com.
It does not cover the public websites, booking pages, application forms and contact forms that our customers publish through the platform under their own name. Each of those organizations is responsible for its own privacy notice, and questions about information you gave them belong to them first. Section 2 explains why.
2. Our two roles
FlowLogicx is a multi-tenant platform: each customer organization (a "Customer", for example a driving school, a fleet maintenance shop or a carrier) runs its own workspace. That gives us two different roles under privacy law.
- Service provider for our Customers. Most of the personal information on the platform is entered by Customers about their own students, clients, drivers, employees and contacts. That information belongs to the Customer, the Customer decides why it is collected and how long it is kept, and we process it only on the Customer's instructions under our Terms of Service. If you are one of those people and want to see, correct or delete your record, ask the organization you dealt with. If you contact us instead, we will pass your request to them and help them answer it.
- Organization in our own right. For the people who hold accounts on the platform (Customer staff and administrators), for visitors to our website, for anyone who writes to us through our contact form and for our billing contacts, we decide what is collected and why. The rest of this policy is mostly about that role.
3. What we collect
Account information
Your name, work email address, phone number, job title or role, the organizations you belong to and your permissions within them, your time zone and display preferences, and a password. We store passwords only as a one-way hash; we cannot read them.
Sign-in and security records
Every sign-in attempt, password reset and invitation acceptance is recorded with the date and time, the IP address, the approximate city and country derived from that address, the browser and device type, and whether the attempt succeeded. We record the same details, without the content of your session, when the platform detects something that looks like a hijacked session or a brute-force attempt. These records exist so that you and your organization's administrators can see who accessed the workspace and when.
Activity records
The platform keeps an audit trail of the actions taken in a workspace: which user created, changed or deleted a record, when, from which address and device, and what the value was before and after. Customers rely on this trail for their own accountability and we rely on it for security investigations and for our own compliance reporting. A "last seen" timestamp is also kept while you are signed in so that colleagues can see who is online.
Content you or your organization put on the platform
The records a Customer keeps in its workspace: students and applications, bookings and training sessions, clients, vehicles and drivers, work orders, invoices and payments, uploaded documents, photos and videos, website pages, and messages. This is the information we hold as a service provider (section 2).
Contact form and correspondence
If you write to us through the contact form we receive the name, email address, phone number, location, subject and message you type, together with the IP address and browser the form was sent from. Email, phone and support conversations with us are kept with your account or enquiry.
Billing information
For Customers who pay us: the organization's legal name and business number, the billing contact, invoices and payment history. When a bank or card payment method is set up, the payment provider collects the account or card details directly; we keep only a reference token, the last digits needed to identify the method, and the mandate or authorization record.
Connected services
A Customer may choose to connect third-party services to its workspace, for example Intuit QuickBooks Online for accounting, GoCardless for payment collection, Samsara for fleet telematics, or DataDis for fleet maintenance. When it does, information moves between the platform and that service as the Customer directs. We store the connection credentials encrypted and use them only for the connected purpose.
4. Why we collect it
We collect and use personal information only for purposes a reasonable person would consider appropriate in the circumstances:
- to create and administer accounts and to provide, operate, support and bill for the platform;
- to authenticate users, to protect accounts and the platform from unauthorized access, and to investigate security incidents;
- to keep the audit trail described in section 3 for our Customers and for our own compliance obligations;
- to send transactional messages: invitations, password resets, booking and session confirmations, invoices, receipts, service notices and security alerts;
- to answer your enquiries and provide support;
- to send marketing about FlowLogicx only where you have asked for it or where the law otherwise permits, always with a working unsubscribe link (section 6);
- to understand how the platform is used, in aggregate, so that we can improve it;
- to meet legal and regulatory obligations and to establish, exercise or defend legal claims.
We do not sell personal information, we do not use it for behavioural advertising, and we do not combine it with data from data brokers.
5. Consent
By creating an account, signing in, using the platform or writing to us, you consent to the collection, use and disclosure of your personal information for the purposes in section 4. Where a purpose is obvious from the context and you volunteer the information, the law treats your consent as implied. For anything else we ask you first.
You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting our Privacy Officer (section 12). Withdrawing consent may mean we can no longer provide some or all of the platform to you, and we will tell you what the consequences are before you decide.
Information about minors is collected on the platform only by Customers (for example a driving school enrolling a student under nineteen). The Customer is responsible for obtaining the consent of the minor or of a parent or guardian as the law requires.
6. Electronic messages
Under Canada's anti-spam legislation we send commercial electronic messages only with your express or implied consent. Messages that are part of providing the platform to you (invitations, resets, confirmations, invoices, service and security notices) are transactional and are not marketing. Any marketing message from us identifies Kapeedias Tech Group Inc., gives our contact details and contains an unsubscribe link that works within ten business days.
Customers who send email or text messages to their own contacts through the platform are the senders of those messages and are responsible for their own compliance.
