Legal

Privacy Policy

Last updated: July 2026

Your privacy matters. This policy explains what we collect through the ArchiFlow website, why, and the choices and rights you have — including under the GDPR and CCPA. Note the key distinction: data inside your own on-premises or air-gapped ArchiFlow deployment stays with you.

01Introduction

This Privacy Policy explains how ArchiFlow (“we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you visit our website, request a demo, join the Academy, or otherwise interact with us (the “Site”). It applies to the Site only. It does not govern data processed inside your own ArchiFlow deployment — see the next section.

02Our Role — Site vs. Your Deployment

It is important to distinguish two very different contexts:

  • This website. For personal information collected through the Site, ArchiFlow acts as the data controller, and this policy applies.
  • Your ArchiFlow deployment. ArchiFlow is typically installed on your own infrastructure — on-premises or fully air-gapped. The network data, device inventory, credentials, and configurations it processes stay within your environment, under your control. For that data we are, at most, a data processor acting on your instructions under your Platform Agreement and data-processing addendum — and for a self-managed or air-gapped install, that data never reaches us at all.

In other words: the sensitive operational data your team cares about most does not flow to ArchiFlow or any third-party cloud unless you explicitly choose an optional cloud feature.

03Who Is Responsible for Your Data

For personal information collected through the Site, the ArchiFlow operating entity is the controller. If you have questions about this policy or wish to exercise your rights, reach us using the details in the Contact section below.

04Information We Collect

We collect the following categories of information through the Site:

  • Information you provide. Your name, business email, company, role, phone (if given), and any message content when you request a demo, contact us, apply for evaluation access, or use the chat assistant.
  • Usage & device data. IP address, browser type, device and operating system, pages visited, referring URLs, and interaction events, collected through standard web logs and privacy-respecting analytics.
  • Cookies & similar technologies. Small files used to keep the Site functioning and to understand aggregate usage, as described in the Cookies section.

We do not intentionally collect special categories of data (such as health or biometric data) through the Site, and we ask that you not submit them.

05Where We Get It

We collect information directly from you (forms, email, chat), and automatically from your device as you browse (logs, cookies, analytics). In limited cases we may receive business-contact details from trusted referral or event partners, or enrich a request with publicly available company information to route it correctly.

06How We Use Information

  • respond to demo requests, inquiries, and support questions;
  • provide, maintain, secure, and improve the Site and its content;
  • operate the chat assistant and analyze aggregate usage to make the Site more useful;
  • deliver Academy and evaluation materials you request, and administer early-access programs;
  • send you information you request and, where permitted, relevant product updates you may opt out of at any time; and
  • comply with legal obligations and protect against fraud, abuse, and security threats.

08Cookies & Analytics

We use strictly necessary cookies to operate the Site and, where permitted, analytics cookies to understand aggregate usage. You can control cookies through your browser settings; disabling some cookies may affect Site functionality. We honor recognized browser privacy signals (such as Global Privacy Control) where required by law.

09How We Share Information

We do not sell your personal information. We share it only in limited circumstances:

  • Service providers / processors that host the Site, deliver email, provide analytics, or power the optional AI chat feature — bound by contract to protect your data and use it only on our instructions;
  • Legal & safety disclosures where required by law, regulation, or valid legal process, or to protect our rights and users; and
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

10Sub-Processors

To run the website, we rely on a deliberately small set of sub-processors, by category: website hosting and content delivery, transactional email, product analytics, and the third-party model provider that powers the optional chat assistant. Each is bound by contract to appropriate confidentiality and security obligations, and we keep this list to the minimum needed to operate the Site. A current list is available on request.

For your ArchiFlow deployment, the picture is different by design: a self-managed or air-gapped installation runs without external sub-processors touching your network data. Unlike cloud-only tools that route customer data through a long chain of third-party clouds, ArchiFlow keeps that data where you put it — with you.

11Chat Assistant & AI Processing

If you use the Site's chat assistant, the messages you send may be processed by a third-party AI provider solely to generate a response. Please do not enter confidential information, credentials, or sensitive personal data into the chat. Website chat is separate from the in-product AI copilot, which runs against your own inventory inside your deployment. We do not use your Site interactions to train third-party foundation models; messages may be retained in aggregate, de-identified form to improve the assistant.

12Automated Decision-Making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing of Site data, within the meaning of Article 22 of the GDPR. The chat assistant provides information only and does not decide anything about you.

13International Data Transfers

We and our service providers may process information in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards — such as the EU Standard Contractual Clauses, the UK Addendum, or an equivalent lawful transfer mechanism — to protect it consistent with applicable law. A copy of the relevant safeguards is available on request.

14Data Retention

We keep personal information only for as long as necessary to fulfill the purposes described here — for example, to manage your inquiry and our relationship — and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. Contact and demo-request records are typically retained for the duration of the commercial relationship and a reasonable period afterward; server logs are kept for a shorter period. When no longer needed, information is deleted or anonymized.

15Data Security

We apply administrative, technical, and organizational safeguards appropriate to the risk — including encryption in transit, access controls and least-privilege practices, network segmentation, and monitoring. Security is central to our product philosophy, and we hold the Site to the same standard. You can read more in our Trust Center. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security.

16Data Breach Notification

If a personal-data breach affecting the Site is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay and in line with applicable law.

17Your Privacy Rights (GDPR / UK)

Depending on where you live, you may have the right to access, correct, delete, or port your personal information; to object to or restrict certain processing; and to withdraw consent. Under the GDPR/UK GDPR you may also lodge a complaint with a supervisory authority. To exercise a right, contact us using the details below; we will verify your request and respond within the timeframe required by law.

18U.S. State Privacy Rights (CCPA / CPRA)

If you are a California resident (or in a U.S. state with a comparable law), you have rights to know, access, correct, and delete personal information, and to opt out of its “sale” or “sharing” — we do not sell or share personal information as those terms are defined, nor do we use sensitive personal information for purposes requiring an opt-out. You also have the right not to be discriminated against for exercising your rights. Submit a request using the details below.

19Your Marketing Choices

You can opt out of marketing emails at any time using the unsubscribe link in the message or by contacting us. We will still send you essential service or transactional messages related to a request you made.

20Children's Privacy

The Site is intended for business users and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

21Changes to This Policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice on the Site. Please review it periodically.

22Contact & Data Protection

For privacy questions, to reach our data-protection contact, or to exercise your rights, email agent@archiflow.space. We will respond within the timeframe required by applicable law.

This document is provided for general informational purposes and does not constitute legal advice.