WOW FLŌ
How it worksWho it's forPricingTestimonialsFAQ
Log inSign up
Sign up
Home/Legal Center/Legal Contact
Summary

Company details, legal notice channels, trust and security information, and contact paths by request type.

Related legal pages
Privacy PolicyTerms of ServiceRefund PolicyCookie PolicyAcceptable Use PolicyData Deletion
On this page
Company InformationDirectorContact by SubjectLegal NoticesVATRegulatory InformationData ProtectionResponse TimesApplicable LawWelcome to the WOWFLO.AI Trust Center🏢 Who We Are🔒 Privacy & Data Protection🤖 AI Transparency🔐 Security💳 Payments & Billing📱 Meta & Instagram Integration📋 Legal Documents🌍 International Compliance📞 Contact Trust Center1. Our Commitment to Security2. Infrastructure Security3. Data Encryption4. Access Controls5. Authentication6. Token and API Key Security7. Data Backup8. Vulnerability Management9. Data Breach Response10. Sub-Processor Security11. What You Can Do to Stay Secure12. Responsible Disclosure14. Contact
Legal Center

Legal, Trust & Security

Company details, legal notice channels, trust and security information, and contact paths by request type.

Effective date: 10 June 2026Last updated: 10 June 2026

This page consolidates our Contact & Legal Notice, Trust Center, and Security & Data Protection Statement.



Company Information

Trading Name: WOWFLO.AI
Legal Entity: Ecom Flip Limited
Registered in: England and Wales
Company Registration Number: 13097690
Registered Office Address:
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom

Website: https://wowflo.ai
Business Phone: +44 7468 885940
General Email: info@wowflo.ai


Director

Director: Nargiz Vakilova


Contact by Subject

SubjectContact Method
General enquiriesinfo@wowflo.ai
Privacy and data protectioninfo@wowflo.ai — Subject: "Privacy Enquiry"
GDPR rights requestsinfo@wowflo.ai — Subject: "GDPR Rights Request"
CCPA requests (California residents)info@wowflo.ai — Subject: "California Privacy Rights Request"
Data deletion requestsinfo@wowflo.ai — Subject: "Data Deletion Request"
Billing and subscriptioninfo@wowflo.ai — Subject: "Billing Enquiry"
Refund requestsinfo@wowflo.ai — Subject: "Refund Request"
Copyright / DMCA noticesinfo@wowflo.ai — Subject: "Copyright Infringement Notice"
Security vulnerabilitiesinfo@wowflo.ai — Subject: "Security Vulnerability Report"
Legal notices and correspondenceinfo@wowflo.ai — Subject: "Legal Notice"
Enterprise / business enquiriesinfo@wowflo.ai — Subject: "Enterprise Enquiry"
Affiliate programme enquiriesinfo@wowflo.ai — Subject: "Affiliate Programme"
Press and mediainfo@wowflo.ai — Subject: "Press Enquiry"
AUP violation reportsinfo@wowflo.ai — Subject: "AUP Violation Report"

Legal Notices

Legal notices (including service of process, regulatory correspondence, and formal legal demands) should be sent to:

By post:
Legal Notice — WOWFLO.AI
Ecom Flip Limited
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom

By email:
info@wowflo.ai — Subject: "Legal Notice"

We aim to acknowledge legal notices within 5 business days.


VAT

Ecom Flip Limited is not currently VAT registered. VAT registration will be completed when the annual turnover threshold is reached or earlier if required. This page will be updated with our VAT number upon registration.


Regulatory Information

Ecom Flip Limited is a private limited company registered in England and Wales. It is not a regulated financial services firm and does not provide regulated financial, legal, or medical advice.

WOWFLO.AI is a software-as-a-service platform. Use of the Platform is subject to our Terms of Service.


Data Protection

Data Controller: Ecom Flip Limited
Supervisory Authority: Information Commissioner's Office (ICO)
ICO Registration: Registration pending (to be updated upon ICO registration)


Response Times

We aim to respond to all enquiries within:

  • General enquiries: 2 business days
  • GDPR/data rights requests: acknowledged within 5 working days; full response within 30 days
  • Billing disputes: 2 business days
  • Legal notices: acknowledged within 5 business days
  • Security reports: acknowledged within 5 business days

We operate Monday–Friday (excluding UK public holidays).


