Privacy Policy
Last updated Jul 3, 2026
This Privacy Policy explains what personal information ParFlow collects, why we collect it, who we share it with, and the rights you have. It applies to our website, our application, and the AI agents we operate: for visitors, for our business customers, and for the people whose data our customers manage in ParFlow.
Who we are and what this policy covers
ParFlow is operated by an Israeli licensed business. Full legal details are provided in invoices, order forms, or upon verified business request. You can reach us about privacy at Lior@parflow.cc.
ParFlow provides AI agents and CRM automation for businesses: a website chat agent, messaging agents, a CRM for leads and conversations, appointment booking, optional calendar and messaging integrations, and related automation tools. This policy covers our marketing website (www.parflow.cc), the ParFlow application, and the AI agent widget when it appears on our own pages. When the widget is embedded on a customer's website, the customer's own privacy policy applies alongside this one. See "When we act for our business customers" below.
Our two roles: controller and processor
In short
For our own website, accounts, billing, and the agent on our own pages, ParFlow decides how data is used (we act as the "controller"). For lead, conversation, and CRM data that our business customers collect and manage, the customer decides, and we process the data on their behalf and under their instructions (we act as a "processor" or service provider).
Business customers who embed our agents on their own websites, or connect their own communication channels, are independently responsible (as controllers) for their visitors and end customers, including having a lawful basis to collect that data and their own privacy notice. Our Data Processing Addendum (at /dpa on this site) governs how we process data for them.
Information we collect
From visitors to our site and users of our agent widget
- The content of your conversation with the agent: the messages you type and the replies you receive.
- Contact details you choose to share (such as name, email, phone or WhatsApp number, business name) and one-time verification codes when you verify a contact channel.
- Consent records: the exact consent text you saw, what you agreed to (saving details, being contacted, optional marketing), when, and technical details such as your IP address and browser type. We keep these as evidence of your choices.
- Technical and context data: IP address, browser type, the page you were on, referral or campaign parameters, language, and a session identifier that keeps your conversation together.
- If voice features are enabled and you choose to start a voice conversation, audio or transcripts may be processed and stored to provide the feature.
From our business customers and their team members
- Account details: email address, name, role in the workspace, and login and security data.
- Workspace and business configuration: business details, services, working hours, agent settings, and knowledge content you upload for your agent.
- Billing and subscription information: your plan, subscription status, and usage credits. Payment card details are handled by our payment processor and never reach our servers.
- Support and service communications with us, including emails and messages you send.
Data we process on our customers' behalf
When businesses use ParFlow to run their own agents and CRM, we store and process the data those tools handle for them: leads and contact details, conversation transcripts (chat, messaging, and voice content where voice features are enabled), notes, AI-generated summaries and lead scores, appointments, and payment records the business keeps about its own clients. For this data, the business is the controller and this section of our policy works together with our Data Processing Addendum.
How we use information and our legal bases
Where EU or UK data protection law applies, our processing relies on the legal bases below. Under Israeli law, we collect and use data with your informed consent or where the law otherwise permits, for the purposes stated here.
| Purpose | Data used | Legal basis (EU/UK) |
|---|---|---|
| Answering you and operating the agent conversation | Conversation content, contact details, page context | Legitimate interests; contract (when you ask us for service) |
| Saving your details for follow-up and CRM | Contact details, conversation summary, consent records | Consent (collected in the widget before saving) |
| Marketing updates | Email or phone you provided | Separate, optional consent; never bundled |
| Providing accounts, the application, and billing | Account, workspace, subscription data | Contract; legal obligation (tax and accounting) |
| Security and abuse prevention | IP address, technical logs, session identifiers | Legitimate interests (protecting the service) |
| Improving and supporting the service | Service usage data, support communications | Legitimate interests |
We do not sell personal information, and we do not use your data for third-party advertising.
AI processing
When an AI agent is used, relevant conversation content and business context may be processed by AI service providers to generate responses, improve safety, and operate the service. If voice features are enabled, audio or transcripts may be processed to provide the feature. Our AI providers are contractually restricted from using this data to train generally available models.
- AI responses can be inaccurate. They are not legal, medical, financial, insurance, or other professional advice.
- Conversations may be reviewed by the business you are talking to, and by ParFlow where needed for service operation, support, quality, and safety.
- Please avoid sharing highly sensitive information (such as government ID numbers, full payment card details, or health information) in a conversation unless it is genuinely necessary.
For more on how the agent works and its limits, see our AI Disclosure at /ai-disclosure.
Cookies and similar technologies
We use only essential cookies and local browser storage needed for the site and the agent widget to work (for example, remembering your language and keeping your chat session together). We do not run analytics, advertising, or marketing tracking. Details are in our Cookie Policy at /cookie-policy.
Service providers we work with
We use a small number of trusted third-party providers to run the service. They process data only on our behalf, under agreements that require appropriate safeguards:
- Cloud hosting and database infrastructure.
- AI processing services that power agent responses and search.
- Email delivery services for verification, notifications, and summaries.
- Payment processing services (for paid plans).
- Communications and messaging services (only when a messaging channel such as WhatsApp is enabled).
- Calendar integration services (only when a customer connects their calendar).
More detail about these categories is published on our Third-Party Processing page at /subprocessors. For verified business customers, additional provider information may be made available under a commercial or data processing agreement where appropriate.
