Legal
Privacy Policy
1. Introduction
Welcome to Secure-Flows. This Privacy Policy (the "Privacy Policy" or "Policy") constitutes an integral part of our Terms and Conditions ("T&Cs") and governs the data collection, processing, and safeguarding practices executed by Secure-Flows ("Secure-Flows", "we", "us", or "our"). This document outlines the rigorous framework under which we manage, store, utilize, collect, process, transfer, and securely delete personal information.
This Policy applies to our business Customers, their authorized personnel, organizational representatives, prospective corporate clients, visitors of our official Websites, and any user who accesses, deploys, uses or interacts with our platform, Products, or Services (collectively "you" or "Customer"). Capitalized terms utilized but not explicitly defined within this Policy shall carry the designated meanings set forth in our T&Cs.
Please review this document carefully to understand our data processing protocols. By accessing our Websites or deploying and using our Services and Products, you acknowledge that you have read, comprehended, and agreed to be bound by the terms of this Policy. If you object to any segment of this framework, you must immediately refrain from accessing our platform and Products or utilizing our Services.
Secure-Flows operates as the Data Controller (or equivalent legal designation under applicable privacy laws) for the data processed in connection with our core platform, operational interfaces, and digital assets. Our data infrastructure is engineered to meet and exceed global regulatory frameworks. As the Data Controller, we assume direct responsibility for ensuring that your personal data is handled with structural integrity, legal compliance, and robust security.
2. Customer Responsibility and End-User Compliance
Where the Customer utilizes our Products and Services to monitor, process, or secure data relating to its own employees, contractors, third-party contractors, vendors or end-users ("Customer’s Users"), the Customer acknowledges and agrees that it acts as the sole and absolute data controller of such data. For the avoidance of doubt, depending on the specific technical configuration, deployment model, or level of data obfuscation applied within the Customer's environment, Secure-Flows may not access, receive, or process any Personal Data of Customer’s Users at all. To the extent that any such data is processed, transmitted, or hosted within our infrastructure, Secure-Flows acts strictly and only as a Data Processor (or an entity holding the data on behalf of the Customer), and under no circumstances, subject to the applicable laws, shall Secure-Flows be deemed a Data Controller or Joint Controller of Customer’s User data. For more information regarding Customer responsibilities please visit our Terms and Conditions site.
3. Data Collection
During your interactions with our Products, Services, and Websites, we collect both personal and non-personal data parameters to deliver security solutions designed for seamless integration. We broadly divide data categories as follows:
Non-Personal Data
We may collect aggregated, non-identifiable, and anonymized technical information transmitted automatically by your device or browser interface ("Non-Personal Data"). This includes browser types, hardware versions, language preferences, operating system details, and timestamp logs. We use this data strictly to maintain compatibility, perform statistical optimization, and preserve infrastructure uptime. For the avoidance of doubt, any Non-Personal Data that is linked or correlated with identifiable Personal Data shall be treated as Personal Data for as long as such linkage persists.
Personal Data
In order to provide our Services and Products and operate our Websites we may collect from you an individually identifiable information, namely information that identifies an individual or may, with reasonable effort, be used to identify an individual (“Personal Data” or “Personal Information”). The nature of the Personal Data we collect, and process depends on your specific engagement with the Services, Products and Websites and our legal obligations. We generally categorize the collection of Personal Data into three primary channels:
- Information You Provide Us: When you create an account, purchase a subscription, or contact support, we collect the details you provide, such as your name and email address.
- Information Collected Automatically: When you use our Services, Websites or Products, our systems automatically log technical metadata details like your IP address. Please note that private data is never logged to protect the Customer and its End Users privacy.
- Information Collected from Third-Parties: If you use a third-party service that provides us services, we may receive certain details that identify you.
The detailed types of Personal Data that we collect as well as the purpose for processing such data are specified below. For the avoidance of doubt, any Non-Personal Data connected or linked to any Personal Data shall be deemed as Personal Data as long as such connection or linkage exists.
4. Categorized Personal Data
A. Account and Contact Details
Data Set: When registering an account, purchasing a subscription, or contacting support, you may provide us or our third-party providers your full name, email address, phone number, name, address, job title, confirmation of legal adult status (18+), and the full text, attachments, or metadata of support tickets.
In addition, you may provide to us or our third-party providers authentication credentials (usernames, passwords, etc.), however, please note that in no event Secure-Flows shall store them in their own storage bases.
Purpose of Processing: We process this Account and Contact Details dataset primarily to authenticate user identities, configure secure access controls and user roles within our platform, manage and maintain your profile, effectively deliver our core Services, track and resolve technical customer support tickets, process billing, manage Customer relationships, follow up on commercial business leads, and communicate critical, non-marketing administrative or security alerts.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest.