Applicable Law

All legal matters relating to WOWFLO.AI and Ecom Flip Limited are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales, save where applicable consumer protection law provides otherwise.



Trust Center


Welcome to the WOWFLO.AI Trust Center

This page brings together everything you need to understand how WOWFLO.AI protects your data, complies with applicable law, and maintains the trust of our users, business partners, and regulators.


🏢 Who We Are

CompanyEcom Flip Limited
Trading asWOWFLO.AI
Registered inEngland and Wales
Company number13097690
Address71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK
DirectorNargiz Vakilova
Contactinfo@wowflo.ai
Phone+44 7468 885940
Websitehttps://wowflo.ai

🔒 Privacy & Data Protection

We are committed to:

  • Processing only data that is necessary for providing our service
  • Being transparent about what data we collect and how we use it
  • Complying with UK GDPR, EU GDPR (for EU users), and applicable data protection laws
  • Never selling your personal data
  • Deleting your data when you ask us to

Key policies:

  • Privacy Policy
  • GDPR Rights Notice
  • CCPA Notice (California residents)
  • User Data Deletion Policy
  • Cookie Policy

Data controller: Ecom Flip Limited, registered in the UK
Supervisory authority: Information Commissioner's Office (ICO), United Kingdom
ICO registration: Registration pending (to be updated upon ICO registration)

Data storage location: Amazon Web Services, eu-west-2 (London, United Kingdom)
Data retention: Personal data deleted within 90 days of account deletion (subject to legal retention requirements)


🤖 AI Transparency

WOWFLO.AI uses AI to power its content creation features. We believe in transparent AI.

AI systems we use:

AI ProviderRoleType
Anthropic (Claude)Script and content generationLarge language model
ElevenLabsVoice synthesis and voice cloningNeural text-to-speech
HeyGenAI avatar generation (via redirect)Video synthesis

Our commitments:

  • We do not use your content to train AI models
  • We require explicit consent before processing biometric data (voice, face)
  • We disclose AI-generated content as AI-generated
  • We comply with EU AI Act transparency requirements as a global standard
  • We apply content restrictions to prevent harmful AI use

Full details: AI Usage & Disclosure Policy


🔐 Security

We take the security of your data seriously.

Our security measures include:

  • ✅ HTTPS/TLS encryption on all connections
  • ✅ Data encrypted at rest (AES-256 on AWS)
  • ✅ Content Security Policy allowlisting approved script sources on the web app
  • ✅ Encrypted storage of Instagram tokens and API credentials
  • ✅ Role-based access control for staff
  • ✅ Multi-factor authentication for administrative access
  • ✅ AWS-certified infrastructure (ISO 27001, SOC 2)
  • ✅ Regular security reviews
  • ⏳ Penetration testing — planned before public launch

Report a security vulnerability: info@wowflo.ai — Subject: "Security Vulnerability Report"

Full details: Security & Data Protection Statement


💳 Payments & Billing

Payment processor: Stripe, Inc. (PCI-DSS Level 1 certified)
Your card details: Never stored by WOWFLO.AI — processed exclusively by Stripe
Subscriptions: Transparent auto-renewal with 7-day advance notice
Refunds: 14-day satisfaction guarantee on first Pro Plan subscription

Full details: Refund Policy | Subscription Terms


📱 Meta & Instagram Integration

We use the Instagram Graph API in compliance with Meta's Platform Terms and our approved Meta Developer Application.

