Scope of this Privacy Policy
This policy applies to personal data processed through:
- the AgentFlow website and public marketing pages;
- the AgentFlow business messaging and automation platform;
- the AgentFlow Android application;
- browser-based access to the customer panel and related WebView experiences;
- AgentFlow APIs, webhooks, integrations and connected applications;
- account registration, billing, support, sales and demo requests; and
- communications sent directly to AgentFlow.
This policy does not replace the privacy notice of a AgentFlow business customer. Businesses using AgentFlow remain responsible for providing appropriate notices and obtaining required permissions from their own customers, contacts, employees and other data subjects.
When AgentFlow is a controller or processor
AgentFlow may act in different privacy roles depending on the data and processing activity:
- Controller: AgentFlow determines why and how account, website, billing, security, sales, support and direct relationship data is processed.
- Processor or service provider: When a business customer submits contacts, messages, templates, media, customer records or other business content to AgentFlow, AgentFlow generally processes that data on the customer’s instructions to provide the service.
- Business customer responsibility: The customer determines the purpose of its messaging, selects recipients, manages lawful permissions and is responsible for the accuracy and legality of the data it uploads or connects.
Enterprise customers may contact AgentFlow to discuss data-processing terms relevant to their account and use case.
Categories of data we collect or process
The categories depend on the products and features used.
Account and identity data
- name, business name, username and account identifier;
- email address, phone number and contact details;
- role, team membership and account permissions;
- business verification or onboarding information where required; and
- support, sales and account correspondence.
Billing and transaction data
- plan, subscription, invoice, payment status and transaction references;
- billing contact and tax information where applicable; and
- limited payment information received from payment processors.
AgentFlow does not intentionally store complete payment-card details when payment is handled by an external payment processor.
WhatsApp and business messaging data
- WhatsApp Business Account and phone-number identifiers;
- business profile, template and messaging configuration data;
- contact phone numbers and customer profile information provided by the business;
- message content, media, attachments, timestamps and delivery events;
- conversation assignment, status, tags, notes and agent activity; and
- campaign, automation, webhook and API event data.
Technical and usage data
- IP address, browser, operating system, device and app information;
- login activity, session identifiers and authentication events;
- feature use, page views, clicks, app interactions and diagnostics;
- crash reports, error logs, performance and security telemetry; and
- cookie, local-storage or similar technology identifiers.
Integration and uploaded content
- API keys, webhook configuration and connected-account identifiers;
- CRM, spreadsheet, e-commerce, order, product, customer and notification data;
- documents, knowledge sources and media uploaded for platform or AI features; and
- configuration settings and metadata associated with integrations.
How we collect data
AgentFlow may receive data:
- directly from a user, account owner, administrator or agent;
- from a business customer that uploads or connects customer information;
- automatically from browsers, devices, applications, cookies and logs;
- from Meta and the WhatsApp Business Platform;
- from payment, hosting, analytics, security and support providers;
- from CRM, e-commerce and other connected integrations; and
- from public business sources where reasonably needed for verification or support.
How we use personal and business data
AgentFlow uses data to:
- create, secure and administer accounts;
- provide two-way messaging, agent inbox, campaigns and automation;
- send messages and receive delivery events through supported Cloud API and related access methods;
- provide AI-assisted replies, knowledge features and human handover controls;
- operate APIs, webhooks and requested integrations;
- process subscriptions, invoices and payments;
- provide support, onboarding, notices and service communications;
- monitor availability, diagnose faults and improve reliability;
- protect accounts, prevent abuse, fraud, spam and security incidents;
- enforce applicable terms and platform policies;
- meet legal, tax, accounting, compliance and regulatory obligations; and
- send marketing communications where permitted, with available opt-out controls.
Where applicable law requires a legal basis, processing may rely on performance of a contract, legitimate interests, consent, compliance with legal obligations or another basis permitted by law.
WhatsApp Business Platform data
AgentFlow connects eligible businesses to WhatsApp messaging capabilities, including official Cloud API access where configured. Message delivery and related platform events may involve Meta and are subject to Meta and WhatsApp terms, privacy practices and technical requirements.
Business customers are responsible for:
- obtaining valid consent or another lawful basis before messaging contacts;
- using approved templates where required;
- maintaining accurate recipient and opt-out records;
- avoiding spam, prohibited content, deception, harassment and abuse; and
- providing their own privacy notice to message recipients.
AgentFlow does not own customer contacts or message content submitted by a business customer. Access and use are limited to operating, securing, supporting and improving the contracted service, complying with customer instructions and meeting legal or platform obligations.
AI-assisted features and uploaded knowledge
When a customer enables AI features, AgentFlow may process message content, conversation history, instructions, uploaded documents and approved business knowledge to generate responses, summaries, classifications or other requested outputs.
- Customers control whether AI features are enabled for their workflows.
- Human handover and AI pause controls remain available where supported.
- Customers should not upload data they are not authorised to process.
- Sensitive data should be limited to what is necessary for the intended business purpose.
- AI outputs may be inaccurate and should be reviewed where decisions or important customer outcomes are involved.
Depending on the configured feature, selected content may be processed by an AI infrastructure or model provider acting as a service provider. Customers with specific requirements should contact AgentFlow before enabling the feature.
Android application and related services
This policy applies to the AgentFlow Android application, including WebView-based or browser access to the customer panel where used. App downloads and release details are available on the Download page.
