Legal, Trust & Security
Company details, legal notice channels, trust and security information, and contact paths by request type.
This page consolidates our Contact & Legal Notice, Trust Center, and Security & Data Protection Statement.
Company Information
Trading Name: WOWFLO.AI
Legal Entity: Ecom Flip Limited
Registered in: England and Wales
Company Registration Number: 13097690
Registered Office Address:
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
Website: https://wowflo.ai
Business Phone: +44 7468 885940
General Email: info@wowflo.ai
Director
Director: Nargiz Vakilova
Contact by Subject
| Subject | Contact Method |
|---|---|
| General enquiries | info@wowflo.ai |
| Privacy and data protection | info@wowflo.ai — Subject: "Privacy Enquiry" |
| GDPR rights requests | info@wowflo.ai — Subject: "GDPR Rights Request" |
| CCPA requests (California residents) | info@wowflo.ai — Subject: "California Privacy Rights Request" |
| Data deletion requests | info@wowflo.ai — Subject: "Data Deletion Request" |
| Billing and subscription | info@wowflo.ai — Subject: "Billing Enquiry" |
| Refund requests | info@wowflo.ai — Subject: "Refund Request" |
| Copyright / DMCA notices | info@wowflo.ai — Subject: "Copyright Infringement Notice" |
| Security vulnerabilities | info@wowflo.ai — Subject: "Security Vulnerability Report" |
| Legal notices and correspondence | info@wowflo.ai — Subject: "Legal Notice" |
| Enterprise / business enquiries | info@wowflo.ai — Subject: "Enterprise Enquiry" |
| Affiliate programme enquiries | info@wowflo.ai — Subject: "Affiliate Programme" |
| Press and media | info@wowflo.ai — Subject: "Press Enquiry" |
| AUP violation reports | info@wowflo.ai — Subject: "AUP Violation Report" |
Legal Notices
Legal notices (including service of process, regulatory correspondence, and formal legal demands) should be sent to:
By post:
Legal Notice — WOWFLO.AI
Ecom Flip Limited
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
By email:
info@wowflo.ai — Subject: "Legal Notice"
We aim to acknowledge legal notices within 5 business days.
VAT
Ecom Flip Limited is not currently VAT registered. VAT registration will be completed when the annual turnover threshold is reached or earlier if required. This page will be updated with our VAT number upon registration.
Regulatory Information
Ecom Flip Limited is a private limited company registered in England and Wales. It is not a regulated financial services firm and does not provide regulated financial, legal, or medical advice.
WOWFLO.AI is a software-as-a-service platform. Use of the Platform is subject to our Terms of Service.
Data Protection
Data Controller: Ecom Flip Limited
Supervisory Authority: Information Commissioner's Office (ICO)
ICO Registration: Registration pending (to be updated upon ICO registration)
Response Times
We aim to respond to all enquiries within:
- General enquiries: 2 business days
- GDPR/data rights requests: acknowledged within 5 working days; full response within 30 days
- Billing disputes: 2 business days
- Legal notices: acknowledged within 5 business days
- Security reports: acknowledged within 5 business days
We operate Monday–Friday (excluding UK public holidays).
Applicable Law
All legal matters relating to WOWFLO.AI and Ecom Flip Limited are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales, save where applicable consumer protection law provides otherwise.
Trust Center
Welcome to the WOWFLO.AI Trust Center
This page brings together everything you need to understand how WOWFLO.AI protects your data, complies with applicable law, and maintains the trust of our users, business partners, and regulators.
🏢 Who We Are
| Company | Ecom Flip Limited |
| Trading as | WOWFLO.AI |
| Registered in | England and Wales |
| Company number | 13097690 |
| Address | 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK |
| Director | Nargiz Vakilova |
| Contact | info@wowflo.ai |
| Phone | +44 7468 885940 |
| Website | https://wowflo.ai |
🔒 Privacy & Data Protection
We are committed to:
- Processing only data that is necessary for providing our service
- Being transparent about what data we collect and how we use it
- Complying with UK GDPR, EU GDPR (for EU users), and applicable data protection laws
- Never selling your personal data
- Deleting your data when you ask us to
Key policies:
- Privacy Policy
- GDPR Rights Notice
- CCPA Notice (California residents)
- User Data Deletion Policy
- Cookie Policy
Data controller: Ecom Flip Limited, registered in the UK
Supervisory authority: Information Commissioner's Office (ICO), United Kingdom
ICO registration: Registration pending (to be updated upon ICO registration)
Data storage location: Amazon Web Services, eu-west-2 (London, United Kingdom)
Data retention: Personal data deleted within 90 days of account deletion (subject to legal retention requirements)
🤖 AI Transparency
WOWFLO.AI uses AI to power its content creation features. We believe in transparent AI.
