INFLOWAVE PRIVACY POLICY

Last Updated: March 2026

This privacy notice for AIAGS Ltd d/b/a Inflowave ("Inflowave", "we", "us", or "our"), describes how and why we collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:

  • Visit our website at https://inflowave.io, or any website of ours that links to this Privacy Policy.
  • Use the Inflowave platform, marketplace, API, integrations, dashboard, or any other applications we provide.
  • Connect third-party accounts (e.g., Instagram, Facebook, Google Calendar, Zoom).
  • Engage with us via onboarding calls, offboarding calls, support, live chat, email, or any sales or marketing activities.

Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices.

If you do not agree with our policies and practices, do not use our Services.

For further inquiries, contact support@inflowave.io.


SUMMARY OF KEY POINTS

This summary provides key points from our privacy notice. You can find out more details by clicking the link associated with each key point or by using the TABLE OF CONTENTS below.

What personal information do we process?

When you visit, register, or use our Services, we process personal information such as contact details, usage logs, connected account data, calendar content, communication transcripts, analytics, demographic information, business data, and payment status.

See: WHAT INFORMATION DO WE COLLECT?

Do we process sensitive data?

We do not collect or process sensitive categories such as health, religious, biometric, political, or ethnicity data.

See: WHAT INFORMATION DO WE COLLECT?

Do we receive information from third parties?

Yes. We process data from connected platforms such as Instagram, Facebook, Google Calendar (read/write access), Zoom, and your usage of extensions or APIs.

See: WHAT INFORMATION DO WE COLLECT?

How do we process your information?

We process your information to provide and improve our Services, deliver CRM and automation features, recommend marketplace connections, train AI models only if explicitly introduced in the future and only with opt-in consent, and comply with security and legal requirements.

See: HOW DO WE PROCESS YOUR INFORMATION?

Do we share your information?

We only share data with service providers (e.g., hosting, payments, security monitoring, email delivery). We do not sell personal data.

See: WHEN AND WITH WHOM DO WE SHARE PERSONAL INFORMATION?

How long do we keep your data?

We retain data according to a category-based retention schedule (see Section 5), including up to 12 months for CRM data and longer where legally required.

See: HOW LONG DO WE KEEP YOUR INFORMATION?

How do we keep your information safe?

We maintain strong technical and organizational security controls (encryption, hashing, TLS, CSP, rate limiting, secret scanning, RLS, and SOC/ISO vendor compliance).

See: HOW DO WE KEEP YOUR INFORMATION SAFE?

Do we collect data from minors?

No. Users must be 18 or older.

See: DO WE COLLECT INFORMATION FROM MINORS?

What are your rights?

Depending on your location, you may have rights regarding accessing, deleting, correcting, restricting, or exporting your data.

See: WHAT ARE YOUR PRIVACY RIGHTS?

How can you exercise your rights?

Submit your request to: support@inflowave.io


TABLE OF CONTENTS


1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In short: We collect personal information you voluntarily provide to us.

We collect personal information that you provide when you register, subscribe, connect accounts, participate in calls, upload content, interact with our platform, or communicate with us.

The personal information we collect includes, but is not limited to:

  • Name, email address, phone number
  • Login credentials (stored encrypted/hashed)
  • Instagram/Facebook profile identifiers
  • Social media analytics and messaging metadata
  • Google Calendar events (read/write where authorized)
  • Zoom meeting data (only as required to schedule or join sessions)
  • Marketplace profile data (voluntary opt-in)
  • CRM data, lead details, message history, and contact lists
  • Communication transcripts from in-app support or chat
  • Demographic and business category selection
  • Payment status (paid/unpaid), plan tier, transaction times

(full payment card details are stored by Stripe and not by Inflowave)

Sensitive Information.

We do not process sensitive information (such as health, religion, politics, biometric data, or protected classification data).

Payment Data.

Payments are processed by third-party providers including Stripe and CoinPayments (for crypto transactions). We only store whether you have paid and your subscription history. Full card or wallet information is never stored by Inflowave. For more on their policies, visit:


Information automatically collected

In short: We automatically collect certain device and usage information.

