Legal

Privacy Policy

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Solution Flow PTE. LTD.
1 North Bridge Road #B1-35
High Street Centre, Singapore 179094
UEN: 202500502C
Email: support@thesolutionflow.com
Telephone and WhatsApp Business: +65 8034 9633
Website: www.thesolutionflow.com

A representative in the Union pursuant to Art. 27 GDPR has not been designated.

Solution Flow PTE. LTD. is the operator of this website and provides its services under the Solution Flow brand. Responsibility for data protection matters relating to this website lies exclusively with Solution Flow PTE. LTD.

Contact for data protection matters:
Racha Chaipanya
Email: support@thesolutionflow.com

2. General information on data processing

The protection of your personal data is of great importance to us. We process personal data confidentially and in accordance with the applicable statutory data protection provisions and this Privacy Policy.

Personal data is any information that can be used to identify you personally. This Privacy Policy explains the nature, scope and purpose of the collection and use of personal data, as well as your rights as a data subject.

3. Data collection on our website

3.1 Access data and server log files

When you visit our website, technical information is automatically collected:

  • IP address
  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname
  • Date and time of the server request
  • Pages accessed and volume of data transferred

This data is technically necessary to ensure the operation and security of the website and is not merged with other data sources. It arises on the infrastructure of our host, who operates the web server and an upstream content delivery network (CDN) for us; further details are provided in Section 3.7.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability, security and optimisation of the website).

3.2 Contact

When you contact us by email, telephone, WhatsApp Business or via this website's questionnaire (see Section 3.3), the data transmitted is processed, in particular:

  • Name (if provided)
  • Email address
  • Telephone number (if provided)
  • Other voluntary details

This processing is carried out exclusively to handle your enquiry.

We provide the telephone number +65 8034 9633 on this website and in our emails as a contact channel via WhatsApp Business. If you write to us there, we process your telephone number, the profile name stored there and the content of your message in order to answer your enquiry. WhatsApp is not operated by us; the provider's own data protection provisions, over which we have no influence, additionally apply to processing within the service, and data may in the process be processed outside the European Economic Area. If you would prefer to avoid this, please write to us instead at support@thesolutionflow.com.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in communication).

3.3 Questionnaire

On this website, you can fill out a questionnaire to prepare for an information call. Participation is voluntary. As long as you do not submit the questionnaire, no data is transmitted to us. When you submit it, we process:

  • Your name
  • Your email address
  • Your telephone number, if you fill in the voluntary field
  • Your answers to the five questions in the questionnaire (experience with financial instruments, amount under consideration, free availability of this amount, planned time horizon, handling of interim losses)
  • The language version used, as well as the date and time of receipt according to server time
  • Your consent, given by means of the mandatory checkbox in the questionnaire: by this, you confirm that you have read this Privacy Policy and agree to the processing of your details for the purpose of preparing the information call.

Name, email address and this consent are required so that we can accept the questionnaire and reply to you; without these details, the questionnaire cannot be submitted. The telephone number is voluntary; without it, we can only reach you by email. There is no statutory or contractual obligation to provide this data.

Your answers are automatically assigned to one of three groups according to fixed, predefined rules. This categorisation determines which next step is displayed to you after submission and suggested in the confirmation email: an appointment suggestion, or initially our informational content. It is not investment advice and not an assessment of you as a person; our content remains accessible to you in any case, and you can write to us by email at any time, independently of this.

Automated decision-making, including profiling within the meaning of Art. 22(1) and (4) GDPR, which produces legal effects concerning you or similarly significantly affects you, is not associated with this categorisation.

Upon submission, the following happens:

  • Your details are stored as a non-public entry in the database of our WordPress website, which is operated by our host (Section 3.7). No IP address is stored for this entry.
  • We receive a notification at support@thesolutionflow.com containing your details. The email address you provided is set as the reply address.
  • You receive a confirmation at the email address you provided, indicating the respective next step.

Access to the stored entries is restricted exclusively to logged-in users of our website with the appropriate authorisation; there are currently two people with administrator rights. The entries are not publicly accessible.

We delete your details from the questionnaire no later than six months after the last contact, provided this does not result in a business relationship; this applies both to the entries in our database and to the associated email correspondence. If a business relationship results, the statutory retention periods apply.

You can withdraw your consent at any time with effect for the future and request the deletion of your details. An informal email to support@thesolutionflow.com is sufficient. The lawfulness of the processing carried out up to the withdrawal remains unaffected by this.

To protect against automated submissions, when the questionnaire is submitted we check an additional field that is invisible to you, as well as the time elapsed between starting and submitting the questionnaire, and we limit the number of submissions per hour. For this count, your IP address is used exclusively in the form of a hash value as a counter key; it is not stored in plain text and does not appear in your entry. The counter expires after one hour.

Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (pre-contractual measures); for protection against automated submissions, Art. 6(1)(f) GDPR (legitimate interest in preventing misuse).

