Scope and our role
This Privacy Policy explains how AlchemyWorkflow ("AlchemyWorkflow," "we," "us," or "our") handles personal information when you visit alchemyworkflow.ai, contact our sales or implementation teams, attend an event, receive marketing communications, or use an AlchemyWorkflow tenant, integration, API, workflow, or related service (collectively, the "Services").
For website, sales, business-contact and account-administration information, AlchemyWorkflow generally acts as a data controller or business. When we process information submitted to a customer tenant, connected system or workflow on behalf of an enterprise customer, we generally act as a processor or service provider under the customer agreement and applicable Data Processing Addendum. The customer remains responsible for determining the purposes and lawful basis of that processing.
AlchemyWorkflow is delivered through a sales-led enterprise model. We do not offer public self-service registration. Customer environments are provisioned following discovery and an applicable statement of work or order, and customer users are invited by an authorized customer administrator.
Information we collect
Information you provide directly
- Sales and contact information: name, work email, company, role, team size, current systems, project objectives and any information included in a consultation request.
- Account and administrator information: business contact details, organization membership, role, authentication identifiers, access status and administrator-managed permissions.
- Implementation and support information: process documentation, workflow requirements, system diagrams, support requests, meeting notes and communications with our teams.
- Customer Content: data, records, files, prompts, instructions, approvals, comments and other materials submitted to a customer tenant or processed through a configured workflow.
- Feedback and research: survey responses, product feedback and information shared during interviews or usability sessions.
Information from connected services
When an authorized customer administrator connects CRM, marketing, communications, content, support, analytics, storage or internal systems, the Services may access and process the records, metadata and permissions necessary to perform the configured workflow. The exact data depends on the connection, scopes selected by the customer and the workflow design.
Information collected automatically
- device, browser, IP address, operating system and approximate location derived from IP;
- pages viewed, links clicked, referring pages, session timing and website interaction data;
- service logs, workflow execution events, integration status, error information, security events and diagnostic data; and
- cookie and similar-technology identifiers, subject to your available choices.
How we use information
We may use personal information to:
- respond to consultation requests, evaluate fit and prepare discovery sessions, proposals, SOWs and implementation plans;
- provision, configure, secure, operate and support dedicated customer tenants;
- authenticate users, enforce administrator-managed access and maintain organization membership and permissions;
- execute workflows, process business rules, route approvals and perform actions in connected systems;
- provide technical support, investigate incidents, maintain service reliability and prevent fraud, abuse or unauthorized access;
- measure website and service performance, understand feature usage and improve usability;
- develop and test new functionality using aggregated, de-identified or otherwise appropriately protected data;
- send service, security, administrative and contractual communications;
- send marketing communications where permitted, with an option to unsubscribe; and
- comply with law, enforce agreements and protect the rights, safety and integrity of AlchemyWorkflow, our customers and others.
AI and automated processing
Configured workflows may use artificial intelligence or machine-learning systems to classify information, summarize content, generate drafts, recommend actions or support routing and decision steps. AI-generated results may be incomplete, inaccurate or unsuitable for a particular purpose. Customers are responsible for configuring appropriate review, approval and human oversight for consequential use cases.
Depending on the customer configuration and applicable agreement, inputs and outputs may be processed by AlchemyWorkflow infrastructure or approved subprocessors. We do not use identifiable Customer Content to train a general-purpose model unless expressly authorized in writing. We may use aggregated or de-identified operational data to maintain, secure and improve the Services where permitted by contract and law.
The Services are not intended to make solely automated decisions that produce legal or similarly significant effects about individuals unless the customer has implemented an appropriate lawful basis, notice, safeguards and human review.
Legal bases for processing
Where GDPR, UK GDPR or similar law applies and we act as controller, we rely on one or more of the following legal bases:
- Contract: to take requested pre-contract steps or perform an agreement;
- Legitimate interests: to operate, secure, improve and market our business where those interests are not overridden by individual rights;
- Consent: where consent is requested, including for certain cookies or marketing activities; and
- Legal obligation: to comply with applicable law, lawful requests and recordkeeping duties.
Data retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security, comply with legal obligations, resolve disputes and enforce agreements. Retention periods vary by data type, customer configuration and contract.
- Sales and business-contact information may be retained while an opportunity or customer relationship remains active and for a reasonable period afterward.
- Account and administrator records are generally retained for the life of the applicable tenant and for a limited period after termination for security, audit and legal purposes.
- Customer Content is retained according to the applicable agreement, SOW, DPA and tenant configuration. Deletion from active systems and backups may occur on different schedules.
- Security, audit and workflow logs may be retained for a defined operational or contractual period.
- Aggregated or de-identified information that can no longer reasonably identify an individual may be retained for longer periods.
Enterprise customers should refer to their agreement for specific export, return and deletion commitments.
Security
We use administrative, technical and organizational safeguards designed to protect information against unauthorized access, use, alteration, disclosure or destruction. Depending on the implementation, these measures may include encryption in transit, access controls, role-based permissions, environment separation, monitoring, logging, backup and incident-response procedures.
No method of transmission or storage is completely secure. Customers are responsible for maintaining secure credentials, configuring appropriate permissions, reviewing invited users and using the Services in accordance with their security obligations.
International transfers
AlchemyWorkflow and our service providers may process information in countries other than the country where it was collected. Those countries may have different data-protection laws. Where required, we use appropriate safeguards such as contractual transfer clauses, data-processing agreements or other legally recognized transfer mechanisms.
Hosting region, data residency and customer-specific transfer requirements should be documented in the applicable order, SOW or DPA.
Privacy rights and choices
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability or objection; to withdraw consent; or to appeal a decision about a privacy request. You may also have the right to opt out of targeted advertising, certain profiling, sale or sharing of personal information.
If your information was submitted to an AlchemyWorkflow tenant by one of our enterprise customers, please contact that customer first. We will assist the customer with verified requests as required by the applicable DPA and law.
To exercise a right regarding information controlled by AlchemyWorkflow, email privacy@alchemyworkflow.ai. We may verify your identity and authority before completing a request. You may also lodge a complaint with your local data-protection authority.
Children and sensitive information
The Services are intended for business users and are not directed to children under 18. We do not knowingly collect personal information from children through the website.
Unless expressly authorized in an applicable agreement and supported by appropriate controls, customers should not submit protected health information, payment-card data, government identifiers, biometric identifiers, special-category data or other highly sensitive information to the Services.
Third-party services
The Services may contain links to or integrate with third-party services. Those third parties control their own privacy and security practices. A customer’s authorization of an integration permits AlchemyWorkflow to exchange data with that service as necessary to perform the configured workflow, but it does not make AlchemyWorkflow responsible for the third party’s independent practices.
Changes and contact
We may update this Policy to reflect changes in the Services, law or our practices. We will post the updated version and revise the "Last updated" date. Where required, we will provide additional notice of material changes.
Privacy questions and requests may be sent to privacy@alchemyworkflow.ai. Legal notices relating to an enterprise engagement should also be delivered using the notice method in the applicable agreement.