Privacy Policy

Privacy Policy

Information pursuant to Articles 13 and 14 of the General Data Protection Regulation (“GDPR”)

Last updated: 25 August 2026

1. Controller

The controller responsible for the processing described in this Privacy Policy is:

Enterflowsoft GmbH
Stella-Klein-Löw-Weg 8
1020 Vienna
Austria

Company registration number: FN 670353p
VAT identification number: ATU82874837

Email: info@enterflow.ai
Website: https://enterflow.ai/

Privacy-related questions and requests may be sent to info@enterflow.ai.

2. Scope of this Privacy Policy

This Privacy Policy applies to:

  • our website;

  • our website-based AI voice demonstration;

  • enquiries, sales communications and customer support;

  • contractual relationships with customers, suppliers and business partners;

  • AI voice agents, chat agents, email agents, document-processing agents and workflow automations operated by or for Enterflowsoft GmbH;

  • personal data processed for the security, maintenance and operation of our services.

3. Our role and the nature of our services

3.1 Enterflowsoft GmbH as controller

We act as the controller when we determine the purposes and means of processing, particularly for:

  • operating and securing our website;

  • providing our public AI demonstration;

  • responding to enquiries;

  • managing prospects, customers, suppliers and business partners;

  • invoicing and accounting;

  • protecting and enforcing legal rights;

  • our own service-security and compliance activities.

3.2 Enterflowsoft GmbH as processor

When an organisation uses an Enterflow AI agent for its own callers, customers, employees or business processes, that organisation normally determines why the personal data is processed and is therefore the controller. Enterflowsoft GmbH processes the data on that organisation’s documented instructions as its processor.

In these cases, processing is governed by a data processing agreement pursuant to Article 28 GDPR.

The customer is responsible for:

  • establishing an appropriate legal basis for processing;

  • providing required privacy and AI disclosures;

  • determining appropriate retention settings;

  • responding to data-subject requests;

  • deciding whether calls may legally be recorded;

  • complying with employment, telecommunications, consumer-protection and sector-specific laws.

If you interacted with an AI agent operated for one of our customers, you should normally direct your privacy request to that customer. We will assist the customer as required by our data processing agreement.

3.3 Nature of our services and telecommunications status

Enterflowsoft GmbH provides application-layer software, AI agents, software integrations, automated data-processing services and related information-technology services.

Enterflowsoft GmbH does not:

  • provide or operate a public communications network;

  • offer a publicly available electronic communications service;

  • allocate, supply or resell telephone numbers;

  • provide telecommunications connectivity, SIP trunks or carrier services; or

  • convey, originate or terminate telephone calls in the capacity of a telecommunications provider.

Any telephone numbers, connectivity, SIP trunks or carrier services used with our software are provided by independent telecommunications providers and remain subject to the contractual relationship between the relevant customer and that provider.

Our software may connect to customer-authorised telecommunications interfaces solely to provide application-layer AI and automation functionality.

Based on this current service model, Enterflowsoft GmbH does not act as a provider of a public communications network or public communications service subject to the notification requirement under § 6 of the Austrian Telecommunications Act 2021 (“TKG 2021”).

If the nature of our services changes, including through the future provision or resale of telephone numbers, connectivity or telecommunications transmission services, we will reassess the applicable regulatory requirements before offering those services.

4. Categories and sources of personal data

Depending on how you interact with us, we may process the following categories of personal data.

4.1 Website and technical data

  • IP address;

  • date, time and duration of access;

  • requested page or resource;

  • browser, device and operating-system information;

  • referring page;

  • approximate geographic region derived from the IP address;

  • error, security and diagnostic information.

4.2 Contact and business data

  • name;

  • organisation and position;

  • business email address;

  • business telephone number;

  • correspondence and meeting information;

  • enquiries, proposals and contract information;

  • billing, transaction and payment information.

4.3 AI-agent interaction data

  • spoken or written content submitted to an agent;

  • audio streams during a voice interaction;

  • transcripts or summaries where enabled;

  • telephone number or other communication identifier;

  • call time, duration, status and routing information;

  • appointment, reservation or enquiry information;

  • instructions, prompts and agent responses;

  • documents or data submitted to an agent;

  • information retrieved from customer-authorised systems;

  • actions taken by an agent, such as creating a CRM entry, scheduling an appointment or sending a confirmation.

4.4 Integration and customer-system data

Depending on the customer’s configuration, agents may process data from CRM, calendar, email, telephony, support, document-management, ERP or other systems authorised by that customer.

We may obtain personal data:

  • directly from you;

  • from one of our customers;

  • through authorised integrations;

  • from service providers acting on our or our customer’s behalf;

  • from publicly available business sources where permitted by law.