Depending on the application version and configuration, the app or website may use mobile, analytics or platform services that process data such as:
- IP address and approximate network information;
- device, app-instance or advertising identifiers;
- app interactions, session and feature-use data;
- crash logs, diagnostics and performance data;
- fraud-prevention and security signals; and
- advertising and consent information where advertising is enabled.
Third-party providers process data under their own terms and privacy policies. Users may manage advertising and privacy settings through their device and account controls where available.
Third-party integrations and connectors
When a customer connects AgentFlow to a third-party system such as a CRM, spreadsheet, e-commerce platform or other business tool, AgentFlow may process store, order, product, customer and configuration data required to provide the workflows requested by that customer.
Depending on permissions and features, this may include:
- account or store identifiers and installation information;
- order, status, product and fulfilment details;
- customer name, email, phone and related profile fields;
- notification preferences, template mappings and delivery events; and
- webhook events and integration logs.
AgentFlow limits connected data use to providing, securing, supporting and improving the authorised integration and complying with legal or platform obligations. Customers remain responsible for their own privacy notice, customer permissions and use of WhatsApp notifications.
Sale of data and advertising disclosures
AgentFlow does not sell personal information for monetary consideration.
The Android app or website may use analytics, advertising or measurement services. Under some privacy laws, certain disclosures of identifiers to advertising or analytics providers may be described as “sharing” or targeted advertising even when no money is received for personal information.
Where required, AgentFlow will provide applicable consent, opt-out or settings controls. Users may also manage advertising identifiers, permissions and personalised-ad settings through their browser, device or account controls.
Data security
AgentFlow uses reasonable technical and organisational safeguards designed to protect data against unauthorised access, loss, misuse, alteration and disclosure. Measures may include:
- encrypted network connections using HTTPS/TLS where applicable;
- access controls, authentication and role-based permissions;
- credential, token and secret-management controls;
- logging, monitoring, backup and recovery procedures;
- security updates and vulnerability remediation;
- provider and infrastructure security controls; and
- staff access restrictions based on operational need.
No internet service can guarantee absolute security. Customers are responsible for protecting account credentials, limiting user permissions, maintaining secure devices and promptly reporting suspected account compromise.
Data retention, export and deletion
AgentFlow retains data for as long as reasonably needed to provide the service, maintain security, resolve disputes, enforce agreements and meet legal, tax, accounting and compliance requirements.
Retention periods vary according to the data category:
- account and subscription data may be retained while an account is active;
- billing and transaction records may be retained for legally required periods;
- customer messaging data may be retained according to account settings, service needs and customer instructions;
- security, fraud and audit logs may be retained for protective and evidentiary purposes;
- temporary, expired, cache, session and non-essential diagnostic data may be deleted or anonymised when no longer needed; and
- backup copies may remain for a limited backup cycle before being overwritten.
Where an export feature is available, account administrators may export supported contacts, conversations or records from the dashboard.
A verified account or data deletion request can be submitted by contacting agentflowcloud@gmail.com. Eligible deletion requests are normally completed within 30 days after identity and authority are verified, except where data must be retained for legal, tax, billing, fraud, security, dispute or compliance purposes.
Deleting a AgentFlow account does not automatically delete data held independently by Meta, WhatsApp, Google, payment providers or another connected service. Requests relating to those providers may need to be submitted directly to them.
International data transfers
AgentFlow and its service providers may process data in countries other than the country where a user or customer is located. Privacy laws and government-access rules may differ between jurisdictions.
Where required, AgentFlow uses contractual, organisational or other lawful safeguards intended to support international data transfers. Customers with data-location or transfer requirements should contact AgentFlow before purchasing or enabling relevant integrations.
Your privacy rights and choices
Depending on location and applicable law, a person may have rights to:
- request access to personal data;
- request correction of inaccurate or incomplete data;
- request deletion of eligible data;
- request restriction of or object to certain processing;
- request a portable copy of eligible data;
- withdraw consent where processing relies on consent;
- opt out of non-essential marketing communications;
- opt out of certain targeted advertising or data sharing where applicable; and
- submit a complaint to an appropriate data-protection authority.
AgentFlow may need to verify identity, account ownership or authority before acting on a request. Requests can be limited or declined where permitted by law, including where they affect another person’s rights, conflict with legal obligations or cannot be reliably verified.
When AgentFlow processes customer contact or message data solely on behalf of a business customer, the request should normally be directed first to that business. AgentFlow will support verified customer instructions where required.
Children’s privacy
AgentFlow is a business platform and is not directed to children. Users must have legal authority to enter into the applicable agreement and operate a business account.
Business customers must not knowingly use AgentFlow to collect or process children’s personal data without an appropriate lawful basis, required notices and parental or guardian permission where applicable. Contact AgentFlow if you believe children’s data has been submitted improperly.
Changes to this Privacy Policy
AgentFlow may update this policy to reflect changes in services, technologies, integrations, legal requirements or provider rules. The latest version will be published on this page with an updated revision date.
Where appropriate, material changes may also be communicated through email, account notices or an in-product message. Continued use after an effective update is subject to the revised policy and applicable Terms & Conditions.
Contact AgentFlow about privacy
Contact AgentFlow for privacy questions, data requests, account deletion, security concerns or clarification about a connected service. Website: agentfllow.com.
Privacy and data requests
Include the registered account email, business name and a clear description of the request. Do not email passwords, complete payment-card details or unnecessary sensitive data.
Email: agentflowcloud@gmail.com
WhatsApp: +923091456953
Address: Head Marala Rd, Behlolpur, Gujrat, Pakistan