Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Last updated: August 24, 2026
1. Information We Collect
We collect information you provide directly, including:
- Account information (name, email, company name)
- Lead and contact data you input into the platform
- Conversation and message content
- Payment and billing information
- Usage data and analytics
- Account security and sign-in records (see section 7)
2. How We Use Your Information
We use the collected information to:
- Provide and maintain our services
- Process transactions and send related information
- Send you technical notices and support messages
- Improve and personalize the service
- Develop new features and functionality
3. Information Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this privacy policy. We may share data with:
- Service providers who assist in operating our platform
- Third-party integrations you explicitly connect
- Law enforcement when required by law
4. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Your information is stored on secure servers with encryption at rest and in transit. Access is governed by role-based permissions, each customer's data is isolated at the database layer, and administrative actions are recorded in an audit log. We do not currently hold a SOC 2 Type II or ISO 27001 certification; we will update this page if that changes.
5. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt out of marketing communications
6. Cookies and Tracking
We use cookies and similar technologies to improve your experience, analyze usage patterns, and deliver personalized content. You can control cookie preferences at any time using the button below.
7. Account Security and Sign-In Monitoring
To protect your account against unauthorised access, we record technical details of every sign-in to a QualiFlow account. This is a security measure, not analytics or advertising. It is therefore not governed by the cookie preferences above and cannot be switched off, because doing so would remove your ability to be told that someone else is using your account.
What we record
- The network (IP) address the sign-in came from
- The device and browser description your browser reports — its user agent
- The time of the sign-in and the method used (password, one-time code, or a connected Google or Microsoft account)
- An approximate location worked out from that address — country and region only. We do not derive or store a city, and we do not attempt to work out where you personally are
- The network operator (ASN) the address belongs to — for example a mobile carrier, an internet provider, or a VPN service
- Where sign-in monitoring is switched on, a random device identifier we place in your browser as a strictly necessary cookie. It contains no account details and identifies nothing about you — it lets us tell “this browser again” from “a browser we have not seen”. We store only a one-way hash of it, never the value itself
That is the whole list. The location is approximate and often wrong about where you are: it is worked out from the network address rather than from your device, so a VPN or a mobile network will regularly show a different country. We treat it that way ourselves — a location on its own never triggers an alert. If we add anything to this list, this section will say so before we do it, not afterwards.
The location lookup runs on our own servers against a local copy of the GeoLite2 database. Your address is not sent to anyone to do it, and this introduces no new sub-processor. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Where this stands today. Sign-in monitoring is switched off by default, and it is off in production now. While it is off we record only the network address, the user agent, the time and the sign-in method — no device cookie is placed and no location is derived. No location database is deployed yet either, so even where monitoring is switched on, no country, region or network operator is currently being worked out from your address. We describe all of it here in advance because a disclosure has to come before the processing it describes, never after it — so this section already covers what happens when each part is turned on, and we will not quietly begin any of it without having said so first.
Why we are allowed to do this
Our lawful basis is legitimate interests under Article 6(1)(f) GDPR, relying on Recital 49, which recognises processing that is strictly necessary and proportionate for ensuring network and information security as a legitimate interest. We have carried out and documented a Legitimate Interests Assessment for this processing. You may object to it under Article 21; contact our Data Protection Officer using the details in section 10.
What we use it for — and what we never use it for
- Telling you when your account is signed in to from a device we have not seen before
- Letting you sign out of every device and reset your password if a sign-in was not you
- Investigating a suspected compromise of your account
We use it for nothing else. This data is never used for advertising, profiling, product analytics or sales enrichment, is never sold or shared for those purposes, and is never used to monitor attendance or working patterns.
How long we keep it
- First 90 days — the full record
- At 90 days — the IP address and user agent are removed
- Up to 13 months — a reduced record: the time, the method used, and whichever of the approximate country, region, network operator and device identifier were recorded. These are what let us recognise a device and a pattern a year later; the address and the user agent, which identify you most directly, are gone by then
- After 13 months — the record is deleted
This schedule is set and enforced by QualiFlow. A business account’s own data-retention settings do not shorten or extend it, so that no one holding an account can quietly erase the evidence of their own unauthorised access.
Seeing and acting on your own sign-ins
You can review your sign-in history — every time your account was signed in to, including sessions that have since ended — and the devices currently signed in to your account, at any time under Settings → Security. You can sign out of every device from there. You see only your own sign-ins and your own sessions, never another person’s. All of the rights described in section 5 apply to this data.
8. Google Workspace Data and Limited Use
If you connect a Gmail account to QualiFlow, this section governs that data and takes precedence over anything more general elsewhere in this policy.
QualiFlow AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access, and why
- Reading incoming mail. We read messages that arrive at the connected address after you connect it, so your customers’ email appears in your QualiFlow inbox alongside their SMS, WhatsApp and web-chat messages.
- Marking mail as read. Once QualiFlow has handled a message we mark it read in Gmail, so your own inbox reflects what has been dealt with and nobody answers the same customer twice.
- Sending replies. We send replies from your address, in the thread the customer wrote to, so they hear back from the business they contacted.
We do not delete, archive or move your mail, we do not change message content, and we do not read historic mail from before you connected the account.
We never train AI models on your Google data
QualiFlow uses AI to draft replies, so the content of a customer’s email is sent to an AI provider to produce that reply. That is the only reason it leaves our systems, and it is subject to a hard limit:
We do not use Google Workspace data — raw, aggregated, anonymised or derived — to create, train, retrain or improve any machine-learning or artificial-intelligence model, our own or anyone else’s.
Our AI providers are Azure OpenAI Service (Microsoft) and the OpenAI API. Both are used under commercial API terms that prohibit training on data submitted through them; neither is a consumer tier. We use no other AI or ML provider for Google data.
Who can see it
- We do not sell your Google data, and we do not use it for advertising or to build profiles.
- We do not transfer it to any third party other than the AI providers named above, who process it only to generate your reply.
- No one at QualiFlow reads your Google data except where you explicitly ask us to for a support request you have raised, or where we are legally required to.
Turning it off
Disconnecting the mailbox in QualiFlow — under Channels, then Email — revokes our access immediately and deletes the stored authorisation. You can also revoke it from your Google account permissions page.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Upon account deletion, we will delete or anonymize your data within 30 days, except where legally required to retain it.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last Updated” date.
11. Contact Us
For privacy-related questions, please contact our Data Protection Officer at privacy@qualiflow.ai
Last Updated: August 24, 2026