5. Purposes and legal bases

We process personal data for the following purposes and legal bases:

PurposeLegal basisDelivering requested demonstrations and contractual servicesArticle 6(1)(b) GDPRResponding to enquiries and preparing proposalsArticle 6(1)(b) GDPR and, where applicable, Article 6(1)(f) GDPROperating, maintaining and securing the website and servicesArticle 6(1)(f) GDPRPreventing fraud, abuse and security incidentsArticle 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPRCustomer, supplier and contract administrationArticle 6(1)(b) GDPR and Article 6(1)(f) GDPRAccounting, taxation and statutory record-keepingArticle 6(1)(c) GDPREstablishing, exercising or defending legal claimsArticle 6(1)(f) GDPRMarketing to existing business contacts where legally permittedArticle 6(1)(f) GDPRMarketing activities requiring consentArticle 6(1)(a) GDPRRecording calls where consent is requiredArticle 6(1)(a) GDPROther processing specifically requested by youArticle 6(1)(b) or Article 6(1)(a) GDPR, depending on the circumstances

Our legitimate interests include:

  • operating a secure and commercially viable service;

  • responding to business enquiries;

  • maintaining customer and business relationships;

  • improving system reliability;

  • detecting and preventing misuse;

  • protecting our systems and legal rights.

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

6. AI agents and transparency

Our services may use artificial intelligence to understand requests, generate responses, extract information, perform administrative actions and interact with authorised external systems.

An AI voice or communication agent should identify itself as an AI system at the beginning of an interaction unless this is already obvious from the circumstances.

AI-generated information can be incomplete or incorrect. Our customers are responsible for implementing appropriate human oversight, particularly where an interaction concerns healthcare, financial services, insurance, employment, legal matters or another significant decision.

7. AI voice agents and recordings

Voice audio must be processed in real time so that an AI voice agent can understand and respond.

Granting browser or device microphone permission enables this live processing. Microphone permission does not, by itself, constitute consent to store an audio recording.

7.1 Public website demonstration

For the public demonstration on our website:

  • raw audio is processed during the active connection;

  • Enterflowsoft GmbH does not intentionally create or retain a raw audio recording;

  • Enterflowsoft GmbH does not retain a conversation transcript after the demonstration ends;

  • business information or website addresses submitted to configure the demonstration are deleted within 24 hours;

  • limited technical and security logs may be retained as described in Section 13.

Our AI infrastructure provider may retain API content in abuse-monitoring logs for up to 30 days under its standard configuration unless approved enhanced retention controls, such as Zero Data Retention or Modified Abuse Monitoring, apply.

7.2 Customer-deployed agents

For customer-deployed agents:

  • call recording is disabled by default;

  • the agent must disclose that it is an AI system;

  • if call recording is enabled, the caller must receive an appropriate notice before recording begins;

  • consent must be obtained where consent is required by applicable law;

  • the customer’s recording and retention settings must be documented in the relevant agreement or service configuration.

Unless a different, legally justified period is documented with the customer:

  • recordings are retained for 30 days;

  • transcripts and AI-generated summaries are retained for 30 days;

  • communication metadata is retained for 90 days.

Customers may select a shorter standard retention period, such as 7 days.

Retention of recordings, transcripts or summaries beyond 90 days requires a documented operational or legal need and must be recorded in the data processing agreement, service agreement or applicable retention schedule.

Data exported to a customer’s own CRM, calendar, email, ERP or other system is subject to that customer’s retention policy.

We do not use voices for biometric identification, voiceprint creation or emotion recognition unless this is separately agreed, legally assessed and transparently disclosed.

8. Special-category data

Voice calls, documents and free-text fields may contain health information or other special categories of personal data under Article 9 GDPR.

Please do not provide special-category data through the public website demonstration.

Special-category data may be processed in customer-deployed systems only where:

  • the customer has identified an applicable legal basis under Article 6 GDPR;

  • the customer has identified an applicable condition under Article 9 GDPR;

  • the processing is covered by a data processing agreement;

  • appropriate access, security and retention controls have been implemented; and

  • a data protection impact assessment has been completed where required.

We do not intentionally process special-category data through our public demonstration.

9. Use of data for AI training

Enterflowsoft GmbH does not use customer content, recordings, transcripts, communications or documents to train shared or general-purpose AI models unless the relevant customer or data subject has provided an explicit, separately documented opt-in and the processing has an appropriate legal basis.

Our OpenAI API configuration does not opt customer content into model training. OpenAI states that API data is not used to train its models by default.

We may use irreversibly anonymised operational statistics that can no longer be linked to an identifiable person to measure service performance and improve system reliability.

10. Automated decision-making

Our standard services do not make decisions based solely on automated processing that produce legal effects or similarly significant effects for individuals within the meaning of Article 22 GDPR.

AI agents may perform limited administrative actions, such as:

  • routing a call;

  • collecting information;

  • suggesting an appointment time;

  • scheduling an appointment;

  • preparing a draft response;

  • classifying an enquiry;

  • creating an entry in a customer-authorised system.

Material decisions should be subject to appropriate human oversight.

