Legal

SmartFlow AI Full Privacy Policy

Privacy information for website visitors, business contacts, clients, suppliers, applicants and service interactions

Last updated: 3 August 2026

This Privacy Policy explains how SmartFlow uses personal information when it acts as a controller. Where SmartFlow processes information only for a business client, that client normally decides why and how the information is used and its privacy notice should provide the primary explanation.

1. Who we are

SmartFlow AI LTD (company number 17134477), trading as SmartFlow AI, is incorporated in England and Wales with registered office at 11 Totman Close, Rayleigh, Essex, SS6 7UZ.

For the controller activities described in this Policy, SmartFlow is responsible for deciding why and how your personal information is used. You can contact us at contact@smart-flow.uk or by post at 11 Totman Close, Rayleigh, Essex, SS6 7UZ.

“Personal information” means information relating to an identified or identifiable person. It does not include information that has been irreversibly anonymised.

2. Scope and our different data-protection roles

This Policy applies to our website, enquiries, sales, client and supplier relationships, events, marketing, recruitment, security and business administration, and to AI or voice interactions where SmartFlow determines the purpose and essential means of processing.

We often provide technology to business clients. If we handle personal information only under a client’s instructions, the client is normally the controller and SmartFlow is its processor. The client’s privacy notice should explain that use, including the lawful basis and how to exercise rights. We will pass an appropriate request to the client where necessary.

In some activities SmartFlow and another organisation may each be independent controllers or may act as joint controllers. We will identify the actual roles and provide any additional information required for that activity.

This Policy does not cover a third party’s independent processing, even if its service connects to ours. You should read that organisation’s privacy notice.

3. Information we may collect

  • Identity and contact information: name, title, employer, role, business address, email, telephone number, account identifiers and communication preferences.
  • Commercial and relationship information: enquiries, proposals, orders, contracts, meeting notes, service requirements, approvals, support history, feedback, billing status and relationship records.
  • Website and device information: IP address, approximate location derived from IP, device and browser type, operating system, referral source, pages and functions used, timestamps, cookie identifiers, consent choices and security logs.
  • Communication information: emails, messages, form submissions, meeting records and, where enabled and appropriately notified, call audio, transcripts, summaries, classifications and interaction metadata.
  • Service and account information: authorised-user details, roles, permissions, authentication events, configuration choices, audit logs and information needed to operate or secure an account.
  • Financial and transaction information: billing contact, invoices, payment status, tax information and limited payment-related references. We should not receive full payment-card security credentials unless an approved payment provider expressly requires and protects them.
  • Marketing information: interests, campaign source, engagement, event attendance, consent records, opt-outs and suppression-list entries.
  • Recruitment information: application, CV, work history, qualifications, interview notes, right-to-work evidence and information needed for recruitment checks. A separate recruitment notice may provide additional detail.
  • Supplier and professional information: contact, role, due-diligence, contract, insurance, capability, performance and payment details.
  • Information you choose to provide: this may include personal information about another person. You must have authority to provide it and should direct them to this Policy where appropriate.

4. How we receive information

We receive information directly from you when you use our website, contact us, attend a meeting or event, contract with us, use a Service, apply for a role or communicate with an AI or voice system.

We may receive information from your employer or colleagues, our clients, authorised referral partners, public business sources, Companies House, professional networking platforms, event organisers, service providers, integrations and systems you authorise.

Where a client supplies information for a client-controlled Service, we process it under the client’s instructions and the client is responsible for the lawfulness and transparency of collection.

5. Why we use information and our lawful bases

PurposeInformation usedLawful basis
Respond to enquiries; scope, propose and contract for ServicesIdentity, contact, commercial and communication informationLegitimate interests in developing and administering our business; steps requested before a contract; contract where you contract personally
Deliver, configure, support and secure ServicesContact, account, service, device, communication and transaction informationContract; legitimate interests in dependable delivery, security and client support; legal obligation where applicable
Operate AI, automation or voice interactions for our own purposesContact, audio, transcript, message, interaction and service informationLegitimate interests where proportionate; contract; consent where required for a specific activity; legal obligation
Bill, collect payment and maintain financial recordsIdentity, contact, financial, transaction and contract informationContract; legal obligation; legitimate interests in credit control and financial administration
Protect systems, investigate misuse and manage incidentsAccount, device, log, communication and security informationLegitimate interests in security, fraud prevention and protection of people and assets; legal obligation
Manage client, supplier and professional relationshipsIdentity, contact, relationship, contract and communication informationLegitimate interests in operating and improving our business; contract
Send business marketing and measure engagementContact, marketing, relationship, device and engagement informationConsent where required by PECR; otherwise legitimate interests, subject to the right to object
Improve services, quality, prompts, workflows and supportFeedback, service, interaction and appropriately minimised usage informationLegitimate interests in improving quality and safety; consent where required. Client personal data is not used to train general-purpose models unless expressly agreed and lawfully documented
Recruit and assess applicantsIdentity, contact, recruitment and communication informationSteps before a contract; legitimate interests in recruitment; legal obligation; explicit consent or employment/social-protection condition where needed for special-category data
Establish, exercise or defend legal rights and comply with lawRelevant information from any categoryLegal obligation; legitimate interests; establishment, exercise or defence of legal claims

