Privacy policy

Template document. Review with legal counsel before publishing.

1. Who we are

AgentFlow provides software for building and operating AI voice and chat agents. When you use the platform to run agents, you are the data controller for the end-user conversations you process, and we act as a processor on your instructions.

2. What we collect

  • Account data: name, email address, hashed password, and authentication provider identifiers.
  • Organisation data: workspace name, industry, members and their roles.
  • Agent configuration: prompts, business rules, workflow graphs and widget settings.
  • Knowledge-base content you upload, and the derived text chunks and embeddings.
  • Conversation data: chat transcripts, call transcripts, call metadata, tool executions and appointments.
  • Usage and billing data: conversation counts, voice minutes, token counts and estimated provider cost.
  • Technical data: IP address, user agent, request identifiers and audit records of privileged actions.

3. What we never store in the clear

  • Passwords — stored only as a salted scrypt hash.
  • API keys — stored only as a SHA-256 digest; the plaintext is shown once at creation.
  • Integration credentials — encrypted with AES-256-GCM before they touch the database.
  • Payment card details — handled by the payment provider; the platform never receives them.

4. Sub-processors

Depending on the features you enable, conversation content may be sent to your configured LLM provider (for example OpenAI or Anthropic), to ElevenLabs for speech, to your telephony carrier for phone calls, to Google for calendar operations, and to your own n8n instance for workflow automation. You choose these providers and supply the credentials.

5. Retention and deletion

Organisations can configure a retention window; conversations past that window are purged automatically by a background job. You can delete individual conversations, knowledge documents and contacts at any time. Deleting your account anonymises your personal data and revokes every session. Backups are retained for a limited period as described in your contract.

6. Recording and consent

Call recording is off by default. When you enable it, the agent plays a consent message at the start of the call and the consent event is recorded alongside the call. You are responsible for ensuring recording and outbound calling comply with the law in the jurisdictions you operate in, including do-not-call rules.

7. Your rights

Depending on your jurisdiction you may have rights of access, rectification, erasure, restriction, portability and objection. Contact us using the details on the contact page and we will respond within the period required by applicable law.

8. Security

We use encryption in transit, encryption of stored credentials, role-based access control, tenant isolation enforced in both the application and the database, rate limiting, audit logging and signed webhooks. No system is perfectly secure; report suspected vulnerabilities through the contact page.

9. Changes

Material changes to this policy will be announced in-product before they take effect.