Privacy Policy

Last Updated: 22/05/2025

Introduction

Call Flows AI Ltd. (along with our affiliated companies, collectively referred to as "Call Flows AI", "we", "our", or "us") is dedicated to protecting the privacy of your Personal Data. We are committed to ensuring that your data is processed securely, used appropriately, and that our practices are transparently communicated to our Clients, their end-users (referred to as "End-Users"), individuals who use our services on behalf of our clients (Users), and visitors to our website or other online properties (Prospects).

This Privacy Policy outlines how we collect, use, store, disclose, and otherwise process Personal Data in connection with our AI-powered voice assistant services for Shopify stores (the "Platform"), our website (https://callflows.ai/), and other related services, online advertisements, content, and communications (collectively, the "Services").

Please read this Privacy Policy carefully. By using our Services, you acknowledge that you have understood and agree to the terms of this policy. If you are a Client, your use of our Services is also governed by our Terms of Service.

You are not legally obligated to provide us with Personal Data. However, some Services may not be available or fully functional without it.

1. What Personal Data We Collect and How

We collect different types of Personal Data depending on your interaction with us:

1.1. Data Processed on Behalf of Our Clients ("Client-Owned Data")

As part of our Platform, we process Personal Data that our Clients (Shopify store owners) provide or instruct us to collect. A core function of our Platform involves integration with our Clients' Shopify stores via the Shopify API, as authorized by the Client. This means much of the Client-Owned Data is sourced directly from, or synchronized with, the Client's Shopify account. This Client-Owned Data may include:

Our Role: When processing Client-Owned Data, Call Flows AI acts as a "data processor" (or "service provider" under laws like CCPA/CPRA) on behalf of our Client, who is the "data controller" (or "business"). Our processing is governed by our agreements with the Client, including our Data Processing Addendum (DPA), and their lawful instructions. Clients are responsible for authorizing our access to their Shopify store data via the Shopify API and for ensuring they have a lawful basis for collecting and instructing us to process this Client-Owned Data, including obtaining necessary consents from End-Users.

1.2. Data of Our Clients and Their Users ("User Data")

We collect Personal Data about our Clients and individuals who use the Platform on their behalf (e.g., account administrators, billing contacts). This User Data includes:

Our Role: For User Data, Call Flows AI acts as a "data controller" (or "business") for our own legitimate business purposes (e.g., service provision, billing, improvement of services). When User Data is part of Client-Owned Data (e.g., usage logs specific to a Client's account), we act as a "data processor".

1.3. Data of Our Website Visitors and Prospects ("Prospect Data")

We collect Personal Data from individuals who visit our website, interact with our online ads, or communicate with us as potential clients or partners. This Prospect Data includes:

Our Role: Call Flows AI acts as a "data controller" (or "business") for Prospect Data.

1.4. Data from AI Interactions (Specific to Voice Services)

Given our service involves AI-powered voice assistants, we specifically collect and process:

CCPA Notice: In the past 12 months, we may have collected the following categories of Personal Data (as defined by the CCPA): Identifiers; Commercial Information; Customer Record Information; Internet or other electronic network activity; Geolocation Data; Audio, Electronic, Visual, or Similar Information; and Inferences. We do not knowingly collect sensitive Personal Data as defined by the CCPA without explicit consent or as directed by our Clients.

2. How We Use Your Personal Data

We use Personal Data for the following purposes, relying on the lawful bases indicated:

2.1. Client-Owned Data:

2.2. User Data & Prospect Data:

3. Data Location and International Transfers

We and our authorized Service Providers (see Section 5) may maintain, store, and process Personal Data in various locations globally. Our primary data storage servers for Call Flows AI are located in the European Union (EU) and the United States (US). Our Service Providers may process data in other jurisdictions, including but not limited to the United Kingdom, Australia, and the Philippines, as reasonably necessary for the proper performance and delivery of our Services, or as may be required by law.

Client-Owned Data will only be processed in locations permitted by our Data Processing Addendum and other agreements with the Client.

Call Flows AI Ltd. is headquartered in Bulgaria, a member state of the European Union, and as such, operates under the General Data Protection Regulation (GDPR). Data processing within the EEA is inherently covered by GDPR. For transfers of Personal Data from the EEA, Switzerland, and the UK to countries outside of these areas that are not considered to offer an adequate level of data protection (such as to some of our Service Providers or to our US-based operations), we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, the UK Information Commissioner's Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC), or other legally approved transfer mechanisms. You can request a copy of the applicable SCCs by contacting us.

Call Flows AI Inc. (our US entity) complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. We adhere to the DPF Principles for Personal Data received from the EU, UK, and Switzerland in reliance on these frameworks. In cases of onward transfers to third parties, we remain liable under the DPF Principles. To learn more and view our certification, please visit https://www.dataprivacyframework.gov/.

