Privacy Policy
Who we are
The Futures Hub B.V. (trading as Flux Forward) is the data controller for all Flux Forward services.
KVK: 98261223 · BTW: NL868420116B01
Registered in the Netherlands
Contact: [email protected]
This policy covers all services under the Flux Forward brand, including:
fluxforward.world — main website
app.fluxforward.world — Flux Forward App, Activation Scan, and Dashboard
blog.fluxforward.world — Flux Forward Insights
howtoin.nl — How to in NL. This service also has a service-specific privacy notice at howtoin.nl/privacy.
What we collect and why
What we store. What you enter and confirm, in four parts. A short career profile: a headline, skills, education entries (qualification, institution, year) and languages with a proficiency level. Up to five experience entries: job title, employer, start and end date, and whether the role is current. Your preferences: target job titles, the kinds of opportunities you are looking for, seniority, preferred locations, working mode, maximum office days per week, maximum commute time, languages, and any employers you want excluded. Your situation: whether you need visa sponsorship, and a planning runway in days that you state yourself. We also store ordinary operational fields so the app knows what you have confirmed and when, such as revision counters and confirmation timestamps.
Some answers start pre-filled from your existing profile. To avoid asking you the same thing twice, we may pre-fill two Career Navigation answers from what your Flux Forward profile already holds: your location becomes a suggested preferred location, and your preferred language becomes a suggested language. A pre-filled language is given a default proficiency of "professional" that you did not choose, so please correct it if it is wrong. We only pre-fill when you have not already answered that step yourself. Your answer about needing sponsorship is never pre-filled — we show you what you told us before and ask you to confirm it. Everything pre-filled is visible and editable on screen, and none of it becomes stored Career Navigation data until you save that step. We never write anything back to your main profile.
Whether Career Navigation is switched on for you. If we ever need to switch this feature on or off for an individual account — for example during a limited preview — we store one small record on your account noting that the feature has been enabled or disabled for you, and when. It holds only the name of the feature, your account identifier, whether access is active or withdrawn, and those dates. Only we can set it — you cannot change it yourself, and it is not part of your career information. It is deleted with the rest of your data when you delete your account.
Career Navigation does not ask you for a free-text summary or for written evidence statements. Earlier versions of the setup did, and if you filled those in before they were removed, the values stay on your existing record until you delete your account. Nothing in the app asks for them any more.
What we do with it. We use your confirmed answers to narrow and order your own reading of opportunities we already publish, to explain why an opportunity appears where it does, and to give you planning context.
To be precise about which answers actually affect what you see: the ordering uses the kinds of opportunities you are looking for, your target job titles, your preferred locations, your working mode, your languages, any employers you excluded, whether you need sponsorship, and your planning runway. The rest — your headline, skills, education, experience entries, seniority, maximum office days and maximum commute — is stored as your own career record so you can keep it up to date and so the app knows your setup is complete. It does not currently change which opportunities are highlighted.
Career Navigation does not decide your eligibility for anything, does not determine your immigration status, does not decide whether an employer will hire you, does not apply for anything on your behalf, and does not send anything about you to an employer. No employer, university, partner or institution receives your Career Navigation profile, your results or the reasons behind them.
Sponsorship and planning runway. If you tell us you need visa sponsorship, we use that only as planning context, to compare against what a vacancy itself says about sponsorship. We do not use it to infer your nationality and we do not use it to judge whether you would qualify for anything. The planning runway is a number of days you state yourself so we can give you a sense of timing. It is not a permit expiry date, we do not check it against any official record, and it is not immigration advice.
Please leave sensitive details out. Career Navigation never asks for special-category or sensitive personal information, and you should not type any into the free-text fields. That means no health information, religion, political opinions, trade-union membership, sexual life or orientation, biometric or genetic information, and no passport number, BSN, permit number, immigration-case or legal-case details.
Opportunity assessments are not saved. Your profile, experiences, preferences and situation are stored in your account so you can come back and change them. What you see in Your Opportunity Space and on an opportunity page is worked out fresh from your answers each time you open it and is not stored: we keep no band, no ranking, no score and no record of any assessment. If you separately choose to save an opportunity, we keep the limited reference described below, not the assessment.
How long we keep it. Your Career Navigation data is kept while your account is active, so it is still there when you come back. Your stated situation goes stale after 30 days and we ask you to confirm it is still accurate before we use it again — going stale does not delete it, and nothing here is deleted automatically on a timer. You can change your answers at any time, and deleting your account deletes your Career Navigation data along with the rest. Legal basis: contract (Art. 6(1)(b) GDPR) — this is the feature you asked us to set up for you.
