Privacy Policy
This policy explains what personal data may be processed when you use the BPFlow AI website, why the processing takes place, how long the data is retained, and what rights you have.
1. Scope
BPFlow AI is an independent personal project focused on business process automation. This policy applies to bpflowai.com and explains the processing of personal data related to visiting the website and contacting BPFlow AI through the communication channels listed on the website.
As the controller operates from the Netherlands, this policy is primarily prepared with the EU General Data Protection Regulation (GDPR) in mind. Depending on the circumstances, additional data-protection requirements in other jurisdictions may also apply.
2. Data controller
The controller determines the purposes and means of the personal-data processing described in this policy.
Controller: Michael Krupnow
Project: BPFlow AI
Location: The Netherlands
Website: bpflowai.com
Contact: Telegram @bpflowai
3. Personal data that may be processed
3.1. Technical data when visiting the website
To deliver the website, keep it secure and diagnose technical issues, the server infrastructure may automatically process technical HTTP request data, which may include:
- IP address;
- date and time of the request;
- requested URL and HTTP method;
- server response status and amount of data transferred;
- browser or device User-Agent;
- Referer information when provided by the browser;
- technical information required for diagnostics and security.
3.2. Data when contacting BPFlow AI through Telegram
If you choose to contact BPFlow AI through Telegram, the data processed may include your name or username, message content, contact details, files and any other information that you decide to send.
3.3. What the website currently does not include
The current version of the website has no registration form, user account or first-party enquiry form. It also does not intentionally use advertising profiling or analytics/advertising cookies.
4. Purposes of processing and legal bases
Personal data may be processed for the following purposes:
- Operating and protecting the website. Technical logs may be used to deliver pages, diagnose errors, prevent abuse and maintain information security. The legal basis is the controller's legitimate interest (Article 6(1)(f) GDPR).
- Responding to enquiries and discussing a potential project. When you contact BPFlow AI about a possible service or cooperation, processing may be necessary in order to take steps before entering into a contract (Article 6(1)(b) GDPR), or may rely on the legitimate interest in handling ordinary business enquiries (Article 6(1)(f) GDPR).
- Compliance with legal obligations. In specific circumstances, data may be processed where required by applicable law (Article 6(1)(c) GDPR).
If a future type of processing requires consent, consent will be requested separately before that processing begins.
5. Recipients and categories of recipients
BPFlow AI does not sell personal data and does not disclose it to third parties for their own advertising.
A limited amount of technical data may be processed by infrastructure, hosting or network service providers needed to operate the website. Data may also be disclosed when required by applicable law or a lawful request from a competent authority.
If you use Telegram, your data is additionally processed by Telegram under its own terms and privacy policy.
6. Transfers outside the EEA
If the infrastructure or services used by BPFlow AI involve a transfer of personal data outside the European Economic Area, an applicable GDPR transfer safeguard must be used where required.
If you independently choose to use Telegram, further processing by that service is governed by Telegram's own privacy documentation. You should review the external service's privacy terms before using it.
7. Retention periods
Personal data is not kept longer than necessary for the purpose for which it was obtained.
- technical server logs are retained according to server log-rotation settings and only for as long as needed for operation, diagnostics, security and incident investigation;
- business correspondence is retained for the period of the communication and relevant follow-up, and is deleted or restricted when it is no longer needed;
- longer retention may apply where necessary to meet a legal obligation, resolve a dispute or establish, exercise or defend legal claims.
8. Your rights
Where provided by the GDPR, you may request:
- access to your personal data;
- rectification of inaccurate data;
- erasure of personal data;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability where the right applies;
- withdrawal of consent at any time where processing is based on consent.
To exercise your rights, contact the controller through Telegram @bpflowai. A reasonable identity check may be required before a request is fulfilled in order to protect personal data.
You also have the right to lodge a complaint with a competent supervisory authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (AP).
9. Data security
Reasonable technical and organisational measures are used to protect personal data, taking into account the nature of the website and the information processed. Access to infrastructure and data is limited to what is needed for operation, security and handling enquiries.
10. Automated decision-making and profiling
The current version of the website does not use visitor personal data for automated decision-making that produces legal or similarly significant effects, and it does not perform advertising profiling of visitors.
11. Changes to this policy
This policy may be updated when the website functionality, infrastructure, communication channels or applicable requirements change. The current version will be published on this page with the date of the latest update.
12. Privacy contact
For questions about the processing of personal data or to exercise rights available under the GDPR, contact:
This version of the policy describes the website's current configuration: no first-party enquiry form, advertising analytics or user accounts. The policy should be reviewed before any such functionality is introduced.