Last updated: March 2026
CaptiveFlow, operated by MSP Kickstart Limited (company number 16297973, registered in England and Wales), is committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we approach data protection and the measures we have in place to ensure compliance.
CaptiveFlow operates in a dual capacity. For venue operator accounts (our customers), MSP Kickstart Limited is the data controller. We determine the purposes and means of processing your account information, billing details, and usage data. For WiFi guest data collected through venue captive portals, the venue operator is the data controller. MSP Kickstart Limited acts as the data processor, processing guest data on behalf of and under the instructions of the venue operator. This distinction is important because it means venue operators have primary responsibility for ensuring they have a lawful basis for collecting guest data and for responding to data subject requests from their guests.
A Data Processing Agreement (DPA) is available on request for all venue operators. The DPA sets out the terms under which CaptiveFlow processes guest data on your behalf, including the nature and purpose of processing, the types of data processed, our security obligations, and our obligations regarding sub-processors. To request a copy, please contact us at hello@captiveflow.co.uk.
All CaptiveFlow data is stored using Supabase, with databases hosted in the European Union. This ensures that personal data remains within jurisdictions that provide adequate levels of data protection under UK GDPR. We do not transfer personal data outside of the EU/UK unless required by a sub-processor with appropriate safeguards in place.
WiFi guests whose data is collected through CaptiveFlow portals have the following rights under UK GDPR: the right of access to their personal data, the right to rectification of inaccurate data, the right to erasure (the right to be forgotten), the right to restrict processing, the right to data portability, and the right to object to processing. Guests wishing to exercise these rights should contact the venue where they connected to WiFi in the first instance, as the venue is the data controller. If the venue is unable to assist, or if the request relates to data CaptiveFlow holds as a data controller, guests can contact us directly at hello@captiveflow.co.uk. We will respond to all valid requests within 30 days.
CaptiveFlow enforces explicit opt-in for marketing consent. The marketing checkbox on all captive portals is unchecked by default and cannot be changed to default to checked. This ensures that marketing consent is always freely given, specific, informed, and unambiguous, as required by UK GDPR. Venue operators are responsible for managing marketing communications and honouring opt-out requests from guests who have previously consented.
CaptiveFlow does not engage in automated decision-making or profiling as defined by UK GDPR. While we track whether a guest is a returning visitor (based on whether their email has been seen at the same venue before), this is a simple factual record and does not involve any automated assessment of personal characteristics or behaviour.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, MSP Kickstart Limited will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR. We will also notify affected venue operators without undue delay so they can fulfil their own notification obligations to data subjects where required. We maintain internal breach detection and response procedures and regularly review them to ensure they remain effective.
CaptiveFlow uses the following sub-processors to deliver our service. Supabase provides database hosting, user authentication, file storage, and serverless edge functions, with data hosted in the EU region. Resend provides transactional email delivery for system notifications such as password resets, team invitations, and account alerts. We review our sub-processors regularly and will notify venue operators of any changes to this list. We do not share, sell, or provide access to personal data to any other third parties.
MSP Kickstart Limited is registered with the Information Commissioner's Office as a data controller and data processor. If you have concerns about how we handle personal data that we have been unable to resolve, you have the right to lodge a complaint with the ICO at ico.org.uk.
For any questions about GDPR compliance or data protection at CaptiveFlow, please contact us at hello@captiveflow.co.uk. MSP Kickstart Limited, registered in England and Wales, company number 16297973.