ZenFlowPro

Privacy Policy

Last Updated: 25 February 2026 Effective: 1 April 2026 Version: 2.0

1. Introduction

ZenFlowPro Ltd ("ZenFlowPro", "we", "us", or "our") is a provider of AI-powered chatbot solutions delivered as a software-as-a-service (SaaS) platform. Our services include intelligent virtual assistants, Microsoft 365 integrations, conversation analytics, and workflow automation tools for businesses.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and — where applicable — the EU General Data Protection Regulation (EU GDPR).

Please read this policy carefully. By using our services, you acknowledge that you have read and understood it. If you have questions, please contact us at privacy@zfp.cz.

2. Data Controller

The data controller responsible for your personal data is:

Where we process personal data on behalf of our business clients (e.g., conversation logs generated by end users of a client's chatbot), the client acts as the data controller and ZenFlowPro acts as a data processor. In such cases, processing is governed by our Data Processing Agreement (DPA).

3. What Data We Collect

Category Data Elements Source
Account Data Company name, contact name, email address, billing address, VAT number, ICO number (Czech clients) You (at sign-up)
Service Data Conversation logs, chat messages, uploaded documents and files processed within the chatbot You and your end users
Usage Data Number of credits used, API call counts, feature usage metrics, timestamps of interactions Automated collection
Technical Data IP addresses, browser type and version, device type, operating system, screen resolution (widget context) Automated collection
Payment Data Transaction references, invoice records. Card numbers and payment credentials are processed directly by Stripe — we never store or have access to full card numbers. Stripe
Microsoft 365 Data Calendar events, email metadata and content, OneDrive/SharePoint files — only when you explicitly grant OAuth consent for each scope Microsoft Graph API (with your consent)
Note on M365 Data: Microsoft 365 integration is entirely optional. We only request the specific permissions (scopes) needed for the features you enable, and you can revoke access at any time via your Microsoft account settings.

4. Why We Collect Data (Legal Bases)

Under UK GDPR and EU GDPR, we must have a lawful basis for each processing activity. The table below sets out our purposes and the corresponding legal bases:

Purpose Data Categories Legal Basis
Providing and managing your account Account Data, Service Data Contract performance (Art. 6(1)(b))
Delivering AI chatbot responses Service Data (chat interactions) Contract performance (Art. 6(1)(b))
Billing and invoicing Account Data, Payment Data Contract performance (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c))
Service improvement and analytics Usage Data, Technical Data Legitimate interest (Art. 6(1)(f)) — improving our platform
Technical support and troubleshooting Technical Data, Service Data Legitimate interest (Art. 6(1)(f)) — ensuring service reliability
Microsoft 365 integration Microsoft 365 Data Consent (Art. 6(1)(a)) — explicit OAuth consent
Marketing communications Account Data (email) Consent (Art. 6(1)(a)) — opt-in only
Security monitoring and fraud prevention Technical Data Legitimate interest (Art. 6(1)(f)) — protecting the service

Where we rely on legitimate interest, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments at any time.

5. AI Processing Disclosure

Our service uses third-party artificial intelligence providers to deliver core functionality. When you interact with our chatbot, you are communicating with an AI-powered system, not a human. It is important that you understand how your data is processed by these systems.

5.1 Anthropic (Claude API) — AI Responses

Conversation messages you send through the chatbot are transmitted to Anthropic's Claude API to generate intelligent responses. Anthropic processes data as a sub-processor under our Data Processing Agreement. Your conversations are not used to train AI models. We do not send your name, email address, or other personally identifiable information to Anthropic unless you voluntarily include such information in your chat messages.

5.2 OpenAI (Whisper) — Audio Transcription

If you use voice input or upload audio files, these are sent to OpenAI's Whisper API for speech-to-text transcription. Audio data is processed in real time and is not retained by OpenAI beyond the duration of the API request. Audio data is not used to train OpenAI's models. OpenAI acts as a sub-processor under our DPA.

5.3 ElevenLabs — Text-to-Speech

Where text-to-speech functionality is enabled, text is sent to ElevenLabs for voice synthesis. ElevenLabs processes this data as a sub-processor under our DPA.

5.4 AI Transparency (EU AI Act)

In compliance with Article 50 of the EU AI Act (Regulation 2024/1689), we ensure that all individuals interacting with our AI chatbot are clearly informed that they are communicating with an artificial intelligence system. Our chatbot widget displays an "AI-powered" indicator. AI-generated content is intended to be identifiable as such and will be labelled in a machine-readable format in accordance with applicable transparency obligations as they come into effect.

