By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
Capillary®FLOW

Privacy Policy

Effective date: 9 July 2026  ·  Last updated: 9 July 2026

This Privacy Policy explains how Capillary®Flow collects, uses, and protects your personal data when you visit our website or contact us.

1.Who we are

Capillary®Flow (“Capillary Flow”, “we”, “us”, “our”) is the controller of the personal data described in this policy. This policy covers our website capillaryflow.com. Our domain capillarybunkers.com redirects to this site and is covered by the same policy.

Controller: Capillary®Flow
Address: Teknologgatan 2, 411 32 Gothenburg, Sweden
Privacy contact: privacy@capillaryflow.com

2.What personal data we collect

Data you provide to us

When you complete our contact form or otherwise get in touch, we collect your first and last name, email address, phone number, country, company name, business area, and the content of your message.

Data collected automatically

When you visit the site, we and our providers may collect your IP address (and approximate location), device, browser and operating-system details, the pages you view and links you click, interactions such as form submissions and downloads, and cookie or similar identifiers (see Section 5).

We do not intentionally collect special-category (sensitive) personal data through this website.

3.How we use your data, and our legal bases

  • Responding to your inquiry — using your contact-form data. Legal basis: taking steps at your request before entering a contract, and our legitimate interest in responding to inquiries (GDPR Art. 6(1)(b) and 6(1)(f)).
  • Managing the relationship in our CRM (HubSpot) — using your contact and interaction data. Legal basis: our legitimate interest in managing leads and customers (Art. 6(1)(f)).
  • Protecting our forms from spam and abuse (reCAPTCHA) — using IP, device and interaction signals. Legal basis: our legitimate interest in security and fraud prevention (Art. 6(1)(f)).
  • Website analytics and performance measurement — using cookie identifiers and usage data. Legal basis: your consent (Art. 6(1)(a)).
  • Advertising, remarketing and conversion measurement (Google Ads, Meta, LinkedIn) — using cookie identifiers, hashed email/phone, and usage data. Legal basis: your consent (Art. 6(1)(a)).
  • Marketing communications, where you opt in — using your name and email. Legal basis: your consent (Art. 6(1)(a)).

Where we rely on consent, you can withdraw it at any time (see Sections 5 and 8). Where we rely on legitimate interest, you can object (see Section 8).

4.Who we share your data with

We share personal data with the following providers only as necessary for the purposes above. We do not sell your personal data.

  • HubSpot (HubSpot, Inc.) — CRM, contact forms, and marketing tracking. Receives contact-form data, interaction data, and cookies.
  • Google (Analytics 4 and Google Ads) — analytics, advertising, and conversion measurement. Receives cookie identifiers and usage data, and a hashed (irreversible) version of your email/phone via Enhanced Conversions, only where you have given marketing consent.
  • Meta (Facebook Pixel) — advertising and conversion measurement. Receives cookie identifiers and usage data, only with marketing consent.
  • LinkedIn (Insight Tag) — advertising and conversion measurement. Receives cookie identifiers and usage data, only with marketing consent.
  • Google reCAPTCHA — spam and abuse protection on forms. Receives IP, device, and interaction data.
  • Cookiebot (Usercentrics A/S) — cookie-consent management. Receives consent records and anonymized IP.
  • Webflow (Webflow, Inc.) — website hosting. Receives server logs and technical data.

We may also disclose data where required by law or to protect our legal rights.

5.Cookies and tracking technologies

We use cookies and similar technologies. Non-essential cookies (analytics and marketing) are only set after you give consent through our cookie banner, which is managed by Cookiebot and implements Google Consent Mode v2. Necessary cookies are always active because the site cannot function without them.

You can change or withdraw your consent at any time using the cookie-settings link on the site, or by clearing cookies in your browser.

The main third-party technologies we use are:

  • Google Analytics 4 — website analytics (statistics consent).
  • Google Ads — remarketing and conversion tracking (marketing consent).
  • Google Enhanced Conversions — sends a hashed, irreversible version of your email/phone to Google to measure ad conversions (marketing consent).
  • Meta Pixel — advertising and conversion measurement (marketing consent).
  • LinkedIn Insight Tag — advertising and conversion measurement (marketing consent).
  • HubSpot — CRM and marketing analytics (statistics consent).
  • Google reCAPTCHA — form security (necessary / legitimate interest).

A full, automatically updated list of the cookies we use — including provider, purpose, and duration — is shown below:

6.International data transfers

Some of our providers — including Google, Meta, LinkedIn, HubSpot, and Webflow — are based in, or transfer data to, the United States and other countries outside the EU/EEA.

Where we transfer personal data outside the EU/EEA, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, the provider’s certification under the EU–U.S. Data Privacy Framework, together with supplementary measures where needed. You can request a copy of the relevant safeguards using the contact details in Section 8.

7.How long we keep your data

We keep personal data only as long as necessary for the purposes it was collected for:

  • Contact-form / inquiry data: up to 24 months after our last contact, unless a business relationship develops.
  • CRM records (HubSpot): for the duration of the business relationship and up to 24 months thereafter.
  • Analytics data (Google Analytics 4): event data is retained for 2 months and user-level data for 14 months.
  • Cookie-consent records: 12 months, after which you are asked to renew your consent.

When data is no longer needed, we delete or anonymize it.

8.Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (the “right to be forgotten”).
  • Restrict processing in certain circumstances.
  • Data portability — receive your data in a portable format.
  • Object to processing based on legitimate interest, including direct marketing.
  • Withdraw consent at any time, without affecting processing already carried out.

We do not make decisions producing legal effects about you based solely on automated processing.

To exercise any of these rights, contact us at privacy@capillaryflow.com. We will respond within one month.

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Swedish supervisory authority:

9.Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.

10.Children

Our website and services are not directed at children under 16, and we do not knowingly collect their personal data.

11.Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available on this page, and the “Last updated” date above reflects the latest changes.

12.Contact

Capillary®Flow: Teknologgatan 2, 411 32 Gothenburg, Sweden
privacy@capillaryflow.com