This Privacy Policy sets out how Unflow collects, uses, discloses and otherwise processes personal data in connection with the website unflow.io, the products and services offered by Unflow, and any related communications. It is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”), the GDPR as retained in the law of the United Kingdom (the “UK GDPR”), Portuguese Law No. 58/2019 of 8 August, and applicable United States federal and state privacy laws. Capitalized terms not defined in this Policy have the meaning given to them in the GDPR.
Controller and contact details
1.1 Unflow operates through two legal entities: Unflow Lda., a company incorporated in Portugal, and Unflow LLC, a limited liability company incorporated in the State of Texas, United States (each “Unflow”, “we”, “us” or “our”).
1.2 The controller of personal data processed in connection with unflow.io is Unflow Lda. The controller of personal data processed in connection with a commercial relationship is the Unflow entity named on the relevant proposal, order or invoice.
1.3 Unflow has designated a data protection lead who is responsible for overseeing compliance with this Policy and with applicable data protection law. The data protection lead may be contacted at privacy@unflow.io. All requests and inquiries concerning personal data should be addressed to that address.
Personal data we collect
2.1 Usage data. When you visit unflow.io, we collect technical and usage information, including pages viewed, interactions with page elements, referring URL, campaign parameters, approximate geographic region, browser and device type, and an Internet Protocol (IP) address. Where analytics is enabled in accordance with Section 6, visitors are assigned a pseudonymous identifier that does not directly identify them.
2.2 Data you provide. When you submit a form, request or book a meeting, subscribe to a service, purchase a workshop, apply for a role or otherwise contact us, we collect the information you provide, which may include your name, business email address, telephone number, company, job title, company size, budget range, project details, professional profile links, location and the content of your messages. Upon such submission, usage data previously associated with your pseudonymous identifier may be linked to you.
2.3 Payment data. Payments are processed by Stripe. Card details are entered directly into fields served by Stripe and are not received or stored by Unflow. We receive transaction records, billing contact details and the status of payments.
2.4 Site assistant. Where the assistant on unflow.io is available and you use it, we process the questions you submit and the responses generated, together with any booking details you provide through it.
2.5 Client project data. Personal data contained in systems or materials made available to us by a client in the course of an engagement is processed in accordance with Section 8.
2.6 We do not knowingly collect special categories of personal data within the meaning of Article 9 GDPR, and we ask that you do not submit such data through our website.
Purposes and legal bases
3.1 We process personal data only where we have a lawful basis under Article 6(1) GDPR, as follows:
(a) to respond to inquiries, schedule meetings and prepare proposals, on the basis of steps taken at your request prior to entering into a contract (Article 6(1)(b)) or, for business contacts, our legitimate interest in responding to commercial inquiries (Article 6(1)(f));
(b) to perform contracts with clients, including invoicing, payment processing, project delivery and related communications, on the basis of contractual necessity (Article 6(1)(b));
(c) to measure and improve the performance of our website by means of analytics cookies and similar technologies, on the basis of your consent (Article 6(1)(a));
(d) to send marketing communications, on the basis of your consent (Article 6(1)(a)) or, where permitted by applicable law in respect of existing business contacts, our legitimate interest (Article 6(1)(f)), subject in every case to your right to opt out;
(e) to assess applications for employment or engagement, on the basis of steps taken at your request prior to entering into a contract (Article 6(1)(b)) and our legitimate interest in recruitment (Article 6(1)(f));
(f) to secure our website and services, prevent spam, fraud and abuse, and enforce rate limits, on the basis of our legitimate interest in the security and integrity of our systems (Article 6(1)(f)); and
(g) to comply with accounting, tax and other legal obligations, and to establish, exercise or defend legal claims, on the basis of legal obligation (Article 6(1)(c)) and our legitimate interest (Article 6(1)(f)).
3.2 Where processing is based on legitimate interest, we have assessed that such interest is not overridden by your interests or fundamental rights and freedoms. You may request further information on that assessment by contacting the data protection lead.
3.3 The provision of personal data is not a statutory requirement. The provision of contact details is necessary for us to respond to an inquiry, and the provision of billing details is a contractual requirement for the purchase of services. Failure to provide such data will prevent us from responding or contracting, as applicable.