Transparency commitment: All AI sub-processors are bound by Data Processing Agreements that include obligations regarding data security, confidentiality, limitation of use, and deletion upon termination. None of these providers use your data for model training. We use zero-retention API configurations where available.

6. Who We Share Data With

We share personal data only with the following categories of sub-processors, each operating under a Data Processing Agreement:

Sub-Processor Location Purpose Transfer Safeguard
Anthropic (Claude AI) San Francisco, USA AI-powered chatbot responses Standard Contractual Clauses (SCCs)
OpenAI (Whisper) San Francisco, USA Audio transcription Standard Contractual Clauses (SCCs)
Microsoft Azure Canada Central / EU Cloud hosting and infrastructure Microsoft DPA, UK Adequacy
Stripe USA / EU Payment processing Standard Contractual Clauses (SCCs)
Fakturoid Czech Republic (EU) Invoicing (Czech clients only) Intra-EU — no additional safeguard needed
ElevenLabs USA Text-to-speech (if enabled) Standard Contractual Clauses (SCCs)

We do not sell, rent, or trade your personal data to any third party. We may also disclose data where required by law, regulation, court order, or governmental authority.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods are:

Data Category Retention Period Reason
Account Data Duration of contract + 6 months Account management and post-termination queries
Conversation Logs Maximum 90 days (configurable per client) Service delivery and quality assurance
Billing & Invoice Data 10 years Legal and tax requirements (UK Companies Act, HMRC)
Usage Analytics 24 months (aggregated) Service improvement and trend analysis
Technical Logs 30 days Security monitoring and debugging

Business clients may configure shorter conversation log retention periods through their admin dashboard. When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised.

8. Cookies and Local Storage

Our approach to cookies and browser storage is intentionally minimal. We use only strictly necessary mechanisms as detailed below.

8.1 Cookies

Cookie Name Purpose Duration Type
admin_token Maintains authenticated session for the administrative dashboard. Set only upon successful administrator login. 7 days Strictly necessary (httpOnly, secure, sameSite=lax)

8.2 Browser Local Storage (Widget)

The ZenFlowPro chatbot widget, when embedded on the Customer's website, may use the following browser storage mechanisms on the end user's device:

Storage Key Type Purpose Duration
recordings_{clientId} localStorage Offline backup of audio transcription records (max 50 entries). Contains transcription text, duration, and timestamps — no personally identifiable information unless voluntarily included in the transcription content. Persistent (until manually cleared)
m365SessionId sessionStorage Temporary Microsoft 365 session identifier for authenticated users. Session only (cleared on tab close)
m365UserEmail sessionStorage Display of logged-in user's email in the widget interface. Session only (cleared on tab close or logout)
tenantId sessionStorage Microsoft 365 tenant identifier for API routing. Session only (cleared on tab close or logout)

8.3 What We Do Not Use

8.4 Legal Basis

All cookies and browser storage mechanisms listed above are strictly necessary for the operation of the service and fall within the exemptions provided by the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data Use and Access Act 2025. Accordingly, we do not require a cookie consent banner for these mechanisms.

You can configure your browser to block or delete cookies and local storage data, but this may affect your ability to use our service.

9. Your Rights Under GDPR

Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

Right Description
Right of Access You can request a copy of the personal data we hold about you (Subject Access Request). We will respond within one calendar month.
Right to Rectification You can ask us to correct inaccurate or incomplete personal data.
Right to Erasure You can request deletion of your personal data where there is no compelling reason for its continued processing ("right to be forgotten").
Right to Restrict Processing You can request that we limit how we use your data in certain circumstances (e.g., while we verify its accuracy).
Right to Data Portability You can request your data in a structured, commonly used, machine-readable format (e.g., JSON or CSV).
Right to Object You can object to processing based on legitimate interest or direct marketing at any time.
Right to Withdraw Consent Where processing is based on consent (e.g., M365 integration, marketing), you can withdraw consent at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint You have the right to complain to a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. EU residents may contact their local Data Protection Authority.

To exercise any of these rights, please email privacy@zfp.cz. We will respond to all legitimate requests within one calendar month. In exceptional cases (complex or numerous requests), we may extend this by up to two additional months, and we will notify you if this applies.

We may need to verify your identity before processing your request. We will not charge a fee unless the request is manifestly unfounded or excessive.

10. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@zfp.cz.

11. International Transfers

Some of our sub-processors are located outside the United Kingdom. The specific transfer mechanisms we rely on for each transfer route are set out below.

