Privacy and Data Security Policy
1. Overview and Purpose
This Privacy and Data Security Policy describes the data processing principles and security standards of FlexApp Desktop Studio, the flexapp.com enterprise portal, and enterprise mobile applications (iOS / Android) compiled and deployed via this No-Code engine.
As a platform offering high-level product management, custom No-Code infrastructure, and B2B consulting, FlexApp accepts the protection of its enterprise clients' data privacy, trade secrets, source code logic, and end-user data as a core responsibility.
2. Store-Independent Updates (OTA) and Version Control Architecture
The FlexApp infrastructure enables mobile applications to deploy new pages, UI updates, and workflow modifications instantly without needing to submit a new app version to the Apple App Store or Google Play Store.
Version Control Only: The only contact made with FlexApp servers upon mobile app launch is checking whether a new layout/UI update is available for the application.
- Limited Processing Scope: FlexApp servers perform only version number and layout template verification at this stage. No other processing occurs on FlexApp servers during this query.
- Complete Isolation from User Data: End-user identity data, form contents, personal information, or in-app operations are strictly isolated and never transmitted to or processed by FlexApp servers during update checks.
3. Architectural Security and Direct API Communication (Zero-Data Interception)
Unlike traditional No-Code or SaaS platforms, the FlexApp architecture is engineered with complete "Data Sovereignty" principles. Under this scope, we provide the following technical and legal assurances:
- Proxy-Free Architecture: Once the mobile app validates the latest UI template, it routes all subsequent data traffic solely and directly to your organization's backend servers and API endpoints.
- Zero-Data Interception: FlexApp servers never act as a bridge, proxy, gateway, or middleman layer in HTTP/HTTPS communications between mobile apps and your enterprise web services.
- Payload and Logging Privacy: In-app user interactions, queries, authentication credentials, financial/operational records, and API responses are processed directly between the mobile device and your servers. FlexApp infrastructure cannot monitor, inspect, store, or log this data stream.
4. Standalone Mobility Guarantee
To ensure continuity for your business operations, deployed mobile applications are not dependent on FlexApp core servers at runtime:
- System Independence: Even if the FlexApp platform, licensing servers, or web portal undergo maintenance, become unavailable, or go offline entirely, your previously installed mobile applications continue to operate without interruption.
- Direct Service Connection: Should update checks fail, the mobile app engine falls back gracefully using the cached template and connects directly to your enterprise servers to sustain workflows.
5. Portal Modules and Processed Enterprise Data
On enterprise dashboards accessed via flexapp.com, only limited data necessary for service administration, license validation, and distribution management is securely processed:
- My Projects Module: Project configuration templates, UI layouts, component settings, and version history data created via Desktop Studio.
- My Licenses Module: Active license tiers assigned to your organization, expiration dates, module permissions, and Desktop Studio device binding records.
- Access Control (RBAC) Module: Full name, email address, role definitions, and permission level records of authorized enterprise portal users.
- General Statistical Metrics: Anonymized metrics collected to evaluate overall platform stability and performance (e.g., total API call counts, active app version distribution ratios, and system crash statistics).
- APK and IPA Distribution Links: Secure, time-limited, and encrypted download links generated for authorized enterprise users to download Android (APK) and iOS (IPA) build packages compiled in Desktop Studio.
6. Desktop Studio, Local `.flx` File Architecture, and Offline Security
FlexApp Desktop Studio is a standalone desktop application utilizing local client architecture:
- Local File Storage (`.flx`): All projects, database connection schemas, visual architecture, and screen flows designed by developers inside Desktop Studio are stored locally in `.flx` project files.
- Explicit Action Required (Commit / Push): A `.flx` project file is never transmitted or automatically pushed to FlexApp servers unless an explicit "Commit" or "Push" action is initiated by the developer inside Desktop Studio.
- No Upload Obligation: Storing or uploading project files to FlexApp central servers is entirely optional. Your organization may keep development workflows strictly offline on local disks or within private version control systems (e.g., self-hosted Git repositories).
- Secure Synchronization: When a developer chooses to push a project to servers for collaboration or compilation, transmission occurs exclusively over secure channels protected by TLS 1.3 encryption.
7. Data Ownership, Intellectual Property, and Right to Be Forgotten (GDPR / KVKK)
All intellectual property and database rights for `.flx` project files, UI designs, business logic, database schemas, and generated APK/IPA packages created with FlexApp Desktop Studio belong entirely to your organization. Under GDPR and KVKK regulations, your organization reserves the right to export project data at any time or request permanent deletion upon contract termination.
8. Cookies and Session Security
On the flexapp.com portal and Desktop Studio login interfaces, essential technical cookies are utilized solely for secure authentication (JWT/Session tokens), session persistence, and preference management. Our platform does not employ advertising or third-party tracking cookies.
9. Security Incident and Audit Notification
FlexApp is hosted on isolated cloud infrastructure meeting rigorous security standards. All infrastructure undergoes routine penetration testing and security audits. In the event of a potential cybersecurity threat, affected enterprise administrators will be notified promptly.
10. Contact and Data Controller
If you have any questions regarding the FlexApp Enterprise Privacy Policy, `.flx` local file security, OTA update verification architecture, or portal access management, please feel free to reach out:
Email: [email protected]
Web: flexapp.com