This policy covers what Kflows collects, why, and what you can do about it. It's written to be read rather than to be impressive.
1. Who we are
Kflows Ltd is a digital consultancy registered in Northern Ireland, company number NI738243, registered office 18 Dublinhill Road, Dromore, BT25 1SY. We are registered with the Information Commissioner's Office, reference ZC110393. For anything in this policy, email info@kflows.co.uk.
2. Controller or processor: which one applies to you
This matters, because it decides whose policy you should be reading.
Where Kflows is the controller. Our own client relationships, billing, this website, and our own B2B marketing. We decide why and how that data is processed, and this policy covers it.
Where Kflows is the processor. When we build and run systems for a client, we handle their customers' data on their instructions only, under a separate Data Processing Agreement. The client is the controller and their own privacy notice governs it, not this one. This includes messaging channels we operate on a client's behalf, covered in section 5.
3. What we collect
- Identity and contact data: name, job title, company name, business address, email, phone number.
- Booking data: if you book a call, Calendly collects your name, email and anything you type into the form, and shares it with us so we turn up prepared. Calendly's own policy covers their side.
- Email: if you email us, we have your email address. We use it to reply. You are not added to a mailing list.
- Message content: if you message a WhatsApp number we operate, see section 5.
- Financial and transaction data: records of what you bought. Card details are processed by Stripe; we never store card numbers.
- Technical and usage data: IP address, browser, and how you use the site. The site sets no advertising cookies and runs no tracking pixels.
- Business contact data from third parties: where you are a contact at a UK limited company, PLC or LLP, we may obtain business contact details from Companies House, LinkedIn, and B2B data providers, only where UK law permits direct B2B marketing. Where we get your details from a source other than you, we say so in our first communication and give you a way to object.
4. Why we process it, and our lawful basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Registering clients and delivering contracted services | Performance of a contract |
| Billing, debt recovery, tax and accounting records | Legal obligation (HMRC 6 to 7 year retention) |
| Replying to your enquiry or running a call you booked | Legitimate interests |
| B2B marketing to corporate subscribers (retained 24 months from last contact) | Legitimate interests (written assessment available on request) |
| Marketing to sole traders, partnerships and other non-corporate subscribers | Consent (PECR) |
5. WhatsApp and other messaging channels
Kflows operates WhatsApp business numbers, both for itself and on behalf of clients, using the official WhatsApp Business Platform.
- What is collected. Your phone number, your WhatsApp profile name, and the content and timestamps of the messages you send and receive on that number.
- Who the controller is. If the number belongs to one of our clients, that client is the controller and their privacy notice applies. Kflows processes those messages only on their instructions. Ask us and we will tell you which business operates a given number.
- WhatsApp's own role. Messages travel through the WhatsApp Business Platform, operated by WhatsApp Ireland Ltd, a Meta company. Their handling of your data is governed by their own terms, not by this policy.
- Where messages are stored. Message content and conversation history are stored in our infrastructure, hosted in the UK or EEA, so that a conversation can continue where it left off and so the business can answer you properly.
- Retention. Conversation history is kept for no longer than 24 months from the last message in the conversation, or sooner where the client whose number it is instructs us to delete it. After that it is deleted or anonymised.
- You can stop it. Reply STOP, or say you want to opt out in your own words, and messaging stops. Ask for a human and you get one.
6. Automated replies and AI
Some of the messaging numbers we operate are answered by an automated assistant built on large language models, used under enterprise or API terms with zero-retention and no-training-on-your-input conditions. It answers questions, and it can pass you to a person.
Be aware that its replies are sent without a person checking each one first. It does not make decisions about you that have legal or similarly significant effects: it cannot approve or refuse credit, price you differently, or accept or reject an application. You can ask for a human at any point and the conversation is handed over. You also have the right to object to our use of AI to process your personal data.
We also use AI tools internally to summarise publicly available information, draft outreach, and classify inbound replies. A person reviews and approves outbound marketing before it is sent.
7. Who we share it with
Only service providers who help us operate: messaging, email delivery, payment processing, calendar booking, CRM, hosting, and the AI providers described above. Each is bound by written terms to process personal data only on our instructions.
Some are based outside the UK. Where we transfer personal data out of the UK we rely on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or UK International Data Transfer Agreements. A current list of the processors we engage is available on request to info@kflows.co.uk. Nothing is sold.
8. How long we keep it
Only as long as we need it. Client information (identity, contact, financial, transaction) is kept six years after you stop being a client, in line with HMRC rules. B2B marketing data is kept 24 months from last contact. Messaging history is covered in section 5. After those periods, data is securely deleted or anonymised.
9. How we protect it
Encrypted connections (TLS 1.2+), multi-factor authentication, role-based access, and regular security reviews. Access is limited to those with a business need. We have procedures for suspected data breaches and will notify you and the regulator where legally required.
10. Your rights
Under UK GDPR you can ask us to:
- give you access to your personal data, or a copy of it;
- correct it if it is wrong or incomplete;
- erase it;
- stop processing it for direct marketing. This right is absolute under Article 21(2): we must stop, no balancing test;
- restrict processing, or transfer your data to someone else;
- withdraw consent, where consent is what we relied on;
- stop using AI to process your personal data.
Email info@kflows.co.uk. There is normally no fee and we aim to respond within one month.
You can also complain to the Information Commissioner's Office at ico.org.uk. We would rather you gave us the chance to fix it first.
11. Other sites
Links to third-party sites are not covered by this policy. When you leave ours, read theirs.
12. Changes
We keep this policy under review. The date at the top reflects the most recent material change.