Privacy policy Flxion – Website and Application

Version 1.1 – 21 December 2021



1.1.   Your privacy is very important to us. This Privacy Policy (hereinafter “Privacy Policy”) is created to inform you about how we treat your personal data, and how you can exercise control over that data. It defines your legal rights and obligations towards Flxion.

Our Privacy Policy can be subject to future amendment and modification. In this event we will notify you with an invite to take a look at these changes, whom we will clearly indicate in the Privacy Policy

1.2     FLXION OÜ, with registered offices in Estonia, Pikk tn 51-7, 10133 Tallinn and registered with registry code 16262966 (hereinafter “Flxion”) and available via (hereinafter: the ‘’Website’’; takes responsibility for the processing of your personal data on the Application and Website as a “data controller”.

1.3     The collection and processing of personal data is governed by strict conditions, enforced by the law. Flxion acts in accordance with :

  1. the EU Regulation of 2016 concerning the protection of individuals with regards to the processing of personal data, regarding the free movement of such data and repealing Directive 95/46/EC;
  2. and/or all (future) Estonian laws regarding the implementation of this Regulation.

1.4     This Privacy Policy is applicable, inter alia, to how we handle your personal data through our ‘’Services’’ being the services offered, following and linked to our ‘’Website’’ and the ‘’Application’’, being the designated definition in this Privacy Policy for the following as a whole:

  1. The Flxion Dashboard;
  2. The Flxion App; and
  3. The Flxion Platform;

If you want to use our Services, we will first need your express approval (opt-in) of this Privacy Policy. This means you approve of how we collect, use and process your personal data.

You are not obliged to provide us with your personal data, however you must understand that we are not able to deliver you the Services in case you refuse to provide us with certain personal data.


2.1    Personal data Flxion collects:

  • Category 1 – User details:

    • information concerning your Flxion user account, e.g. your LoginID, password, name and surname, language, gender, timezone, preferences;
    • your contact information, e.g. your (mobile)telephone number(s), e-mail address, address, fax; and
    • business information, e.g. your organisation, bank account, IBAN, BIC, VAT-number, invoices; and
    • project information, e.g. your projects, timesheets, invoices, project and driving expenses and team members.
  • Category 2 – Your communications through our Services
    • information about the communication you had with Flxion, or through the Application and/or Services, e.g. when you had a problem with the Application and/or Services and asked for support or when you used the Live Chat within the Application.
  •  Category 3 – Your usage of our Services:
    • your usage data obtained by placing cookies (see article 7)
    • information relating to more ‘’technical’’ aspects of your use of the Application and/or Services, e.g. your IP address (also without registration), which version of the App you use, …

2.2     Flxion can obtain personal data though different means:

  1. during your use of our Application and/or Services;
  2. by your company administrator who creates a user account for you;
  3. by filling out questionnaires (for instance when you give us feedback, or when you use our support function)
  4. via social media (for instance when you like, or contact us on Facebook)
  5. by placing cookies (see article 7);



We want to highlight that Flxion collects and processes your personal information for one overarching goal, i.e. to offer you a safe, comfortable and personalized Flxion experience.

That being said, your personal data will only be processed for the following purposes:

3.1.    General purposes

  • Category 1: In order to manage your account on the Application and to make sure you can enjoy the Application and the services related to the Application fully, based on the execution of the agreement which you requested;

  • Category 1 and 2: In order to properly and easily address or notify you, or to be addressed by you. Also, to be able to follow up on your communication to us – all based on the execution of the agreement, which you requested;

  • Category 3: To maintain the safety of our Application and/or Services and improve them, as well as to create statistics based on the “legitimate interest” of Flxion to improve the Application and/or Services;

3.2.    Direct marketing:

By accepting our privacy policy, your personal data (category 1 to 3) will be used for direct marketing purposes.

In case you have given your consent and you are added to Flxion’s direct mailing list, Flxion may use your personal data to send you marketing material as well as other material relating to Flxion, her products and/or services.

Flxion can also transfer some of your personal data to her partners, for direct marketing purposes relating to Flxion, her products and/or services.

