Privacy Policy

Effective Date: 01/16/2023
Last Updated: 07/01/2026

This Privacy Policy applies to personal data that Mindflow processes for its own purposes, including data relating to website visitors, prospects, customers, account users, support contacts and job applicants. It does not govern Customer Content or Customer Personal Data processed by Mindflow on behalf of a customer, which is governed by the applicable agreement and Data Processing Agreement.

Who is responsible for your personal data?

Who is responsible for your personal data?

The data controller is Mindflow, a société par actions simplifiée registered with the Paris Trade and Companies Register under number 893 124 511, with registered office at 128 rue La Boétie, 75008 Paris, France.

Privacy contact and Data Protection Officer: privacy@mindflow.io.

When customers use the Mindflow platform to process Customer Content or Customer Personal Data for their own purposes, the customer determines the relevant purposes and means of processing and Mindflow acts as a Processor or Subprocessor, as described in the Data Processing Agreement.

Who does this Policy apply to?

Who does this Policy apply to?

  • Visitors to the Mindflow website and users of website forms;

  • Prospects, commercial contacts, partners and event participants;

  • Customers, account administrators and authorised users, including users of paid, free, trial or Community Editions;

  • People who contact customer support or otherwise communicate with Mindflow;

  • Job applicants and prospective team members; and

  • Other individuals whose professional contact information is lawfully provided to Mindflow.

What personal data do we collect?

What personal data do we collect?

  • Identity and contact data, such as name, business email address, phone number, postal address and user identifier;

  • Professional data, such as employer, role, department, business interests and professional profile information;

  • Account and authentication data, such as account identifier, login information, role and access settings;

  • Contract, transaction and billing data, such as Order Forms, invoices, billing contacts and payment status. Full payment-card details are processed by the applicable payment provider, where relevant;

  • Technical and usage data, such as IP address, browser, device, operating system, timestamps, pages or features used, referral source, security events and diagnostic logs;

  • Communications data, including demo requests, form submissions, support messages, meeting information and feedback;

  • Marketing and preference data, including subscriptions, communication preferences, campaign interactions and event participation;

  • Recruitment data, including CV, application information, qualifications, professional history and interview notes; and

  • Information that you voluntarily provide to Mindflow.

Why do we process personal data?

Why do we process personal data?

Purposes

Typical data

Legal basis

Typical retention

Responding to enquiries, demo requests and commercial discussions

Identity, contact, professional and communication data

Steps taken at your request before entering a contract and/or Mindflow’s legitimate interest in responding and developing its business

Up to 3 years after the last meaningful contact, unless a relationship continues or a shorter period is required

Creating and administering accounts, including free, trial and Community Editions

Identity, contact, account, authentication, technical and usage data

Performance of the applicable Terms or contract; legitimate interest in administering and securing the Services

For the life of the account, then generally up to 24 months, subject to security, legal and contractual requirements

Managing contracts, orders, invoices and customer relationships

Identity, professional, contract, transaction and billing data

Performance of a contract; compliance with legal obligations; legitimate interest in business administration

For the business relationship, then archived as required for evidence and legal obligations; invoices are generally retained for 10 years

Providing support and communicating with users

Identity, account, communications, diagnostic and technical data

Performance of a contract and/or legitimate interest in responding, supporting users and improving service quality

For the time needed to handle the request, then generally up to 3 years where needed for follow-up, evidence or service improvement

Securing, operating and improving the website and Services

Technical, usage, account, security, diagnostic and aggregated data

Legitimate interest in operating, protecting and improving Mindflow; compliance with legal obligations where applicable

Security and connection logs are generally retained for 6 to 12 months, or longer where reasonably necessary to investigate an incident or comply with law

Website analytics and audience measurement

Cookie identifiers, IP address, browser, device and browsing data

Consent where required; legitimate interest for strictly necessary or exempt measurement where permitted by law

As described in the Cookie Policy and the applicable consent-management settings

Marketing and business communications

Identity, professional, contact, preference and interaction data

Consent where required; otherwise legitimate interest in B2B communications, subject to your right to object

Until consent is withdrawn or objection is received, and generally no longer than 3 years after the last meaningful interaction

Recruitment

Identity, contact, CV, qualifications, employment history and interview information

Steps before entering an employment contract; legitimate interest in assessing candidates; consent for an extended candidate pool

For the recruitment process; up to 2 years after the last contact where consent has been provided for the candidate pool

Compliance, disputes and protection of rights

Any data reasonably relevant to the obligation, investigation, claim or dispute

Legal obligation and/or legitimate interest in establishing, exercising or defending legal rights

For the applicable statutory limitation period or as required by law

Website hosting and Framer

Website hosting and Framer

The Mindflow website is designed, published and hosted using Framer, provided by Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands. Framer processes website technical data and, where applicable, website form submissions on Mindflow’s behalf as a service provider.

