Flexiflock is not associated with "Flock" Cameras or any surveillance/license-plate-reader company.

Back to HomeDocument 8 of 10

Data Processing & Security Policy

Entity: Hashtag Thrift LLC d/b/a Flexiflock | Website: www.flexiflock.com
Effective Date: October 5, 2026 | Last Updated: October 5, 2026

1.0 Purpose

1.1 This Data Processing & Security Policy ("Security Policy") supplements the Privacy Policy by detailing how Hashtag Thrift LLC d/b/a Flexiflock ("Flexiflock") collects, classifies, processes, stores, protects, and disposes of data. Designed to satisfy Fla. Stat. § 501.171 (FIPA) and applicable federal data security requirements.

2.0 Data Classification

  • Public — marketing content, published blog posts, publicly posted policies.
  • Internal — internal communications, operational workflows, vendor contracts.
  • Confidential — client intake forms, payment records, legal documents prepared for clients.
  • Restricted — personally identifiable information (PII), health information, financial account details; access limited to authorized personnel only.

3.0 Data Processing Principles

  • Lawfulness, Fairness, and Transparency.
  • Purpose Limitation — data used only for stated, legitimate purposes.
  • Data Minimization — only necessary data is collected.
  • Accuracy and Rectification — reasonable steps to correct or delete inaccurate data.
  • Storage Limitation per the retention schedule below.
  • Integrity and Confidentiality — protection against unauthorized access, loss, or damage.

4.0 Technical Security Measures

  • TLS Encryption in Transit (TLS 1.2+); HTTP redirected to HTTPS.
  • AES-256 Encryption at Rest for sensitive personal data.
  • Multi-Factor Authentication (MFA) for administrative and sensitive-data access.
  • Firewalls and Intrusion Detection/Prevention Systems.
  • Regular Vulnerability Scanning and security assessments.
  • Secure Coding Practices (input validation, output encoding, OWASP Top 10 protections).

5.0 Organizational Security Measures

  • Least-Privilege Access Controls.
  • Annual Staff Training on data protection and incident reporting.
  • Vendor Due Diligence and mandatory data processing agreements.
  • Written Incident Response Plan covering detection, escalation, containment, notification, and remediation.

6.0 Data Breach Notification (Fla. Stat. § 501.171)

6.1 Internal escalation required within twenty-four (24) hours of discovery.

6.2 Affected Florida residents notified within thirty (30) calendar days of determination.

6.3 Breaches affecting 500+ Florida residents trigger simultaneous notification to the Florida Attorney General.

6.4 Notifications include incident description, affected categories/individuals, mitigation steps, protective recommendations, and contact information.

7.0 Data Retention Schedule

  • Client engagement records — 7 years after engagement conclusion.
  • Financial and accounting records — 5 years from close of relevant fiscal year.
  • Marketing and prospect data — 2 years from last interaction.
  • Security and access logs — 1 year, rolling.
  • Data subject rights requests and correspondence — 3 years from resolution.

8.0 International Data Transfers

8.1 Personal data is primarily stored and processed within the United States; Flexiflock does not intentionally transfer data abroad without appropriate legal safeguards.

8.2 Cloud vendors processing data in multiple jurisdictions are evaluated for compliance, with contractual security commitments required.

© 2026 Hashtag Thrift LLC d/b/a Flexiflock | www.flexiflock.com | Confidential – Legal Use Only

We use cookies to operate our site and, with your consent, for analytics and marketing, consistent with the Florida Digital Bill of Rights. See our Cookie Policy for details.