3.4 Storage in your browser, cookies and consent

This website does not use cookies for analytics, advertising or recognition. Instead, for its operation, it uses two storage mechanisms provided by your browser:

  • sf_consent in local storage (localStorage): this records whether you selected “Essential only” or “Accept all” in the consent notice. Only in this way can we respect your decision and avoid showing you the notice again on every visit. The entry remains stored until you delete it.
  • sf_quiz_done and sf_quiz_result in session storage (sessionStorage): after the questionnaire is submitted, its result is stored there, including your name, your email address, any telephone number provided and your answers, so that the “Information call” page can pick this up and display the appointment booking to you there. This copy in your browser is not transmitted to us; your details are transmitted to us when the questionnaire is submitted (Section 3.3). It is deleted as soon as you close the browser tab.

These entries are not used to recognise you across multiple websites or to track your behaviour. If storage in your browser is blocked, you can still read the website and submit the questionnaire. The consent notice will then reappear on every visit, and the “Information call” page will not be automatically unlocked after submission. In that case, please write to us at support@thesolutionflow.com.

Technically necessary cookies may be set by the website software used (WordPress and the page cache used), in particular when logging in to the protected administration area. As a visitor to the public pages, you are generally not affected by this.

Scripts that require consent are only executed after you have selected “Accept all” in the notice; until then, they are deactivated in the delivered page. If you select “Essential only” or make no selection, they remain permanently inactive. Audience measurement (Section 3.6) is currently controlled via this notice. Independently of this, Calendly's appointment calendar is only loaded after you click it yourself (Section 3.5). We do not use Google Analytics, Google Tag Manager, advertising and marketing technologies, social media plugins, embedded videos or externally loaded fonts.

You can withdraw your consent at any time with effect for the future by deleting the browser data stored for this website, usually found in your browser's settings under “Clear browser data” or “Website data”. This removes the sf_consent entry; on your next visit, the notice will reappear and you can decide again.

Legal basis: Art. 6(1)(a) GDPR (consent) for all non-essential storage and access operations; Art. 6(1)(f) GDPR (legitimate interest in technical operation) for storing your selection in the consent notice; Art. 6(1)(b) GDPR (pre-contractual measures) for the temporary storage of the questionnaire result in your browser.

For more information, see the Cookie Notice.

3.5 Online appointment booking (Calendly)

For booking information calls, we use the Calendly service provided by Calendly, LLC, 1315 Peachtree St NE, Atlanta, GA 30309, USA. The appointment calendar is only loaded after you have actively started it with a click (two-click solution). Only with this click is a connection established to Calendly's servers; no data is transmitted to Calendly before that.

When you use the appointment booking, Calendly processes in particular:

  • Name
  • Email address
  • selected appointment (date and time)
  • IP address and technical connection data
  • further voluntary details in the booking form

This processing serves exclusively to arrange and carry out the information call. Calendly is a provider based in the USA; loading the calendar transmits data there, and Calendly may set its own cookies in doing so. Processing by Calendly is governed by the provider's privacy policy: calendly.com/privacy.

Which details are required for a booking is determined by Calendly's booking form; without the details requested there, no booking can be made. There is no obligation to use this route: if you would prefer to avoid this transmission, do not load the calendar, but write to us at support@thesolutionflow.com: we will then arrange the appointment with you by email.

Legal basis: Art. 6(1)(a) GDPR (consent through actively loading the calendar) and Art. 6(1)(b) GDPR (pre-contractual measures).

3.6 Audience measurement (Burst Statistics)

For audience measurement, we use the WordPress plugin Burst Statistics. It only runs after you have selected “Accept all” in the consent notice. If you select “Essential only” or make no selection, no audience measurement takes place: the script is delivered with the page but remains deactivated and is not executed.

Measurement takes place without cookies and without transmission to third parties. All data is processed and stored exclusively on our own server. The plugin is configured so that it does not create a device fingerprint; an anonymous key that changes daily is used to distinguish between visits. IP addresses are not stored permanently. If your browser sends the “Do Not Track” setting, no measurement takes place either.

Information on the use of our website is collected, such as pages visited and time spent on the site. The evaluation is carried out in aggregated form. For the retention period, see Section 7.

Legal basis: Art. 6(1)(a) GDPR (consent). How to withdraw this consent is explained in Section 3.4.

3.7 Service providers and recipients of data

To operate this website and for our communications, we use the following service providers. They process data partly on our behalf and partly on their own legal bases:

  • Our host (Hostinger) — operation of the web server, upstream content delivery network (CDN) and our email mailboxes. This is where the access data referred to in Section 3.1 is generated; the database containing the entries from the questionnaire is also located on this server. We will provide you with the company name and server location on request.
  • Brevo (Brevo SAS, Paris, France) — technical delivery of the confirmation to you and the notification to us. This involves processing the sender and recipient address, subject line and content of the respective message. We do not send newsletters or promotional emails. Emails that we later write to you personally from our mailbox run via our host's infrastructure.
  • Calendly, LLC, USA — appointment booking, only after you have loaded the calendar yourself (Section 3.5).
  • The provider of the WhatsApp Business messenger — if you write to us via the telephone number given in the Imprint and in the footer; further details in Section 3.2.

