QONFLO AI — PRIVACY POLICY
Last Updated: 10 February 2026
This Privacy Policy explains how Qonflo AI ("Qonflo AI", "we", "us", or "our") collects, uses, shares, and protects Personal Data when you: visit our websites and pages that link to this Privacy Policy (the "Site"); create an account, administer an account, or otherwise use our software platform and related services (the "Services"); contact us for support, sales, onboarding, or other inquiries; or receive marketing communications from us (where permitted by law). This Privacy Policy should be read together with our Terms and Conditions of Service.
1. Scope and Roles (Controller vs. Processor)
- When Qonflo AI acts as a Controller
- Qonflo AI acts as a Personal Data Controller when we determine the purposes and means of processing, such as for:
- account administration and billing for Customers and users who sign up;
- sales/marketing and relationship management with prospects and Customers;
- operating the Site, analytics, and security; and
- compliance and legal obligations.
- In these situations, this Privacy Policy describes our processing.
- When Qonflo AI acts as a Processor (Customer Data)
- When a business Customer uses Qonflo AI to manage contacts and communicate with End Users (for example via WhatsApp), Qonflo AI generally acts as a Personal Data Processor on behalf of the Customer, and the Customer is the Personal Data Controller for that Customer Data.
- In those cases:
- the Customer decides what Personal Data is collected and used, who is messaged, what is sent, and why; and
- Qonflo AI processes Customer Data to provide the Services, secure them, and support the Customer.
- If you are an End User receiving messages from a Qonflo AI Customer, your privacy questions and requests should usually be directed to the business that contacted you, because that business controls the processing.
- If you are a Customer and need a DPA, you may request one by contacting us (see Section 14).
2. Definitions
- Personal Data means information relating to an identified or identifiable individual, as defined under applicable data protection laws (including Indonesia’s PDPL and implementing regulations).
- Customer Data means data submitted to or processed through the Services by or on behalf of a Customer (including messages, contact lists, CRM records, and metadata).
- End User means an individual with whom a Customer communicates using the Services (e.g., the Customer’s customer, lead, patient, student, user).
- Meta Platforms includes Meta Platforms, Inc. and its affiliates and products/services, including the WhatsApp Business Platform.
3. Personal Data We Collect
- Personal Data you provide to us (Controller context)
- We may collect the following categories of Personal Data when you interact with us directly:
- Account and profile data
- name, email address, phone number
- company name, job title, department
- login and authentication data (e.g., encrypted password, SSO identifiers)
- Billing and payment-related data
- billing address, tax information (if applicable)
- invoice details and payment status
- Note: We typically use third-party payment processors; we may not store full card numbers.
- Communications
- messages you send to us (support tickets, emails, feedback)
- call recordings or meeting notes where permitted by law and with notice/consent where required
- Customer reference/marketing preferences
- preferences for receiving marketing communications
- opt-in/opt-out records
- Personal Data collected automatically (Site/Services usage)
- When you access the Site or Services, we may automatically collect:
- Device and technical data
- IP address, device identifiers
- browser type, operating system
- language, time zone
- Usage and log data
- pages/screens visited, features used, timestamps
- event logs, error logs, audit logs
- approximate location derived from IP (not precise GPS unless you explicitly provide it)
- Cookies and similar technologies
- We use cookies and similar technologies as described in Section 9.
- Personal Data from third parties
- We may receive Personal Data from:
- your employer or organization if they create your user account;
- resellers/partners or referral sources (where applicable);
- Third-Party Services you connect (integrations), based on your configuration and permissions; and
- Meta Platforms in connection with WhatsApp Business Platform operations (see Section 8), depending on what you connect and how the integration works.
- Customer Data processed through the Services (Processor context)
- Customers may upload or generate Customer Data in the Services, which may include:
- End User identifiers and contact data (names, phone numbers, emails, customer IDs)
- conversation content (message text, attachments) where enabled by the Customer
- messaging metadata (timestamps, delivery status, conversation IDs)
- CRM records (notes, tags, deal stages, custom fields)
- support and operational information included by Customers
- Important: Qonflo AI does not decide what Customer Data a Customer collects or sends. Customers are responsible for ensuring they have a lawful basis/consent to provide and process this data.
