Introduction

At TruFlow ("we," "our," or "us"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our no-code compliance lab platform and related services.

By using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

This Privacy Policy applies to all users of our platform, including visitors to our website, registered users, and enterprise customers. We may update this policy from time to time, and we will notify you of any material changes.

Information We Collect

Personal Information

We may collect the following types of personal information when you interact with our services:

  • Contact Information: Name, email address, phone number, business address, and job title
  • Account Information: Username, password, account preferences, and security settings
  • Business Information: Company name, industry, organization size, and business requirements
  • Payment Information: Billing address, payment method details, and transaction history (processed securely through third-party providers)
  • Communication Data: Records of your communications with us, including support tickets, emails, and chat logs
  • Profile Information: Professional background, role responsibilities, and compliance requirements
  • Verification Data: Information required for identity verification and account security
  • Preferences: Language settings, notification preferences, and customization choices

Technical Information

We automatically collect certain technical information when you use our platform:

  • Usage Data: Information about how you use our platform, features accessed, time spent, and interaction patterns
  • Device Information: IP address, browser type and version, operating system, device identifiers, and hardware specifications
  • Log Data: Server logs, error reports, performance metrics, and system diagnostics
  • Cookies and Tracking: Information collected through cookies, web beacons, and similar tracking technologies
  • Location Data: General geographic location based on IP address (not precise location)
  • Network Information: Connection type, ISP information, and network performance data
  • Security Data: Authentication logs, security events, and threat detection information
  • Performance Metrics: Platform performance data, load times, and user experience metrics
  • Integration Data: Information from third-party integrations and API connections

Workflow and Compliance Data

When you use our compliance auditing services, we process:

  • Workflow Information: AI-generated workflows, process definitions, and automation scripts submitted for analysis
  • Audit Results: Compliance scan results, vulnerability reports, risk assessments, and remediation recommendations
  • Configuration Data: Settings and preferences for compliance policies, security rules, and governance frameworks
  • Metadata: File properties, creation dates, modification history, and version information
  • Compliance Reports: Generated reports, certifications, trust badges, and compliance documentation
  • Policy Data: Custom compliance policies, regulatory requirements, and organizational standards
  • Risk Assessments: Security risk evaluations, threat analysis, and vulnerability classifications

How We Use Your Information

We use the collected information for the following legitimate business purposes:

  • Service Provision: To provide, maintain, improve, and personalize our compliance auditing platform and related services
  • Account Management: To create and manage your account, authenticate users, process payments, and maintain subscription services
  • Communication: To send service-related notifications, updates, security alerts, and marketing communications (with your consent)
  • Security and Fraud Prevention: To detect, prevent, and address technical issues, fraud, security vulnerabilities, and unauthorized access
  • Analytics and Improvement: To analyze usage patterns, understand user behavior, and improve our services and user experience
  • Compliance and Legal: To comply with legal obligations, regulatory requirements, and respond to lawful requests
  • Business Operations: To conduct business operations, including mergers, acquisitions, asset sales, and corporate restructuring
  • Customer Support: To provide technical support, troubleshoot issues, and respond to customer inquiries
  • Research and Development: To develop new features, improve existing services, and conduct research on compliance technologies
  • Quality Assurance: To monitor service quality, conduct testing, and ensure platform reliability
  • Personalization: To customize your experience, provide relevant recommendations, and tailor our services to your needs

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following limited circumstances:

Service Providers and Partners

We may share information with trusted third-party service providers who assist us in operating our platform:

  • Cloud Infrastructure: Hosting providers, content delivery networks, and data storage services
  • Payment Processing: Secure payment processors and billing service providers
  • Customer Support: Help desk platforms, communication tools, and support ticket systems
  • Analytics and Monitoring: Website analytics, performance monitoring, and user experience tools
  • Security Services: Threat detection, fraud prevention, and cybersecurity monitoring services
  • Communication Services: Email delivery, SMS services, and notification platforms
  • Integration Partners: Third-party applications and services that integrate with our platform

Legal Requirements and Protection

We may disclose your information when required by law or to protect our rights and users:

  • Legal Process: In response to court orders, subpoenas, search warrants, or other legal proceedings
  • Government Requests: To comply with government or regulatory agency requests and investigations
  • Rights Protection: To protect our rights, property, safety, or the rights and safety of our users
  • Fraud Investigation: To investigate suspected fraud, security breaches, or violations of our terms
  • Emergency Situations: To address emergencies that threaten the physical safety of any person
  • Regulatory Compliance: To meet regulatory reporting requirements and compliance obligations

Business Transfers

In the event of a merger, acquisition, sale of assets, or other business transaction, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

Consent-Based Sharing

We may share your information with third parties when you have given us explicit consent to do so, such as when you authorize integrations with other platforms or services.