Our commitments:

  • We request only minimum necessary Instagram permissions
  • We store access tokens encrypted and delete them on account deletion
  • We maintain a Data Deletion Instructions page: /data-deletion
  • We have passed Meta App Review for our requested permissions
  • We comply with Meta's Platform Terms and Data Use Policy

Full details: API & Integrations Disclosure


📋 Legal Documents

DocumentPurpose
Terms of ServiceRules governing use of WOWFLO.AI
Privacy PolicyHow we collect and use personal data
Cookie PolicyCookies and tracking technologies
Acceptable Use PolicyWhat you may and may not use WOWFLO.AI for
Refund PolicySubscription refund terms
Subscription TermsBilling and subscription details
Data Processing AddendumFor enterprise/business customers
AI Usage & Disclosure PolicyHow AI is used in the Platform
User Content PolicyYour content and our licence
Intellectual Property PolicyIP ownership and rights
Copyright & DMCA PolicyCopyright and infringement notices
User Data Deletion PolicyHow to delete your data
Security StatementOur security practices
Third-Party Services DisclosureServices we rely on
API & Integrations DisclosureAPI integration details
GDPR Rights NoticeYour GDPR rights
CCPA NoticeCalifornia privacy rights
Meta Data Deletion InstructionsInstagram data deletion
Contact & Legal NoticeCompany and contact information

🌍 International Compliance

FrameworkStatus
UK GDPR✅ Compliant
EU GDPR✅ Applied as global standard
UK PECR (cookies)✅ Cookie consent implemented
EU AI Act (Art. 52 transparency)✅ Applied as global standard
Meta Platform Policy⏳ App Review pending submission
Stripe Terms✅ Compliant
CCPA✅ Disclosed (US users)
Illinois BIPA✅ Explicit biometric consent

📞 Contact Trust Center

For questions about privacy, security, compliance, or any concerns:

Email: info@wowflo.ai
Post: Ecom Flip Limited, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK

We take all trust and safety concerns seriously and aim to respond within 2 business days.


This Trust Center was last updated in June 2026. We update it as our practices and policies evolve.



Security & Data Protection Statement


1. Our Commitment to Security

Ecom Flip Limited is committed to protecting the security of user data processed through WOWFLO.AI. This statement describes our current security practices. We continuously review and improve our security posture as the Platform evolves.

This statement is provided for transparency and does not constitute a warranty or SLA. For enterprise security requirements, contact info@wowflo.ai.


2. Infrastructure Security

Cloud Provider: WOWFLO.AI is hosted on Amazon Web Services (AWS), one of the world's leading cloud platforms. AWS is certified under ISO 27001, SOC 2, and PCI-DSS, among other standards.

Data Region: Our primary data region is eu-west-2 (London, United Kingdom), ensuring that personal data is stored within the United Kingdom.

Network Security:

  • All external communications are protected by TLS 1.2 or higher
  • Firewall rules restrict access to production systems
  • AWS Security Groups and VPC configuration limit network access
  • Production environments are isolated from development environments

3. Data Encryption

In Transit: All data transmitted between your browser and WOWFLO.AI is encrypted using TLS (Transport Layer Security) protocol, version 1.2 or higher. We enforce HTTPS on all connections.

At Rest: All data stored on AWS (databases, file storage) is encrypted at rest using AES-256 encryption, implemented through AWS services (RDS encryption, S3 server-side encryption, EBS encryption).

Access Tokens: Instagram access tokens, API keys, and other sensitive credentials are stored in encrypted form using AWS Key Management Service (KMS) or equivalent. These are never stored in plain text.


4. Access Controls

Principle of Least Privilege: Staff access to user data is granted only where necessary for their role, and access is restricted to the minimum required.

Role-Based Access Control (RBAC): Access to production systems and user data is managed through RBAC policies.

Audit Logging: Access to production data is logged. Logs are retained for security monitoring.

Regular Access Reviews: Staff access rights are reviewed regularly and revoked upon role changes or departure.


5. Authentication

User Authentication: Users can sign in either with a one-time email verification code or, where available, Google Sign-In. These public sign-in methods do not require a long-lived WOWFLO.AI password.

Admin Authentication: All administrative access to production systems requires multi-factor authentication (MFA).

Session Management: WOWFLO.AI currently authorises API requests with short-lived JWT access tokens. Access and refresh tokens are stored in the signed-in user's browser local storage, refreshed through the token refresh flow while they remain valid, and removed on logout or when refresh or validation fails.