The words you typed into Capture are not stored, sent to analytics or kept as history by Flux Forward. OpenAI receives them as an external processor. The OpenAI project used for Capture has Global residency, so processing is not restricted to a particular region and may take place outside the EEA. Requests use
store:false, which turns off OpenAI application-state logging for the response, and this project is not selected for sharing API inputs and outputs with OpenAI to improve or train models. These controls do not prevent OpenAI's standard abuse-monitoring retention: request content may normally be retained for up to 30 days, or longer where required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Do not submit confidential, sensitive, or special-category personal data in Capture.
The model can only propose values from the existing closed Situation Context: the kind of goal, a Study, Work, Build or Undecided route where present, up to three supported city keys, and one blocker category. You see the complete proposed summary and what would change before anything is saved. Nothing is written unless you press the confirmation button. If you confirm, we store one current structured summary in your account, plus limited operational fields such as confirmation times, revision numbers, a bounded outcome and a reference to an accepted next move. We also keep the current UTC day, a request count and an update time under your account to enforce a daily interpretation limit; that counter contains no Capture text or model output. Flux Forward may use the confirmed summary on Home, My context, Next moves, For you and Journey. You can correct or remove it in My context, including after access to a limited Beta ends.
Saved opportunities. If you press Save on an opportunity, we store only its canonical Flux Forward opportunity identifier and the time you saved it. We do not copy the vacancy title, employer, description or the link you used into your saved record. The app looks up the current public opportunity from that identifier when you return, so a listing can change or become unavailable. Free accounts can keep up to three saved opportunities at once; Plus and eligible organization access can have a larger allowance. Removing one deletes that saved reference. A plan downgrade does not silently delete references you already saved, and you can still remove them.
Saving or viewing an opportunity does not mean that Flux Forward applied for it, that you are eligible, that the employer is interested, that sponsorship is guaranteed, or that Flux Forward recommends it as a hiring or immigration decision. These account features do not send your Situation Context, saved references or Career Navigation answers to an employer, university, partner or institution.
How long we keep it. Flux Forward does not retain raw Capture prose. OpenAI normally retains request content for up to 30 days for abuse monitoring under its standard controls, even though application-state storage is disabled for the request; OpenAI states that it may retain it longer where required by law or reasonably necessary to prevent harm. Situation Context is current-state only: correcting it replaces the previous structured values rather than creating a history. The current Context, the limited usage counter and saved opportunity references remain while your account is active until you remove the relevant feature data or delete your account. Deleting your account deletes both feature records and the usage counter. Legal basis: contract (Art. 6(1)(b) GDPR) — the transient interpretation and confirmed records provide the account features you chose to use.
__Host-ff_sso. It lets fluxforward.world, blog.fluxforward.world and app.fluxforward.world recognise that you are signed in, so Fluxy can use your account without asking you to sign in again on each site. The cookie is set only for auth.fluxforward.world, is sent only over HTTPS, cannot be read by scripts on any page, and contains a signed session token associated with your Flux Forward account. It never contains your password. It lasts up to 14 days at a time and is renewed while you stay signed in to the app; it ends when you sign out. When you sign out, it is replaced by a marker that records only that you signed out and when, contains no account data, and is kept for up to 180 days so the other Flux Forward sites sign you out too. While you are signed in, Fluxy messages you send on the website or the blog go through this sign-in service, which adds your account and passes them to Fluxy; the service does not store or log their content. The website and the blog keep no sign-in credentials in your browser; if a sign-out cannot be confirmed straight away, they keep only a note that it is still to be completed. The sign-in service runs on Google Cloud (Firebase) as our data processor, in the EU (Belgium), and is reached through Cloudflare. Your sign-in on this website uses the same Firebase Auth account as the app; the Google sign-in scripts are only loaded when Fluxy on this website offers you the option to sign in. Legal basis: providing the service you asked for (Art. 6(1)(b) GDPR).
ff_consent_v1. It is set on fluxforward.world and shared with our subdomains, which is how the same choice applies to the blog and the app without asking you again on each one. It records only that a choice was made, whether analytics was allowed, which analytics services you were told about, and when — it contains no account data and no advertising identifiers. It is kept for up to 400 days unless you change or clear it. You can change your choice at any time through Cookie settings, or clear the cookie through your browser settings. If you reject analytics, no Google Analytics or PostHog cookies are created, because neither measurement library is ever loaded. If you allow analytics, Google Analytics sets its own cookies in your browser — these usually have names beginning with _ga, and the exact set can vary with Google's own configuration and your browser settings. PostHog also sets one first-party cookie, whose name begins with ph_.
Legal basis for processing
Contract (Art. 6(1)(b) GDPR) — account data, scan results, Career Navigation setup data, confirmed Situation Context and saved opportunity references are processed to deliver the account features you choose to use.
