CChamberflow
Privacy

Whose data it is, where it lives, and how to get it back.

Who is responsible for what, where data is stored, which providers process it, how long it is kept, and how to ask for a copy or deletion. Last updated 12 September 2026. VentureLK LLC, Delaware, United States, operates Chamberflow.

Two roles

Chamberflow is a platform chambers of commerce run their membership on. Whose data it is decides who answers for it.

  • A chamber’s members, applicants, event guests and subscribers: the chamber is the controller. It decides why the data is collected and how it is used. VentureLK LLC, which operates Chamberflow, is the processor and acts only on the chamber’s instructions under a written agreement. Each chamber publishes its privacy notice on its website at /privacy.
  • Visitors to this website and people who ask us for a demo: VentureLK LLC is the controller. We keep the name, organisation and email address you give us on the demo form so that we can reply, and nothing else about you.
  • Staff accounts on the platform: a name, an email address and a password stored as a bcrypt hash, plus an audit log of what each account did, with time, network address and browser.

Where the data is

The application and the database run in Singapore. Nothing is stored in China or in the United States, with the exceptions listed here.

  • Application hosting: Vercel, Singapore region.
  • Database: Postgres on Neon, Amazon Web Services Singapore. Documents a chamber uploads are stored in that database and served only to signed-in people of that chamber.
  • Email delivery: Resend, United States. A chamber can send from its own domain once it has verified it in Settings; until then mail leaves from a shared address carrying the chamber’s name.
  • Drafting assistance for chamber staff: Mistral AI, France, on the paid plan. The model receives the record being drafted about, never credentials, card data or a whole roster, and Mistral’s commercial terms say the data is not used for training.
  • Public images on chamber websites and newsletters: Vercel Blob. No personal data is stored there.
  • Card payments: the payment provider the chamber has chosen, on that provider’s pages. Card numbers never reach Chamberflow.

How long it is kept

A chamber decides its own retention for its members’ records. These are the platform’s rules.

  • A chamber can download everything it holds, as one file, from Settings, any day, without asking us.
  • When a chamber stops using Chamberflow, its data is deleted on its written request, except for the financial records it must keep, which are exported to it first.
  • One-time sign-in codes expire within minutes and are stored only as hashes.
  • The database keeps a short point-in-time history for recovery from mistakes, and full copies are taken before every planned change to a chamber’s data.
  • Demo-form enquiries are kept while we are in contact and removed when you ask.

Security, in one paragraph

The detail is on the security page. The short version is what a board usually asks.

  • Everything travels over TLS. Payment-provider credentials are encrypted at rest with AES-256-GCM. Staff passwords are bcrypt hashes; members have no password and sign in with a one-time code sent to their email.
  • Every staff session is bound to one chamber. Every action is written to an audit log with a name against it.
  • Marketing email goes only to contacts who have consented, every message carries an unsubscribe link, and suppressions are honoured across campaigns.

This website

We measure this site without following you around the web.

  • Page views are counted with a cookieless analytics beacon. There is no Google Analytics, no advertising pixel and no third-party font.
  • The only cookies are the ones that keep a signed-in person signed in and one that remembers which chamber a host belongs to.

Your rights, and how to use them

For your own data held by a chamber, write to the chamber; its notice names the address. For anything VentureLK LLC holds as controller, write to us.

  • A copy of what we hold about you, correction of anything wrong, deletion of what we no longer need, and an end to any marketing.
  • Write to lawrence@pgintel.dev. We act within ten working days and confirm in writing what we did.
  • If you are in the European Union you can also complain to your local data protection authority; in Taiwan, to the authority responsible for the Personal Data Protection Act.

The security detail is on the security page. The privacy policy for the Chamberflow member app is at /mobile/privacy.