AI systems we use:
| AI Provider | Role | Type |
|---|---|---|
| Anthropic (Claude) | Script and content generation | Large language model |
| ElevenLabs | Voice synthesis and voice cloning | Neural text-to-speech |
| HeyGen | AI avatar generation (via redirect) | Video synthesis |
Our commitments:
- We do not use your content to train AI models
- We require explicit consent before processing biometric data (voice, face)
- We disclose AI-generated content as AI-generated
- We comply with EU AI Act transparency requirements as a global standard
- We apply content restrictions to prevent harmful AI use
Full details: AI Usage & Disclosure Policy
🔐 Security
We take the security of your data seriously.
Our security measures include:
- ✅ HTTPS/TLS encryption on all connections
- ✅ Data encrypted at rest (AES-256 on AWS)
- ✅ Content Security Policy allowlisting approved script sources on the web app
- ✅ Encrypted storage of Instagram tokens and API credentials
- ✅ Role-based access control for staff
- ✅ Multi-factor authentication for administrative access
- ✅ AWS-certified infrastructure (ISO 27001, SOC 2)
- ✅ Regular security reviews
- ⏳ Penetration testing — planned before public launch
Report a security vulnerability: info@wowflo.ai — Subject: "Security Vulnerability Report"
Full details: Security & Data Protection Statement
💳 Payments & Billing
Payment processor: Stripe, Inc. (PCI-DSS Level 1 certified)
Your card details: Never stored by WOWFLO.AI — processed exclusively by Stripe
Subscriptions: Transparent auto-renewal with 7-day advance notice
Refunds: 14-day satisfaction guarantee on first Pro Plan subscription
Full details: Refund Policy | Subscription Terms
📱 Meta & Instagram Integration
We use the Instagram Graph API in compliance with Meta's Platform Terms and our approved Meta Developer Application.
Our commitments:
- We request only minimum necessary Instagram permissions
- We store access tokens encrypted and delete them on account deletion
- We maintain a Data Deletion Instructions page: /data-deletion
- We have passed Meta App Review for our requested permissions
- We comply with Meta's Platform Terms and Data Use Policy
Full details: API & Integrations Disclosure
📋 Legal Documents
| Document | Purpose |
|---|---|
| Terms of Service | Rules governing use of WOWFLO.AI |
| Privacy Policy | How we collect and use personal data |
| Cookie Policy | Cookies and tracking technologies |
| Acceptable Use Policy | What you may and may not use WOWFLO.AI for |
| Refund Policy | Subscription refund terms |
| Subscription Terms | Billing and subscription details |
| Data Processing Addendum | For enterprise/business customers |
| AI Usage & Disclosure Policy | How AI is used in the Platform |
| User Content Policy | Your content and our licence |
| Intellectual Property Policy | IP ownership and rights |
| Copyright & DMCA Policy | Copyright and infringement notices |
| User Data Deletion Policy | How to delete your data |
| Security Statement | Our security practices |
| Third-Party Services Disclosure | Services we rely on |
| API & Integrations Disclosure | API integration details |
| GDPR Rights Notice | Your GDPR rights |
| CCPA Notice | California privacy rights |
| Meta Data Deletion Instructions | Instagram data deletion |
| Contact & Legal Notice | Company and contact information |
🌍 International Compliance
| Framework | Status |
|---|---|
| UK GDPR | ✅ Compliant |
| EU GDPR | ✅ Applied as global standard |
| UK PECR (cookies) | ✅ Cookie consent implemented |
| EU AI Act (Art. 52 transparency) | ✅ Applied as global standard |
| Meta Platform Policy | ⏳ App Review pending submission |
| Stripe Terms | ✅ Compliant |
| CCPA | ✅ Disclosed (US users) |
| Illinois BIPA | ✅ Explicit biometric consent |
📞 Contact Trust Center
For questions about privacy, security, compliance, or any concerns:
Email: info@wowflo.ai
Post: Ecom Flip Limited, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK
We take all trust and safety concerns seriously and aim to respond within 2 business days.
This Trust Center was last updated in June 2026. We update it as our practices and policies evolve.
Security & Data Protection Statement
1. Our Commitment to Security
Ecom Flip Limited is committed to protecting the security of user data processed through WOWFLO.AI. This statement describes our current security practices. We continuously review and improve our security posture as the Platform evolves.
This statement is provided for transparency and does not constitute a warranty or SLA. For enterprise security requirements, contact info@wowflo.ai.
2. Infrastructure Security
Cloud Provider: WOWFLO.AI is hosted on Amazon Web Services (AWS), one of the world's leading cloud platforms. AWS is certified under ISO 27001, SOC 2, and PCI-DSS, among other standards.
Data Region: Our primary data region is eu-west-2 (London, United Kingdom), ensuring that personal data is stored within the United Kingdom.
Network Security:
- All external communications are protected by TLS 1.2 or higher
- Firewall rules restrict access to production systems
- AWS Security Groups and VPC configuration limit network access
- Production environments are isolated from development environments
3. Data Encryption
In Transit: All data transmitted between your browser and WOWFLO.AI is encrypted using TLS (Transport Layer Security) protocol, version 1.2 or higher. We enforce HTTPS on all connections.