4. Data Retention

Client-Owned Data: We retain Client-Owned Data according to our Client's instructions and as specified in our DPA and other agreements with them.

User Data and Prospect Data: We retain this data for as long as reasonably necessary to provide our Services, maintain our relationship with you, comply with legal and contractual obligations, and protect ourselves from potential disputes (e.g., for log-keeping, record-keeping). We determine retention periods based on the nature of the Personal Data, potential risks, processing purposes, and legal requirements.

We are not obligated to retain your Personal Data for any specific period unless required by law or agreement and may delete it at any time. For questions about our data retention policy, contact us at contact@callflows.ai.

5. Data Disclosure and Sharing

We do not sell your Personal Data in the traditional sense. However, some data sharing, particularly in the context of online advertising technologies, might be considered a "sale" or "sharing" under certain US state privacy laws (see Section 12).

We may disclose Personal Data in the following circumstances:

CCPA Disclosure Summary (Last 12 Months): We may have disclosed Identifiers; Internet/electronic network activity; Geolocation Data; Commercial Information; Customer Record Information; Audio/Electronic Information; and Inferences for legal compliance, to Service Providers, within Client accounts, for protecting rights/safety, and to our affiliates. Identifiers; Internet/electronic network activity; Geolocation Data; Customer Record Information; Commercial Information; and Inferences may have been disclosed to Partners and Event Sponsors.

6. Cookies and Tracking Technologies

We and our Service Providers (including advertising partners like Google, Facebook/Meta, X, and Shopify) use cookies, pixels, web beacons, and similar tracking technologies to provide and monitor our Services, analyze performance, personalize your experience, and for advertising purposes (such as serving targeted ads and measuring campaign effectiveness). Such cookies and similar files or tags may also be temporarily placed on your device. Certain cookies and other technologies serve to recall Personal Data, such as an IP address, as indicated by you or collected automatically.

For detailed information about the types of cookies used (including those from third-party advertising partners), why we use them, and how you can manage your cookie preferences (including opting out of certain tracking for advertising purposes), please see our comprehensive Cookie Policy. You may also be able to manage some cookie preferences through our website's "Cookie Settings" feature (if available) or your browser settings.

7. Communications

Service Communications: We may contact you with important information about our Services, such as updates, billing issues, or security notices. You generally cannot opt out of these essential communications.

Promotional Communications: We may send you emails or other messages about new features, special offers, or events. You can opt out of promotional communications at any time by using the "unsubscribe" link in the communication, adjusting your user profile settings, or emailing contact@callflows.ai.

8. Data Security

We are committed to protecting the security of your Personal Data. We implement and maintain a range of reasonable and appropriate industry-standard security measures designed to prevent unauthorized access, use, alteration, disclosure, or destruction of Personal Data. These measures include:

We regularly review and update our security practices to address new and evolving threats and to adapt to changes in industry standards and regulations. However, please be aware that despite our best efforts, no security system is impenetrable, and we cannot guarantee the absolute security of any Personal Data stored with us or with any third parties. The transmission of information via the internet is not completely secure, and any transmission is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on the Services by you or third parties.

If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately notify us by contacting us at contact@callflows.ai.

9. Your Data Subject Rights

Depending on applicable law (e.g., GDPR, CCPA/CPRA, VCDPA), you may have rights concerning your Personal Data, including:

To exercise these rights, please email contact@callflows.ai. We may need to verify your identity before processing your request. If your request concerns Client-Owned Data, we will forward it to the relevant Client (the data controller) as they are responsible for handling such requests.

You may also have the right to lodge a complaint with your local data protection authority.

DPF Inquiries: For complaints related to our Data Privacy Framework compliance, please contact contact@callflows.ai. If unresolved, Call Flows AI Inc. has committed to cooperate with EU DPAs, the UK ICO, and the Swiss FDPIC. Under certain conditions, you may invoke binding arbitration (see DPF Principles). The FTC has investigatory and enforcement powers over Call Flows AI Inc.

10. Data Controller and Processor Roles

Understanding these roles is important under laws like GDPR and CCPA/CPRA:

Our Clients, as data controllers for Client-Owned Data, are responsible for the lawful basis of processing and for responding to data subject requests concerning that data.

11. Security and Data Breach Notification

We have internal incident response policies to manage potential security incidents involving Personal Data. We employ reasonable administrative, technical, and organizational measures to protect Personal Data. In the event of a data breach involving Personal Data that is likely to result in a risk to the rights and freedoms of individuals, we will take steps according to our procedures and applicable laws, which may include notifying affected individuals or authorities in a timely manner as required.

If you have questions about our security practices, contact us at contact@callflows.ai.

12. Additional Notices

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your Personal Data, please contact us at:
Call Flows AI Ltd.
Email: contact@callflows.ai
Bulgaria, Sofia, blvd Vitosha 1A