In beta with first customers. Out of beta and taking new customers from 26 October. Talk to us

Legal

Privacy policy

Last updated: 4 October 2026

This privacy policy explains how StencilFlow ("we", "us") handles personal data when you visit stencilflow.io or contact us. We process personal data in line with the General Data Protection Regulation (GDPR).

This policy covers our website and our contact with prospective customers. Data that customers process in the StencilFlow platform is covered by the data processing agreement with that customer, in which the customer is the controller and we are the processor.

Who is responsible

StencilFlow is a product of Tensoric B.V. (Chamber of Commerce number 42046955). Tensoric B.V. is the controller for the processing described here. For any question about privacy, or to exercise your rights, email info@stencilflow.io.

What we process and why

Contact form and email. The contact form on this website does not store anything itself: it opens your own email client with your details filled in. When you send that email, or email us directly, we receive:

  • Your name, work email address and company.
  • Optionally your role, the process you are interested in, the number of cases per month, the systems involved and your message.
  • Anything else you choose to include in your email or attachments.

We use this to answer your request, plan a conversation and follow up on it. The legal basis is taking steps at your request before a possible agreement, and our legitimate interest in responding to business enquiries.

Website visits. When you visit the website, our hosting provider processes technical data such as your IP address, browser type and the pages requested. This is needed to deliver the website and to keep it secure. The legal basis is our legitimate interest in a working and secure website. We do not use analytics or advertising trackers, and we do not build visitor profiles.

Fonts. The website loads its typeface from Google Fonts. Your browser then connects to Google's servers, which receive your IP address. The legal basis is our legitimate interest in a consistent and readable website.

What we do not do

  • We do not sell or rent personal data.
  • We do not use your data for automated decision-making or profiling.
  • We do not add you to a mailing list without your explicit consent.

Who receives your data

We share personal data only with service providers we need to run our business, such as our email and hosting providers. They process the data on our behalf, under a processing agreement, and only for the purposes described here. We share data with authorities only when the law requires it.

Some of these providers are based in, or have parent companies in, the United States. Where personal data is transferred outside the European Economic Area, this happens on the basis of the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

How long we keep it

  • Enquiries and related correspondence: up to two years after our last contact, unless it leads to an agreement.
  • Data related to an agreement: as long as the agreement runs, and afterwards as long as the law requires, for example seven years for financial records.
  • Technical website logs: for a short period, as set by our hosting provider, generally no longer than a few weeks.

How we protect it

We take appropriate technical and organisational measures to protect personal data against loss and unauthorised access. These include encrypted connections, access only for people who need it, and multi-factor authentication on the systems we use.

Your rights

You have the right to access, correct or delete your personal data, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on consent, you can withdraw it at any time. Email your request to info@stencilflow.io. We respond within one month. We may ask you to confirm your identity first.

If you are not satisfied with how we handle your data, please tell us first. You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your own country.

Changes

We may update this policy when our services or the law change. The date at the top shows when it was last changed. We will announce significant changes on this website.