Privacy Policy
This Policy explains how [COMPANY LEGAL NAME], trading as AIFlowDeck ("AIFlowDeck," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you use our website, application, APIs, and Model Context Protocol integrations (the "Service").
1. Who is responsible
[COMPANY LEGAL NAME] is the controller, except when a customer agreement makes us a processor acting on a business customer's instructions. Contact us at [PRIVACY EMAIL] or [REGISTERED ADDRESS].
2. Information we process
Accounts and security
Usernames, encrypted password hashes, roles, invitation information, login timestamps, authentication tokens, and security records. We do not store plain-text passwords.
Workspace content
Tasks, descriptions, goals, projects, bookmarks, tags, links, assignees, teams, outcomes, dependencies, dates, decisions, initiatives, agent profiles, governance settings, and learning-cycle notes that users choose to enter.
Activity and technical data
Task changes, MCP actions, governance events, action context, actor names, timestamps, IP addresses, request headers, device or browser type, and diagnostic information needed to operate and secure the Service.
Browser storage
The current application uses browser local storage for an authentication token, username, navigation order, and workspace-view preferences. [CONFIRM WHETHER PRODUCTION HOSTING, ANALYTICS, SUPPORT, OR PAYMENT PROVIDERS SET COOKIES.]
Connected AI services
When an authorized user connects an AI client through MCP, we process authorization and client details, tool calls, and workspace data needed to complete them. The AI provider may independently process prompts and returned data under its own policies.
3. How we use information
- Provide accounts, workspaces, planning, reporting, export, governance, and MCP features.
- Authenticate users and connected clients and preserve accountability records.
- Provide support, monitor reliability, and troubleshoot errors.
- Detect abuse, fraud, security incidents, and prohibited activity.
- Comply with law, enforce agreements, and communicate material service changes.
Where required, our legal bases include contract performance, legitimate interests, legal obligations, and consent. Business customers are responsible for the legal basis for information they enter.
4. Disclosure and subprocessors
We may disclose information to infrastructure, database, monitoring, email, support, payment, and security providers; integrations chosen by authorized users; professional advisers; transaction counterparties; or authorities where law or safety requires it. We do not sell personal information for money. Publish the verified subprocessor list at [SUBPROCESSOR URL], including provider purpose and location.
5. International transfers
Information may be processed outside its country of origin. Where required, we use adequacy decisions, standard contractual clauses, or another lawful mechanism. [INSERT ACTUAL HOSTING REGIONS AND TRANSFER MECHANISM.]
6. Retention
We retain account and workspace information while the account or customer agreement is active and for [RETENTION PERIOD] afterward. Operational logs are retained for [LOG RETENTION PERIOD], and backups for [BACKUP RETENTION PERIOD]. Deletion from backups follows the normal expiry cycle.
7. Security
Safeguards include password hashing, access controls, production transport encryption, request throttling, service isolation, audit events, and backup procedures. No system is completely secure. Customers must protect credentials, configure users correctly, and grant only necessary MCP permissions.
8. Your rights
Depending on location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, withdraw consent, and complain to a regulator. Contact [PRIVACY EMAIL]. We may verify identity or route a request to the responsible business customer. Supported workspace exports are available in the Service.
9. Children
The Service is intended for business users, is not directed to children under 16 or the applicable minimum age, and does not knowingly collect children's personal information.
10. Third parties and changes
We do not control third-party websites or connected providers. Review their terms before sending data. We may update this Policy and will revise the date and provide additional notice where required.
11. Contact
[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
[PRIVACY EMAIL]
[SUPPORT URL]