MME Flow
01

About GDPR and this page

The General Data Protection Regulation, commonly known as GDPR, establishes rules for protecting personal data and sets out rights for individuals whose personal data is processed.

MME Flow provides customer communication tools that may involve processing information such as customer contact details, conversations, account information, technical data and information made available through connected services.

This page explains our general approach to GDPR and related data protection responsibilities. It should be read together with our Privacy Policy, Cookie Policy, Terms & Conditions and any applicable customer agreement.

Important This page provides general information about our data protection approach. Whether GDPR applies, and what an organisation must do to comply with it, depends on the particular processing activity and circumstances involved.
02

When GDPR may apply

GDPR may apply depending on factors such as where an organisation is established, where the individuals whose data is processed are located, the nature of the processing and the services being offered.

Businesses using MME Flow remain responsible for determining which privacy and data protection laws apply to their own activities, customer relationships and communication practices.

Compliance depends on use Using a software platform does not by itself make an organisation GDPR compliant. Compliance also depends on the organisation's processing activities, legal basis, notices, procedures, security measures and how the platform is configured and used.
03

Controller and processor roles

GDPR distinguishes between organisations that determine why and how personal data is processed and organisations that process personal data on their behalf. These roles are commonly described as controller and processor.

MME Flow as controller

MME Flow may act as a controller for personal information processed for our own purposes, such as website interactions, account administration, billing, support requests, service management, security and business communications.

MME Flow as processor

When a business uses MME Flow to process its own customer contacts, conversations and related communication data, MME Flow may process that information on the customer's behalf.

Customer as controller

A business using MME Flow generally determines why it collects and uses personal information relating to its own customers, leads or contacts.

Roles depend on context

The same organisation can act as a controller for some processing activities and as a processor for others. The correct role depends on who determines the purposes and means of the specific processing involved.

04

Data protection principles

Where GDPR applies, personal information should be handled in accordance with the core data protection principles.

Lawfulness

Lawfulness, fairness and transparency

Personal data should be processed lawfully, fairly and in a way that is transparent to the individuals concerned.

Purpose

Purpose limitation

Personal information should be collected for specified and legitimate purposes and not used in a way that is incompatible with those purposes.

Minimum

Data minimisation

Organisations should process personal information that is adequate, relevant and limited to what is necessary for the intended purpose.

Accuracy

Accuracy

Reasonable steps should be taken to keep relevant personal information accurate and appropriately updated.

Retention

Storage limitation

Personal information should not be kept in identifiable form for longer than necessary for the purposes for which it is processed.

Security

Integrity and confidentiality

Personal information should be protected using technical and organisational measures appropriate to the risks involved.

Responsibility

Accountability

Organisations should be able to demonstrate that appropriate measures are in place to meet their data protection responsibilities.

05

Lawful bases for processing

Where GDPR requires a lawful basis, the appropriate basis should be identified for the specific processing activity before personal data is processed.

Contract

Processing may be necessary to provide requested services or perform obligations under a contract with an individual or organisation.

Legitimate interests

In appropriate circumstances, processing may rely on legitimate interests after considering the purpose involved and the rights and interests of affected individuals.

Consent

Certain processing activities may rely on valid consent where consent is required or is the appropriate lawful basis. Where applicable, consent must be capable of being withdrawn.

Legal obligations

Processing may be necessary to comply with applicable legal, regulatory or statutory requirements.

Other lawful bases recognised by GDPR may apply in particular circumstances. The appropriate basis depends on the purpose and context of the processing and should not be selected simply because it is convenient.

06

Customer and messaging data

Businesses may use MME Flow to manage contacts, customer conversations, chatbot interactions, support enquiries, broadcasts, automated workflows and team communication.

Where MME Flow processes this information on behalf of a customer, the customer generally determines the purpose of the processing and is responsible for establishing an appropriate lawful basis where GDPR applies.

  • Collect and use personal information only for appropriate and defined business or communication purposes.
  • Provide required privacy information to individuals where applicable.
  • Establish consent or another appropriate lawful basis where required for messaging or marketing activity.
  • Respect applicable opt-out, objection and communication preference requests.
  • Avoid using MME Flow to process personal information in a way that violates applicable data protection law.
07

Individual data protection rights

Where GDPR applies, individuals may have a number of rights relating to their personal data. The exact rights and conditions depend on the processing involved.

  • The right to receive information about how personal data is being processed.
  • The right to request access to personal data.
  • The right to request correction of inaccurate or incomplete personal data.
  • The right to request erasure in circumstances where that right applies.
  • The right to request restriction of certain processing.
  • The right to object to certain processing where applicable.
  • The right to data portability in circumstances where that right applies.
  • Rights relating to certain automated decision-making and profiling activities where applicable.
  • The right to withdraw consent where processing relies on consent, without affecting processing carried out before withdrawal.
  • Where applicable, the right to raise a concern or lodge a complaint with the relevant data protection supervisory authority.