We collect logs and diagnostic data required for:

  • Security
  • Analytics
  • Performance optimization
  • Fraud and abuse prevention

This includes:

  • IP address
  • Device and browser characteristics
  • Operating system, language preferences
  • Session IDs, click actions, timestamps
  • Feature usage, pages accessed, scroll and UI events
  • Error logs, crash reports, and throttling data
  • Login history, authentication events, failed login attempts

Heatmaps and user journey recordings

We may use tools like Microsoft Clarity (on certain pages) for UX research. These recordings exclude social media message content and sensitive data fields.


Information collected from integrations

When you connect third-party accounts, we may process relevant authorized data from:

IntegrationPurpose
Instagram/FacebookMessaging access, analytics, automation, CRM enrichment
Google Calendar (Read/Write)Scheduling content and events
ZoomJoining, generating, or scheduling calls
API/WebhooksSending or receiving Inflowave CRM data

We collect only data needed to provide our Services.


Marketplace Data (Opt-In Only)

If you join our marketplace, you may choose what information to display publicly. This may include:

  • Follower count
  • Engagement metrics
  • Audience demographics (aggregated)
  • Industry/style categories
  • Pricing ranges or collaboration preferences

You control what is displayed and may remove marketplace visibility at any time.


2. HOW DO WE PROCESS YOUR INFORMATION?

In short: We process your information to operate our Services, deliver automation and analytics, improve user experience, ensure security, comply with legal requirements, and—only if you opt in—to train our AI systems.

We process your personal data for the following purposes:

A. To facilitate account creation, authentication, and platform access

This includes:

  • Multi-step onboarding verification (including calls)
  • Credential management and session tracking
  • Integrations authorization and disconnection
  • Offboarding procedures before account cancellation

B. To provide and maintain core platform functionality

Including but not limited to:

  • Unified messaging inbox
  • Social media automation (DMs, comments, scheduling)
  • CRM contact storage and AI responses
  • Calendar event creation, suggestions, and reminders
  • Analytics reporting and influencer/brand metrics
  • Audience and engagement insights

C. AI and Automated Processing

Inflowave does not use customer conversations, CRM data, or social media messages to train artificial intelligence models by default.

If AI-based training or learning is introduced in the future:

  • It will be strictly opt-in
  • It will require explicit user consent
  • It will be governed by a separate AI Data Consent Policy

Users may withdraw consent at any time without impacting their ability to use the platform.

D. To maintain marketplace listings

If enabled by the user:

  • Marketplace profiles
  • Profile metrics
  • Suggested collaborations
  • Visibility to brands/influencers

Marketplace participation is voluntary and revocable.

E. To send administrative information

We may use information to send:

  • Account notices
  • Security alerts
  • Renewal reminders
  • Offboarding requests before cancellation
  • Payment failure notifications

F. For support, onboarding, and offboarding communications

We may process data to:

  • Troubleshoot issues
  • Conduct onboarding and training sessions
  • Verify removal of connected accounts before cancellation
  • Ensure safe termination of integrations

G. For training, auditing, and quality control

This may include:

  • Support call recordings (if applicable)
  • Interaction logs
  • User behavior analysis (for quality improvement)
  • Testing new features in controlled environments

H. For marketing and promotional purposes

We may process personal information to:

  • Send promotional and product update emails
  • Deliver targeted ads to your business on platforms like Facebook & Google (business targeting only)
  • Improve retargeting accuracy using first-party conversion APIs

Server-Side Conversion Tracking

We use server-side conversion tracking (Meta Conversions API and Google Analytics Measurement Protocol) to measure the effectiveness of our advertising. When you register for an account or complete a purchase, we send hashed, non-reversible identifiers (such as a SHA-256 hash of your email address) to Meta and Google from our servers. This does not use cookies or any client-side tracking technology.

The legal basis for this processing is:

  • Contract performance (GDPR Art. 6(1)(b)) — tracking that a registration or purchase occurred is necessary to fulfill our contractual obligations (account activation, billing).
  • Legitimate interest (GDPR Art. 6(1)(f)) — measuring advertising effectiveness to allocate marketing spend efficiently, which does not override your rights given the data is irreversibly hashed before transmission.

Data sent server-side includes only: hashed email, hashed name (if provided), event type (e.g., "Purchase", "Registration"), transaction value, and a unique event identifier for deduplication. No browsing behavior, device fingerprint, IP address, or cookie data is transmitted.