Consent (Art. 6(1)(a) GDPR) — Google Analytics and newsletter subscriptions are only activated after you explicitly accept or opt in. You can withdraw consent at any time through the cookie banner, newsletter preference or unsubscribe links, or by emailing us.
Legitimate interest (Art. 6(1)(f) GDPR) — basic server logs and security monitoring needed to keep the service running, and answering messages you choose to send us. When you write to us through a contact form, including Message Flux Forward, our legitimate interest is receiving the message you deliberately sent, replying to it, and keeping a limited record of that exchange so we can follow up. We do not use contact messages for marketing, and sending one never subscribes you to anything. You can object to this processing at any time by emailing [email protected].
How long we keep your data
Account and scan data — kept as long as your account is active. We delete inactive accounts (no login for 24 months) unless you ask us to keep your data.
Contact messages — when you write to us through a contact form, including Message Flux Forward, your message is stored as a record in our own systems and is also delivered to us as an ordinary email. These are kept differently, so we describe both.
The record in our systems is deleted 12 months after the last contact we have logged about it. If you also opted into the newsletter, we remove the message itself but keep the record of your newsletter consent, because that is a separate choice with its own retention — deleting an old message never unsubscribes you.
The email in our mailbox is ordinary correspondence, in the same way as any email you send to a person. It stays in that mailbox until we delete it, and it is not covered by the automatic 12-month deletion above. You can ask us to delete it at any time.
We also keep a basic contact entry recording that you contacted us, when, and which page you wrote from, so we recognise you if you write again. For Message Flux Forward this entry does not contain the text of your message.
If the conversation becomes part of an ongoing customer, partnership, paid-service, contractual, or other working relationship, the relevant records may instead be kept under the retention rules that apply to that relationship.
Newsletter data — kept until you unsubscribe or ask us to delete it. If you unsubscribe, we may keep a minimal suppression record so we do not accidentally resubscribe you.
Career Navigation data — your career profile, experiences, preferences and situation are kept while your account is active. Your stated situation goes stale after 30 days and needs reconfirming before we use it again, which is not the same as deleting it; nothing here is removed automatically on a timer. Opportunity assessment bands, rankings and scores are never stored. Deleting your account deletes all of it.
Situation Context and saved opportunities — Flux Forward does not retain raw Capture prose. OpenAI normally retains it for up to 30 days for abuse monitoring under its standard controls and may retain it longer under its stated legal or harm-prevention exceptions. The current structured Situation Context, the limited text-free interpretation counter and saved opportunity references are kept while your account is active until you remove the relevant feature data or delete your account. Leaving a Beta or changing plan does not itself delete them. Situation Context has no history of earlier structured values. Deleting your account deletes both feature records and the usage counter.
Analytics data — Google Analytics data is retained for 14 months (the minimum configurable in GA4).
Fluxy technical records — the short technical record of a Fluxy answer is kept for 30 days. A report you send us about a Fluxy answer is kept for 90 days. Both are deleted automatically when that period ends.
Local storage — stays in your browser until you clear it or delete your account.
You can delete your account at any time from your profile. Section 5 sets out what deletion removes and the limited records we must keep.
Your rights under GDPR
As a person in the EU/EEA, you have the following rights. Email us at [email protected] to exercise any of them. We will respond within 30 days.
What deleting your account does. You can delete your account and the personal app data associated with it at any time from your profile. We remove your account and user-owned app data, cancel any active subscription, and request deletion of associated analytics data. PostHog may finish deleting previously collected historical analytics data asynchronously after your account is gone. We retain only records we must keep for legal, accounting and contract purposes, such as financial administration and evidence of a purchase, for the applicable retention period.
International data transfers
Your account data, scan results, and FluxOS CRM data are stored with the infrastructure providers we use to operate Flux Forward. The main ones are Cloudflare, which hosts our website, blog and app and runs the Fluxy backend; Google Firebase, which holds your account and app data in the EU (Netherlands, europe-west4); and Supabase, which hosts the FluxOS database, including public form submissions and CRM records, in the EU (Ireland). Where possible we use EU-based storage or providers with data processing terms.
Google Analytics, Brevo and PostHog may involve processing outside the Netherlands or the EU. We rely on appropriate safeguards such as data processing agreements, Standard Contractual Clauses, and available adequacy mechanisms where applicable.
Changes to this policy
We will update this page when our practices change. The "Last updated" date at the top reflects the current version. For significant changes, we will notify logged-in users by email.
For the rules governing use of the service, see our Terms of Service.
Questions or requests?
Email us directly. We aim to respond within 5 business days for general questions and within 30 days for formal GDPR requests.
[email protected]