Back to Legal
Legal

Privacy Policy

Last updated: 1 August 2026

This Privacy Policy describes how SmartFlow AI Technology Limited handles personal data across Ghost Protocol, our websites, and related services.

1. Introduction

SmartFlow AI Technology Limited ("SmartFlow", "we", "us", or "our") provides Ghost Protocol and related products. This Privacy Policy explains what personal data we collect, why we collect it, and the choices you have when interacting with our websites, platform, and integrations.

This policy applies to visitors of our websites, users of our hosted services, and anyone who communicates with SmartFlow. If you access Ghost Protocol through an organization that licenses our platform, that organization is the controller of the data inside their workspace and their own privacy notice governs how that data is used.

2. Data we collect

Account data: name, work email, company, role, and authentication identifiers when you create or use a SmartFlow account.

Usage data: pages visited, actions taken inside the product, feature interactions, device and browser metadata, and approximate location derived from IP address.

Customer content: workflows, prompts, connected-source records, and outputs that you or your organization submit to Ghost Protocol so we can run the requested automations.

Support and communications: messages, attachments, and call notes when you contact our team or respond to surveys.

Billing data: company billing details and transaction records. Card data is processed by our payment provider and is not stored on SmartFlow systems.

3. How we use personal data

To provide and operate Ghost Protocol, including executing the workflows you configure.

To secure our services, prevent abuse, and investigate suspicious activity.

To improve features, troubleshoot issues, and develop new capabilities — using aggregated or de-identified data wherever possible.

To communicate product updates, security notices, and (with appropriate consent) marketing content you can opt out of at any time.

To comply with legal obligations and enforce our agreements.

5. Sharing and subprocessors

We do not sell personal data. We share data only with vetted subprocessors that help us deliver the service — including cloud hosting, observability, analytics, payment processing, and customer support tooling. Each subprocessor is bound by written data-protection terms.

A current list of subprocessors is available on request via privacy@smart-flowai.com. We may also disclose data when required by law, to protect rights and safety, or in connection with a corporate transaction, in which case affected customers will be notified.

6. International transfers

Personal data may be processed in regions where SmartFlow or our subprocessors operate. Where data leaves the EEA, UK, or other regulated regions, we rely on appropriate safeguards such as Standard Contractual Clauses and supplementary technical and organizational measures.

7. Retention

We retain personal data for as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Customer content is retained for the lifetime of the workspace and deleted within a reasonable window after account closure, subject to backup rotation.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You can exercise these rights by emailing privacy@smart-flowai.com. If SmartFlow processes your data on behalf of your employer or another controller, please direct the request to that organization and we will assist them in responding.

9. Cookies

Our websites use a small set of cookies for essential functionality, product analytics, and (with consent) marketing measurement. You can manage cookie preferences through your browser settings or the cookie banner on our sites.

10. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, and destruction. For details, see our Security Overview.

11. Children

Ghost Protocol and our websites are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@smart-flowai.com and we will remove it.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced via the product or by email to account administrators before they take effect.

13. Contact us

SmartFlow AI Technology Limited — privacy@smart-flowai.com. For data-protection requests, please include sufficient information to verify your identity and the nature of your request.

Questions about this policy? Email privacy@smart-flowai.com or visit our legal hub.