Privacy Policy

Version 1.3 Last updated 8 August 2026
Pre-launch notice. Served Social is currently in free early-access trial — paid subscriptions are not yet live. These Terms & Conditions, Privacy Policy and Fair Usage Policy come into full effect once paid subscriptions are active, at which point a published support address will also go live. Until then, reach us through the feedback box in your dashboard — it comes straight to us — or by post at the registered office below.

This policy explains what personal data GG Flows collects, why we collect it, how we use and protect it, and the rights you have over it. It is written for a UK small-business audience — plain English, but legally binding.

Who we are. GG Flows is a trading name of G Green Holdings Ltd (company number 16314439), a company registered in England & Wales, whose registered office is Unit 20 Ptarmigan Place, Attleborough Fields Industrial Estate, Nuneaton, Warwickshire, CV11 6RX. For the personal data described in this policy, G Green Holdings Ltd is the data controller unless stated otherwise. We are the "data processor" for the limited activities described in section 6.

1. Scope

This policy covers our two product lines:

  • Flow & overlay build service — we build branded Klaviyo email/SMS marketing flows and StreamLabs/OBS live-draw overlay scenes for prize-competition operators.
  • Served Social — our software product that generates on-brand social posts, reels, marketing emails and SMS content and delivers them to the client as a download pack. Where a client connects their own GoHighLevel account, it can also create those posts in that account's Social Planner at the client's request.

It applies to our clients (the businesses that buy our services), people who contact us or request access, and visitors to servedsocial.com.

2. The personal data we collect

From client businesses and their staff

  • Account & contact details — business name, contact name, email address, phone number, and login credentials (passwords are stored only as a secure one-way hash).
  • Brand & competition data — your competition website URL(s) and publicly available information scraped from them (competition names, prices, ticket counts, end dates, published winners), plus the brand assets you upload (logos, mascot images, product photos, example posts and ad copy).
  • Connected-account access — Klaviyo API keys/account access (flow-build clients) and, where a Served Social client chooses to connect one, a GoHighLevel private-integration token and Location ID (stored encrypted). These are credentials we hold to act on your instructions. We do not hold logins, passwords or OAuth tokens for Facebook, Instagram or any other social network.
  • Billing data — subscription status and the details needed to take payment. Card details are handled by our payment processor (see section 5) and are not stored on our servers.
  • Usage & technical data — log data, IP address, device/browser information, and records of how you use the product, used to run, secure and improve the service.
  • Consent records — the date and time you accepted these policies at sign-up.

End-customer data inside your Klaviyo account

When we build flows for you, we access the contact data held inside your own Klaviyo account (your subscribers). We do not own or export this data — see section 6.

3. How we use your data, and our legal basis

PurposeLawful basis (UK GDPR)
Providing the service you signed up for (generating content, delivering your pack, creating posts in a GoHighLevel account you have connected and confirmed, building flows/overlays)Performance of a contract
Taking payment and managing your subscriptionPerformance of a contract
Securing the service, preventing abuse, keeping logsLegitimate interests
Improving and supporting the productLegitimate interests
Service and account emails (e.g. welcome, password reset, important notices)Performance of a contract / legitimate interests
Optional marketing emails from GG Flows about our own productConsent (you can opt out at any time)
Meeting legal, tax and accounting obligationsLegal obligation

4. How AI generation uses your assets

Served Social uses AI to generate content. We handle your uploaded assets carefully and by category:

  • Style references — used only as a visual style guide for AI image generation; they are not reproduced directly in output.
  • Brand marks (logos, frames, watermarks) — used only to composite onto generated images. They are not sent to the AI model as image-generation input. One exception, so this is not misleading: when we pick your logo off your website, a picture of the candidates plus a screenshot of your homepage is sent to Anthropic's model to confirm we have chosen the right one.
  • Text/ad references — used only as tone reference for caption generation; they are not reproduced verbatim.

Photographs are transmitted, not just described. Where you upload a photo as a reference for an image, that photograph is sent as image data to our image provider (Google). Photographs from your own website, and a screenshot of it, are sent to Anthropic so the AI can see what your business actually looks like and write and check work accordingly. Some of those photographs contain people — your team, your customers. This is how the product works rather than an incidental transfer, so we would rather state it plainly than leave it implied.

Logos and text-heavy assets are excluded from image-generation prompts, and every image request carries an explicit instruction excluding text, typography and logos. We do not use your data to train third-party AI models, and our AI subprocessors (see section 5) act on our instructions under their own commitments not to train their base models on API content.