11.1 UK to Canada (Microsoft Azure)

Our primary hosting infrastructure is located in Microsoft Azure's Canada Central data centre. Canada benefits from a UK adequacy decision under the Personal Information Protection and Electronic Documents Act (PIPEDA) for private-sector commercial activities. Accordingly, transfers of personal data from the UK to Canada are permitted without additional safeguards, and this is our primary transfer mechanism for hosted data.

11.2 UK to United States (AI Providers, Stripe)

Personal data is transferred to the United States for processing by Anthropic (Claude API), OpenAI (Whisper API), Stripe (payment processing), and ElevenLabs (text-to-speech). For these transfers, we rely on the following mechanisms, in order of preference:

11.3 EU to UK

For our clients based in the European Union (including the Czech Republic), transfers of personal data from the EU to the UK are covered by the renewed EU adequacy decision adopted by the European Commission on 19 December 2025, which remains valid until 27 December 2031. No additional safeguards such as Standard Contractual Clauses are required for EU-to-UK transfers.

11.4 Transfer Risk Assessments

We conduct and maintain Transfer Risk Assessments (TRAs) for each sub-processor located in a country without an adequacy decision. These assessments evaluate the legal framework of the recipient country, the risk of government access to data, and the effectiveness of the supplementary measures we have in place.

11.5 Supplementary Measures

In addition to the contractual and legal safeguards described above, we implement the following supplementary technical measures for all international transfers:

You may request a copy of the relevant transfer safeguards, including our Transfer Risk Assessments, by contacting us at privacy@zfp.cz.

12. Automated Decision-Making

Under Article 22 of the UK GDPR (as amended by the Data Use and Access Act 2025) and Article 22 of the EU GDPR, individuals have rights relating to solely automated decision-making that produces legal effects or similarly significant effects.

ZenFlowPro's AI chatbot does not make solely automated decisions with legal or similarly significant effects on individuals. The chatbot provides informational responses, answers questions based on the Customer's knowledge base, and assists with routine tasks. It does not make decisions about individuals' legal rights, eligibility for services, credit, employment, or similar matters.

If a Customer configures the chatbot to assist with processes that may involve automated decision-making with significant effects (such as eligibility assessments, complaint triage with binding outcomes, or automated approvals), the Customer, as the Data Controller, is solely responsible for:

ZenFlowPro will assist Customers in meeting these obligations through its technical capabilities (e.g., conversation logging, human escalation features) but does not assume the responsibilities of the Data Controller in such scenarios.

13. Aggregated and De-Identified Data

ZenFlowPro may create De-Identified Data by anonymising and aggregating information derived from the use of our services. "De-Identified Data" means data that has been modified so that it does not identify, and cannot reasonably be used to identify, any individual or any specific Customer.

13.1 How We Create De-Identified Data

We apply appropriate technical measures to ensure that De-Identified Data cannot reasonably be used to identify any individual, including:

13.2 How We Use De-Identified Data

We may use De-Identified Data for the following purposes:

13.3 Legal Basis

Under Recital 26 of the UK GDPR and EU GDPR, the principles of data protection do not apply to anonymous information — that is, information which does not relate to an identified or identifiable natural person, or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. De-Identified Data, as described in this section, constitutes anonymous information and is therefore outside the scope of data protection legislation.

13.4 Your Rights

Customers may opt out of having their data included in aggregated datasets by providing written notice to privacy@zfp.cz. Upon receipt of such notice, we will exclude the Customer's data from future aggregation within a reasonable timeframe (not exceeding 30 days).

14. Widget Data Collection

The ZenFlowPro chatbot widget is embedded on our Customers' websites and collects data from the Customer's website visitors (end users). This section explains the data collection that occurs through the widget.

14.1 What the Widget Collects

When an end user interacts with the chatbot widget, the following data may be collected:

14.2 Pre-Chat Notice

ZenFlowPro provides a configurable pre-chat notice within the widget that informs end users that they are interacting with an AI-powered system and that their messages will be processed. This notice can be customised by the Customer to include a link to the Customer's own privacy policy.

14.3 Customer Responsibilities

The Customer (as Data Controller) is responsible for:

ZenFlowPro provides template privacy notice text and configurable consent mechanisms within the widget to assist Customers in meeting these obligations.

15. Children

Our services are designed for business use and are not intended for individuals under the age of 16. We do not knowingly collect or process personal data from children under 16.

If we become aware that we have inadvertently collected personal data from a child under 16, we will take prompt steps to delete that data. If you believe a child has provided us with personal data, please contact us at privacy@zfp.cz.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

When we make material changes, we will:

We encourage you to review this page periodically. The "Last Updated" date at the top of this page indicates when the policy was most recently revised.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We aim to respond to all privacy-related enquiries within 5 business days.

UK Supervisory Authority: If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113