Privacy Policy

Effective Date: 01/16/2023
Last Updated: 01/16/2023

You can read this privacy policy in french here.

This Privacy Policy describes the privacy practices of Mindflow (“Mindflow,” “we,” or “us”). It applies to the information we collect about you when you use our website (https://mindflow.io/) or services (collectively, the “Services”), or when you otherwise communicate with us. Please note that our Services are designed for enterprise customers, and we process personal information of business contacts who work for those customers. This statement does not apply to the information we process on behalf of our customers via our service (which is subject to our customer agreements), but it does apply to the information we collect about the individuals that use these solutions on behalf of our customers. 

We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this statement and in cases where there are material changes, we will provide you with additional notice (such as adding a statement to our website homepage or sending you a notification) prior to the changes becoming effective. We encourage you to review the Privacy Policy whenever you access the Services or otherwise interact with us to stay informed about our information practices and the choices available to you.

Who is the data controller?

Who is the data controller?

The data controller is MINDFLOW, a simplified joint-stock company registered with the Registry of Trade and Companies of Paris under the number 839 124 511 and whose head office is located at 128 rue de la Boétie 75008 Paris (hereinafter “Us” or “We”).

However, when our customers use our services, we collect and process personal data on their behalf and for their own purposes. Our customers are, therefore, data controllers in accordance with Article 4 of GDPR. We act as a processor and as a service provider.

What personal data do we collect?

What personal data do we collect?

Personal data is a data that identifies an individual directly or indirectly, in particular by reference to an identifier such as a name.

We may collect the following personal data:

  • Identification data (last name, first name, email address, postal address, phone number, user name/relevant client ID);

  • Data relating to your professional life (company name, job title);

  • Connection data (logs, encrypted password);

  • Browsing data (IP address, pages viewed, date and time of connection, browser used, operating system, user ID, advertising ID, device type);

  • Data related to recordings from telephone calls with our customer care service (content of the calls, dates of the calls);

  • Data you voluntarily choose to share with Mindflow

We inform you when collecting your personal data whether some of these data are mandatory or optional. Mandatory data are indicated with an asterisk. 

On what legal basis, for what purposes, and for how long do we keep your personal data?

On what legal basis, for what purposes, and for how long do we keep your personal data?

Purposes

Legal basis

Data retention period

To provide you with a demo of our services and to contact you if necessary.

Our legitimate interest to provide you with a demo of our services.

Your personal data are retained for a period of 3 years starting from the last contact with us.

To create an account on the Website.

Taking steps at your request prior to entering into a contract.

Your personal data are retained for the duration of your account.
Your connection logs are kept for 6 months to 1 year. 
If your account is inactive for a period of 2 years, it will be deleted if you do not respond to our reactivation email.

To perform operations related to contracts, orders, invoices and customer relationship management.

Performance of a contract to which you are party.

Personal data are retained for the duration of our business relationship. In addition, the data relating to your transactions are archived for probationary purposes for a period of 5 years.

To create a database of customers and leads.

Our legitimate interest in developing and promoting our business.

For our customers: their personal data are retained for the duration of our business relationship. For our leads: their personal data are retained for a period of 3 years starting from the last contact with you.

To send newsletters, requests, and direct marketing mailings.

Our legitimate interest in winning customer loyalty and informing our customers/leads of our latest news.

Personal data are retained for a period of 3 years starting from the last contact with you (e.g., communication, action).

To answer your information request and other inquiries.

Our legitimate interest in responding to your inquiries.

Personal data are retained during the processing of your request and is deleted once the request has been processed.

To improve our services.

Our legitimate interest in improving our services.

Recording of telephone calls: 6 months from the date of collection Telephone call content analysis documents: 1 year from the date of collection.

To process your applications.

Taking steps at your request prior to entering into a contract.

The data are retained for the necessary time to process your application.

To create an applicant pool.

Your consent.

Personal data are retained for a period of 2 years from the last contact with you.

To comply with our legal and regulatory obligations.

