Privacy Policy
Last updated: July 24, 2026SystemFlow Automation (“SystemFlow,” “Company,” “we,” “our,” or “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit our website, communicate with us, use our services, or interact with an AI voice agent operated through the SystemFlow platform.
This Policy applies to website visitors, prospective customers, SystemFlow customers, authorized dashboard users, and callers whose information is processed through a SystemFlow-powered phone agent.
1. Our Role When Processing Information
Information SystemFlow controls
SystemFlow determines how information is used when you visit our website, request a demonstration, contact us, purchase a subscription, create an account, or communicate directly with SystemFlow.
Information processed for our customers
When a caller contacts a business using a SystemFlow voice agent, SystemFlow generally processes the call, recording, transcript, caller information, and related data on behalf of that business and according to its instructions.
A signed Service Agreement, Order Form, Statement of Work, or Data Processing Addendum may provide additional privacy terms for a particular customer.
2. Information We Collect
The information we collect depends on how you interact with SystemFlow. We may collect the following categories of information.
Website and inquiry information
- Name, email address, telephone number, and company name.
- Industry, business needs, service interests, and requested features.
- Information included in contact forms, emails, or demo requests.
- Appointment details and communications with our team.
Customer and account information
- Customer contact information and business details.
- Usernames, account identifiers, roles, and dashboard permissions.
- Selected plan, included minutes, subscription, and billing status.
- Support requests, configuration instructions, and approval history.
- Knowledge-base content, company policies, services, and FAQs.
Caller and communication information
- Caller name, telephone number, and reason for calling.
- Call date, time, duration, status, and routing information.
- Audio recordings and written transcripts.
- Questions asked and responses provided during a call.
- Requested services, appointment information, and lead details.
- Notes, classifications, qualification results, and follow-up status.
- Text messages, email notifications, and related communications.
Integration and connected-system information
- Information exchanged with customer-authorized CRM, scheduling, communication, or business-software systems.
- Record identifiers, customer records, lead information, appointment details, call-routing instructions, and integration results.
- Credentials or access tokens needed to operate an approved integration.
Technical and usage information
- IP address, browser type, device type, and operating system.
- Pages visited, referring pages, and general interaction information.
- Login activity, feature usage, errors, and system-performance data.
- Security logs, diagnostic records, and suspected misuse.
Payment information
Payments may be processed by a third-party payment provider. SystemFlow may receive payment status, billing address, transaction identifiers, payment-method type, and limited account information. We generally do not directly store complete payment-card or bank-account credentials.
3. Sources of Information
We may obtain information:
- Directly from you.
- From a SystemFlow customer that configures or uses the services.
- From callers interacting with an AI voice agent.
- From customer-authorized integrations and connected systems.
- Automatically through our website, dashboard, and services.
- From telephone, AI, hosting, payment, and communication providers.
- From publicly available business information.
4. How We Use Information
We may use information to:
- Provide, operate, maintain, and secure the SystemFlow platform.
- Answer and process calls through AI-powered phone agents.
- Record, transcribe, classify, summarize, and route calls.
- Capture, organize, qualify, and deliver leads to customers.
- Send approved email, text-message, or dashboard notifications.
- Configure prompts, call flows, routing, and knowledge bases.
- Operate customer dashboards and authorized integrations.
- Schedule appointments or collect scheduling requests.
- Create and manage customer accounts and subscriptions.
- Process payments, invoices, renewals, and usage charges.
- Respond to inquiries and provide customer support.
- Monitor usage, prevent fraud, and investigate misuse.
- Troubleshoot errors and improve system reliability.
- Enforce our agreements and protect legal rights.
- Comply with legal and regulatory obligations.
5. AI Voice Agents, Recordings, and Transcripts
SystemFlow services may use artificial intelligence, automated speech recognition, language models, synthetic voices, call recording, and transcription technology.
When enabled by a SystemFlow customer, a call may be recorded, transcribed, summarized, analyzed, classified, or routed automatically. Information from the call may appear in the customer’s SystemFlow dashboard or connected business systems.