5. Who we share data with (subprocessors)

We use a small number of trusted providers to run the service. We share only what each needs to do its job:

ProviderPurpose
Anthropic (Claude API)Generating post/email/SMS copy from your brand profile, and reading images: photographs from your website, a screenshot of it, your logo candidates, and the finished cards we check before delivery
Google Cloud / Vertex AI, and the Google Gemini APIGenerating images from brand-derived prompts, including any photograph you supply as a reference. Both are Google services and either may be used
Google (Maps / Places API)Checking your business's published contact details and opening hours, where that lookup is enabled
HighLevel (GoHighLevel)Only if you connect your own GoHighLevel account: we upload the images you approved to your media library and create the approved posts in your Social Planner. Your captions and images are sent to HighLevel to do this.
KlaviyoYour own email/SMS marketing platform (your account — we access it on your behalf)
StripePayment processing (card data is handled directly by Stripe)
RailwayApplication hosting
CloudflareDNS, CDN and security
ResendSending our own service emails

Some of these providers are located outside the UK. Where personal data is transferred internationally, we rely on the UK's adequacy regulations or on standard contractual clauses / the UK International Data Transfer Addendum to keep it protected. We do not sell your personal data.

6. When we are a data processor

For the end-customer data held inside your Klaviyo account, you remain the data controller and GG Flows acts only as your data processor: we access and process that data solely to build and configure the flows you have asked for, on your documented instructions, and we do not use it for any other purpose. A Data Processing Agreement (DPA) is available on request for clients who grant us Klaviyo access.

7. How long we keep it

  • Generated media (posts, images, reels, videos) is automatically purged from the product after 31 days. Download your pack when a batch finishes and keep it — the download button gives you the most recent batch, so once you generate again the previous one is only available until it is purged.
  • Account and brand data (your profile, uploaded brand assets, connected-account tokens) is kept while your account is active. If you delete your account it is destroyed immediately, not on a schedule — see section 9. We keep only those records we must retain to meet a legal obligation.
  • What we read from your website (the page text, the contact details published on it, the pictures on it, and a screenshot) is kept for 31 days and then deleted. If you generate again after that, we read the site afresh rather than working from an old copy. Some of that material may include information about other people — staff named on your site, photographs of your team — and this is the limit on how long we hold it.
  • Security log entries (sign-ins and sign-in attempts, password and credential changes, administrative actions, each with the IP address it came from) are kept for 12 months, so that a security incident can be investigated and reported accurately. If you delete your account we keep the entries but strip your email address and IP from them, so the record that something happened survives without the personal data. The single entry recording the deletion itself keeps your email address, because a deletion record with no subject cannot evidence that your request was carried out; we hold that one entry under our legal obligation to demonstrate compliance.
  • Trial accounts that lapse without subscribing are removed automatically after a short grace period.
  • Billing and tax records are kept for as long as UK law requires (generally 6 years).

8. How we protect your data

We use encryption in transit (HTTPS), hashed passwords, access controls, and reputable infrastructure providers. Connected-account credentials (Klaviyo, GoHighLevel) are encrypted at rest, are never displayed back to you or to us once saved, and are held only to perform the actions you have authorised. You can disconnect and delete a GoHighLevel token from your Brand page at any time. No online service can be guaranteed 100% secure, but we take reasonable and appropriate technical and organisational measures to protect your data.

9. Your rights

Under UK GDPR you have the right to access, correct, delete or restrict the use of your personal data, to object to certain processing, to data portability, and to withdraw consent where we rely on it.

Two of these you can exercise yourself, immediately, without asking us. On your Brand & assets page:

  • Download my data gives you a zip containing everything we hold — your account record, your brand profile and voice, every asset you uploaded, everything we generated for you, and what we read from your website at sign-up. It deliberately excludes your password hash and your stored GoHighLevel token, because those are credentials rather than information about you; the file explains this.
  • Delete my account destroys all of it permanently and at once — the account, the brand, the uploads, the generated media and the website record. There is no undo and we keep no copy. One thing we cannot reach: anything already uploaded into your own GoHighLevel account stays in your account, and you should remove it there.

For anything else — correction, restriction, objection — use the feedback box in your dashboard or write to us at the registered office above, and we will respond within one month. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to put things right first.

10. Cookies

We use only the cookies necessary to run the service — chiefly to keep you signed in and to keep the service secure. We do not use advertising or third-party tracking cookies. The "keep me signed in" box on the sign-in page is what sets the 30-day cookie; leave it unticked and you are signed out when you close the browser.

Our typefaces are served from our own domain rather than from a font network, so simply loading a page here does not disclose your IP address to a third party for that purpose. The one third-party script we do load is Cloudflare Turnstile, on the sign-in, sign-up and request-access pages only, to tell people apart from bots.

11. Children

Served Social and our flow/overlay services are business tools intended for use by people aged 18 or over. They are not directed at children and we do not knowingly collect data from anyone under 18.

12. Changes to this policy

We may update this policy from time to time. The version number and "last updated" date at the top show the current version, and we will notify clients of material changes by email or in-product.

13. Contact

Questions about this policy or your data? Use the feedback box in your dashboard, or write to G Green Holdings Ltd at the registered office above.