Legal
Privacy Policy
ContentFlow ("we", "us") respects your privacy and processes personal data in line with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations. This policy explains what we collect through this website, how we use it, and the rights you have over your data.
What we collect
When you contact us through this site, we collect only the details you choose to share:
- Name: so we can address you correctly.
- Company: to understand your organisation and context.
- Work email: to reply to your inquiry.
- Message: the content of your request.
Website analytics run only with your consent and are aggregate. They measure page views and traffic trends, with IP addresses anonymized.
How we use your data
We use the details you provide to:
- Respond to your inquiries and questions.
- Arrange product demos and follow-up conversations.
- Share relevant product information you have asked about.
We do not sell personal data, and we do not use your contact details for unrelated marketing.
Legal basis
Under the PDPL, we process your data on the basis of your consent when you submit an inquiry, and on the basis of our legitimate business interest in responding to and managing that inquiry. Where processing relies on consent, you may withdraw it at any time.
Sharing and processors
We do not sell or trade personal data. We share limited information with the sub-processors named below, who help us operate this website and platform and communicate with you. These providers act on our instructions and are bound to protect your data. We may also disclose data where required by applicable law or competent authority.
Sub-processors
- Cloud hosting (Riyadh, Saudi Arabia, inside the Kingdom): runs the application, the database and file storage.
- Off-site encrypted backup storage (outside the Kingdom): stores nightly backups, encrypted with AES-256 before they leave our infrastructure.
- Google Analytics 4 and Microsoft Clarity (outside the Kingdom): website analytics only, loaded only after a visitor accepts the cookie banner.
- Google's font service (outside the Kingdom): supplies the typefaces used across the site. Loads on every page before any cookie choice, because the page cannot render its text without them; the request necessarily discloses the visitor's IP address and browser to Google. Not analytics, and no cookie is set by it.
- A Saudi payment gateway (inside the Kingdom): processes card payments for paid plans.
- Twilio (outside the Kingdom): delivers SMS and WhatsApp messages, used only when a customer enables those channels.
- Firebase Cloud Messaging (outside the Kingdom): delivers push notifications, used only when a customer enables push.
- A transactional email provider (outside the Kingdom): sends sign-up, verification and notification email. We are not naming this provider here because it was not independently verifiable this round.
- Inbound contact email (outside the Kingdom): mail sent to our published contact address is received and stored through Google's business email service, and is kept only as long as needed to answer the inquiry.
Data retention
We keep inquiry data only as long as needed to respond to your request and maintain a reasonable record of our correspondence, after which it is deleted or anonymised. Aggregate, non-identifying analytics may be retained indefinitely.
Your rights under the PDPL
Subject to the conditions and exceptions in the PDPL, you have the right to:
- Access: request confirmation of, and access to, the personal data we hold about you.
- Correction: request that inaccurate or incomplete data be corrected.
- Deletion: request that your personal data be deleted.
- Object or restrict: object to or request restriction of certain processing.
- Withdraw consent: withdraw consent you previously gave, without affecting processing already carried out.
To exercise any of these rights, email hello@contentflow.click. We will respond within the timeframes required by the PDPL and may need to verify your identity before acting on a request.
Security
We apply reasonable organisational and technical measures to protect personal data against unauthorised access, disclosure, alteration, or loss. No method of transmission or storage is completely secure, but we work to keep our safeguards appropriate to the sensitivity of the data we handle.
Data residency and international transfers
Today ContentFlow runs as a single deployment on infrastructure located in Riyadh, Saudi Arabia, so production content and end-user data are processed in the Kingdom; that is a property of how we are currently deployed rather than a control the product enforces, encrypted backups and some third-party processors are handled outside the Kingdom, and an in-Kingdom-only arrangement is something we agree in writing on an Enterprise plan rather than something this page can promise.
Where data is transferred internationally, we take steps to ensure an adequate level of protection consistent with the PDPL.
Processing on behalf of clients
When ContentFlow processes end-user data on behalf of a client (for example, content and workspace data within a customer's account), the client remains the data controller and ContentFlow acts as a data processor. That processing is governed by our agreement with the client, and inquiries about such data should be directed to the relevant client.
Cookies and analytics
With your consent, this website uses Google Analytics to understand aggregate traffic. Analytics loads only after you accept the cookie banner, IP addresses are anonymized, and we do not set advertising or remarketing cookies. Declining sets no analytics cookies at all. For details, see our cookies notice.
With your consent, we also use Microsoft Clarity to see how visitors use the site through aggregated metrics, heatmaps, and session replays. It is provided by Microsoft and data is processed under Microsoft's privacy terms. Session replays mask text you type. Like our other analytics, Clarity only loads after you accept the cookie banner.
Separately from analytics, this page and others on the site load their typefaces from Google's font service on every page load, before any cookie choice is made, because the page cannot render its text without them; that request necessarily discloses your IP address and browser details to Google, sets no cookie, and is not analytics, though Google is a recipient of that limited technical data as a result. We are looking at serving these typefaces ourselves to remove this dependency; no date is set for that change. Some pages on this site also write a randomly generated, first-party identifier to your browser's local storage before you choose, used only to fetch that page's own text from our servers. Neither is analytics and neither is gated by the cookie banner. Full detail on what each page stores and when is in the Cookies, local storage and analytics section of our Terms.
Children
Our service is directed at businesses and is not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. When we do, we will revise the "Last updated" date above. Material changes will be communicated where appropriate.
Contact
For any question about this policy or your personal data, email hello@contentflow.click.