AI systems may process the content of a conversation to understand the caller’s request, provide an automated response, collect information, determine routing, or perform another customer-approved action.
SystemFlow does not sell call recordings or transcripts. We do not use customer call content to build or train a publicly available SystemFlow AI model unless the affected customer has expressly agreed in writing.
Third-party AI and voice providers may process information under the applicable account settings, product terms, contractual terms, and privacy practices associated with their services.
6. Call-Recording and Communication Consent
The SystemFlow customer is responsible for determining which calling, recording, transcription, messaging, marketing, privacy, and consent laws apply to its business and intended use of the services.
Customers are responsible for approving and using legally appropriate:
- Call-recording announcements.
- AI-agent disclosures.
- Consent language.
- Text-message notices and opt-out instructions.
- Outbound-call authorization.
- Privacy notices provided to callers and customers.
If you are a caller and have questions about why a call was recorded or how the business uses your information, contact the business you called. You may also contact SystemFlow for assistance identifying the appropriate customer.
7. How We Disclose Information
We may disclose information in the following circumstances.
SystemFlow customers
Caller information, recordings, transcripts, messages, lead details, and related information may be provided to the business that operates the applicable AI voice agent and its authorized users.
Service providers
We may disclose information to providers that help us operate AI models, voice generation, telephone services, phone numbers, hosting, storage, email, text messaging, payments, security, analytics, support, and integrations.
Customer-authorized integrations
Information may be transmitted to CRM platforms, scheduling tools, communication systems, or other software when the customer requests or authorizes the integration.
Legal, safety, and security purposes
We may disclose information when reasonably necessary to comply with law, respond to lawful legal process, enforce an agreement, investigate fraud, prevent harm, protect security, or defend the rights of SystemFlow, our customers, callers, or others.
Business transactions
Information may be disclosed in connection with a merger, acquisition, financing, reorganization, sale of assets, or transfer of all or part of the SystemFlow business, subject to appropriate confidentiality and legal requirements.
With permission
We may disclose information for another purpose when the relevant person or customer directs us to do so or provides permission.
8. Third-Party Service Providers
Depending on the customer’s configuration, SystemFlow may use providers such as:
- ElevenLabs for voice-agent and synthetic-voice functionality.
- Twilio for telephone numbers, calling, routing, and messaging.
- OpenAI or other AI providers for language-processing functionality.
- Payment processors for subscription and invoice payments.
- Hosting, storage, email, security, and backup providers.
- Customer-selected CRM and business-software platforms.
Providers receive only the information reasonably required for their assigned function or the applicable customer configuration. Their services may also be governed by their own terms and privacy policies.
The providers used for a particular customer may change as services, integrations, pricing, security requirements, or technology change.
9. Sale of Personal Information and Advertising
SystemFlow does not sell personal information for monetary payment.
We do not sell call recordings, transcripts, lead information, or customer business data.
SystemFlow does not currently use caller communication data for cross-context behavioral advertising or targeted advertising unrelated to providing the requested services.
10. Cookies and Similar Technologies
Our website and dashboard may use cookies, local storage, log files, and similar technologies for:
- Essential website and account functionality.
- Login sessions and authentication.
- Security and fraud prevention.
- Remembering user preferences.
- Understanding website and service performance.
- Diagnosing errors and improving usability.
You can control many cookies through your browser settings. Blocking essential cookies may prevent portions of the website or dashboard from working correctly.
11. Data Retention
We retain information for as long as reasonably necessary to provide the services, maintain business and financial records, resolve disputes, enforce agreements, protect security, and comply with legal obligations.
Retention periods may vary based on:
- The type and sensitivity of the information.
- The customer’s selected plan and configuration.
- Customer instructions and signed agreements.
- Operational, security, and backup requirements.
- Billing, tax, legal, and recordkeeping obligations.
