GDPR, Data Protection & Security

Stood Flows is a dedicated architectural analysis utility designed to provide visibility and optimization for Salesforce Organizations while maintaining a Zero-Persistence footprint for business data. By strictly decoupling technical metadata from business records, Stood Flows ensures that sensitive information—including PII, financial data, and commercial intel—never enters our permanent storage. Built on a foundation of "Read-Only" technical constraints and hosted exclusively within the European Economic Area (EEA), the platform offers enterprise-grade transparency into system health without the security risks associated with traditional data ingestion or third-party exposure.


1. Governance and Compliance Overview

Stood Flows is committed to the highest standards of data privacy and security. This document outlines our "Privacy by Design" architecture, specifically tailored for Salesforce Organizations.

Stood Flows operates as a Data Processor under the General Data Protection Regulation (GDPR). Our core mission is to provide architectural clarity and flow analysis without compromising the integrity or confidentiality of your corporate business data.


2. The "Zero Business Data" Guarantee

Stood Flows is engineered to be content-blind. Our systems are designed to analyze the "how" (structure) without ever needing the "what" (content).

2.1 Absolute Exclusion of Record Data

We provide a factual and legally-backed guarantee that the following categories of data never leave your Salesforce environment and are never stored on Stood Flows databases:

2.2 Controlled License Analysis (Ephemeral Processing)

To provide accurate License and User Access Analysis, Stood Flows may temporarily fetch User IDs or Email Addresses.


3. Technical Safeguards & "Double-Lock" Security

Our integration with Salesforce is governed by a dual-layer security protocol that ensures data can only be viewed, never altered.

3.1 Restricted Permission Recommendation

Stood Flows advocates for the Principle of Least Privilege. We provide specific guidance for clients to utilize restricted, Read-Only permission sets when authenticating the integration, ensuring that our access is limited by your own internal security policies from day one.

3.2 Hard-Coded Query Restrictions

Beyond the permissions granted by the user, Stood Flows has established Hard Rules within our core engine:


4. Metadata Storage and Usage

Stood Flows only persists the "Technical Blueprint" of your Organization. This metadata is used to visualize your technical environment and contains no commercial "payload." This includes:


5. Confidentiality & Non-Disclosure (NDA)

Stood Flows treats your Salesforce architectural metadata with the same rigor as sensitive PII.


6. Infrastructure & Sovereignty

Our infrastructure is built on Tier-IV data center technology, providing enterprise-grade protection:


7. Formal Identification & Commitment

This commitment is issued by Hway Digital SAS, a company established in France, registered under the number 929 820 116 (RCS Versailles), and represented by its President, Pierre Lecointre.

As the Data Processor, Hway Digital SAS assumes full legal responsibility for the technical and organizational measures described herein. Our commitment to data protection is central to our corporate governance and is overseen directly by the executive leadership.

For more information about our data security guarantees contact: contact@stoodcrm.com.

Published with Nuclino