This consent can be revoked at all times, for free and without motivation, by clicking the unsubscribe button below every promotional e-mail.

3.3.    Transfer to third parties:

In order to process your personal data, we provide access to your personal data to our employees.

Flxion will also appeal to third parties in executing the agreement, to provide the requested service in order to optimize your experience with our Application and/or Services.

Yet, personal data is primarily processed for internal purposes within Flxion.

Flxion won’t sell, let, hand out your personal data nor place them at disposal of third parties, except in the situations provided for in this policy, or unless your explicit and preliminary consent.

Flxion has taken all legal and technical precautions to prevent unauthorized access and use.

We guarantee a similar level of protection by imposing contractual obligations to these third parties that are similar to this Privacy Policy and guarantee that the medical secrecy rules that protect patient medical data will at all times be respected.

In case of whole or partial reorganization or cession of Flxion’ activities, whereby Flxion reorganizes, transfers, ceases her business activity or in case Flxion goes bankrupt, your personal data may be transferred to new entities or third parties.

Flxion will try, if reasonably possible, to inform you beforehand of the fact that Flxion transfers your personal data to a third person. You must be aware that this is not always possible, because of what is realizable for Flxion, whereas we also need to take technical and commercial reasons into account.

3.4.    Legal requirements:

In extraordinary circumstances it may occur that Flxion is obliged to transfer your personal data following a court order, or in order to comply with imperative laws and/or regulations. Flxion will, if reasonably possible, try to inform you on beforehand, unless revealing this information is subject to legal constraints.



We will store and process your personal data for the period we’re legally obliged to do so, or for as long as this is essential for the purposes of the processing, as well as the contractual relationship between you/your company and Flxion.

Therefore, we keep a record of your data for as long as your account is active, or if your personal data is necessary to offer you a particular service. Additionally, in certain circumstances we might retain a limited amount of information for the period it would be of vital importance to to maintain the security of our Products.

Concrete, your personal data will be stored for the following terms:

  • Category 1: We keep your user details as long as your account is active and the following 5 years;
  • Category 2: We keep your communications through our Services as long as your account is active and the following 5 years;
  • Category 3: We keep your usage of our Services as long as your account is active and the following 5 years.


Article 5 – YOUR RIGHTS

5.1.    Right of access and right to obtain a copy

You have the right to freely obtain at any moment access to your personal data, as well as to be informed about the purpose of the processing by Flxion. We would like to invite you to check our Terms of Use for some extra information on this topic.

5.2.    Right to rectification, erasure or restriction

You have the choice to share your personal data with Flxion.

You also have the right to request Flxion to rectify your personal data. Please note that you can change your account information in the Application at any time on the ‘’Profile’’ page.

You can also request the processing of your personal data to be restricted, if you think your data is inaccurate and you subsequently notified us about this.

Additionally, you have the right to request Flxion to erase your data in as far we were not able to anonymize it.

Also, if Flxion cannot access, change or delete your data – e.g. because it is stored on your device – you should understand that we do not really have the time to come and stop by, so it will be up to you to undertake these actions yourself.

Furthermore, you acknowledge that a refusal to share data or a request to erase these data will make the delivery of several Flxion services impossible.

5.3.    Right to object:

You have the right to object to the processing of your personal data when you have serious and legitimate reasons to do so.

You also have the right to object to the use of your personal data for purposes of direct marketing. In such case specific reasoning will not be requested.

5.4.    Right to data portability:

You have the right to obtain your personal data which is processed by Flxion in a structured, commonly used format and/or to transfer this data to another data controller.

5.5.    Right to withdraw consent:

When the processing is based on prior consent you have the right to withdraw this consent.

5.6.    Automated decisions and profiling:

You have the right to request us not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

5.7.    Exercising your rights:

You can exercise your rights by contacting us with a copy of your ID (one sided, no social security number needed) as attachment.

If you contact us by e-mail or by mail, please enclose a copy of your ID (one sided, no social security number needed) as attachment.

5.8.    Right to file a complaint:

You have the right to file a complaint with the Estonian Data Protection Inspectorate, which is the Lead Supervisory Authority of Flxion. However, you are always free to contact your own European or EU-vested authority thereto.