You may opt out of marketing communications at any time.

I. To deliver billing, subscriptions, and refunds

We process information necessary for:

  • Payment verification
  • Subscription status tracking
  • Refund eligibility decisions
  • Chargeback dispute responses

J. To protect our Services

Including:

  • Fraud detection
  • Abuse prevention
  • Account takeover monitoring
  • Enforcement against prohibited activities

K. To comply with law

We may process information to:

  • Meet legal obligations
  • Respond to lawful requests
  • Fulfill tax or regulatory requirements
  • Maintain transaction records

In short: We process your personal information only when legally permitted.

A. Contractual Necessity

To provide the Services requested by you, including:

  • Account creation
  • Integrations and automation
  • Analytics and reporting
  • Marketplace participation when opted in

Required for:

  • AI data usage
  • Marketplace visibility
  • Marketing communications
  • Certain tracking and analytics technologies

You may withdraw consent at any time.

C. Legitimate Interests

Where processing is reasonably expected and does not override your rights, including:

  • Platform improvement
  • Internal security and fraud prevention
  • Trend analysis and optimization
  • Business targeting ads (not personal targeting)

Including tax, compliance, and regulatory retention requirements.

E. Vital Interests

Such as preventing harm due to fraud, account hijacking, or malicious use.


4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In short: We only share information with service providers, regulatory authorities when required, and with marketplace participants if you choose to share.

We share data with the following categories of recipients:

CategorySub-ProcessorCompliance
Database & AuthCloud database provider (AWS)SOC 2 Type II, AES-256
Secret ManagementCloud KMS providerSOC 2, ISO 27001, FIPS 140-2
Payment ProcessingStripePCI DSS Level 1
Crypto PaymentsCoinPaymentsPCI compliant
Email DeliverySendGrid (Twilio)SOC 2 Type II, ISO 27001
UX AnalyticsMicrosoft ClarityGDPR compliant
Social PlatformMeta (Instagram/Facebook)EU-US Data Privacy Framework
Calendar IntegrationGoogle Calendar APISOC 2, ISO 27001
Video ConferencingZoomSOC 2 Type II
Marketplace ConnectionsOnly if user opts inN/A

Business Transfers

If Inflowave is involved in a merger, acquisition, restructuring, financing, or sale of company assets, your information may be transferred as part of the transaction.

No Selling of Personal Data

We do not sell personal data under any jurisdiction, including CCPA guidelines.

Where Is Your Data Stored?

Your data is hosted in the following geographic locations:

InfrastructureLocationPurpose
Primary Database**Canada**Main data storage
Database Backups**Poland (European Union)**Encrypted geo-redundant backup
Database Backups**Singapore**Encrypted geo-redundant backup
Encryption Keys**Cloud KMS (US)**Secret management only
  • All database storage uses AES-256 disk encryption at rest.
  • All data in transit is protected by TLS 1.2+ with HSTS enforcement.
  • Backups are encrypted with AES-256, stored separately from production, and automatically purged on a 90-day rolling basis.
  • Recovery Time Objective (RTO): 24 hours. Recovery Point Objective (RPO): 24 hours.

International Data Transfers

Some of our service providers (including Meta, Stripe, Google, Zoom, and infrastructure providers) are located outside the United Kingdom and European Economic Area.

When we transfer personal data internationally, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Addendum

Canada benefits from an EU adequacy decision, while transfers to other countries (including the United States for Google Cloud secret management and Singapore for backups) are safeguarded by Standard Contractual Clauses and the UK Addendum.

These safeguards ensure your data receives the same level of legal protection regardless of where it is processed.

Third-Party Platform Data (Meta / Instagram / Facebook)

When you connect Instagram or Facebook, Inflowave processes data in accordance with Meta's Platform Terms and Data Protection Requirements.

You may revoke Inflowave's access to Meta platforms at any time through:

  • Your Inflowave account settings, or
  • Your Meta Business or Facebook account settings

Meta is not responsible for how Inflowave processes your data after it is received through Meta APIs.


5. HOW LONG DO WE KEEP YOUR INFORMATION?

In short: We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Notice and to meet legal, tax, and regulatory obligations.