Call recordings and transcripts may be retained according to the customer’s account settings, plan, or agreement. Customers may request deletion or export of eligible information, subject to applicable contractual, legal, security, and backup limitations.
Information removed from an active system may remain temporarily in backups, security logs, or legally required records before being deleted or overwritten.
12. Data Security
We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Security measures may include access controls, account authentication, system monitoring, restricted administrative access, backups, provider security controls, and other safeguards appropriate to the nature of the services.
No website, telephone system, internet transmission, storage platform, or electronic service can be guaranteed to be completely secure. Customers are responsible for protecting their account credentials and promptly reporting suspected unauthorized access.
13. Privacy Rights and Requests
Depending on your residence and applicable law, you may have the right to:
- Confirm whether we process your personal information.
- Access certain personal information.
- Correct inaccurate personal information.
- Request deletion of certain personal information.
- Obtain a portable copy of eligible information.
- Opt out of certain sales, targeted advertising, or profiling.
- Withdraw consent when processing is based on consent.
- Appeal the denial of an eligible privacy request.
These rights are not absolute. We may retain or decline to delete information when permitted or required for security, fraud prevention, legal compliance, billing, dispute resolution, or other lawful purposes.
To submit a privacy request, contact us using the information at the end of this Policy. We may ask for information reasonably necessary to verify your identity, locate the relevant information, and prevent unauthorized requests.
Authorized agents may submit requests where permitted by law, but we may require proof of the agent’s authority and verification of the individual’s identity.
To appeal a decision concerning a privacy request, reply to our decision and clearly state that you are requesting an appeal.
14. Requests Concerning a SystemFlow Customer
When SystemFlow processes caller information on behalf of a business customer, we may refer your request to that customer or ask the customer for instructions before responding.
Customers are responsible for reviewing and responding to privacy requests involving information they control. SystemFlow will provide reasonable assistance as required by the applicable agreement and law.
15. Sensitive and Regulated Information
Customers and callers should not provide highly sensitive information unless its collection is necessary, expressly approved, and supported by an appropriate system configuration and written agreement.
Highly sensitive information may include:
- Social Security numbers.
- Complete payment-card or banking credentials.
- Passwords and private authentication credentials.
- Government identification numbers.
- Detailed medical or health information.
- Biometric or precise location information.
- Information concerning children.
Standard SystemFlow services are not offered as HIPAA-compliant services by default.
Customers may not use SystemFlow to create, receive, maintain, or transmit protected health information unless SystemFlow has approved the use in writing, the parties have signed an appropriate Business Associate Agreement, and the applicable providers and configuration support the required safeguards.
16. Children’s Privacy
SystemFlow’s website and business services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13 through our website.
Customers may not intentionally configure SystemFlow services to collect personal information from children in violation of applicable law.
If you believe a child has provided information to SystemFlow inappropriately, contact us so that we can review and address the request.
17. Data Processing Locations
SystemFlow operates in the United States. Information may be processed, transmitted, or stored in the United States or other locations where our service providers operate.
Privacy and data-protection laws may differ between jurisdictions. Where required, we may use contractual or other measures designed to support lawful data transfers.
18. External Websites and Services
Our website or services may contain links to external websites, integrations, or third-party platforms. This Privacy Policy does not govern information independently collected by those third parties.
Review the privacy terms of an external service before providing information to it.
19. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our services, providers, business practices, security measures, or legal obligations.
Updates will be posted on this page with a revised “Last updated” date. Material changes may also be communicated by email, through the dashboard, or by another reasonable method.
Continued use of the services after an updated Policy becomes effective means the updated Policy will apply to future use, subject to applicable law and any controlling signed agreement.
20. Terms of Service
Use of SystemFlow’s website and services is also governed by our Terms of Service.
21. Contact Us
Questions, privacy requests, correction requests, and deletion requests may be sent to:
SystemFlow Automation
Email:
dylansanuita@gmail.com
Please include enough information for us to understand your request, identify the applicable account or business, and locate the relevant information.