Version 2026-08-24 · Effective date: August 24, 2026
This Privacy Policy explains how SeppFlow ("we," "us," "our") collects, uses, and protects personal data in connection with the SeppFlow platform (the "Service"). It applies to (a) account holders and their staff ("Users") and (b) end‑customers of Users whose data is processed through the Service ("Customer Data"). For Customer Data, SeppFlow generally acts as a data processor / service provider on behalf of the User, who remains the data controller and is responsible for their own compliance with applicable law.
The controller responsible for User account data is [TODO: legal entity name and registered address]. Contact for privacy questions: [TODO: privacy contact email]. If a data‑protection officer or EU/Israel representative is appointed, list them here.
Account and billing information you provide when registering: name, company name, work email, phone number, country, industry, and password (stored as a salted hash, never in plain text). Payment details are collected and stored by our third‑party payment processor, not by SeppFlow directly.
Customer Data you or your team enter into the Service on behalf of your own clients: names, contact details, service addresses, quotes, invoices, schedules, and related business records.
Usage and device information collected automatically: IP address, browser/user‑agent, pages visited, and timestamps — used for security, fraud prevention, and diagnosing issues. This also includes the IP address and user‑agent recorded at the moment you accept these documents, for consent verification.
Communications you send us (support requests, emails) and, if you opt in, marketing communications.
We use personal data to: provide, maintain, and secure the Service; authenticate accounts and prevent fraud or abuse; process payments and manage subscriptions; provide customer support; send transactional communications (e.g., account, billing, and security notices); send marketing communications only if you opted in, and let you opt out at any time; and comply with legal obligations.
Where applicable law requires a stated legal basis (e.g., under Israel's Privacy Protection Law or an EU/UK framework if it applies to you), we rely on: performance of our contract with you (providing the Service you signed up for); our legitimate interests in operating and securing the Service; your consent, where we ask for it (e.g., optional marketing emails); and compliance with legal obligations. [TODO: confirm applicability of GDPR/UK GDPR if SeppFlow serves customers in those regions, and complete this section accordingly].
We use strictly necessary cookies (e.g., session/authentication cookies) required for the Service to function, and a locale‑preference cookie to remember your chosen language. [TODO: list any analytics or marketing cookies actually in use, and add a cookie‑consent banner if required in your target markets].
We do not sell personal data. We share it only with: subprocessors who help us run the Service (see Section 7); professional advisors (legal, accounting) under confidentiality obligations; a successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy continuing to apply; and law enforcement or regulators when required by law, or to protect the rights, property, or safety of SeppFlow, our users, or others.
We use third‑party service providers to operate the Service, which may include hosting/infrastructure, database, and payment‑processing providers. [TODO: list actual subprocessors by name and function — e.g., cloud hosting provider, payment processor — and where their servers are located, since this affects cross‑border transfer disclosures].
[TODO: state where data is hosted and, if data is transferred between Israel, the U.S., or other countries, describe the transfer mechanism relied on (e.g., adequacy decision, standard contractual clauses)].
We retain account and Customer Data for as long as the account is active, and for a reasonable period afterward to comply with legal, tax, or accounting obligations, resolve disputes, and enforce agreements. Consent records (see Section 11) are retained on an append‑only basis as a durable evidentiary record and are not deleted when a document version changes. You can request deletion of your account data subject to these retention needs.
Subject to applicable law, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing, including withdrawing marketing consent at any time. Israeli residents may have rights under the Privacy Protection Law, 5741‑1981 (including the right to inspect and request correction of data held in a database, per Sections 13–14). U.S. residents may have rights under applicable state privacy laws (e.g., access, deletion, and opt‑out of sale/sharing, where those laws apply to SeppFlow). To exercise a request, contact us using the details in Section 13.
When you accept these documents (for example, during registration), we store a record containing your user ID, organization, the document type and version accepted, the timestamp, the acceptance source, and technical metadata (IP address and user‑agent) necessary to demonstrate that consent was given. These records are append‑only: accepting a new version creates a new record rather than overwriting the previous one, so a full history is preserved.
We use administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit, hashed password storage, and access controls limiting who can view account and Customer Data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Questions about this Policy or requests regarding your data can be sent to [TODO: privacy contact email].
We may update this Policy from time to time. If we make material changes, we will notify you and, where required, ask you to re‑accept before the changes take effect.