4. How We Use Personal Data (Purposes)
- To provide and operate the Services
- create and manage accounts
- authenticate users and enable access controls
- provide requested features (CRM, messaging, dashboards, automations, APIs)
- process transactions and send invoices/receipts
- To secure and maintain the Services
- monitor for suspicious activity, fraud, abuse, and security incidents
- troubleshoot, error detection, performance monitoring
- enforce our Terms and prevent prohibited use
- To provide support and communicate with you
- respond to inquiries and support requests
- send administrative messages (service notices, security alerts, billing notices)
- To improve and develop our products (including analytics)
- analyze feature usage and performance
- improve reliability, user experience, and security
- develop new features and integrations
- Where possible, we use aggregated and/or de-identified data for analytics and service improvement.
- Marketing and sales (where permitted)
- send product updates, newsletters, event invitations, and promotional communications
- personalize marketing based on your interactions
- You can opt out at any time (see Section 11).
- Legal compliance
- comply with applicable laws, regulations, lawful requests, and legal processes
- protect rights, safety, and property of Qonflo AI, Customers, End Users, and the public
5. Legal Bases for Processing (Where Required)
- Depending on applicable law and the specific context, Qonflo AI processes Personal Data on one or more of the following bases:
- Consent (e.g., marketing where consent is required; certain cookies)
- Contract necessity (e.g., to provide the Services you requested)
- Legal obligation (e.g., tax, accounting, compliance requests)
- Legitimate interests (e.g., securing and improving the Services, preventing fraud), balanced against your rights and interests
- Vital interests / public interest (in limited circumstances, where applicable)
- For Customer Data processed on behalf of Customers, the Customer is responsible for establishing the appropriate legal basis and providing required notices and consents to End Users.
6. Sensitive / Specific Personal Data
- Our approach
- We do not intentionally request “sensitive” or “specific” categories of Personal Data (such as health data, biometrics, genetic data, political opinions, sexual orientation, criminal records, or precise financial credentials), unless explicitly needed for a specific use case and handled in compliance with applicable law.
- Customer Data may include sensitive data
- Customers may choose to store or transmit such data within Customer Data. In that case:
- the Customer is responsible for ensuring lawful processing; and
- Qonflo AI will process such data only as necessary to provide the Services and as instructed by the Customer.
7. How We Share Personal Data
- Service providers (sub-processors)
- We use trusted vendors to help deliver the Services, such as:
- cloud hosting and infrastructure
- analytics and monitoring
- customer support tools
- email delivery and communications
- payment processing
- security tools and fraud prevention
- These vendors are authorized to process Personal Data only as necessary to provide services to us and are bound by confidentiality and appropriate data protection obligations.
- Third-Party Services and integrations you enable
- If you choose to connect Third-Party Services (including Meta Platforms / WhatsApp), we will share/receive data as required to make the integration work, based on your settings and permissions.
- Corporate transactions
- If we are involved in a merger, acquisition, restructuring, financing, or sale of assets, Personal Data may be transferred as part of that transaction, subject to appropriate safeguards.
- Legal and safety reasons
- We may disclose Personal Data if we believe in good faith that disclosure is necessary to:
- comply with law, regulation, court order, or lawful government request;
- enforce our Terms, investigate suspected violations, or protect platform integrity;
- detect, prevent, or address fraud, abuse, security, or technical issues; or
- protect the rights, property, or safety of Qonflo AI, our users, Customers, End Users, or the public.
- With your direction or consent
- We may share data when you direct us to do so or when we have your consent.
8. WhatsApp / Meta Platforms Data (Important)
- If a Customer connects the Services with the WhatsApp Business Platform (or other Meta services), then:
- Meta is a separate platform
- Meta Platforms controls its services, policies, availability, and enforcement.
- Customer is the sender/controller
- The Customer controls message content, recipients, and purpose.
- Data may flow through Meta
- Message content and metadata may be transmitted to and from Meta Platforms as part of delivering the messaging service.
- Policy compliance
- Customers are responsible for complying with WhatsApp/Meta policies, including consent and opt-out requirements.
