Reading time
12 sections · approximately 12 minutes. This document is written in plain language to keep our practices transparent. Defined terms have their first meaning carried throughout.
Introduction
This Privacy Policy describes how ChatinFlow Teknoloji A.Ş. (“ChatinFlow”, “we”, “us”) processes personal data when you visit our websites, use our applications, or interact with our customer support.
We act as a data controller for personal data collected through our marketing site and when you create an account. When you use our platform to send messages to your audience, you act as a data controller and we act as a data processor on your behalf, governed by our Data Processing Addendum (DPA).
Information we collect
We collect information in three ways: data you provide, data generated through your use of the product, and data we receive from third parties.
Data you provide
- Account data: name, email, role, organization, billing address.
- Workspace content: flows, templates, AI prompts, contact lists.
- Support communications: messages you send our team.
Data generated through use
- Product telemetry: feature usage, performance metrics, error reports.
- Authentication events: sign-in attempts, session metadata.
- Audit logs: workspace and admin actions.
Data from third parties
- Connected platforms: profile and message metadata from Meta, X, TikTok, and other connected channels you authorize.
- Payment processors: tokenized billing references from Stripe.
- Identity providers: SSO claims from your IdP.
How we use information
We use the data above to:
- Provide, secure, and improve the ChatinFlow platform.
- Authenticate users and prevent abuse.
- Process billing and tax obligations.
- Communicate product updates, security notices, and (with your consent) marketing.
- Comply with legal obligations and enforce our Terms.
We do not sell personal data, and we do not use your workspace content to train shared AI models. Optional AI features explicitly disclose any inference provider before use, and you can opt-out at the workspace level.
Lawful basis (GDPR)
Where the EU General Data Protection Regulation applies, we rely on the following lawful bases:
- Contract (Art. 6(1)(b)): to deliver the service you signed up for.
- Legitimate interests (Art. 6(1)(f)): to secure our service and improve product quality.
- Consent (Art. 6(1)(a)): for non-essential cookies and marketing emails.
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, and law enforcement requests.
International transfers
ChatinFlow processes data in the EU, US, and (optionally) APAC. Where data is transferred outside the European Economic Area or the United Kingdom, we rely on:
- EU Standard Contractual Clauses (Module 2 / Module 3) and the UK Addendum.
- Supplementary measures, including encryption in transit and at rest.
- EU-only residency on Enterprise plans where required.
Retention
We retain personal data only as long as necessary for the purposes described above. Default retention periods:
- Account & billing: until account closure plus 24 months for tax obligations.
- Workspace content: customer-controlled. Default is 24 months for messages and 365 days for audit logs.
- Telemetry: aggregated after 90 days; raw event data deleted at 365 days.
Customers can configure shorter retention windows from workspace settings or via the API.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete data subject to legal obligations.
- Object to processing or restrict its use.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@chatinflow.com. We respond within 30 days.
Security
ChatinFlow maintains a comprehensive information security program, including SOC 2 Type II and ISO/IEC 27001:2022 certifications. Controls include encryption (TLS 1.3, AES-256), least-privilege access, audit logging, network segmentation, and 24×7 incident response.
A full overview is published on our Trust Center. Suspected vulnerabilities can be reported to security@chatinflow.com.
Children
ChatinFlow is not intended for children under 16. If we learn that we have collected personal data from a child under 16 without verified parental consent, we will delete it promptly.
Changes & contact
We may update this Privacy Policy from time to time. Material changes are communicated via in-product notice and email at least 30 days before they take effect.
Questions? Reach our Data Protection Officer at dpo@chatinflow.com or our EU representative at the address listed in our DPA.
Questions about this document?
Reach our legal and privacy team directly. We respond to most requests within five business days.