B. Online Identifiers and Internet Activity
Data Set: We or our third-party providers may collect internet Protocol (IP) addresses, unique cookie identifiers, pixel tags, web beacons, and coarse geographic localization derived from IP lookups, or any other similar unique online identifiers generated during your session, alongside system diagnostic log files, system performance metrics, login timestamps, browser types, and device configurations.
Purpose of Processing: (i) Core operational functionality, stability, platform infrastructure security, anomaly monitoring, and proactive cyber-threat or fraud prevention; and (ii) analytical evaluation of system interactions, interface performance optimizations, and user journey diagnostics.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest. however, when we process Online Identifiers for analytical, statistical, or marketing purposes, we do so subject to your explicit consent under, which you may withdraw at any time.
C. Usage Data
Data Set: We or our third-party providers may collect clickstream data, access timestamps, and internal activity logs, alongside specialized SaaS usage metrics such as concurrent active user sessions, storage capacity utilization, bandwidth consumption, API calls, and flow metadata regarding monitored data streams.
Purpose of Processing: To facilitate core provisioning of our services, verify subscription limits, monitor storage quotas, perform capacity planning, track consumption-based billing variables, and run internal analytical modeling to enhance overall platform resilience.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest. However, when we process Usage Data for analytical, statistical, or marketing purposes, we do so subject to your explicit consent under, which you may withdraw at any time.
D. Services and Products Data
Data Set: We or our third-party providers may collect technical architecture configurations and platform metrics harvested directly from the Customer’s integrated environments, cloud infrastructures, application layers, and networks, including active API flows, network routing topologies, software log outputs, security encryption protocols, data leak indicators, and system error logs ("Services Data").
Purpose of Processing: To deliver real-time traffic monitoring, data stream optimization, automated anomaly detection, vulnerability mapping, and security posture enforcement, as well as utilizing anonymized datasets for machine learning model training and global threat intelligence aggregation.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest.
E. Invoicing and Payment Details
Data Set: Third-parties payment processors providers may collect cardholder or account owner's full name, billing email address, address, country, tax identification number (such as VAT or EIN), and financial payment configurations, including credit card details, bank account identifiers, or alternative payment methods.
Purpose of Processing: To facilitate invoicing, authenticate financial transactions, manage corporate subscription renewals, and manage commercial accounting workflows. Secure-Flows utilizes Paddle as an integrated third-party payment processor and Merchant of Record. Transactions are securely managed on Paddle's infrastructure governed by their independent privacy regulations, which we highly recommend reviewing.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest.
F. Career and Recruitment Data
Data Set: Curriculum Vitae (CV/Resume) files, application text, contact variables, cover letters, professional portfolios (e.g., LinkedIn), academic credentials, professional references, and evaluation notes generated during internal interviews.
Purpose of Processing: To evaluate job applicant qualifications, manage recruitment pipelines, conduct pre-employment validation, maintain records for legal defense against potential hiring claims, or contact candidates for future matching openings.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest.
G. Marketing, Newsletters, and Social Media
Data Set: Professional email addresses, names, corporate titles, social media handles, public profile interactions (likes, shares, comments), and direct messages submitted via corporate social accounts (e.g., LinkedIn, X).
Purpose of Processing: To distribute requested corporate newsletters, product update alerts, and promotional insight briefs, nurture business sales leads, manage online brand engagement, and analyze aggregate audience demographics.
Lawful Basis: We process your data to fulfill our contractual obligations and provide you the requested Services. Additionally, certain purposes, such as operational and security aspects, are conducted based on our legitimate interest.
5. Processing Mechanics and Safeguards
Secure-Flows implements advanced computational technologies to process personal data using structured, automated operations (including collection, system logging, transmission-based disclosure, alignment, erasure, and destruction). Beyond standard operational workflows, we process Personal Data to proactively block harmful, fraudulent, or illegal operations, such as identity theft, unauthorized platform intrusion, data extraction, or general system misuse.
Furthermore, personal records are processed to enforce our T&Cs and protect the database architecture and network integrity of our ecosystems. The execution of processing activities for general security preservation and fraud prevention is carried out based on our legitimate interests.
6. Data Sharing Protocols
Secure-Flows does not sell personal data. We disclose collected personal profiles exclusively under the following verified scenario frameworks:
A. Authorized Third-Party Service Providers
Data That Will Be Shared: All types of Personal Information.