We do not pass on your data for advertising purposes. Beyond this, we only disclose personal data where we are legally obliged to do so. We are happy to answer questions about our service providers at support@thesolutionflow.com.

4. Legal bases for processing

Processing is based on:

  • Art. 6(1)(a) GDPR – consent
  • Art. 6(1)(b) GDPR – contract / pre-contractual measures
  • Art. 6(1)(c) GDPR – legal obligation
  • Art. 6(1)(f) GDPR – legitimate interest

5. Transfers to third countries

The controller is based in Singapore. Data that you send to us, such as your details from the questionnaire or an email to us, are therefore also processed outside the European Economic Area when we read and handle them. There is no adequacy decision by the European Commission for Singapore under Art. 45 GDPR. We are additionally subject to the Singapore Personal Data Protection Act (PDPA).

The technical infrastructure of this website is operated by the service providers named in Section 3.7. The web server, the database and our email mailboxes are operated by our host; we will provide you with the server location on request.

A transfer to the USA takes place in particular when you load Calendly's appointment calendar yourself with a click. The basis for this transfer is the consent you give with this click (Section 3.5). There is no adequacy decision for the USA that applies generally to every recipient; access to data by authorities there therefore cannot be ruled out. You can avoid this transfer by not loading the calendar and instead writing to us by email. In addition, data may be processed outside the European Economic Area if you write to us via WhatsApp Business (Section 3.2), as well as within the infrastructure named in Section 3.7.

On request, we will inform you which basis under Art. 44 et seq. GDPR a specific transfer relies on; where appropriate safeguards under Art. 46 GDPR exist for a transfer, you will receive a copy on request. Please contact support@thesolutionflow.com for this.

To protect your data, we implement the technical and organisational measures described in Section 8.

6. Rights of data subjects

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent given (Art. 7(3) GDPR)
  • Lodging a complaint with a supervisory authority (Art. 77 GDPR)

Regarding the right to object: Where we process data on the basis of a legitimate interest (Sections 3.1, 3.2, 3.3 and 3.4), you may object at any time to this processing on grounds relating to your particular situation. An informal email to support@thesolutionflow.com is sufficient.

Regarding the right to lodge a complaint: Regardless of whether you have contacted us before, you may lodge a complaint with a data protection supervisory authority, in particular the authority for your habitual residence, your place of work, or the place where the infringement you suspect took place.

This is how you exercise your right of withdrawal in practice: you withdraw your consent to audience measurement by deleting the browser data stored for this website (Section 3.4). You withdraw your consent to the processing of the details from the questionnaire informally by email (Section 3.3). In each case, the withdrawal takes effect for the future.

Please direct your requests to: support@thesolutionflow.com

7. Retention period

  • Server log files: max. 7 days; they are generated on our host's infrastructure, which manages them for us (Section 3.7).
  • Details from the questionnaire and the associated email correspondence: 6 months after the last contact, provided this does not result in a business relationship. If a business relationship results, the statutory retention periods apply.
  • Other contact enquiries (email, telephone, WhatsApp Business): until processing has been completed, unless statutory retention periods require otherwise.
  • Data from an appointment booking (Section 3.5): until the information call and the subsequent correspondence have concluded; storage at the provider is additionally subject to its own retention periods, over which we have no influence.
  • Spam protection counter (Section 3.3): 1 hour.
  • Storage in your browser: sf_consent, until you delete the website data in your browser; sf_quiz_done and sf_quiz_result, until you close the browser tab.
  • Data from audience measurement (Section 3.6): until you withdraw your consent; otherwise for as long as it is required for the statistical evaluation of website usage.
  • Contract-relevant data: in accordance with statutory retention periods (up to 10 years).

8. Data security

We implement appropriate technical and organisational measures, including:

  • encrypted transmission of all pages via HTTPS (SSL/TLS), additionally secured by the Strict-Transport-Security security header
  • further security headers on every delivery (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy)
  • restricted access to the entries from the questionnaire: they are not public, cannot be retrieved via search or via the website's programming interface, and are only accessible to logged-in users with the appropriate authorisation
  • strict validation of all submitted form fields on the server: only known fields and values are accepted, addresses and links in the name field are rejected, and the reply address of the notification email cannot be altered by free text
  • protection against automated submissions and a limit on submissions per hour (Section 3.3)

9. Changes to this Privacy Policy

This Privacy Policy is updated in the event of legal, technical or structural changes. The version currently published on the website is always authoritative.

Last updated: September 2026 · Solution Flow PTE. LTD., Singapore