Where we rely on legitimate interests, we assess the purpose, necessity and impact on your rights. You may ask for more information about the relevant assessment. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

If we need information to enter into or perform a contract or comply with law and you do not provide it, we may be unable to proceed or may have to suspend the relevant activity.

6. AI, voice calls, recording and transcription

A SmartFlow or client service may use an AI voice agent, chatbot, assistant, workflow or analysis system. Where appropriate, the interaction should disclose that you are communicating with an AI system and explain any recording or transcription.

Depending on the configured purpose, the system may process your contact details, words, voice audio, transcript, language, selections, appointment or enquiry details, conversation metadata and generated summary. It may classify an enquiry, retrieve approved information, route a call, create a task, update an authorised record or book an appointment.

AI and transcription systems can make mistakes. Do not provide passwords, full payment-card security details, or unnecessary medical, legal, financial or other sensitive information. Ask for a person where an issue is urgent, sensitive, unclear or could materially affect you.

Where SmartFlow provides the system for a client, the client normally determines the purpose, lawful basis, scripts, audience, retention and actions. Please use the client’s privacy contact for rights requests. SmartFlow will assist the client as required.

We do not intend to make solely automated decisions producing legal or similarly significant effects about you in our own controller activities unless we first identify a lawful basis, provide the required information, assess the risks and implement appropriate safeguards, including human intervention where required.

7. Special-category and criminal-offence information

Special-category information includes information about health, racial or ethnic origin, political opinions, religion, trade-union membership, genetics, biometrics used for identification, sex life or sexual orientation. Criminal-offence information receives additional protection.

We ask you not to provide this information unless it is necessary and the relevant notice or collection process explains why it is needed. If incidental sensitive information appears in a communication, we will restrict and minimise its use.

Where we intentionally process special-category or criminal-offence information as controller, we will identify both an Article 6 lawful basis and an additional lawful condition, apply suitable safeguards and complete a data protection impact assessment where required.

8. Cookies and similar technologies

Our website may use cookies, pixels, local storage, tags or similar technologies. Strictly necessary technologies support functions such as security, network management, consent choices and requested services. Other technologies may support preferences, analytics or marketing.

We will not set or access non-essential technologies before obtaining valid consent where PECR requires it. You can refuse or withdraw non-essential consent without losing access to the core website, although optional features may be affected.

The cookie information and consent tool made available on our website identifies the technologies, providers, purposes, categories and durations used on the live site. You can update available choices through the “Cookie Settings” link displayed on the website and through your browser settings.

Third-party content may set its own technologies only after the required choice. Blocking cookies may not prevent server-side security logs or information strictly necessary to provide a requested service.

9. Direct marketing

We may send relevant business-to-business updates about SmartFlow services where we have consent or another lawful route under PECR and data-protection law. We will identify ourselves and provide a simple way to opt out in each electronic marketing message.

You can object or unsubscribe at any time by using the message link or contacting contact@smart-flow.uk. We will retain the minimum information needed on a suppression list so that we respect the request.

We do not sell personal information. We will not use purchased or scraped contact lists without documented due diligence on collection, transparency, PECR status and objections.

Client-directed campaigns are controlled by the client. The client is responsible for audience selection, permissions, suppression, Telephone Preference Service or Corporate Telephone Preference Service screening where relevant, scripts and marketing compliance.

10. Sharing personal information

We share personal information only where necessary and with appropriate controls. Recipients may include: personnel and contractors; hosting, AI, telephony, CRM, calendar, email, messaging, analytics, security and support providers; professional advisers, auditors and insurers; payment and finance providers; business clients where an interaction concerns them; regulators, courts, law enforcement or other authorities where lawfully required; and a buyer, investor or successor involved in a genuine corporate transaction.

Service providers acting as processors must use information only for authorised purposes, protect it and support our compliance. Some providers act as independent controllers for their own regulated or operational purposes; their notices apply to that processing.

The precise providers used may depend on the Service and client configuration. You may request information about material providers relevant to SmartFlow’s controller processing by contacting contact@smart-flow.uk.

We do not disclose personal information publicly or to advertisers for their own unrelated marketing unless we clearly explain the arrangement and have a lawful basis.