- Qonflo AI disclosures to Meta
- Qonflo AI may share limited data, logs, and metadata with Meta Platforms where required to:
- enable the integration,
- comply with Meta policies,
- investigate messaging quality/compliance issues, or
- respond to enforcement actions.
9. Cookies and Similar Technologies
- We use cookies and similar technologies on the Site and, where applicable, within the Services.
- Cookies may be used for:
- Strictly necessary (security, authentication, session management)
- Preferences (language, settings)
- Analytics (understanding Site/Services usage and performance)
- Marketing (where enabled and permitted)
- You can control cookies through your browser settings. If you disable cookies, some features may not function properly.
- If your jurisdiction requires cookie consent banners or specific opt-in mechanisms, we will provide them where applicable.
10. Data Retention
- We retain Personal Data only as long as necessary for the purposes described in this Privacy Policy, including:
- to provide the Services and maintain business records
- to comply with legal, accounting, and tax obligations
- to resolve disputes and enforce agreements
- to maintain security logs and prevent abuse
- Customer Data retention: For Customer Data processed as a Processor, retention is generally controlled by the Customer’s use of the Services, plan settings, and contractual terms. After termination, we may delete Customer Data after a reasonable period, subject to legal obligations and backup cycles.
11. Your Rights and Choices
- Depending on applicable law (including the PDPL), you may have rights such as:
- Right to information about processing activities
- Right of access to your Personal Data
- Right to correction/rectification
- Right to deletion/erasure or destruction (subject to legal exceptions)
- Right to withdraw consent (where processing is based on consent)
- Right to object to certain processing (e.g., direct marketing)
- Right to restrict or delay processing in certain circumstances
- Right to data portability (where applicable)
- Rights related to automated decision-making (where applicable)
- How to exercise your rights
- Email us at admin@qonflo.ai with:
- your name and contact details,
- the relationship you have with Qonflo AI (Customer user, prospect, etc.),
- the request you want to make, and
- enough information for us to verify your identity.
- End Users receiving messages from Customers
- If you are an End User and want to exercise rights relating to messages you received from a business using Qonflo AI, please contact that business directly.
- We may assist Customers in fulfilling requests where applicable and where we are permitted to do so.
- Marketing opt-out
- You can opt out of marketing emails at any time using the unsubscribe link in the email or by contacting us at admin@qonflo.ai.
- Administrative/service communications (e.g., billing, security notices) are not marketing and may still be sent.
12. Security
- Safeguards
- We implement reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure.
- However, no method of transmission or storage is 100% secure.
- You are responsible for maintaining the confidentiality of your account credentials and using appropriate security controls (e.g., strong passwords, 2FA where available).
- Data breach notifications
- If we become aware of a Personal Data breach, we will assess and take reasonable steps to mitigate it and will notify affected parties and/or regulators as required by applicable law.
13. International (Cross-Border) Transfers
- Our service providers and infrastructure may be located in multiple countries. As a result, Personal Data may be transferred to and processed in countries other than where you live.
- Where required by law, we will implement appropriate safeguards for cross-border transfers (for example, contractual protections and other lawful mechanisms).
14. Children’s Privacy
- The Services are not intended for children, and we do not knowingly collect Personal Data from individuals under 18 (or the age of majority in the relevant jurisdiction).
- If you believe a child has provided Personal Data to us, contact us at admin@qonflo.ai.
15. Third-Party Links
- The Site or Services may contain links to third-party websites or services.
- Their privacy practices are governed by their own policies, not this Privacy Policy.
- We are not responsible for third-party privacy practices.
16. Changes to This Privacy Policy
- We may update this Privacy Policy from time to time.
- We will post the updated version and revise the “Last Updated” date.
- If changes are material, we may provide additional notice as required by law.
- Your continued use of the Site/Services after the effective date of an updated Privacy Policy constitutes acceptance to the extent permitted by law.
17. Contact Us
- If you have questions or requests regarding this Privacy Policy or our privacy practices, contact:
- Qonflo AI
- Email: admin@qonflo.ai
- Address: Intiland Tower, 3rd Floor (Subco), Jl. Panglima Sudirman No. 101–103, Surabaya, East Java 60271, Indonesia