Framer may use cloud infrastructure and other subprocessors located within or outside the European Economic Area. Where a transfer outside the EEA takes place, Mindflow and its providers rely on an applicable adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism. Mindflow does not represent that all website data is hosted exclusively in the European Union.

Artificial intelligence features

Artificial intelligence features

Mindflow may process account, usage, security and support information associated with AI Features for the purposes described in this Policy. AI Inputs, AI Outputs, Customer Configurations and Customer Data processed on behalf of a customer are governed by the applicable Terms and Data Processing Agreement.

Mindflow does not use Customer Data, AI Inputs, AI Outputs or Customer Configurations to train or fine-tune a general-purpose artificial intelligence model unless the customer expressly opts in in writing. Where a user connects a customer-managed AI account or API key, the selected provider’s terms and settings also apply.

Cookies and similar technologies

Cookies and similar technologies

The website uses cookies and similar technologies for essential functionality and, subject to your choices, analytics, personalisation and marketing. Non-essential technologies are used only where permitted and, when required, after consent.

You can review the current categories and providers, change your choices or withdraw consent through the Cookie Policy and the Cookie Preferences control available on the website. Withdrawing consent does not affect processing that occurred before withdrawal.

For more information on cookies management, please consult our Cookies Policy (www.mindflow.io/cookie-policy-eu)

Who receives personal data?

Who receives personal data?

Personal data may be accessed, on a need-to-know basis, by:

  • Authorised Mindflow personnel;

  • Website, cloud, hosting and content-management providers, including Framer;

  • CRM, marketing, communications, scheduling and event providers;

  • Customer support, collaboration and productivity providers;

  • Analytics, security, monitoring and fraud-prevention providers;

  • Recruitment platforms and professional advisers;

  • Payment, accounting and financial service providers; and

  • Public authorities, courts or other recipients where disclosure is required by law or necessary to protect legal rights.

Mindflow may also disclose personal data in connection with a proposed or completed financing, merger, acquisition, reorganisation or transfer of all or part of its business, subject to appropriate confidentiality and data-protection safeguards.

International transfers

International transfers

Some service providers may process personal data outside the EEA. Mindflow uses appropriate safeguards for such transfers, including adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses and supplementary technical, organisational or contractual measures where required.

You may request further information about the safeguards applicable to a particular transfer by contacting privacy@mindflow.io.

Security

Security

Mindflow implements appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure. No information system is completely secure, and Mindflow cannot guarantee absolute security.

Your rights

Your rights

Subject to applicable law, you may have the right to:

  • Obtain information about and access to your personal data;

  • Request correction of inaccurate or incomplete data;

  • Request deletion or restriction of processing;

  • Object to processing based on legitimate interests and object at any time to direct marketing;

  • Withdraw consent at any time where processing is based on consent;

  • Receive data you provided in a structured, commonly used and machine-readable format where the right to portability applies;

  • Provide instructions concerning personal data after death where French law applies; and

  • Lodge a complaint with the CNIL or another competent supervisory authority.

To exercise a right, contact privacy@mindflow.io. Mindflow may request information reasonably necessary to verify your identity and will respond within the periods required by applicable law.

Children

Children

The website and Services are intended for professional and business use and are not directed to children. Mindflow does not knowingly collect personal data from children through the website.

Changes to this Policy

Changes to this Policy

Mindflow may update this Privacy Policy to reflect changes in its activities, Services or legal obligations. The date at the top of the Policy identifies the latest version. Where a change is material, Mindflow will provide additional notice where reasonably appropriate.

Contact

Contact

Mindflow — 128 rue La Boétie, 75008 Paris, France

Email: privacy@mindflow.io

Data Protection Officer: privacy@mindflow.io