Privacy Policy

Last Updated: November 8, 2025

1. Introduction

Enactory Ltd ("we," "our," or "us") operates Crewflow ("the Service"), an AI-powered customer support platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

Data Controller: Enactory Ltd (Company Number: 15664650)

We are committed to protecting your privacy and complying with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR).

2. Information We Collect

2.1 Information You Provide to Us

Account Information: Email address, password (encrypted), organization name, display name.

Platform Integrations: OAuth tokens for email platform integrations, help center connections, customer data source integrations.

Customer Support Data: Email conversations processed through our AI, sentiment analysis results, draft responses, customer notes.

2.2 Information Collected Automatically

Usage Data: IP address, browser type and version, device information, features used, time and date of usage, referring URLs.

AI Processing Data: Conversation analysis metrics, response quality feedback, system performance data.

3. How We Use Your Information

We process your personal data for the following purposes:

  • Service Delivery: Provide AI-powered customer support analysis, authenticate users, process conversations, generate response drafts.
    Legal Basis: Performance of a contract (GDPR Art. 6(1)(b))
  • AI Model Improvement: Analyze usage patterns to improve AI accuracy, train sentiment analysis models, optimize response generation.
    Legal Basis: Legitimate interests (GDPR Art. 6(1)(f))
  • Communications: Send product updates, provide customer support, send service notifications.
    Legal Basis: Consent (GDPR Art. 6(1)(a)) for marketing

4. Data Sharing and Disclosure

We do not sell your personal data.

We share information only with trusted third-party service providers:

Provider Purpose Location
Scaleway SAS Hosting, Database & AI Processing France (EU)
Bunny.net CDN & Storage Slovenia (EU)
Stripe, Inc. Payment Processing Ireland (EU)
Mailjet SAS Transactional Email Delivery France (EU)

5. International Data Transfers

Your data stays in the EU.

All data processing occurs within the EU. No international data transfers outside the EU occur.

This means your data remains within EU jurisdiction at all times, providing the highest level of data protection without reliance on EU-US Data Privacy Framework or Standard Contractual Clauses.

6. Data Retention

We retain your personal data only as long as necessary:

  • Account information: Duration of account + 90 days after deletion
  • Conversation data: 90 days from processing (or as required by your retention policy)
  • Analytics data: 1 year from date of collection
  • AI training data: Anonymized and aggregated (no personal identifiers)

7. Your Rights

Under UK GDPR and EU GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data (GDPR Art. 15)
  • Right to Rectification: Correct inaccurate personal data (GDPR Art. 16)
  • Right to Erasure: Request deletion of your data (GDPR Art. 17)
  • Right to Data Portability: Receive your data in a machine-readable format (GDPR Art. 20)
  • Right to Object: Opt out of processing based on legitimate interests (GDPR Art. 21)
  • Right to Lodge a Complaint: Contact the ICO (UK) or your local data protection authority (EU)

How to Exercise Your Rights: Email us at . We will respond within 30 days.

8. Security Measures

We implement industry-standard security practices to protect your data:

  • Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based permissions; strict data isolation per customer
  • AI Processing: Conversations processed in secure EU infrastructure
  • Monitoring: Automated security scanning and anomaly detection
  • Incident Response: 72-hour breach notification process (GDPR Art. 33)

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights:

  • Right to Know: What personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal data
  • Right to Opt-Out: Opt out of the "sale" of personal information (we do not sell data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

10. Contact Us

For privacy inquiries, data requests, or concerns:

Email:

Mail:
Enactory Ltd
27 Old Gloucester Street
London, United Kingdom
WC1N 3AX

Your privacy is our priority.