Retention Schedule

Data CategoryRetention Period
Instagram & Facebook messages12 months after account cancellation
CRM contacts, leads, pipelines12 months after account cancellation
Marketplace profiles & metricsUntil disabled or account deletion + 12 months
Platform analytics & usage logs24 months
Support tickets & chat transcripts3 months
Zoom, calendar, and meeting integration data3 months
Security, fraud & audit logsAs required for security and legal defense
Billing, invoicing, and tax records6 years (legal obligation)

When the applicable retention period expires, data is either:

  • Permanently deleted, or
  • Irreversibly anonymized

Backups are encrypted and automatically purged on a rolling basis and are never reintroduced into active systems after deletion.


6. HOW DO WE KEEP YOUR INFORMATION SAFE?

In short: We implement organizational and technical safeguards that meet or exceed industry standards.

Data Classification

We classify all data by sensitivity level and apply protection controls accordingly:

ClassificationExamplesProtection
**Confidential**OAuth tokens, API credentials, encryption keysAES-256 Fernet encryption, secret manager only
**Internal**User IDs, account metadata, token metadataEncrypted at rest, access-controlled
**Customer**Email, CRM data, messages, analyticsEncrypted at rest, tenant-isolated (RLS)
**Transient**Meeting data, OAuth state, session tokensNot persisted or deleted immediately after use

Technical Protections:

  • Token encryption (AES-256 via Fernet symmetric encryption)
  • Password hashing (Bcrypt, minimum cost factor 12)
  • JWT authentication
  • Secure in-memory caching
  • TLS 1.2+ encrypted connections (all internal and external)
  • HSTS enforcement
  • CSP headers
  • XSS & CSRF prevention
  • Rate limiting, circuit breakers, abuse throttling
  • Database Row-Level Security (RLS) enforcing tenant isolation
  • Encryption keys managed in a dedicated cloud key management service (never in source code)

Organizational Protections:

  • Least privilege access control
  • Employee confidentiality agreements
  • Key rotation and secret scanning
  • Security audits and monitoring alerts

Breach Notification

In the event of a personal data breach:

  • Regulatory authorities (ICO) notified within 72 hours as required by UK GDPR
  • Affected users notified within 24 hours if the breach poses high risk to your rights and freedoms
  • Notifications include a description of affected data categories, steps taken, and user guidance

Despite our safeguards, no method of transmission over the Internet is guaranteed completely secure.


7. DO WE COLLECT INFORMATION FROM MINORS?

In short: We do not knowingly collect or market to individuals under 18 years of age.

By using the Services, you represent and warrant that you are:

  • At least 18 years old, or
  • A parent/guardian legally consenting to a minor's limited use for business purposes.

If we become aware that data has been collected from a child under 18:

1. We will deactivate the associated account, and

2. We will delete personal data from our systems within a commercially reasonable time.

If you believe a minor has provided data to Inflowave, contact: support@inflowave.io


8. WHAT ARE YOUR PRIVACY RIGHTS?

In short: Depending on your location, you may have rights that give you more control over your data.

These rights may include the ability to:

  • Request access to your data
  • Request rectification (correct errors)
  • Request deletion (in certain cases)
  • Request restriction or objection to processing
  • Request data portability (where applicable)
  • Withdraw consent (e.g., AI data usage, marketing)

You may exercise these rights at any time by contacting:

support@inflowave.io

If we rely on consent to process your data, you may withdraw consent at any time. This withdrawal will not affect:

  • Data processing before the withdrawal
  • Processing relying on a different lawful basis (such as legal obligations)

Opting Out of Marketing

You may opt out of:

  • Promotional emails (via unsubscribe links)
  • Business-targeted ads (by contacting support@inflowave.io)

Note: We may still send transactional messages (e.g., receipts, security alerts).

Account Termination Requests

If you request account deletion:

  • Offboarding must be completed
  • Connected accounts must be disconnected
  • Some data (e.g., billing records) may be retained to comply with laws

Right to Lodge a Complaint

If you are located in the European Union, you also have the right to lodge a complaint with your local data protection authority or with the UK Information Commissioner's Office (ICO) as our lead supervisory authority.