7. Where your information is kept and who processes it
We choose service providers that meet our security standards, we limit what each one receives to what its job needs, and we bind each one by contract to protect the information and use it only for us. Some of these providers store or process information outside Canada, mainly in the United States, and while it is there it may be subject to the laws of that country. The table lists them.
| Provider | What it does for us | What it receives | Where |
|---|---|---|---|
| Cloud hosting | Runs the application and the database, including automated backups | Everything on the platform | Data centres in Canada |
| File storage | Stores uploaded files, photos, videos and logos | Uploaded media and the organization it belongs to | May be outside Canada |
| Email delivery | Delivers email sent by the platform, with a second provider as a fallback | Recipient address, subject, message content | Servers outside Canada |
| Bot protection | Tells sign-in and public forms apart from automated abuse | IP address, browser details and the interaction with the checkbox | United States |
| IP geolocation | Looks up the approximate location of the IP address on each sign-in for the security records in section 3 | IP address only | Outside Canada |
| Content delivery networks | Serve fonts, icons and script libraries used by the pages | IP address and browser details when a page loads | Global |
| Intuit QuickBooks Online, GoCardless, Samsara, DataDis | Optional services a Customer chooses to connect | Whatever the Customer's connection exchanges (customers, invoices, payments, vehicles, drivers, maintenance records) | Per each provider's own notice; the Customer's agreement with that provider governs |
Our own staff and contractors can access personal information only when their work requires it, under confidentiality obligations, and every such access is logged.
8. When we disclose information
Beyond the providers in section 7 we disclose personal information only:
- within your own organization: your administrators can see your account details and your activity in their workspace;
- when the law requires it, for example to comply with a subpoena, warrant, court order or a lawful request from a Canadian public body, or when disclosure is otherwise authorized by the Personal Information Protection Act;
- to protect the rights, property or safety of Kapeedias Tech Group Inc., our Customers or the public, including to investigate fraud or a security incident;
- as part of a sale, merger or financing of our business, in which case the recipient is bound by this policy and you will be told of any change in control.
9. How we protect it
We protect personal information with safeguards appropriate to its sensitivity:
- all traffic to and from the platform is encrypted in transit (TLS), and the database and backups are encrypted at rest;
- passwords are hashed; sign-in is protected by rate limiting, a bot check and session-hijack detection; sessions expire when the browser closes;
- each Customer's workspace is isolated from every other; access inside a workspace is role-based and every change is audited;
- public-facing forms carry rate limits, page-bound tokens and a bot check;
- credentials for connected services are encrypted at rest and never shown again after they are entered;
- our staff use least-privilege access with named accounts, and production infrastructure is not reachable from the public internet.
No system is perfectly secure. If a breach of our safeguards creates a real risk of significant harm to you, we will notify you and the relevant privacy commissioner as soon as feasible, and we will notify the affected Customer so that it can meet its own obligations. We keep a record of every breach involving personal information.
10. How long we keep it
- Account information: for as long as the account exists, then for up to one year so that the account can be restored if it was closed by mistake and so that our audit trail stays complete.
- Sign-in, security and activity records: at least one year, because they are used to make decisions about access, and longer where a security investigation or a legal obligation requires it.
- Customer content: for as long as the Customer's subscription lasts and the export period in our Terms of Service, after which it is deleted from the live platform and ages out of backups on their normal cycle.
- Contact form enquiries: until the enquiry is closed and for up to two years afterwards so that we can follow up.
- Billing records: seven years, as Canadian tax law requires.
When information is no longer needed for the purpose it was collected for, or for a legal requirement, we delete it or make it anonymous.
11. Your rights
You have the right to ask us what personal information we hold about you, how we have used it and who we have disclosed it to, and to ask us to correct anything that is inaccurate or incomplete. Write to our Privacy Officer (section 12). We will verify your identity, respond within thirty business days, and tell you in writing if we need more time or if a legal exception prevents us from releasing something. Where the Act allows it we may charge a minimal fee for access requests, and we will give you an estimate before doing any work.
If the information you are asking about was entered by one of our Customers, we will direct you to that organization or forward your request to it, because it is the organization responsible for that record.
You can update most of your own account details yourself from your profile after signing in.
12. Privacy Officer
Our Privacy Officer is responsible for this policy and for answering your questions and requests:
Kapeedias Tech Group Inc.
Attention: Privacy Officer
P.O. Box 21024 Southgate, Chilliwack, BC V2P 2M0, Canada
Email: hello@flowlogicx.com
Phone: +1 604 791 2932
13. Cookies
The platform uses one strictly necessary session cookie and no tracking cookies. The details are in our Cookie Policy.
14. Changes to this policy
We may update this policy as the platform and the law change. The effective date at the top of the page always shows the current version. If a change materially affects how we use your personal information we will tell account administrators by email before it takes effect, and continuing to use the platform after that date means you accept the updated policy. Earlier versions are available from the Privacy Officer on request.