Privacy Policy
SmartAutomateFlow ("we," "us," or "our") respects your privacy. This policy explains how we collect, use, and protect your personal data.
Last updated: August 13, 2026
1. What We Collect
We believe in data minimization — we only collect what we genuinely need to serve you better.
Contact Information
When you fill out our contact form or get started form
- Name (first and last)
- Email address
- Company name (optional)
- Message or project details
Usage Data (Anonymous)
Collected automatically when you visit our website
- Pages visited and navigation paths
- Browser type and version
- Device type (desktop/mobile/tablet)
- Referring website
- Time spent on pages
- Approximate geographic location (country level)
Cookie Preferences
Your choices regarding cookie categories
- Essential cookies (always on)
- Analytics consent status
- Marketing consent status
- Preference timestamp
Client Data (Post-Engagement)
Only after signing a service agreement
- Business contact details
- Project requirements documentation
- Technical access credentials (you provide)
- Communication records
We never collect sensitive personal data (health, political opinions, religious beliefs, sexual orientation, genetic data) through our website.
2. Lawful Basis for Processing (GDPR)
Every data processing activity has a legal basis under GDPR Article 6:
Legitimate Interest (Art. 6(1)(f))
Processing necessary for our legitimate interests
- Responding to your inquiries via contact forms
- Improving our website functionality and UX
- Security monitoring and fraud prevention
- Marketing communications (you can opt out anytime)
Consent (Art. 6(1)(a))
Processing based on your explicit consent
- Analytics cookies beyond essential ones
- Marketing cookies and retargeting
- Newsletter subscriptions (if implemented)
Contract Performance (Art. 6(1)(b))
Processing necessary to fulfill our contract
- Delivering agreed-upon services
- Billing and invoicing
- Project communication and reporting
- Support and maintenance activities
Legal Obligation (Art. 6(1)(c))
Processing required by law
- Retaining financial records per EU tax law
- Responding to lawful government requests
- Enforcing our legal rights
3. How We Use Your Data
Transparency about data usage is core to our privacy commitment:
Service Delivery
- Responding to your inquiries within 24 hours
- Preparing proposals and quotes
- Delivering automation projects
- Providing ongoing support
Website Improvement
- Analyzing user behavior patterns
- Identifying and fixing UX issues
- A/B testing features (with consent)
- Performance optimization
Communication
- Sending project updates
- Sharing relevant resources (with consent)
- Requesting feedback
- Service announcements
Security & Compliance
- Detecting and preventing fraud
- Maintaining audit logs
- Complying with legal obligations
- Protecting your data from breaches
4. Data Retention Periods
We don't keep your data longer than necessary:
Contact Form Submissions
- Contact Form Submissions: 12 months from last contact
Analytics Data (Aggregated)
- Analytics Data (Aggregated): 26 months (anonymized after 14 months)
Cookie Preferences
- Cookie Preferences: Until changed or browser cookies cleared
Client Project Data
- Client Project Data: Duration of contract + 7 years (legal requirement)
Email Communications
- Email Communications: 3 years from last interaction
5. Your GDPR Rights
You have powerful rights over your personal data. Exercise them anytime by emailing us at Enquiry@smartautomateflow.com
Right of Access (Art. 15)
Request a complete copy of all personal data we hold about you, including processing purposes and recipients.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete data. Keep your information up-to-date for better service.
Right to Erasure / 'Right to be Forgotten' (Art. 17)
Request deletion of your data when it's no longer necessary, you withdraw consent, or you object to processing.
Right to Restrict Processing (Art. 18)
Limit how we use your data while maintaining it — useful during disputes or verification.
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV) to transfer to another service.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling and direct marketing.
Rights Related to Automated Decision-Making (Art. 22)
Not subject to automated decisions — human review is always available.
Response Time: We respond to all requests within 30 days. Complex requests may take up to 90 days (we'll notify you).
7. Security Measures
We implement industry-standard security practices to protect your data:
Encryption in Transit
TLS 1.3 for all data transmission (HTTPS only)
Encryption at Rest
AES-256 encryption for databases and backups
Access Controls
Role-based access, principle of least privilege, MFA enforced
Regular Audits
Quarterly security reviews, penetration testing annually
Incident Response
72-hour breach notification as required under GDPR Art. 33
Vendor Assessment
All third-party processors vetted for GDPR compliance
8. Third-Party Processors
We share data only with carefully vetted service providers:
Cloud Infrastructure (AWS/Vercel)
EU/EEA (Ireland, Frankfurt)Website hosting, database, CDN
Email Service (Resend)
EU/EEASending transactional emails
Analytics (Google Analytics)
US with SCCs in placeWebsite usage analytics (with consent)
CRM/Project Tools
EU/EEA preferredClient project management (post-engagement)
All processors are bound by Data Processing Agreements (DPAs) with equivalent protection standards.
9. International Data Transfers
Your data is primarily stored and processed within the European Union. If international transfers occur: • **US Transfers**: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission • **Adequacy Countries**: Freely transfer to countries with EU adequacy decisions • **Supplementary Measures**: Encryption, access controls, and contractual safeguards applied We monitor regulatory developments and update mechanisms as needed.
Your data is primarily stored and processed within the European Union. If international transfers occur: • **US Transfers**: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission • **Adequacy Countries**: Freely transfer to countries with EU adequacy decisions • **Supplementary Measures**: Encryption, access controls, and contractual safeguards applied We monitor regulatory developments and update mechanisms as needed.
10. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us immediately.
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this privacy policy periodically to reflect changes in our practices, technology, or legal requirements. All updates will be posted on this page with a revised date.
Material changes will be communicated via email or prominent website notice before taking effect.
Contact Our Data Protection Team
For any privacy-related inquiries, data subject requests, or to exercise your rights:
Data Protection
Enquiry@smartautomateflow.comLegal Inquiries
Enquiry@smartautomateflow.comDPO (Data Protection Officer)
Available upon request for clients requiring formal DPA agreements