FLUXIQ
Diagnose · Solve · Keep Flowing
Built for UK Gas Engineers
FluxIQ boiler diagnosis software logo
Version 1.0 · June 2025

Data Processing & GDPR Notice

Last updated: June 2025

This notice explains how FluxIQ processes personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It supplements the Privacy Policy with additional technical detail relevant to engineers and business owners.

1. Data Controller

FluxIQ is the data controller for personal data processed through this platform. Contact for data protection matters: privacy@fluxiq.app

2. Categories of Personal Data Processed

CategoryExamplesLegal Basis
Identity dataName, email addressContract
Professional credentialsGas Safe registration number, companyLegal obligation
Diagnostic session dataFault codes, symptoms, AI responsesContract
Feedback dataEngineer notes, outcome ratingsContract / Legitimate interests
Technical dataIP address, browser type, session logsLegitimate interests
Consent recordsAccepted documents, versions, timestampsLegal obligation
Payment dataSubscription status (our payment processor holds card data)Contract

3. Sub-Processors

FluxIQ uses trusted third-party providers to securely operate the platform, process payments, support AI-assisted diagnostics, and deliver essential functionality. Each provider operates under a written Data Processing Agreement and, where applicable, appropriate international transfer safeguards (such as UK Standard Contractual Clauses).

A current sub-processor list is available on request from privacy@fluxiq.app.

4. Automated Decision-Making

FluxIQ uses AI to generate diagnostic suggestions. This constitutes automated processing but does not constitute solely automated decision-making that produces legal or similarly significant effects. All AI outputs are presented as suggestions for review by a qualified human engineer. No automated decision is taken about you personally; AI suggestions relate to appliances, not individuals.

5. Data Security Measures

FluxIQ uses encryption, access controls, audit logging, and secure operational processes to protect user data. Technical and organisational measures are reviewed regularly and refined as the service evolves.

6. Retention Periods

Data TypeRetention PeriodBasis
Account / profile dataAccount lifetime + 2 yearsContract / Legal
Diagnostic session data3 years from session dateLegitimate interests
Consent records6 yearsLegal obligation
Audit log entries6 yearsLegal obligation
Verification documents30 days post-decisionLegal obligation
Payment records (payment processor)7 yearsTax / Legal obligation

7. Your Rights and How to Exercise Them

You may exercise your UK GDPR rights by emailing privacy@fluxiq.app. Responses will be provided within 30 calendar days. We may ask you to verify your identity before processing a request. Some rights are subject to exemptions; where an exemption applies we will explain why.

For erasure requests, note that some data (e.g., audit logs, consent records) may be retained where we have an overriding legal obligation to do so.

You may also exercise data management rights directly within your Account Settings page.

8. Data Breach Notification

In the event of a personal data breach we will notify the ICO within 72 hours where required by UK GDPR. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.