3.4 We do not carry out decision-making based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.
Recipients and processors
4.1 We disclose personal data to service providers acting as processors on our behalf, each bound by a data processing agreement in accordance with Article 28 GDPR. As at the date of this Policy, these comprise: Vercel (website hosting and server infrastructure); Google (Google Tag Manager and Google Analytics, subject to consent, and Google Workspace for email, calendar and video meetings); Attio (customer relationship management); Stripe (payment processing); Resend (transactional email delivery); Cal.com (meeting scheduling); Upstash (rate limiting and scheduling of transactional email); Cloudflare (Turnstile, for bot and spam prevention); Anthropic (language model processing for the site assistant, where available); and Slack (client communication channels).
4.2 Personal data may be shared between Unflow Lda. and Unflow LLC to the extent necessary for the purposes set out in Section 3.
4.3 We may disclose personal data to professional advisers, auditors and insurers, to public authorities where required by law, and to a successor entity in the event of a merger, acquisition or transfer of all or part of our business, subject to equivalent protections.
4.4 We do not sell personal data, and we do not disclose personal data to third parties for their own direct marketing purposes.
International transfers
5.1 Certain recipients identified in Section 4, including Unflow LLC, are located in or process data in the United States or other countries outside the European Economic Area and the United Kingdom.
5.2 Any such transfer is made subject to appropriate safeguards under Chapter V GDPR, namely an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework and its UK Extension where the recipient is certified thereunder, or the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures. A copy of the relevant safeguards may be obtained by contacting the data protection lead.
Cookies and similar technologies
6.1 Strictly necessary technologies, including those required for security, spam prevention and the recording of your consent choice, are used without consent, as permitted by Article 5(3) of Directive 2002/58/EC and the corresponding national implementing laws. Your consent choice is stored in your browser’s local storage.
6.2 Analytics and advertising-measurement technologies are used only after you have given consent through the consent notice presented on your first visit. Until consent is given, such technologies operate in a denied state and do not store identifiers on your device.
6.3 You may withdraw or modify your consent at any time through the cookie settings link in the website footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Retention
7.1 We retain personal data only for as long as necessary for the purposes for which it was collected, specifically:
(a) inquiry and customer relationship data, for the duration of the business relationship or, in respect of prospective clients, for up to 24 months after our last interaction, after which it is deleted or anonymized;
(b) contractual, accounting and invoicing records, for the period required by applicable tax and commercial law, which in Portugal is ten years;
(c) analytics data, for 12 months from collection;
(d) job applications, for up to 12 months after the conclusion of the relevant recruitment process, unless you consent to a longer period; and
(e) data required for the establishment, exercise or defense of legal claims, until the expiry of the applicable limitation period.
Client data processed as processor
8.1 Where Unflow processes personal data on behalf of a client in the course of an engagement, the client is the controller and Unflow acts as processor. Such processing is governed by the data processing agreement entered into with the client and not by this Policy.
8.2 Unless otherwise instructed by the client in writing, Unflow does not copy production personal data to its own systems and uses anonymized or synthetic data for development and testing. Access to client systems is granted on a per-person, least-privilege basis and is revoked upon the conclusion of the engagement or the departure of the relevant team member.
Security
9.1 We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption in transit, access controls and the use of processors that provide sufficient guarantees. Further detail is available on our security page.
9.2 In the event of a personal data breach, we will notify the competent supervisory authority and affected data subjects where and as required by Articles 33 and 34 GDPR and applicable law.
Your rights
10.1 Subject to the conditions and exceptions provided by applicable law, you have the right to: (a) access your personal data; (b) rectification of inaccurate data; (c) erasure; (d) restriction of processing; (e) data portability; (f) object to processing based on legitimate interest, and to object at any time to processing for direct marketing purposes; and (g) withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
10.2 Residents of certain United States states may have additional rights under applicable state law, including the right to know, delete and correct personal information, and the right to opt out of the sale or sharing of personal information and of targeted advertising. We do not discriminate against any person for exercising these rights. Requests may be submitted by you or by an authorized agent.
10.3 To exercise any of these rights, write to privacy@unflow.io. We may request information necessary to verify your identity. We will respond within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you of the extension and the reasons for it within the first month.
10.4 You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The lead supervisory authority for Unflow Lda. is the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal, www.cnpd.pt.
Children
11.1 Our website and services are directed at businesses and are not intended for persons under 16 years of age. We do not knowingly collect personal data from such persons. If we become aware that we have collected such data, we will delete it without undue delay.
Changes to this Policy
12.1 We may amend this Policy from time to time. Each version states its effective date and version number. Where an amendment materially affects the manner in which we process personal data, we will notify clients by email before the amendment takes effect and, where required by law, seek consent.
12.2 Previous versions of this Policy are available on request from the data protection lead.