1. Who controls the data
CompanyFlowHQ is the service operator and data controller for account, billing and website information. Each customer organisation is normally the controller for employee, applicant, lead and contact information entered into its private workspace. CompanyFlow acts as its service provider and processor for that workspace data.
2. Information we collect
We may process account names, business email addresses, authentication records, employee and HR records, job applicants, lead contact details, consent records, campaign information, message delivery events, audit activity, IP-derived security records and support communications. Passwords are stored only as salted cryptographic hashes. Provider tokens are encrypted.
3. Why we use it
- Provide the CRM, marketing automation and HR service requested by a customer.
- Authenticate users, prevent abuse and protect workspaces.
- Send messages only under the customer’s instructions and recorded consent settings.
- Maintain delivery records, diagnose failures and improve reliability.
- Meet legal, tax, fraud-prevention and security obligations.
4. Legal bases
Depending on the context, processing is based on performance of a contract, legitimate interests in operating and protecting the service, compliance with law, or consent. Customers are responsible for having a lawful basis for the people they upload or contact and for honouring marketing opt-outs.
5. Service providers
CompanyFlow may use Cloudflare for hosting and security, Resend for email delivery, Meta for Facebook and WhatsApp connections, Google for advertising connections, and Twilio for SMS when enabled. Only the minimum information needed for the chosen function is shared. Those providers may process data internationally under their own contractual safeguards.
6. Cookies
The application uses a strictly necessary secure session cookie after sign-in. CompanyFlow does not currently place advertising or behavioural-tracking cookies. If non-essential analytics are added later, consent controls will be introduced before they are enabled.
7. Retention and security
Data is kept while a workspace is active and as reasonably required for security, legal or dispute purposes. We use encrypted transport, secure cookies, access controls, rate limits, audit records and encrypted provider credentials. No internet service can promise absolute security.
8. Your rights
Depending on applicable law, you may request access, correction, portability, restriction, objection or deletion. Workspace owners can export a structured copy from the Production Centre and submit a verified deletion request. Employees, leads and applicants should normally contact the organisation that collected their information first.
9. Contact
Email privacy@companyflowhq.com or write to CompanyFlowHQ, 117 St Paul’s Avenue, Harrow, HA3 9PT, United Kingdom. You may also complain to the UK Information Commissioner’s Office.