11. International transfers

Some providers or support teams may process personal information outside the United Kingdom. Before making a restricted transfer, we use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful exception where applicable.

We assess transfer risks and use supplementary contractual, technical or organisational measures where required. We maintain an internal record of relevant countries, providers and transfer safeguards.

You may contact contact@smart-flow.uk for information about the safeguard used for a relevant transfer. We may redact confidential or security-sensitive content from a copy.

12. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose collected, including service delivery, security, dispute, tax, accounting, insurance and legal requirements. We consider sensitivity, volume, risk, contractual needs and whether the purpose can be achieved with less or anonymised information.

Unless a longer or shorter period is required by law, a contract, a documented client instruction or a specific risk, SmartFlow applies the following standard periods:

Record typeStandard retention period
Enquiries not proceeding24 months after last meaningful contact
Client contracts, orders and core relationship recordsSix years after the relationship ends
Invoices, tax and accounting recordsSix years after the end of the relevant financial year, or longer where law requires
Call audio and transcripts controlled by SmartFlowAudio: 90 days; transcripts: 12 months, unless a shorter notice applies or the record is needed for an incident, complaint or claim
Website analytics and consent recordsAs stated in the live cookie information; consent evidence retained for up to three years after the relevant choice
Security and access logs12 months, subject to longer preservation for an incident or investigation
Marketing engagement records24 months after last meaningful engagement; suppression entries retained as necessary to honour objections
Unsuccessful recruitment recordsSix months after the decision, unless the applicant agrees to a longer talent-pool period
Processor-held client dataAs instructed in the client agreement and data-processing terms

13. Security

We use technical and organisational measures proportionate to the risks, which may include access controls, least privilege, multi-factor authentication, encryption in transit, secure credential handling, logging, backups, vulnerability management, workforce confidentiality, supplier review and incident response.

No internet or communications system is completely secure. Please use appropriate care, do not send credentials through unapproved channels and tell us promptly if you suspect unauthorised use.

If a personal-data breach creates a risk to individuals, we will assess notification obligations and work with affected controllers and authorities as required by law.

14. Your data-protection rights

Depending on the circumstances, you may have the right to: be informed; obtain access and a copy; correct inaccurate information; request erasure; restrict processing; receive certain information in a portable format; object to processing based on legitimate interests or direct marketing; withdraw consent; and obtain safeguards relating to qualifying automated decisions.

These rights are not absolute. Exemptions or competing legal duties may apply. We will explain any refusal or limitation.

To exercise a right, contact contact@smart-flow.uk. Please describe the information and relationship involved. We may request proportionate evidence of identity or authority, particularly where disclosure could harm another person.

We normally respond within one month. We may extend by up to two further months for a complex request or multiple requests and will tell you within the first month. We do not usually charge a fee, but may charge a reasonable fee or refuse a manifestly unfounded or excessive request where law permits.

If SmartFlow is only a processor for a client, we will direct the request to or assist the relevant client. This may be necessary because only the client can decide the response.

15. Objections and automated decision-making

You have an absolute right to object to direct marketing. You may also object to processing based on legitimate interests or a public task because of your particular situation. We will stop unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or need the information for legal claims.

Where the law gives you rights concerning a solely automated decision with legal or similarly significant effects, safeguards may include obtaining human intervention, expressing your view and challenging the decision. SmartFlow does not currently make such decisions for its own controller purposes.

16. Children

Our website and business Services are not directed to children, and we do not knowingly seek their information for our own controller purposes. If a Service is intended to interact with children, SmartFlow and the client must conduct a specific legal and risk assessment, provide age-appropriate transparency and implement suitable safeguards before launch.

Contact contact@smart-flow.uk if you believe we have received a child’s information unexpectedly.

18. Changes to this Policy

We may update this Policy to reflect changes in law, guidance, Services, suppliers or processing. We will publish the new version with its effective date and provide additional notice where a change materially affects how we use personal information.

We keep prior versions for appropriate governance and evidence.

19. Contact and complaints

Contact SmartFlow at contact@smart-flow.uk or 11 Totman Close, Rayleigh, Essex, SS6 7UZ with questions, concerns or requests. We aim to resolve concerns fairly and promptly.

You may complain to the UK Information Commissioner’s Office. Its current contact and complaint information is available at https://ico.org.uk/make-a-complaint/. If you are outside the UK, you may also have a right to contact your local data-protection authority.

Please consider contacting us first so we can investigate, but you do not have to do so before contacting a regulator.

SmartFlow AI LTD

Company number 17134477, registered in England and Wales.

contact@smart-flow.uk 11 Totman Close, Rayleigh, Essex, SS6 7UZ
SmartFlow AI Core
System Online
SmartFlow AI
Initialising neural core
0%
click to skip