9. CONTROLS FOR DO-NOT-TRACK FEATURES

Most browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature that signals a preference not to be tracked.

Currently, no uniform industry standard governs compliance with DNT signals; therefore:

We do not currently respond to Do-Not-Track signals.

If standards change, we will update this Privacy Policy accordingly.


10. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In short: If you reside in California, Colorado, Connecticut, Utah, or Virginia, you have specific state-based privacy rights.

A. States Covered

  • California (CCPA/CPRA)
  • Colorado (CPA)
  • Connecticut (CTDPA)
  • Utah (UCPA)
  • Virginia (VCDPA)

B. Categories of Data We Have Collected (Past 12 Months)

CategoryExamplesCollected
IdentifiersName, email, phone, IP, account identifiersYES
Customer RecordsContact info, billing historyYES
Protected Class DataRace, gender, religion, healthNO
Commercial InfoTransaction data, payment statusYES
BiometricFingerprints, facial recognitionNO
Internet ActivityLog data, analytics, interactionsYES
GeolocationApprox. IP-based regionYES (approximate only)
Audio/Visual DataSupport recordings (if applicable)YES
Professional InfoBrand ownership, niche, categoriesYES
Education InfoStudent recordsNO
InferencesAutomated preference modelingNO (unless consented)
Sensitive Personal InfoAs defined by state lawsNO

C. Sale/Sharing of Personal Data

We do not sell personal data, including for advertising purposes.

We may use data with advertising platforms only to target businesses, not individuals.

D. Your Rights Under U.S. State Laws

You may have the right to:

  • Request deletion
  • Request access to data collected
  • Request to know specific data categories
  • Request correction
  • Request opt-out from targeted advertising
  • Request opt-out from automated decision-making (not currently used)

E. How to Exercise These Rights

Email: support@inflowave.io

We may require identity verification to prevent unauthorized actions.


11. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?

Residents of Canada, Australia, New Zealand, and South Africa have certain privacy rights under their respective national laws, including rights to:

  • Request access
  • Request correction
  • File regulatory complaints with their enforcement agencies

Contact: support@inflowave.io

We will respond in accordance with applicable regulations.


12. DO WE MAKE UPDATES TO THIS NOTICE?

In short: Yes, we update this notice as needed to remain legally compliant.

  • The "Last Updated" date at the top reflects the most recent revision.
  • Updates take effect when published on our website.
  • Continued use of the Services indicates acceptance of updated terms.

We may notify you directly of significant changes by:

  • Email
  • In-app notices
  • Banner notifications

Google Calendar Data Access

Google Calendar Integration

InflowaveAI uses Google OAuth 2.0 to access Google Calendar data with user authorization.

With user permission, InflowaveAI may:

  • Create calendar events when appointments are scheduled
  • Read existing calendar events to check availability and prevent double-booking
  • Update or delete events if appointments are modified or canceled

The application only accesses calendar events belonging to the authenticated user.


Data Usage and Storage

Use of Google Calendar Data

Google Calendar data is used solely to provide appointment scheduling and calendar management functionality.

We may store limited appointment-related information necessary to operate the service, such as event ID, date/time, title, and associated lead information. We do not use Google Calendar data for advertising purposes.

Google Calendar data is retained only as long as necessary to provide the service and may be deleted upon user request.


Revocation and Deletion

Revoking Access

Users may revoke Google Calendar access at any time via their Google Account permissions page.

Users may request deletion of their data by contacting: support@inflowave.io


Google API Compliance

InflowaveAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.


For more information, please review our related policies:


13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

You may contact us for data requests, questions, or complaints at:

Email: support@inflowave.io

Legal Entity: AIAGS Ltd

Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Phone: +44 744 533 4361 (for business/legal inquiries)


Data Protection Officer (DPO)

In accordance with Article 37 of the UK GDPR and EU GDPR, Inflowave has appointed a Data Protection Officer:

Mateusz Kielbasa

Email: matt@inflowave.io

The DPO is responsible for overseeing compliance with data protection laws and is the primary contact point for supervisory authorities and users regarding privacy matters.


14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

You may request to:

  • Review your personal data
  • Update or correct it
  • Request deletion (where permitted)
  • Request portability

Submit a request to:

support@inflowave.io