Privacy Policy
Last updated: July 24, 2026
This policy explains what personal data GenovaFlow ("we", "us") collects when you visit genovaflow.ai (including the blog at /blog) or engage our services, why we collect it, and the rights you have over it. The short version: we collect as little as possible, we don't run advertising trackers, our analytics are cookieless, and we never sell personal data.
1. Who is responsible for your data
GenovaFlow is the data controller for personal data processed through this website. For anything in this policy, contact us at contact@genovaflow.com.
2. What we collect, and why
2.1 Browsing the site: no cookies, and a real opt-out
We use PostHog (EU Cloud) for audience measurement in cookieless mode: our analytics writes nothing to cookies, localStorage, or sessionStorage on your device. Visits are grouped using a privacy-preserving identifier that PostHog derives on its servers from your IP address and browser, salted with a key thatrotates every day and is then discarded, and which includes this site's domain so it cannot follow you anywhere else. In practice that means we can count visits and see which pages work, and we cannot recognise you tomorrow, on another device, or on any other website.
We are deliberate about what we do not collect. We strip the device characteristics analytics tools normally read: screen and window size, timezone, browser language, and operating-system version. The single exception is your browser's user-agent string, which is one of the inputs PostHog needs to compute the daily visit identifier described above, and without which a visit cannot be counted at all. Your browser already sends that same string in the headers of every request it makes to every website it loads, so obtaining it reads nothing further from your device. It is used only as an input to that daily hash, and the salt that produced the hash is deleted afterwards, which is what stops the result from identifying you. Your IP address is anonymised by PostHog and is not kept on the stored record. We do not capture advertising click identifiers (such as Google or Meta click IDs). We record only the domain that referred you, never the full referring address. There is no session recording, no heatmapping, no surveys, and no profiling of individuals.
We do record the marketing source that brought you here (a link's campaign tags, or the referring domain) and your country, determined from the network request as it arrives, never your city, and never a stored IP address. This is how we learn which of our videos or articles brings people to the site.
You can switch analytics off entirely, right here, at any time. We also honour the Global Privacy Control and Do Not Track signals: if your browser sends either, we collect nothing from you without you doing anything at all.
Third-party services are kept to a minimum. We self-host our fonts and all brand logos, so arriving on any page of this site contacts no company other than our own host. The only third party that is ever loaded is the booking calendar, and it is loaded only on the pages where booking a call is the point. That means the booking page itself, and the booking section at the foot of the home page once you scroll towards it. If you never scroll that far, nothing is ever requested from them.
2.2 Booking a call
When you book a call, the scheduling is handled by Cal.com, which collects the details you enter (name, email, notes) so the meeting can happen. We receive that booking information and use it solely to prepare for and follow up on your call. Cal.com is based in the United States, and its booking page sets its own cookies and receives your IP address inside the calendar frame. That is why we load it only where booking is the purpose of the page: immediately on the dedicated booking page, because opening it is itself a request to book, and on the home page only once you scroll down to the booking section. Those cookies are strictly necessary to deliver the booking service you asked for. See Cal.com's privacy policy.
2.3 Remembering your place on the page
If you leave a page and come back within 30 minutes, the site scrolls back to where you were. To do that, your browser keeps the scroll position and a timestamp in its per-tab session storage; the entry expires after 30 minutes of inactivity and disappears when the tab closes. On blog articles the same per-tab session storage also remembers how far you read, only so a small "Resume reading" button can offer to take you back to that spot. The button never moves the page on its own, and dismissing it deletes the saved position. Nothing outlives the browser session: everything above lives in session storage only, stays on your device, is not a cookie, is never transmitted anywhere, and is not connected to analytics. Closing the tab or clearing your browser data removes it immediately.
2.4 Contact forms and email
If you contact us by email or through a form on the blog, we keep the message and your contact details for as long as needed to handle the conversation and any engagement that follows.
2.5 Hosting logs
The site is served by Netlify, whose infrastructure may process IP addresses and request metadata in standard server logs for security and delivery purposes.
3. Legal bases, and why there is no cookie banner
European and UK rules allow websites to measure their own audience without a consent banner, provided the measurement is strictly limited. The conditions are that it is used only to produce statistics about how this site is used, that the data is not shared for any other purpose, that no cross-site tracking or advertising profiling takes place, that you are told about it clearly, and that you are given a simple, free way to object. Our setup is built specifically to meet those conditions. That is why we strip device characteristics, refuse advertising identifiers, keep only the referring domain, and put a working off switch above.
Where the GDPR or similar laws apply: we process booking and contact data to take steps toward a contract with you (Art. 6(1)(b)); audience measurement and site security rest on our legitimate interest in understanding and protecting the service (Art. 6(1)(f)), and you can object with one click above, or by email; the AI demo runs on your consent, given when you click to start it (Art. 6(1)(a)).
4. Who we share data with
We share personal data only with the processors needed to run the service:
- Netlify: website hosting and delivery.
- Cal.com: call scheduling (loaded on the booking page, and in the booking section of the home page when you scroll to it).
- PostHog (EU Cloud): cookieless analytics, data stored in the EU.
- Supabase: storage for blog contact-form submissions.
We removed Google Analytics from this site in July 2026, along with every third-party font and icon service, so that ordinary browsing involves no advertising or profiling company whatsoever.
We do not sell personal data, and we do not share it with advertisers or data brokers.
5. Client project data
When we build AI agents for a client business, conversation data, prompts, and logs belong to the client. We access client systems under least-privilege credentials the client controls, use that access only to deliver the agreed work, and do not use client data to train models of our own. Details are set per engagement in the applicable agreement.
6. Retention
- Analytics events: retained by PostHog for up to 12 months, then deleted.
- The visit identifier: the salt that produces it is rotated daily and discarded, so visits cannot be linked across days at all.
- Booking records: kept for the duration of our relationship and up to 24 months afterwards for record-keeping, then deleted.
- Email and form correspondence: kept for as long as needed to handle the conversation and any engagement that follows, and up to 24 months afterwards.
You can ask us to delete your data at any time (see below), and we will.
6a. For visitors in the United States
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We run no advertising pixels of any kind. If your browser sends a Global Privacy Control signal, we treat it as an instruction to stop collecting analytics from you, and we act on it automatically.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete the personal data we hold about you, and to lodge a complaint with your supervisory authority. Email contact@genovaflow.com and we'll act on it promptly. there is no dark-pattern process here.
8. International transfers
Our analytics data stays in the EU. Some processors (for example Netlify or Cal.com) may process data in other countries; where they do, transfers rely on recognized safeguards such as standard contractual clauses.
9. Changes
If this policy changes materially, we'll update this page and the date at the top. We won't quietly weaken it.