We coordinate with verified external contractors and infrastructure providers ("Third-Party Service Providers") to execute core operational components, including cloud data storage, database hosting, cloud service hosting, authentication service, payment service, analytical measurement, marketing outreach tools, technical error debugging, and security audit services. Under strict data processing terms, these service providers receive access solely to data segments that are strictly necessary to deliver their pre-agreed functions. They are contractually prohibited from utilizing, selling, or disclosing your Personal Data for any independent purposes. Firebase (Google), Cloudflare and Render are 3 examples of Secure-Flows Service providers. You can find the Privacy and Security terms of Firebase here https://firebase.google.com/support/privacy, Cloudflare’s Privacy terms here https://www.cloudflare.com/privacypolicy/, and Render’s Privacy terms here https://render.com/privacy.
B. Corporate Business Transfers
Data That Will Be Shared: All data.
In the event that Secure-Flows undergoes a corporate merger, structural acquisition, financial due diligence, organizational reorganization, asset sale, or transition of service to an alternative corporate entity, your personal information may be shared during due diligence phases with legal advisors and counterparties, and transferred as an operational asset to successor entities or affiliates who will assume equivalent rights and obligations.
C. Affiliated Corporate Entities
Data That Will Be Shared: All data.
We may share personal profile segments with our corporate subsidiaries or affiliated companies for centralized internal administrative management, synchronized global sales pipelines, and financial reporting protocols.
D. Statutory Disclosures and Judicial Demands
Data That Will Be Shared: All data types.
In exceptional circumstances, we may disclose or grant law enforcement, regulatory bodies, or judicial officials access to personal parameters in response to a valid court subpoena, search warrant, or administrative order. Such disclosures are executed exclusively if we maintain a good-faith belief that: (a) we are legally compelled to do so; (b) disclosure is necessary to investigate, prevent, or mitigate suspected fraudulent or illegal behavior; (c) it is vital to defend the systemic safety and structural integrity of our Products and Services; or (d) it is mandatory to protect the foundational property, legal rights, or personal safety of our personnel, users, or the general public.
When we share information with services providers and partners, we ensure they only have access to such information that is strictly necessary for us to provide the Services. These parties are required to secure the data they receive and to use the data for pre-agreed purposes only while ensuring compliance with all applicable data protection regulations (such service providers may use other Non-Personal Data for their own benefit).
7. Cookies and Tracking Technologies
The deployment of our Products, Websites, and Services incorporates "Cookies," tracking pixels, local storage objects, and similar automated technologies. These tools are utilized to enable vital platform features, authenticate user sessions, analyze system performance, and optimize your overall experience across our digital ecosystem. For comprehensive information regarding tracking mechanisms, you may consult independent educational resources such as www.allaboutcookies.org.
User Preferences and Opt-Out Framework
Through your native browser settings, you can clear existing cookies, automatically decline certain tracking categories, block third-party scripts, or configure notifications prior to a cookie being stored on your terminal. To manage these parameters, please consult the official configuration documentation provided by your respective browser vendor:
Certain third-party functionalities embedded within our Products and Services deploy independent tracking mechanisms which are governed strictly by those respective third parties' privacy and cookie policies. Please note that blocking or erasing essential or functional cookies may degrade platform responsiveness and limit your access to key operational features. Furthermore, while deactivating targeting cookies will prevent customized B2B advertising, it will not block advertisements entirely, rather, any promotional content displayed across the internet will simply lack personalization and relevance to your professional interests.
8. Cross-Border Data Transfers
Secure-Flows operates a globally distributed cloud infrastructure. Consequently, the Personal Data we collect may be stored, moved, and processed in various territories across the globe, which may maintain data protection frameworks that differ from your local jurisdiction. Whenever such data transfers occur, they are facilitated and managed by our third-party hosting and infrastructure providers, who are bound by applicable privacy regulations and compliance frameworks pursuant to their respective terms of service and data processing agreements. Secure-Flows assumes no direct liability for the data protection practices, security infrastructure, or regulatory compliance of these third-party vendors.
Specifically, to the extent that personal data is transferred out of the European Economic Area (EEA) via our third-party infrastructure, we use our best efforts to ensure that our arrangements with such vendors incorporate appropriate contractual safeguards, including the execution of the EU Standard Contractual Clauses (SCCs) as authorized by the European Commission, supplemented by organizational encryption standards intended to preserve confidentiality.
However, the Customer acknowledges that Secure-Flows relies on the operational compliance of these third-party providers, and Secure-Flows explicitly disclaims any liability should a third-party vendor fail to adhere to such clauses, privacy laws and regulations or security standards.
