1. Data controller
ResourceFlow AI Ltd, registered in England and Wales (company number 16579173).
Registered office: 483 Green Lanes, London, N13 4BS, United Kingdom.
Contact for privacy and legal matters: solutions@resourceflow.ai
2. Personal data we collect
- Account and contact details (name, work email, organization) when you sign up, log in, or request a demo.
- Usage and technical data (pages viewed, device/browser type, approximate location derived from IP) when optional analytics cookies are enabled.
- Security and bot-detection signals processed via Cloudflare Turnstile on protected forms and Supabase Auth endpoints (sign-in, sign-up, and password reset), which may include IP address, browser/user-agent, TLS fingerprint, and related technical signals — solely to distinguish humans from bots.
- Employee, candidate, and payroll data processed on behalf of customers who use the platform — we act as a processor for that data under customer instructions.
- Support communications, feedback, and issue reports you submit voluntarily.
3. How we use personal data
- Provide, secure, and improve the ResourceFlow AI platform.
- Authenticate users and enforce role-based access within customer organizations.
- Respond to demo requests, support enquiries, and contractual obligations.
- Generate aggregated, anonymized analytics to improve product quality when you consent to statistical cookies.
- Comply with legal obligations and protect against fraud, bots, or misuse (including Cloudflare Turnstile on public and authentication forms).
4. Legal bases (UK GDPR / GDPR)
- Contract — to deliver the service our customers subscribe to.
- Legitimate interests — to secure our platform, prevent abuse, and improve reliability.
- Consent — for optional statistical and functional cookies on our marketing site.
- Legal obligation — where applicable tax, accounting, or regulatory duties apply.
5. Cookies and similar technologies
We use necessary cookies and local storage for authentication, session management, and storing your cookie consent choice.
We also use Cloudflare Turnstile (including invisible / interaction-only modes) for bot protection on authentication and public forms. Our auth provider (Supabase) verifies Turnstile tokens on sign-in, sign-up, and password-reset endpoints when CAPTCHA protection is enabled. Non-auth forms (such as demo requests) may be verified by our application directly. Turnstile processes limited client-side Signals that are strictly necessary to detect and block bots. Further detail is in Cloudflare's Turnstile Privacy Addendum at https://www.cloudflare.com/en-gb/turnstile-privacy-policy/ (supplemental to Cloudflare's Privacy Policy).
Optional statistical cookies help us understand how the website is used. Optional functional cookies remember interface preferences such as theme.
You can accept or decline optional cookies via the consent widget or manage preferences at any time on our Cookie settings page.
- See /legal/cookies for category descriptions and preference controls.
6. Hosting, subprocessors, and transfers
Customer data is hosted in EU-region infrastructure provided by our cloud suppliers (including Supabase for database, authentication, and storage).
We use subprocessors for email delivery, payment processing, infrastructure monitoring, and bot protection under data processing arrangements where required. Cloudflare provides Turnstile; Supabase Auth may also invoke Cloudflare Turnstile when CAPTCHA protection is enabled on authentication endpoints. How Cloudflare processes Turnstile Signals (including where Cloudflare acts as processor for securing our site versus as controller to improve Turnstile) is described in the Turnstile Privacy Addendum: https://www.cloudflare.com/en-gb/turnstile-privacy-policy/.
We do not sell personal data. Access is limited to personnel and suppliers who need it to operate the service.
7. Retention
- Marketing-site cookie consent preferences are stored locally for up to 365 days.
- Customer platform data is retained for the subscription term and deleted or returned according to the customer agreement.
- Employees and candidates may exercise rights through their employer's HR administrator or configured DSAR workflows in the platform.
8. Security
We apply tenant isolation, encryption in transit, role-based access controls, and audit logging. Customer organizations configure permissions for their users.
9. Your rights
- Access, rectification, erasure, restriction, portability, and objection where applicable under UK GDPR / GDPR.
- Withdraw consent for optional cookies at any time without affecting necessary site functions.
- Lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority in the EEA.
10. Changes
We may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date.