This does not affect a procedure before the civil court. If you have suffered damages caused by the processing of your personal data, you can file a claim for damages.



6.1.      We have adopted safety measures which are suited on both a technical and an organisational level to avoid the destruction, the loss, the forgery, the adjustment, the non-authorised access or the notification of the personal data by accident to a third party, as well as the non-authorised processing of these data. Nevertheless, if these events would occur and would affect your personal data, Flxion will inform you of the breach without undue delay, including a summary description of the potential impact and a recommendation on measures to mitigate the possible adverse effects of the breach.

Flxion has made sure to encrypt all communications concerning your health-related data. Also, the information on the Flxion servers in Frankfürt, Germany, on IBM Cloud, can only be read by Flxion and/or her employees in possession of the right key. The outside world cannot access this information.

6.2.      Flxion shall not be liable in any way for direct or indirect damages caused by a wrongfully or improper use of the personal data by a third party.

6.3       At the same time, you also share responsibility for maintaining the privacy and security of the Application and/or Services, for example: by not allowing any third party to use your personal Flxion account on the Application and/or Services and avoiding all other non- authorised access to your login and access code. You are solely responsible for the use of the Application and/or Services on your devices, IP address and identification data, as well as for its confidentiality.

6.4       In any case, you need to immediately notify Flxion of any unauthorized use of your personal Account by sending an e-mail to .


Article 7 – Cookies

7.1. What are cookies?

A “cookie” is a small file sent by the Flxion server and placed on your computer’s hard drive. The information stored on these cookies can only be read by us and this only for the duration of the visit to the Website.

7.2. Why do we use cookies?

Our Website uses cookies and similar technologies to distinguish your user preferences from those of other users of our website. This helps us to provide you with a better user experience when you visit our website and also allows us to optimize our website.

As a result of recent legislative changes, all websites targeting certain parts of the European Union are required to obtain your consent to the use or storage of cookies and similar technologies on your computers or mobile devices. This Cookie Policy gives you clear and complete information about the cookies we use and their purpose.

7.3. Types of cookies:

Although there are different types of cookies, which differ in terms of functionality, origin or retention period, the legislation mainly distinguishes between functional or technically necessary cookies on the one hand and all other cookies on the other hand.

Our Website only uses the following cookies:
Functional cookie

Name Function
Authentication cookies

‘Remember me’

Identify the user when he is logged in.
User input cookies

‘Lifestyle Identifier’

Remembering the actions of the user on a website.
User interface customization cookies Used to remember user preferences.

Non-functional cookies

Name Function
Tracking cookies Are used to record the surfing behaviour of visitors.
Social plug-in tracking cookies Used to offer social media modules on a website, such as a Facebook Like button, LinkedIn share button or the ability to retweet a message.

For cookies placed by third parties (e.g. Google Analytics, Plus, Maps, Analytics, Adwords), Bing Search Marketing, Facebook we would like to refer you to the statements made by these parties on their respective websites. Please note that we have no influence on the content of these statements, nor on the content of the third party cookies: Google Analytics cookies.

7.4.     Your consent:

On your first visit to our website, you will be asked to accept our cookies subject to approval of this policy. You can change the cookie settings for our Website at any time via the hyperlink at the bottom of our Website and thus withdraw your consent.

You can refuse the installation of these cookies by selecting “refuse cookies” on the first use of the Website in the pop-up screen provided for this purpose.

You can also refuse or block cookies by changing the configuration parameters of your navigation system. Disabling cookies may mean that you will not be able to use certain functionalities of the Website.

For more information about the cookies themselves, please refer to the relevant websites regarding these cookies (such as Google (, …).

If you have any further questions or comments regarding the processing of your Personal Data, please feel free to contact us by e-mail to

More information about cookies can also be found at:

More information on online behavioural advertising and online privacy can be found here:


Article 8 – Applicable Law and jurisdiction

This Privacy Policy is managed, interpreted and executed in accordance with Estonian law which exclusively applies to every potential dispute.

The courts and tribunals of Tallinn have exclusive jurisdiction to settle any dispute arising out of or in connection to the interpretation or execution of the present Privacy Policy.