Lawfulness, fairness and transparency
Personal data should be processed lawfully, fairly and in a way that is transparent to the individuals concerned.
The General Data Protection Regulation, commonly known as GDPR, establishes rules for protecting personal data and sets out rights for individuals whose personal data is processed.
MME Flow provides customer communication tools that may involve processing information such as customer contact details, conversations, account information, technical data and information made available through connected services.
This page explains our general approach to GDPR and related data protection responsibilities. It should be read together with our Privacy Policy, Cookie Policy, Terms & Conditions and any applicable customer agreement.
GDPR may apply depending on factors such as where an organisation is established, where the individuals whose data is processed are located, the nature of the processing and the services being offered.
Businesses using MME Flow remain responsible for determining which privacy and data protection laws apply to their own activities, customer relationships and communication practices.
GDPR distinguishes between organisations that determine why and how personal data is processed and organisations that process personal data on their behalf. These roles are commonly described as controller and processor.
MME Flow may act as a controller for personal information processed for our own purposes, such as website interactions, account administration, billing, support requests, service management, security and business communications.
When a business uses MME Flow to process its own customer contacts, conversations and related communication data, MME Flow may process that information on the customer's behalf.
A business using MME Flow generally determines why it collects and uses personal information relating to its own customers, leads or contacts.
The same organisation can act as a controller for some processing activities and as a processor for others. The correct role depends on who determines the purposes and means of the specific processing involved.
Where GDPR applies, personal information should be handled in accordance with the core data protection principles.
Personal data should be processed lawfully, fairly and in a way that is transparent to the individuals concerned.
Personal information should be collected for specified and legitimate purposes and not used in a way that is incompatible with those purposes.
Organisations should process personal information that is adequate, relevant and limited to what is necessary for the intended purpose.
Reasonable steps should be taken to keep relevant personal information accurate and appropriately updated.
Personal information should not be kept in identifiable form for longer than necessary for the purposes for which it is processed.
Personal information should be protected using technical and organisational measures appropriate to the risks involved.
Organisations should be able to demonstrate that appropriate measures are in place to meet their data protection responsibilities.
Where GDPR requires a lawful basis, the appropriate basis should be identified for the specific processing activity before personal data is processed.
Processing may be necessary to provide requested services or perform obligations under a contract with an individual or organisation.
In appropriate circumstances, processing may rely on legitimate interests after considering the purpose involved and the rights and interests of affected individuals.
Certain processing activities may rely on valid consent where consent is required or is the appropriate lawful basis. Where applicable, consent must be capable of being withdrawn.
Processing may be necessary to comply with applicable legal, regulatory or statutory requirements.
Other lawful bases recognised by GDPR may apply in particular circumstances. The appropriate basis depends on the purpose and context of the processing and should not be selected simply because it is convenient.
Businesses may use MME Flow to manage contacts, customer conversations, chatbot interactions, support enquiries, broadcasts, automated workflows and team communication.
Where MME Flow processes this information on behalf of a customer, the customer generally determines the purpose of the processing and is responsible for establishing an appropriate lawful basis where GDPR applies.
Where GDPR applies, individuals may have a number of rights relating to their personal data. The exact rights and conditions depend on the processing involved.
Some rights are subject to conditions, exceptions and identity-verification requirements and therefore may not apply in every situation.
MME Flow uses administrative, organisational and technical measures designed to protect personal information against unauthorised access, accidental loss, alteration, disclosure or misuse.
Appropriate safeguards can vary depending on the nature of the information, the service or feature involved, account configuration and the risks associated with the processing.
Security is also a shared responsibility. Customers should protect login credentials, control authorised account access, review connected integrations and maintain appropriate security practices within their own organisation.
No internet-based system, transmission method or storage environment can guarantee absolute security.
MME Flow may use third-party providers to support services such as hosting, infrastructure, communications, security, analytics, customer support, billing and other operational functions.
The provider's data protection role depends on the processing involved. A provider may act as a processor for MME Flow or, where MME Flow processes customer data as a processor, as a sub-processor.
Where required, appropriate contractual and data protection arrangements should apply to processing carried out on behalf of a controller.
Customers may also connect third-party applications, messaging channels, APIs or integrations to MME Flow. Those services are operated under their own privacy, security and data protection terms.
MME Flow or its service providers may process personal information in countries different from the country where a customer or individual is located.
Where GDPR applies to an international transfer, an appropriate transfer mechanism or safeguard should be used where required by law. Depending on the circumstances, recognised mechanisms may include an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism.
The appropriate mechanism depends on the countries involved, the parties to the transfer and the nature of the processing.
Personal information should be retained only for as long as reasonably necessary for the purposes for which it is processed and to meet applicable legal, contractual, security or operational requirements.
Retention periods may vary depending on the type and sensitivity of the information, account status, customer instructions, service requirements, security needs and applicable law.
When personal information is no longer reasonably required, it may be deleted, anonymised or otherwise handled in accordance with applicable requirements and technical processes.
Where MME Flow processes information on behalf of a customer, retention or deletion may also depend on the customer's instructions and the applicable service agreement.
A personal data breach may involve accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.
Where a relevant security incident occurs, appropriate steps may include investigating the incident, containing its effects, reducing further risk and taking notification steps required by applicable law or contractual obligations.
Where MME Flow acts as a processor, GDPR may require us to notify the relevant controller without undue delay after becoming aware of a personal data breach affecting personal information processed on that controller's behalf.
Where MME Flow acts as a controller, applicable law may require notification to a supervisory authority or affected individuals depending on the nature and risk of the breach.
GDPR accountability means organisations should not only follow applicable data protection requirements but should also be able to demonstrate appropriate measures where required.
Depending on the organisation and processing activities involved, measures may include maintaining processing records, documenting lawful bases, assessing privacy risks, managing processors, applying data protection by design and maintaining suitable policies and procedures.
The specific measures required depend on the nature, scope, context and risks of the processing involved.
MME Flow provides tools that can support responsible customer communication, but businesses remain responsible for how they configure and use those tools.
If your request concerns personal information that MME Flow controls directly, you may contact our team with details of your request. We may need to verify relevant information before responding.
If your personal information is processed through MME Flow by one of our business customers, that business may be the appropriate controller to contact regarding your rights.
In those circumstances, MME Flow may assist the relevant customer with its response where appropriate and where required by applicable agreements or data protection law.
Legal rights can be subject to conditions and exceptions, and a request may require sufficient information for the relevant organisation to identify the information and verify the person making the request.
We may update this GDPR and Data Protection page to reflect changes to the MME Flow platform, privacy practices, service providers, legal requirements or data protection guidance.
When this page is updated, the revised version will be published here and the “Last updated” date will be changed.
Where appropriate, material changes may also be communicated through the website, platform, account communications or another suitable method.
If you have a question about GDPR, data protection, your privacy rights or how MME Flow handles personal information, contact our team and provide enough information for us to understand your request.