EFFECTIVE DATE: JULY 27, 2026

Privacy Policy

At Mindflow AI Agency, enterprise security and client data transparency are foundational to every intelligent system we build. This policy outlines our rigorous protocols for protecting your proprietary information.

Enterprise Data Security Standard256-bit End-to-End Encryption & SOC-2 Compliant Protocols

TRANSPARENCY & PRIVACY STATEMENT

Protecting Your Data

Last Revised: September 2026. This Privacy Policy details how Mindflow AI Agency collects, processes, encrypts, and protects client information. We operate under strict zero-leak principles: your proprietary data is never used to train public models without explicit contractual consent.

1. Information We Collect

We gather information to provide high-performance automated systems, seamless workflow integrations, and secure API access. We collect data in three distinct categories:

  • Direct Account Identifiers: Name, professional email address, direct phone number, billing address, and business domain credentials provided during consultation or onboarding.
  • System Integration Telemetry: Webhook logs, pipeline throughput rates, workflow trigger timestamps, and API response performance indices.
  • Technical Metadata: Device type, browser environment, IP geolocation, session interaction duration, and security handshake records.

2. AI & Automated Processing Boundaries

Mindflow AI Agency deploys isolated, enterprise-tier language models and custom agentic pipelines. Data passed through our automated processing infrastructure is subjected to zero-retention policies on third-party model inference nodes. Your business documents, prompt interactions, and workflow inputs remain strictly isolated within your organization's designated workspace tenant.

Critical Summary : SMS & Phone Privacy

We do NOT sell, rent, or share SMS opt-in consent or phone numbers with third parties or affiliates for marketing purposes. You may opt out instantly by replying STOP to any automated dispatch.

3. SMS & Automated Communications

If you elect to receive automated SMS alerts, integration heartbeat notifications, or critical system dispatch logs, your interaction is governed by strict compliance boundaries:

  • Express Consent: Mobile phone numbers are only registered after explicit electronic double opt-in during client onboarding.
  • Zero Third-Party Sharing: No mobile information or messaging consent will be shared with third parties, affiliate marketers, or data aggregators.
  • Instant Opt-Out: Reply STOP, CANCEL, or UNSUBSCRIBE at any time to immediately revoke messaging capabilities.
  • Support & Assistance: Reply HELP to any notification to trigger human escalation from our technical support team.

4. Storage, Encryption & Security Safeguards

All communication channels and API connections utilize AES-256 encryption at rest and TLS 1.3 in transit. Access controls follow strict principle-of-least-privilege architecture, backed by continuous multi-factor authentication, biometric verification, and immutable audit logs.

5. Your Data Rights & Access Controls

Depending on your jurisdiction (including GDPR, CCPA, and CPRA), you retain full sovereignty over your personal and organization-level information:

  • Right to Access: Request a machine-readable export of all stored telemetry and personal metadata.
  • Right to Erasure: Trigger permanent database purging of your account credentials upon service contract termination.
  • Right to Rectification: Correct inaccurate operational records through your account dashboard or verified ticket.
  • Right to Restrict Processing: Pause automated processing and webhook integrations without deleting core profile configurations.

6. Updates, Governance & Contact

We periodically refine this Privacy Policy to reflect evolving regulatory frameworks and automated infrastructure capabilities. Clients will be alerted to material modifications via dashboard notices 30 days prior to enforcement.