Data Security and Protection

We implement comprehensive technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

Technical Safeguards

  • Encryption: Data encryption in transit using TLS 1.3 and at rest using AES-256 encryption
  • Access Controls: Multi-factor authentication, role-based access controls, and principle of least privilege
  • Network Security: Firewalls, intrusion detection systems, and network segmentation
  • Monitoring: 24/7 security monitoring, threat detection, and automated incident response
  • Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scanning
  • Data Backup: Secure, encrypted backups with regular testing and recovery procedures
  • Secure Development: Security-by-design principles and secure coding practices

Organizational Measures

  • Employee Training: Regular security awareness training and privacy education for all personnel
  • Background Checks: Comprehensive background verification for employees with data access
  • Incident Response: Comprehensive incident response plan and breach notification procedures
  • Vendor Management: Due diligence and security assessments for all third-party providers
  • Policy Enforcement: Strict data handling policies and regular compliance audits
  • Physical Security: Secure data centers with biometric access controls and environmental monitoring

While we implement industry-leading security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining the highest security standards and continuously improving our protective measures.

Your Privacy Rights and Choices

Depending on your location and applicable privacy laws, you may have the following rights regarding your personal information:

Data Subject Rights

  • Right of Access: Request access to your personal information we hold and receive a copy of your data
  • Right to Rectification: Request correction of inaccurate, incomplete, or outdated personal information
  • Right to Erasure: Request deletion of your personal information (subject to legal and business requirements)
  • Right to Data Portability: Request a copy of your information in a structured, machine-readable format
  • Right to Restriction: Request restriction of processing under certain circumstances
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes
  • Right to Withdraw Consent: Withdraw consent where processing is based on your consent
  • Right to Lodge Complaints: File complaints with relevant data protection authorities

How to Exercise Your Rights

To exercise these rights, please contact us at [email protected] with your request. We will respond within the timeframe required by applicable law, typically within 30 days.

When submitting a request, please provide sufficient information to verify your identity and specify the right you wish to exercise. We may request additional information to confirm your identity and protect your privacy.

Marketing Communications

You can opt out of marketing communications at any time by:

  • Clicking the unsubscribe link in our emails
  • Updating your preferences in your account settings
  • Contacting us directly at [email protected]

Data Retention and Deletion

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention Criteria

We determine retention periods based on several factors:

  • Service Provision: As long as you maintain an active account or subscription
  • Legal Requirements: To comply with applicable laws, regulations, and legal obligations
  • Business Needs: For legitimate business purposes such as fraud prevention and security
  • Dispute Resolution: To resolve disputes and enforce our agreements
  • Data Sensitivity: More sensitive data may be retained for shorter periods

Specific Retention Periods

  • Account Data: Retained while your account is active and for 3 years after account closure
  • Transaction Records: Retained for 7 years for tax and accounting purposes
  • Support Communications: Retained for 3 years after the last interaction
  • Security Logs: Retained for 1 year for security monitoring and incident response
  • Marketing Data: Retained until you opt out or for 2 years of inactivity
  • Compliance Reports: Retained for 7 years or as required by applicable regulations

Data Deletion

When we no longer need your information, we will securely delete or anonymize it in accordance with our data retention policies and industry best practices. Deletion includes removal from our active systems, backups, and archives.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States and other countries where we or our service providers operate.

Transfer Safeguards

When we transfer your information internationally, we ensure appropriate safeguards are in place:

  • Adequacy Decisions: Transfers to countries with adequacy decisions from relevant authorities
  • Standard Contractual Clauses: EU-approved standard contractual clauses for data transfers
  • Binding Corporate Rules: Internal policies ensuring consistent data protection standards
  • Certification Programs: Participation in recognized privacy certification programs
  • Additional Safeguards: Technical and organizational measures to protect transferred data

Cross-Border Data Processing

We may process your data in multiple jurisdictions to provide our services effectively. All processing locations maintain equivalent levels of data protection through contractual obligations and technical safeguards.

Children's Privacy

Our services are not intended for children under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at [email protected].

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Notify you through our platform, email, or other appropriate means
  • Obtain your consent for material changes where required by law
  • Provide clear information about the nature of the changes

We encourage you to review this Privacy Policy periodically to stay informed about our privacy practices and your rights.

Contact Us

If you have any questions about this Privacy Policy, our privacy practices, or wish to exercise your privacy rights, please contact us:

Privacy Officer: Jennifer Park

Email: [email protected]

Phone: +1 925 483 7062

Address:
TruFlow Privacy Team
4123 Raccoon Street
Concord, CA 94521, USA

We are committed to addressing your privacy concerns and will respond to your inquiries promptly and professionally.