Skip to content
GDPR Compliant

Privacy Policy

SmartAutomateFlow ("we," "us," or "our") respects your privacy. This policy explains how we collect, use, and protect your personal data.

Last updated: August 13, 2026

1. What We Collect

We believe in data minimization — we only collect what we genuinely need to serve you better.

Contact Information

When you fill out our contact form or get started form

  • Name (first and last)
  • Email address
  • Company name (optional)
  • Message or project details

Usage Data (Anonymous)

Collected automatically when you visit our website

  • Pages visited and navigation paths
  • Browser type and version
  • Device type (desktop/mobile/tablet)
  • Referring website
  • Time spent on pages
  • Approximate geographic location (country level)

Cookie Preferences

Your choices regarding cookie categories

  • Essential cookies (always on)
  • Analytics consent status
  • Marketing consent status
  • Preference timestamp

Client Data (Post-Engagement)

Only after signing a service agreement

  • Business contact details
  • Project requirements documentation
  • Technical access credentials (you provide)
  • Communication records

We never collect sensitive personal data (health, political opinions, religious beliefs, sexual orientation, genetic data) through our website.

2. Lawful Basis for Processing (GDPR)

Every data processing activity has a legal basis under GDPR Article 6:

Legitimate Interest (Art. 6(1)(f))

Processing necessary for our legitimate interests

  • Responding to your inquiries via contact forms
  • Improving our website functionality and UX
  • Security monitoring and fraud prevention
  • Marketing communications (you can opt out anytime)

Consent (Art. 6(1)(a))

Processing based on your explicit consent

  • Analytics cookies beyond essential ones
  • Marketing cookies and retargeting
  • Newsletter subscriptions (if implemented)

Contract Performance (Art. 6(1)(b))

Processing necessary to fulfill our contract

  • Delivering agreed-upon services
  • Billing and invoicing
  • Project communication and reporting
  • Support and maintenance activities

Legal Obligation (Art. 6(1)(c))

Processing required by law

  • Retaining financial records per EU tax law
  • Responding to lawful government requests
  • Enforcing our legal rights

3. How We Use Your Data

Transparency about data usage is core to our privacy commitment:

Service Delivery

  • Responding to your inquiries within 24 hours
  • Preparing proposals and quotes
  • Delivering automation projects
  • Providing ongoing support

Website Improvement

  • Analyzing user behavior patterns
  • Identifying and fixing UX issues
  • A/B testing features (with consent)
  • Performance optimization

Communication

  • Sending project updates
  • Sharing relevant resources (with consent)
  • Requesting feedback
  • Service announcements

Security & Compliance

  • Detecting and preventing fraud
  • Maintaining audit logs
  • Complying with legal obligations
  • Protecting your data from breaches

4. Data Retention Periods

We don't keep your data longer than necessary:

Contact Form Submissions

  • Contact Form Submissions: 12 months from last contact

Analytics Data (Aggregated)

  • Analytics Data (Aggregated): 26 months (anonymized after 14 months)

Cookie Preferences

  • Cookie Preferences: Until changed or browser cookies cleared

Client Project Data

  • Client Project Data: Duration of contract + 7 years (legal requirement)

Email Communications

  • Email Communications: 3 years from last interaction

5. Your GDPR Rights

You have powerful rights over your personal data. Exercise them anytime by emailing us at Enquiry@smartautomateflow.com

Right of Access (Art. 15)

Request a complete copy of all personal data we hold about you, including processing purposes and recipients.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data. Keep your information up-to-date for better service.

Right to Erasure / 'Right to be Forgotten' (Art. 17)

Request deletion of your data when it's no longer necessary, you withdraw consent, or you object to processing.

Right to Restrict Processing (Art. 18)

Limit how we use your data while maintaining it — useful during disputes or verification.

Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV) to transfer to another service.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including profiling and direct marketing.

Rights Related to Automated Decision-Making (Art. 22)

Not subject to automated decisions — human review is always available.

Response Time: We respond to all requests within 30 days. Complex requests may take up to 90 days (we'll notify you).

6. Cookies & Tracking Technologies

Cookies are small text files stored on your device. Here's what we use:

Essential Cookies

Required
  • Session management (keeps you logged in)
  • Security tokens (CSRF protection)
  • Preference storage (cookie consent choice)

Duration: Session to 1 year

Analytics Cookies

Optional
  • Google Analytics 4 (aggregated traffic data)
  • Page performance metrics
  • User flow analysis

Duration: 14 - 26 months

Marketing Cookies

Optional
  • LinkedIn Insight Tag (ad effectiveness)
  • Potential future advertising pixels

Duration: 3 - 12 months

7. Security Measures

We implement industry-standard security practices to protect your data:

Encryption in Transit

TLS 1.3 for all data transmission (HTTPS only)

Encryption at Rest

AES-256 encryption for databases and backups

Access Controls

Role-based access, principle of least privilege, MFA enforced

Regular Audits

Quarterly security reviews, penetration testing annually

Incident Response

72-hour breach notification as required under GDPR Art. 33

Vendor Assessment

All third-party processors vetted for GDPR compliance

8. Third-Party Processors

We share data only with carefully vetted service providers:

Cloud Infrastructure (AWS/Vercel)

EU/EEA (Ireland, Frankfurt)

Website hosting, database, CDN

Email Service (Resend)

EU/EEA

Sending transactional emails

Analytics (Google Analytics)

US with SCCs in place

Website usage analytics (with consent)

CRM/Project Tools

EU/EEA preferred

Client project management (post-engagement)

All processors are bound by Data Processing Agreements (DPAs) with equivalent protection standards.

9. International Data Transfers

Your data is primarily stored and processed within the European Union. If international transfers occur: • **US Transfers**: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission • **Adequacy Countries**: Freely transfer to countries with EU adequacy decisions • **Supplementary Measures**: Encryption, access controls, and contractual safeguards applied We monitor regulatory developments and update mechanisms as needed.

Your data is primarily stored and processed within the European Union. If international transfers occur: • **US Transfers**: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission • **Adequacy Countries**: Freely transfer to countries with EU adequacy decisions • **Supplementary Measures**: Encryption, access controls, and contractual safeguards applied We monitor regulatory developments and update mechanisms as needed.

10. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us immediately.

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this privacy policy periodically to reflect changes in our practices, technology, or legal requirements. All updates will be posted on this page with a revised date.

Material changes will be communicated via email or prominent website notice before taking effect.

Contact Our Data Protection Team

For any privacy-related inquiries, data subject requests, or to exercise your rights:

DPO (Data Protection Officer)

Available upon request for clients requiring formal DPA agreements