International data transfers
ParFlow is operated from Israel, and our service providers process data in other countries, including the United States and the European Union. Israel benefits from a European Commission adequacy decision, which allows personal data to flow from the EEA to Israel without additional transfer mechanisms. Where data is transferred onward to providers outside Israel or the EEA, we rely on appropriate safeguards recognised under applicable data protection law. For data from the United Kingdom, we rely on equivalent safeguards recognised under UK law.
How long we keep information
| Data | Retention |
|---|---|
| Widget conversations that did not become a lead | Deleted automatically within 7 days |
| Conversations saved to a business's CRM (with your consent) | Kept in that business's CRM until the business deletes them |
| Voice recordings (where voice features are enabled) | Deleted automatically per the configured period: 30 days by default, up to 90 |
| Consent records | Kept as evidence of consent for as long as relevant |
| Customer account and workspace data | For the life of the account, then deleted or anonymised within a reasonable period |
| Billing records | As required by tax and accounting law |
Other operational data is kept only as long as needed for the purposes described in this policy, or as required by law, and is then deleted or anonymised.
Security
We apply technical and organisational measures appropriate to the data we handle, including encryption in transit and at rest, access controls, separation between customer accounts, and monitoring against abuse. No method of transmission or storage is completely secure, but the service is designed to keep each business's data separate from every other's.
Your rights
Wherever you are, you can ask us to: access the personal data we hold about you, correct it, delete it, or stop a specific use of it (such as marketing). To make a request, email Lior@parflow.cc. We will verify your identity and respond within a reasonable time, as required by the law that applies to you. If your data is held in a business customer's CRM, we may refer your request to that business (see "When we act for our business customers").
You can opt out of marketing messages at any time. Marketing consent is always separate and optional, and withdrawing it does not affect the service.
Israeli privacy rights
We operate under the Israeli Protection of Privacy Law, 5741-1981, as amended (including Amendment 13, in force since August 2025), and the Data Security Regulations. You are not under any legal obligation to provide us personal information; providing it depends on your own choice. Information you provide is kept in databases operated for the purposes described in this policy: responding to enquiries, operating the service and CRM for our customers, billing, and security.
- You have the right to inspect information held about you (section 13 of the law) and to request correction or deletion of information that is inaccurate, incomplete, or outdated (section 14).
- You may withdraw consent to direct marketing at any time, and we will stop such use of your details.
- You may contact the Israeli Privacy Protection Authority with complaints about the handling of your personal data.
Additional rights in the EEA and UK
If you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR give you additional rights over data for which we are the controller: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority (in the UK, the ICO).
We do not use your personal data to make automated decisions that produce legal or similarly significant effects about you. AI-generated replies and lead summaries assist the business you interact with; decisions about you are made by people at that business.
US state privacy rights
US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) apply to businesses that meet certain size and revenue thresholds. ParFlow may not currently meet those thresholds. Regardless, as a matter of practice we extend the core rights (to know, to access, to correct, and to delete personal information) to US residents, and we do not sell or share personal information for cross-context behavioural advertising. If you are a California resident and these laws apply, you also have the right not to be discriminated against for exercising your rights.
Visitors interacting with agents on our US-focused pages can find a dedicated US notice, including state-specific disclosures, at www.parflow.cc/website-agent/privacy-policy.
When we act for our business customers
If you spoke with an AI agent on another business's website, or your details are stored in a business's ParFlow CRM, that business is responsible for your data as the controller, and we process it on their behalf. Requests to access, correct, or delete such data are best sent to that business directly. If you contact us instead, we will pass your request to the business and support them in fulfilling it, as our Data Processing Addendum (at /dpa) requires.
Children
ParFlow is a business tool and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
Google Calendar and Google user data
Connecting a Google Calendar is optional. ParFlow accesses your Google account only if you, as a ParFlow user, explicitly connect it through Google's OAuth consent screen. Scheduling and availability work without it; connecting Google adds real-time calendar checks and writes booking events to your calendar.
When you connect Google Calendar, we request the following Google API scopes and use them only for these purposes:
- Read your calendar availability (calendar.readonly): to check free and busy times and existing events, so the scheduling agent can offer real open slots and avoid double bookings.
- Create and manage events (calendar.events): to create, update, or cancel the booking events that ParFlow schedules on your behalf, and to mark them as ParFlow-created.
- Your Google account email address (userinfo.email): to identify which calendar account is connected and show it in your settings.
We store your Google OAuth tokens encrypted on our servers so the connection can keep working, and these tokens are never exposed to your browser. We also store the booking events ParFlow creates and a limited cache of event busy-times used to calculate availability and display your calendar. We do not store the contents of unrelated calendar events beyond what these features need.
We do not sell Google user data and do not use it for advertising. To offer appointment times during a conversation, ParFlow may include pre-computed available time slots (times only, not event titles, descriptions, or attendees) in requests sent to our AI service provider. Your Google OAuth tokens are never shared with any third party. ParFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar at any time from your ParFlow calendar settings; when you do, we delete the stored access and refresh tokens from our database. You can also review or revoke ParFlow's access directly in your Google Account under Security, in the section for third-party apps with account access.
Changes to this policy
We may update this policy from time to time as the service or legal requirements change. We'll revise the “last updated” date at the top whenever we do, and for material changes we will provide more prominent notice.
Contact us
Questions about this policy, or want to exercise a right? Email us at Lior@parflow.cc.
