Legal
Privacy Policy
Effective 27 September 2026. This notice explains how personal information is handled when you use IndxFlow.
1. Controller
NOVAANTRA for AI Systems Development is the controller of personal data used to operate IndxFlow. Organisations using IndxFlow may separately act as controllers for CRM and other business information they enter; in those cases, we process that information to provide the service on their instructions.
2. Information we process
- Account information, including name, email address, authentication identifiers and workspace membership.
- Business and CRM information, including companies, contacts, leads, opportunities, documents, messages and workflow records supplied by customers.
- Usage and security information, including activity records, feature usage, audit events, IP address, browser and device information.
- Support information and messages you send to us.
- Integration settings and references required to connect services you choose.
- Billing references, plan and subscription status. Complete card details are handled by Paddle and are not stored by IndxFlow.
3. Purposes and legal bases
We process account and workspace data to perform our contract and provide IndxFlow. We process security, audit, service-improvement and support information for our legitimate interests in operating a safe, reliable service. We process records where necessary to comply with legal obligations. Where consent is the appropriate basis, including optional marketing or non-essential cookies if introduced, you may withdraw it.
4. Sharing
We share information only as needed with service providers supporting hosting, authentication, storage, AI functions, communications and customer support; with Paddle as Merchant of Record for product sales, subscriptions, payments, taxes and invoices; with professional legal and accounting advisers; and with authorities when required by law. We do not sell personal data.
5. International processing
Service providers may process information outside your country, including outside the UK or EEA. Where required, we use recognised safeguards such as adequacy decisions, contractual protections or Standard Contractual Clauses.
6. Retention
We keep personal data for as long as needed to provide the service, maintain security and audit records, meet legal obligations and resolve disputes. When no longer needed, information is deleted or anonymised. Retention can vary by record type and an organisation’s instructions.
7. Security
We use appropriate technical and organisational safeguards, including encrypted transport, access controls, workspace isolation and audit records. No online service can guarantee absolute security.
8. Cookies and local storage
IndxFlow uses essential browser storage and cookies for sign-in, security, language and service operation. We do not currently describe optional advertising cookies as part of the service. If optional analytics or marketing technologies are introduced, this notice and consent controls will be updated where required.
9. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. UK and EEA requests are normally answered within one month, subject to lawful extensions.
To make a privacy or deletion request, email support@indxflow.net or use our Contact page. We may need to verify your identity.
10. Updates
We may update this policy as IndxFlow or legal requirements change. The effective date above identifies the current version.
Data controller and service provider
Office 304, Floor 3
Building 2, Street 970
Zone 6, Qatar
Postal Code: 00000C.R. No.: 250847
Commercial License No.: 340804
