Privacy Policy
Last updated: July 24, 2026
This policy explains what personal data Genovaflow ("we", "us") collects when you visit genovaflow.ai (including the blog at /blog) or engage our services, why we collect it, and the rights you have over it. The short version: we collect as little as possible, we don't run advertising trackers, our analytics are cookieless, and we never sell personal data.
1. Who is responsible for your data
Genovaflow is the data controller for personal data processed through this website. For anything in this policy, contact us at contact@genovaflow.com.
2. What we collect, and why
2.1 Browsing the site — no cookies
We use PostHog (EU Cloud) for analytics in cookieless mode: it stores nothing in cookies, localStorage, or sessionStorage on your device, which is why this site shows no cookie banner. Analytics data is limited to pseudonymous usage events (pages viewed, buttons clicked, approximate session grouping derived from a daily-rotating hash). We do not use this data to identify you, and we do not run any advertising or cross-site tracking.
2.2 Booking a call
When you book a call, the scheduling is handled by Cal.com, which collects the details you enter (name, email, notes) so the meeting can happen. We receive that booking information and use it solely to prepare for and follow up on your call. See Cal.com's privacy policy.
2.3 The live AI demo (if you choose to use it)
If the site offers a live "talk to our AI" demo and you start a conversation, your microphone audio and chat messages are processed by our voice platform provider to run the conversation. The demo only activates when you explicitly start it, and your browser will ask for microphone permission first. Don't share sensitive personal information in a demo conversation.
2.4 Contact forms and email
If you contact us by email or through a form on the blog, we keep the message and your contact details for as long as needed to handle the conversation and any engagement that follows.
2.5 Hosting logs
The site is served by Netlify, whose infrastructure may process IP addresses and request metadata in standard server logs for security and delivery purposes.
3. Legal bases
Where the GDPR or similar laws apply: we process booking and contact data to take steps toward a contract with you (Art. 6(1)(b)); cookieless analytics and site security rest on our legitimate interest in understanding and protecting the service (Art. 6(1)(f)); the voice demo runs on your consent, given when you start it (Art. 6(1)(a)).
4. Who we share data with
We share personal data only with the processors needed to run the service:
- Netlify — website hosting and delivery.
- Cal.com — call scheduling.
- PostHog (EU Cloud) — cookieless analytics, data stored in the EU.
- Supabase — storage for blog contact-form submissions.
- Voice platform provider — only if you start a live AI demo conversation.
We do not sell personal data, and we do not share it with advertisers or data brokers.
5. Client project data
When we build AI agents for a client business, conversation data, prompts, and logs belong to the client. We access client systems under least-privilege credentials the client controls, use that access only to deliver the agreed work, and do not use client data to train models of our own. Details are set per engagement in the applicable agreement.
6. Retention
Analytics events are retained by PostHog for up to one year. Booking and correspondence data are kept for the duration of our relationship and for a reasonable period afterwards for record-keeping. You can ask us to delete your data at any time (see below).
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete the personal data we hold about you, and to lodge a complaint with your supervisory authority. Email contact@genovaflow.com and we'll act on it promptly — there is no dark-pattern process here.
8. International transfers
Our analytics data stays in the EU. Some processors (for example Netlify or Cal.com) may process data in other countries; where they do, transfers rely on recognized safeguards such as standard contractual clauses.
9. Changes
If this policy changes materially, we'll update this page and the date at the top. We won't quietly weaken it.