Legal and regulatory obligations.

Invoices are archived for a period of 10 years. In addition, the data relating to your transactions are archived for probationary purposes for a period of 5 years.

To elaborate analytics on your navigation and on the audience of the Website.

Your consent.

The personal data are retained for 2 months.

To process data subjects’ requests to exercise their rights.

Our legitimate interest in responding to your requests and keeping records of them.

If we ask you a proof of identity: we only retain it for the necessary time to verify your identity. Once the verification has been carried out, the proof is deleted. If you exercise your right to object to direct marketing: we keep this information for 3 years.

Who are the recipients of your personal data?

Who are the recipients of your personal data?

Will have access to your personal data:

  1. The staff of our company;

  2. Our processors: hosting provider, our CMS tool, newsletter sending service provider, CRM, automation communication platform, job board, knowledge sharing tool;

  3. If applicable: public and private organizations, exclusively to comply with our legal obligations.

Are your personal data likely to be transferred outside the European Union?

Are your personal data likely to be transferred outside the European Union?

Your personal data is hosted for the duration of the processing on the servers of the company Vultr, located in the European Union.

As part of the tools we use (see the article on the recipients of your personal data, especially our processors), your personal data may be transferred outside the European Union. The transfer of your personal data in this context is secured with the use of the following safeguards:

  • Either personal data are transferred to a country that has been recognized as ensuring an adequate level of protection by a decision of the European Commission, in accordance with article 45 of the GDPR: in this case, this country ensures a level of protection deemed sufficient and adequate to the provisions of the GDPR; or

  • The personal data are transferred to a country whose level of data protection has not been recognized as adequate to the GDPR: in this case, these transfers are based on appropriate safeguards indicated in article 46 of the GDPR, adapted to each provider, including but not limited to the execution of Standard Contractual Clauses approved by the European Commission, the application of Binding Corporate Rules or under an approved certification mechanism; or 

  • The personal data are transferred under any appropriate safeguards described in Chapter V of the GDPR.

What rights do you have regarding your personal data?

What rights do you have regarding your personal data?

You have the following rights with regard to your personal data:

  • Right to be informed: this is precisely why we have drafted this privacy policy as defined by articles 13 and 14 of the GDPR.

  • Right of access: you have the right to access all your personal data at any time as defined by article 15 of the GDPR.

  • Right to rectification: you have the right to rectify your inaccurate, incomplete or obsolete personal data at any time as defined by article 16 of the GDPR.

  • Right to restriction of processing: you have the right to restrict the processing of your personal data in certain cases defined in article 18 of the GDPR.

  • Right to erasure (“right to be forgotten”): you have the right to request that your personal data be deleted and to prohibit any future collection as defined by article 17 of the GDPR.

  • Right to file a complaint to a competent supervisory authority (in France, the CNIL) under GDPR article 77 if you consider that the processing of your personal data constitutes a breach of applicable regulations.

  • Right to define instructions related to the retention, deletion, and communication of your personal data after your death.

  • Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the GDPR provides that you may withdraw your consent at any time. Such withdrawal will not affect the lawfulness of the processing carried out before the withdrawal.

  • Right to data portability: under specific conditions defined in article 20 of the GDPR, you have the right to receive the personal data you have provided us in a standard machine-readable format and to require their transfer to the recipient of your choice.

  • Right to object: You have the right to object to the processing of your personal data as defined by article 21 of the GDPR. Please note that we may continue to process your personal data despite this opposition for legitimate reasons or for the defense of legal claims.

You can exercise these rights by writing us using the contact details below. For this matter we may ask you to provide us with additional information or documents to prove your identity.

What cookies do we use?

What cookies do we use?

For more information on cookies management, please consult our Cookies Policy (www.mindflow.io/cookie-policy-eu)

Contact information for data privacy matters

Contact information for data privacy matters

Contact email: privacy@mindflow.io

Contact address: 128 rue de la Boétie 75008 Paris — FRANCE