Who is responsible for your information?
ZAPPFLOW LTD (company number SC888057) is responsible for the personal information described in this privacy notice when it acts as the controller.
Registered office: G/F, 17 Walker Street, Edinburgh, United Kingdom, EH3 7NE.
For privacy questions, requests or objections, contact sales@zappflow.com.
What information may we collect?
TYPE
EXAMPLES
WHERE IT COMES FROM
Contact information
Name, work email, business and role.
Project forms, email, calls, referrals or business sources.
Project information
Your brief, current systems, URLs, requirements and correspondence.
Information you or your organisation gives us.
Business relationship data
Proposals, project history, invoices, support correspondence and account notes.
Created while discussing or delivering work.
Website usage data
Pages viewed, device/browser information, approximate location, events and referral information where enabled.
Website, server logs and measurement technologies.
Public business data
Business names, websites, roles and professional contact information relevant to B2B activity.
Public websites, directories and other lawful business sources.
How and why do we use it?
Depending on the context, we may use personal information to:
- respond to enquiries and scope potential projects;
- enter into and perform contracts for client work;
- deliver, support, administer and improve ZappFlow services;
- maintain business records, invoices and necessary financial information;
- protect the security and integrity of our website and systems;
- understand and improve how the website is used;
- manage relevant B2B marketing and business development; and
- establish, exercise or defend legal claims and comply with legal obligations.
The lawful basis depends on the activity. It may include contract, legitimate interests, legal obligation or consent where consent is required or chosen as the appropriate basis.
B2B outreach and publicly available business information
ZappFlow may identify and contact organisations or business contacts where we reasonably believe our services may be relevant. This can involve professional information available from business websites, directories or similar public sources.
Where personal data is involved, we assess the appropriate lawful basis under data protection law. Legitimate interests may be appropriate for proportionate B2B activity where the use is reasonably expected and does not override the individual's rights.
Electronic marketing rules can differ depending on whether the subscriber is a corporate body, an individual, a sole trader or certain partnerships. We do not treat legitimate interests as a way to override consent requirements that apply under PECR.
You can object to direct marketing at any time. If you ask us to stop, we may retain limited information on a suppression list so that we can respect that request in future.
Who may we share information with?
We may use carefully selected service providers where needed to operate the website and business, for example hosting, form handling, analytics, communications, cloud infrastructure, payment/accounting services and technical platforms used in a project.
Where another provider processes personal data for us, we expect appropriate contractual and security protections. Some providers may process information outside the UK. Where data protection law requires safeguards for international transfers, we use or rely on the appropriate transfer mechanism.
We may also disclose information where required by law, to professional advisers, or where reasonably necessary to establish, exercise or defend legal rights.
Website audit tools
The Accessibility Audit, Lighthouse / Performance Audit and Cookie & Tracking Audit process a public website address that you choose to submit. ZappFlow may fetch public pages, render them in an automated browser and process technical evidence such as page structure, accessibility findings, performance data, scripts, cookies, consent behaviour and related website metadata in order to produce the requested audit.
The free audit tools use human verification, request validation and quota controls to prevent automated abuse. This can involve processing limited technical identifiers such as IP-derived or browser-derived pseudonymous keys and short-lived audit or session records. Audit responses are returned to the browser and are not intended as permanent storage for website or customer data.
Only submit website addresses that you are authorised to test. The public audit tools are designed for publicly accessible websites and are not intended for password-protected systems, private applications or confidential environments.
AI and operations demos
ZappFlow provides optional interactive AI demonstrations, including the AI Receptionist, Internal AI Assistant, Customer AI Agent and Operations System Builder previews. Information you choose to submit to these demos is processed to generate the requested response or demonstration.
For the AI Receptionist preview, ZappFlow may fetch a limited number of public pages from the website address you provide and use that public content to create a temporary business profile. If you add or correct business context before starting the call, that information is used as temporary context for the demo. During a live voice session, microphone audio, generated speech and conversation content are processed by OpenAI so the conversation can take place.
The public receptionist preview is deliberately read-only. It is not connected to the business's real calendar, CRM, payment systems, messaging systems or phone routing unless explicitly stated otherwise. Do not provide passwords, payment-card information, authentication codes, confidential customer data, special-category personal data or other sensitive information to a public demo.
The Internal AI Assistant can accept temporary documents and manual context that you choose to provide. The Customer AI Agent can accept temporary customer-safe documents. These files are used to create a temporary knowledge environment for the demo. Do not upload passwords, payment-card information, authentication secrets, regulated records, special-category personal data, confidential customer records or material you are not authorised to submit.
The Operations System Builder can accept an optional representative CSV or XLSX workbook. The workbook is parsed temporarily to identify sheets, columns, sample structure and likely workflow relationships. The public demo is intended for sanitised or representative operational data, not confidential customer records or sensitive personal data. Generated application records, activity and operational values are illustrative dummy data unless explicitly stated otherwise.
Temporary AI knowledge sessions are designed to last for approximately 30 minutes. ZappFlow requests deletion of temporary OpenAI files and vector stores when a session ends or expires, and the vector stores are also configured with a short automatic expiry as a backstop. Browser-close cleanup is best-effort, so users should not treat the public demos as storage for sensitive information.
ZappFlow uses Cloudflare Turnstile, signed temporary sessions, request validation and technical rate limits to protect the free AI demos from automated abuse. Temporary website-derived receptionist profiles are retained only for the short period needed to operate the demo. ZappFlow does not store raw call audio or raw call transcripts in its demo analytics store. Aggregate usage events and pseudonymous security/rate-limit identifiers may be processed to operate, protect and improve the service.
ZappFlow configures supported OpenAI API requests not to be stored for application history, but OpenAI and other infrastructure providers may process or retain information in accordance with their own service terms, security requirements and privacy documentation.
How long do we keep information?
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and any related legal, accounting, security or dispute-resolution requirements.
The appropriate period depends on the type of information and relationship. We consider whether an enquiry is still active, whether a client relationship exists, contractual and accounting obligations, limitation periods, security requirements and whether we need a limited suppression record to honour a marketing objection.
Your rights
Depending on the circumstances, UK data protection law may give you rights to access your personal information, correct it, request deletion, restrict or object to processing, receive certain data in a portable format, and withdraw consent where processing relies on consent.
You have an absolute right to object to personal data being used for direct marketing.
To make a request, contact sales@zappflow.com. You also have the right to complain to the UK Information Commissioner's Office if you believe your information has been handled unlawfully.