Some rights are subject to conditions, exceptions and identity-verification requirements and therefore may not apply in every situation.

08

Security and data protection

MME Flow uses administrative, organisational and technical measures designed to protect personal information against unauthorised access, accidental loss, alteration, disclosure or misuse.

Appropriate safeguards can vary depending on the nature of the information, the service or feature involved, account configuration and the risks associated with the processing.

Security is also a shared responsibility. Customers should protect login credentials, control authorised account access, review connected integrations and maintain appropriate security practices within their own organisation.

No internet-based system, transmission method or storage environment can guarantee absolute security.

09

Service providers, processors and sub-processors

MME Flow may use third-party providers to support services such as hosting, infrastructure, communications, security, analytics, customer support, billing and other operational functions.

The provider's data protection role depends on the processing involved. A provider may act as a processor for MME Flow or, where MME Flow processes customer data as a processor, as a sub-processor.

Where required, appropriate contractual and data protection arrangements should apply to processing carried out on behalf of a controller.

Customers may also connect third-party applications, messaging channels, APIs or integrations to MME Flow. Those services are operated under their own privacy, security and data protection terms.

10

International data transfers

MME Flow or its service providers may process personal information in countries different from the country where a customer or individual is located.

Where GDPR applies to an international transfer, an appropriate transfer mechanism or safeguard should be used where required by law. Depending on the circumstances, recognised mechanisms may include an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism.

The appropriate mechanism depends on the countries involved, the parties to the transfer and the nature of the processing.

11

Data retention and deletion

Personal information should be retained only for as long as reasonably necessary for the purposes for which it is processed and to meet applicable legal, contractual, security or operational requirements.

Retention periods may vary depending on the type and sensitivity of the information, account status, customer instructions, service requirements, security needs and applicable law.

When personal information is no longer reasonably required, it may be deleted, anonymised or otherwise handled in accordance with applicable requirements and technical processes.

Where MME Flow processes information on behalf of a customer, retention or deletion may also depend on the customer's instructions and the applicable service agreement.

12

Personal data breaches

A personal data breach may involve accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.

Where a relevant security incident occurs, appropriate steps may include investigating the incident, containing its effects, reducing further risk and taking notification steps required by applicable law or contractual obligations.

Where MME Flow acts as a processor, GDPR may require us to notify the relevant controller without undue delay after becoming aware of a personal data breach affecting personal information processed on that controller's behalf.

Where MME Flow acts as a controller, applicable law may require notification to a supervisory authority or affected individuals depending on the nature and risk of the breach.

13

Accountability and records

GDPR accountability means organisations should not only follow applicable data protection requirements but should also be able to demonstrate appropriate measures where required.

Depending on the organisation and processing activities involved, measures may include maintaining processing records, documenting lawful bases, assessing privacy risks, managing processors, applying data protection by design and maintaining suitable policies and procedures.

The specific measures required depend on the nature, scope, context and risks of the processing involved.

14

Customer responsibilities

MME Flow provides tools that can support responsible customer communication, but businesses remain responsible for how they configure and use those tools.

  • Determine whether GDPR or other privacy laws apply to your organisation and processing activities.
  • Establish an appropriate lawful basis for processing customer and contact information where required.
  • Provide required privacy notices and transparency information to individuals.
  • Control authorised account access and use available security settings appropriately.
  • Manage consent, opt-outs and marketing permissions where applicable.
  • Respond appropriately to data protection requests from individuals.
  • Review third-party services and integrations connected to your MME Flow account.
  • Use customer and messaging information only in accordance with applicable legal and communication requirements.
15

Data protection requests

If your request concerns personal information that MME Flow controls directly, you may contact our team with details of your request. We may need to verify relevant information before responding.

If your personal information is processed through MME Flow by one of our business customers, that business may be the appropriate controller to contact regarding your rights.

In those circumstances, MME Flow may assist the relevant customer with its response where appropriate and where required by applicable agreements or data protection law.

Legal rights can be subject to conditions and exceptions, and a request may require sufficient information for the relevant organisation to identify the information and verify the person making the request.

16

Changes to this page

We may update this GDPR and Data Protection page to reflect changes to the MME Flow platform, privacy practices, service providers, legal requirements or data protection guidance.

When this page is updated, the revised version will be published here and the “Last updated” date will be changed.

Where appropriate, material changes may also be communicated through the website, platform, account communications or another suitable method.

17
Data protection question?

Contact us

If you have a question about GDPR, data protection, your privacy rights or how MME Flow handles personal information, contact our team and provide enough information for us to understand your request.