01Introduction
This Privacy Policy explains how ArchiFlow (“we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you visit our website, request a demo, join the Academy, or otherwise interact with us (the “Site”). It applies to the Site only. It does not govern data processed inside your own ArchiFlow deployment — see the next section.
02Our Role — Site vs. Your Deployment
It is important to distinguish two very different contexts:
- This website. For personal information collected through the Site, ArchiFlow acts as the data controller, and this policy applies.
- Your ArchiFlow deployment. ArchiFlow is typically installed on your own infrastructure — on-premises or fully air-gapped. The network data, device inventory, credentials, and configurations it processes stay within your environment, under your control. For that data we are, at most, a data processor acting on your instructions under your Platform Agreement and data-processing addendum — and for a self-managed or air-gapped install, that data never reaches us at all.
In other words: the sensitive operational data your team cares about most does not flow to ArchiFlow or any third-party cloud unless you explicitly choose an optional cloud feature.
03Who Is Responsible for Your Data
For personal information collected through the Site, the ArchiFlow operating entity is the controller. If you have questions about this policy or wish to exercise your rights, reach us using the details in the Contact section below.
04Information We Collect
We collect the following categories of information through the Site:
- Information you provide. Your name, business email, company, role, phone (if given), and any message content when you request a demo, contact us, apply for evaluation access, or use the chat assistant.
- Usage & device data. IP address, browser type, device and operating system, pages visited, referring URLs, and interaction events, collected through standard web logs and privacy-respecting analytics.
- Cookies & similar technologies. Small files used to keep the Site functioning and to understand aggregate usage, as described in the Cookies section.
We do not intentionally collect special categories of data (such as health or biometric data) through the Site, and we ask that you not submit them.
05Where We Get It
We collect information directly from you (forms, email, chat), and automatically from your device as you browse (logs, cookies, analytics). In limited cases we may receive business-contact details from trusted referral or event partners, or enrich a request with publicly available company information to route it correctly.
06How We Use Information
- respond to demo requests, inquiries, and support questions;
- provide, maintain, secure, and improve the Site and its content;
- operate the chat assistant and analyze aggregate usage to make the Site more useful;
- deliver Academy and evaluation materials you request, and administer early-access programs;
- send you information you request and, where permitted, relevant product updates you may opt out of at any time; and
- comply with legal obligations and protect against fraud, abuse, and security threats.
07Legal Bases for Processing (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: consent (e.g., optional marketing communications); legitimate interests (e.g., responding to your inquiry, securing and improving the Site) balanced against your rights; performance of a contract (e.g., preparing an evaluation you requested); and legal obligation where processing is required by law. You may withdraw consent at any time without affecting prior processing.
10Sub-Processors
To run the website, we rely on a deliberately small set of sub-processors, by category: website hosting and content delivery, transactional email, product analytics, and the third-party model provider that powers the optional chat assistant. Each is bound by contract to appropriate confidentiality and security obligations, and we keep this list to the minimum needed to operate the Site. A current list is available on request.
For your ArchiFlow deployment, the picture is different by design: a self-managed or air-gapped installation runs without external sub-processors touching your network data. Unlike cloud-only tools that route customer data through a long chain of third-party clouds, ArchiFlow keeps that data where you put it — with you.
11Chat Assistant & AI Processing
If you use the Site's chat assistant, the messages you send may be processed by a third-party AI provider solely to generate a response. Please do not enter confidential information, credentials, or sensitive personal data into the chat. Website chat is separate from the in-product AI copilot, which runs against your own inventory inside your deployment. We do not use your Site interactions to train third-party foundation models; messages may be retained in aggregate, de-identified form to improve the assistant.
12Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing of Site data, within the meaning of Article 22 of the GDPR. The chat assistant provides information only and does not decide anything about you.
13International Data Transfers
We and our service providers may process information in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards — such as the EU Standard Contractual Clauses, the UK Addendum, or an equivalent lawful transfer mechanism — to protect it consistent with applicable law. A copy of the relevant safeguards is available on request.
14Data Retention
We keep personal information only for as long as necessary to fulfill the purposes described here — for example, to manage your inquiry and our relationship — and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. Contact and demo-request records are typically retained for the duration of the commercial relationship and a reasonable period afterward; server logs are kept for a shorter period. When no longer needed, information is deleted or anonymized.
15Data Security
We apply administrative, technical, and organizational safeguards appropriate to the risk — including encryption in transit, access controls and least-privilege practices, network segmentation, and monitoring. Security is central to our product philosophy, and we hold the Site to the same standard. You can read more in our Trust Center. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security.
16Data Breach Notification
If a personal-data breach affecting the Site is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay and in line with applicable law.
17Your Privacy Rights (GDPR / UK)
Depending on where you live, you may have the right to access, correct, delete, or port your personal information; to object to or restrict certain processing; and to withdraw consent. Under the GDPR/UK GDPR you may also lodge a complaint with a supervisory authority. To exercise a right, contact us using the details below; we will verify your request and respond within the timeframe required by law.
18U.S. State Privacy Rights (CCPA / CPRA)
If you are a California resident (or in a U.S. state with a comparable law), you have rights to know, access, correct, and delete personal information, and to opt out of its “sale” or “sharing” — we do not sell or share personal information as those terms are defined, nor do we use sensitive personal information for purposes requiring an opt-out. You also have the right not to be discriminated against for exercising your rights. Submit a request using the details below.
19Your Marketing Choices
You can opt out of marketing emails at any time using the unsubscribe link in the message or by contacting us. We will still send you essential service or transactional messages related to a request you made.
20Children's Privacy
The Site is intended for business users and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
21Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice on the Site. Please review it periodically.
22Contact & Data Protection
For privacy questions, to reach our data-protection contact, or to exercise your rights, email agent@archiflow.space. We will respond within the timeframe required by applicable law.
This document is provided for general informational purposes and does not constitute legal advice.