Browser-side Script Controls: To reduce token-theft exposure from browser-side script injection, the public web app is served with a Content Security Policy (CSP) that restricts script loading to same-origin assets plus the specific Google Identity Services and consent-gated Google Analytics endpoints currently required for sign-in and measurement. Because parts of the current UI still rely on inline styles, the present policy keeps a permissive style-src posture for inline styles while we continue reducing that dependency.


6. Token and API Key Security

Instagram access tokens obtained from Meta are:

  • Encrypted before storage using AES-256
  • Accessed only by authorised system processes for publishing
  • Never exposed in logs, error messages, or API responses
  • Deleted immediately upon account disconnection or deletion

Third-party API keys (Anthropic, ElevenLabs) are:

  • Stored as environment variables or in a secrets management service (AWS Secrets Manager or equivalent)
  • Never hardcoded in source code
  • Rotated periodically

7. Data Backup

  • User data is backed up on a regular schedule using AWS backup solutions
  • Backups are stored in encrypted form in the same or geographically redundant AWS region
  • Backup restoration is tested periodically

8. Vulnerability Management

Patching: We apply security patches and updates to our infrastructure on a defined schedule based on severity ratings.

Dependency Management: We monitor our software dependencies for known vulnerabilities and update as required.

Security Reviews: We conduct security reviews of new features and significant changes to the Platform.

Note: We have not yet completed a formal penetration test. Engaging a qualified penetration testing firm before public launch is recommended and is on our pre-launch roadmap.


9. Data Breach Response

Detection: We monitor for security anomalies and have alerting in place for suspicious activity.

Response Procedure:

  1. Incident detected and assessed by designated incident lead
  2. Containment measures applied
  3. Scope of breach assessed (categories and number of individuals affected)
  4. Notification to the Information Commissioner's Office (ICO) within 72 hours where required (where the breach is likely to result in risk to individuals' rights and freedoms)
  5. Notification to affected individuals without undue delay where required
  6. Post-incident review and remediation

Your Responsibility: If you believe your WOWFLO.AI account has been compromised, contact us immediately at info@wowflo.ai.


10. Sub-Processor Security

We engage sub-processors who implement their own security standards. Our key infrastructure sub-processors and their certifications:

Sub-ProcessorSecurity Standards
Amazon Web Services (AWS)ISO 27001, SOC 2 Type II, PCI DSS, GDPR
StripePCI DSS Level 1, ISO 27001
Google (Analytics, OAuth)ISO 27001, SOC 2, GDPR
AnthropicEnterprise security programme
ElevenLabsEnterprise security programme

We conduct due diligence on sub-processors and execute Data Processing Agreements where required.


11. What You Can Do to Stay Secure

You can take the following steps to protect your account:

  • Use a strong, unique password for your Google account (which you use to log into WOWFLO.AI)
  • Enable two-factor authentication on your Google account
  • Do not share your account credentials
  • Log out of WOWFLO.AI when using shared or public devices
  • Regularly review connected applications in your Instagram settings
  • Contact us immediately if you suspect your account has been compromised

12. Responsible Disclosure

If you discover a security vulnerability in WOWFLO.AI, we ask that you:

  1. Do not publicly disclose the vulnerability before giving us a reasonable opportunity to address it
  2. Do not exploit the vulnerability or access user data you are not authorised to access
  3. Report the vulnerability to info@wowflo.ai with the subject line "Security Vulnerability Report"

We are grateful for responsible disclosure and will acknowledge reports within 5 business days. We do not currently operate a formal bug bounty programme but may offer recognition for significant discoveries.


14. Contact

For security-related enquiries:
Email: info@wowflo.ai
Subject: "Security Enquiry"
Post: Ecom Flip Limited, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK

For urgent security matters, email info@wowflo.ai and mark the subject "URGENT – Security".

Back to Legal Center
WOW FLŌ

An AI platform for solo experts: from idea to finished reel in a few clicks. Scripts in your own voice, ready to publish in one click.

Product

How it worksTestimonialsPricingFAQ

Legal

Legal CenterPrivacy PolicyTerms of Service

Support

info@wowflo.aiRefund PolicyLegal Contact
© 2026 WOWFLO.AI · Autopilot content platform.