Privacy Policy
Last updated: March 16, 2026
Your privacy matters. This policy explains what information we collect, how we use it, and the steps we take to protect it. Contact us at [email protected] if you have any questions.
1. Information We Collect
We collect information you provide directly to us, such as when you create an account, connect data sources, or contact us for support. This includes:
- Account information (name, email address, organization details)
- Service configuration data needed to operate integrations (connection strings, API keys, credentials). We store these secrets encrypted at rest and access them only to maintain your data source connections.
- Usage data and analytics about how you interact with ContextFlo
- Communication records when you contact us
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process and complete transactions
- Send you technical notices and support messages
- Respond to your comments and questions
- Monitor and analyze usage patterns and trends
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
3. Legal Basis for Processing
We process personal information under the following legal bases:
- Contractual necessity: Account information and service configuration data required to deliver the ContextFlo platform under our Cloud Service Agreement.
- Legitimate interest: Usage analytics to improve the service, fraud prevention, and security monitoring.
- Consent: Marketing communications, which you may opt out of at any time.
- Legal obligation: Where required to comply with applicable laws or respond to valid legal process.
4. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure.
5. Data Retention
We retain personal information for as long as your account is active or as needed to provide the service. Upon termination or expiration of your subscription, ContextFlo deletes customer content from ContextFlo-managed systems within 60 days unless a different period is specified in your order form. We may retain limited records (such as billing history and data deletion request logs) as required by law or for legitimate business purposes such as audit compliance. Anonymized, aggregated data that cannot identify you may be retained indefinitely.
6. International Data Transfers
ContextFlo is based in the United States and processes data primarily in the US. If you are located outside the US, your information will be transferred to and processed in the US. Where required by applicable law (such as GDPR), we rely on appropriate safeguards including Standard Contractual Clauses. Details of our data processing practices are described in our Data Processing Agreement.
7. Data Sharing
We do not sell or rent personal information. We share limited operational data with trusted subprocessors, such as hosting and infrastructure providers, solely to deliver the ContextFlo service. A current list of these providers is available at contextflo.com/legal/subprocessors. Each subprocessor is bound by our Data Processing Agreement and contractual confidentiality obligations.
8. Your Rights
You have the right to:
- Access and update your personal information
- Request deletion of your personal information
- Opt out of marketing communications
- Request a copy of your data
- Lodge a complaint with supervisory authorities
To submit a data deletion or access request, please use our Data Request Form. You may also email [email protected]. All requests are logged and tracked. We respond within 30 days (or the shorter period required by applicable law) and may request additional information to verify your identity. Rights may be limited in certain jurisdictions where ContextFlo does not operate or where legal exceptions apply.
9. Cookies and Tracking
We use the following categories of cookies:
- Essential cookies: Required for the platform to function (authentication, session management).
- Analytics cookies: Help us understand how the platform is used so we can improve it.
We do not use advertising or third-party tracking cookies. You can control cookie settings through your browser preferences, though disabling essential cookies may prevent the platform from functioning properly.
10. Changes to This Policy
We may update this privacy policy from time to time. When we make material changes, we will provide additional notice (such as email or in-product messaging) before the updates take effect, in addition to updating the "Last updated" date on this page.
11. Contact Us
If you have any questions about this privacy policy, please contact us at [email protected].