At Rest: All data stored on AWS (databases, file storage) is encrypted at rest using AES-256 encryption, implemented through AWS services (RDS encryption, S3 server-side encryption, EBS encryption).
Access Tokens: Instagram access tokens, API keys, and other sensitive credentials are stored in encrypted form using AWS Key Management Service (KMS) or equivalent. These are never stored in plain text.
4. Access Controls
Principle of Least Privilege: Staff access to user data is granted only where necessary for their role, and access is restricted to the minimum required.
Role-Based Access Control (RBAC): Access to production systems and user data is managed through RBAC policies.
Audit Logging: Access to production data is logged. Logs are retained for security monitoring.
Regular Access Reviews: Staff access rights are reviewed regularly and revoked upon role changes or departure.
5. Authentication
User Authentication: Users can sign in either with a one-time email verification code or, where available, Google Sign-In. These public sign-in methods do not require a long-lived WOWFLO.AI password.
Admin Authentication: All administrative access to production systems requires multi-factor authentication (MFA).
Session Management: WOWFLO.AI currently authorises API requests with short-lived JWT access tokens. Access and refresh tokens are stored in the signed-in user's browser local storage, refreshed through the token refresh flow while they remain valid, and removed on logout or when refresh or validation fails.
Browser-side Script Controls: To reduce token-theft exposure from browser-side script injection, the public web app is served with a Content Security Policy (CSP) that restricts script loading to same-origin assets plus the specific Google Identity Services and consent-gated Google Analytics endpoints currently required for sign-in and measurement. Because parts of the current UI still rely on inline styles, the present policy keeps a permissive style-src posture for inline styles while we continue reducing that dependency.
6. Token and API Key Security
Instagram access tokens obtained from Meta are:
- Encrypted before storage using AES-256
- Accessed only by authorised system processes for publishing
- Never exposed in logs, error messages, or API responses
- Deleted immediately upon account disconnection or deletion
Third-party API keys (Anthropic, ElevenLabs) are:
- Stored as environment variables or in a secrets management service (AWS Secrets Manager or equivalent)
- Never hardcoded in source code
- Rotated periodically
7. Data Backup
- User data is backed up on a regular schedule using AWS backup solutions
- Backups are stored in encrypted form in the same or geographically redundant AWS region
- Backup restoration is tested periodically
8. Vulnerability Management
Patching: We apply security patches and updates to our infrastructure on a defined schedule based on severity ratings.
Dependency Management: We monitor our software dependencies for known vulnerabilities and update as required.
Security Reviews: We conduct security reviews of new features and significant changes to the Platform.
Note: We have not yet completed a formal penetration test. Engaging a qualified penetration testing firm before public launch is recommended and is on our pre-launch roadmap.
9. Data Breach Response
Detection: We monitor for security anomalies and have alerting in place for suspicious activity.
Response Procedure:
- Incident detected and assessed by designated incident lead
- Containment measures applied
- Scope of breach assessed (categories and number of individuals affected)
- Notification to the Information Commissioner's Office (ICO) within 72 hours where required (where the breach is likely to result in risk to individuals' rights and freedoms)
- Notification to affected individuals without undue delay where required
- Post-incident review and remediation
Your Responsibility: If you believe your WOWFLO.AI account has been compromised, contact us immediately at info@wowflo.ai.
10. Sub-Processor Security
We engage sub-processors who implement their own security standards. Our key infrastructure sub-processors and their certifications:
| Sub-Processor | Security Standards |
|---|---|
| Amazon Web Services (AWS) | ISO 27001, SOC 2 Type II, PCI DSS, GDPR |
| Stripe | PCI DSS Level 1, ISO 27001 |
| Google (Analytics, OAuth) | ISO 27001, SOC 2, GDPR |
| Anthropic | Enterprise security programme |
| ElevenLabs | Enterprise security programme |
We conduct due diligence on sub-processors and execute Data Processing Agreements where required.
11. What You Can Do to Stay Secure
You can take the following steps to protect your account:
- Use a strong, unique password for your Google account (which you use to log into WOWFLO.AI)
- Enable two-factor authentication on your Google account
- Do not share your account credentials
- Log out of WOWFLO.AI when using shared or public devices
- Regularly review connected applications in your Instagram settings
- Contact us immediately if you suspect your account has been compromised
12. Responsible Disclosure
If you discover a security vulnerability in WOWFLO.AI, we ask that you:
- Do not publicly disclose the vulnerability before giving us a reasonable opportunity to address it
- Do not exploit the vulnerability or access user data you are not authorised to access
- Report the vulnerability to info@wowflo.ai with the subject line "Security Vulnerability Report"
We are grateful for responsible disclosure and will acknowledge reports within 5 business days. We do not currently operate a formal bug bounty programme but may offer recognition for significant discoveries.
14. Contact
For security-related enquiries:
Email: info@wowflo.ai
Subject: "Security Enquiry"
Post: Ecom Flip Limited, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK
For urgent security matters, email info@wowflo.ai and mark the subject "URGENT – Security".