9. Infrastructure Security and Breach Notifications
We implement advanced technical, physical, and administrative security measures engineered to safeguard our cloud infrastructure. These defenses include end-to-end SSL encryption protocols for data in transit, strict database segregation, server-side data minimization, and role-based access restrictions limiting data visibility to authorized personnel on a strict need-to-know basis.
However, please note that no method of transmission over the internet or cloud storage layer can be 100% airtight. While we implement elite defensive safeguards, we cannot guarantee absolute prevention of unauthorized breaches, and Secure-Flows cannot be held liable for malicious third-party hacks that bypass standard industry protocols. In the event of a material security incident compromising your personal data, we will deploy immediate mitigation workflows, notify you via direct administrative channels, and inform the appropriate regulatory supervisory authorities as mandated by applicable global privacy laws.
10. Proportional Data Retention
Secure-Flows stores personal profiles strictly for the duration required to execute the operational purposes detailed within this Policy, all in accordance with statutory limitations, or until an authorized individual requests a formal deletion or opt-out. We retain data for extended intervals under the following conditions: (i) to fulfill legal, corporate tax, regulatory, or mandatory bookkeeping obligations; (ii) to maintain verified historical records of your interactions to resolve active complaints or disputes; or (iii) where there is a reasonable anticipation of pending litigation.
Furthermore, Secure-Flows performs regular data backups and archiving as permitted by and in accordance with applicable regulatory guidelines to ensure system continuity, disaster recovery, and infrastructure security. In the event of an authorized formal deletion request, your Personal Data will be promptly deleted or anonymized from our active production systems. However, such data may temporarily persist in our backup, archival, or disaster recovery environments in an encrypted and isolated state until it is systematically overwritten, purged, or fully deleted in accordance with Secure-Flows’ internal data retention policies and subject to applicable law.
Unless explicitly restricted by statutory mandates, Secure-Flows retains the absolute discretion to systematically delete, purge, or modify technical data within our systems without prior individual notice once we determine it is no longer operationally necessary.
11. Data Subject Rights and Exercise Protocol
Secure-Flows is committed to absolute transparency, allowing individuals to make informed decisions regarding their data privacy. Depending on your primary jurisdiction and the applicable data privacy frameworks, you may possess the following statutory rights regarding your personal profiles:
- § Right of Access – to view a copy of your data;
- § Right to Rectification – to correct inaccurate data;
- § Right to Erasure – to request data deletion;
- § Right to Object or Restrict – to stop or limit data processing;
- § Right to Data Portability – to download or transfer your data to you;
- § Right to Withdraw Consent – to revoke previously given approval;
- § Right to Lodge a Complaint – to complain to a privacy authority.
To exercise any of these statutory rights, please submit a formal request to our compliance team at [email protected]. Please note that to protect your security, we may require additional verification parameters to validate your identity before executing data extractions. We reserve the right to deny requests that fail identity verification or are explicitly restricted under applicable statutory laws.
With respect to Customer’s Users, the Customer acts as the sole and absolute data controller and bears exclusive responsibility for managing, facilitating, and responding to all data subject privacy requests. Any such requests by Customer’s Users must be directed to, and exercised solely against, the Customer. Secure-Flows maintains no direct legal obligation to handle, process, or fulfill privacy rights requests received from Customer’s Users. The provisions of this subsection, and the allocation of responsibilities herein, shall be subject in all cases to the requirements, limitations, and feasibility permitted under applicable law.
12. Age-Gating and Children's Data
Secure-Flows' Services and Products are engineered strictly for business operations and are not directed toward children. We do not knowingly harvest, process, or maintain personal profiles from individuals below the age of legal adulthood or under the age thresholds defined by local privacy laws. If we discover that an underage individual has bypassed our system entry blocks and provided personal data, we will immediately discard and purge that information from our active databases. If you maintain a reasonable belief that a child has shared data with us, please contact us immediately at [email protected].
13. Policy Revisions and Timeline
We reserve the right to modify, amend, or restructure this Privacy Policy at our sole discretion. The most current, legally binding version of this Policy will always be displayed on our Website, featuring an updated "Last Updated" header at the top of the document.
In the event that we execute significant, material adjustments to our processing workflows that directly impact your rights, we will dispatch an administrative notification across our platform interface or via your registered email. All modifications become fully binding within thirty (30) days from their initial display on our digital assets. We highly encourage users to regularly review this page to stay proactively informed about our data protection standards.
14. Corporate Contact Framework
For any legal questions, structural clarity, or to execute your data subject rights regarding this Privacy Policy or our operational cookie parameters, please contact our Data Protection Officer directly at:
Secure-Flows
Attn: Data Privacy & Compliance Dept.
Email: [email protected]