If a customer configures an agent for significant automated decision-making, the customer must complete the required legal assessment and provide the notices, safeguards, contestation procedures and human-review mechanisms required under Article 22 GDPR.

11. Recipients and service providers

We disclose personal data only where necessary to operate the relevant service.

Recipient categories may include:

  • website hosting and content-delivery providers;

  • cloud infrastructure providers, including Amazon Web Services;

  • AI infrastructure providers, including the applicable OpenAI group company under our API agreement;

  • customer-selected telecommunications providers;

  • customer-selected CRM, calendar, email, ERP and workflow providers;

  • communications and technical-support providers;

  • accountants, tax advisers, lawyers, insurers and auditors;

  • competent courts, authorities or law-enforcement bodies where legally required;

  • a purchaser or successor in connection with a lawful corporate transaction.

Customer-selected telecommunications providers independently provide telephone numbers, connectivity and call-transmission services. Enterflowsoft GmbH provides the connected application-layer AI software and does not replace the telecommunications provider.

Processors are engaged under data processing agreements that meet the requirements of Article 28 GDPR.

Customer-selected integrations may also be governed by the customer’s own agreements with those providers.

A current list of relevant subprocessors is available by contacting info@enterflow.ai.

We do not sell personal data.

12. Storage locations and international transfers

Our standard production configuration stores customer application data in cloud regions located in the European Economic Area.

The website and static content may be delivered through international content-delivery networks. This may involve transient processing of IP addresses and technical connection information in the region closest to the visitor.

AI, hosting, support or customer-selected integration providers may process data outside the European Economic Area.

Where personal data is transferred to a country without an adequacy decision, we use an appropriate transfer mechanism, such as:

  • the European Commission’s Standard Contractual Clauses;

  • the EU–US Data Privacy Framework where the recipient is validly certified;

  • additional technical and organisational safeguards where appropriate; or

  • another transfer mechanism permitted under Chapter V GDPR.

Where contractually and technically available, we configure European processing or data residency for AI services. Some provider system data, account information, security information or support data may nevertheless be processed outside the European Economic Area.

You may request further information about applicable transfer safeguards by contacting info@enterflow.ai.

13. Retention periods

We apply the following standard retention schedule unless:

  • a shorter period is configured;

  • continued storage is legally required;

  • a customer acting as controller provides a lawful documented instruction; or

  • data must be preserved for an investigation or legal claim.

Data categoryStandard retentionWebsite access and delivery logs30 daysSecurity and abuse-detection logs90 daysLogs connected to an identified security incidentUntil investigation and remediation are completed, normally no longer than 12 months after closurePublic voice-demo raw audioNot stored by Enterflowsoft GmbHPublic voice-demo transcriptNot retained by Enterflowsoft GmbHPublic demonstration configuration and submitted website informationMaximum 24 hoursOpenAI API abuse-monitoring data under standard settingsUp to 30 days, subject to the provider’s legal and safety exceptionsCustomer-agent recordings, if enabled30 days by default; selectable periods of 7, 30 or 90 daysCustomer-agent transcripts and summaries30 days by default; selectable periods of 7, 30 or 90 daysCall and communication metadata90 daysCustomer-uploaded documents and agent knowledge basesContract term or until deleted by the customer; deleted from active systems within 30 days following terminationAgent configurations and operational customer-account dataContract term plus a maximum of 30 days for export and orderly deletionEnquiries and unsuccessful sales discussions24 months after the last substantive contactMarketing contact dataUntil consent is withdrawn or after 24 months without relevant interactionMarketing objection and suppression recordsAs long as necessary to ensure that the objection continues to be respectedCustomer and supplier contractsContract term plus 3 years, unless longer retention is required for a legal claimSupport tickets3 years after closureInvoices, accounting records and associated documents7 years, or longer where required by Austrian tax law or pending proceedingsConsent and privacy-request records3 years after withdrawal or final completion of the requestAccount-access and administrative audit logs12 monthsEncrypted rolling backupsMaximum 35 daysIrreversibly anonymised statisticsMay be retained indefinitely because they are no longer personal data

When a retention period expires, personal data is deleted or irreversibly anonymised during the next scheduled deletion cycle, ordinarily within 7 days.

Retention may be suspended for data subject to:

  • a legal hold;

  • a regulatory investigation;

  • a security investigation;

  • a contractual dispute;

  • a pending or reasonably anticipated legal claim.

Only the data necessary for the relevant purpose will be retained. It will be deleted when the reason for the extended retention ends.

14. Deletion and backups

Personal data is deleted from active production systems when:

  • the applicable retention period expires;

  • the customer deletes the data;

  • the relevant contract ends and the agreed export period expires; or

  • a valid erasure request is granted.

Following termination of a customer service:

  1. the customer may request an export during a period of up to 30 days;

  2. customer content is deleted from active systems within 30 days;

  3. remaining backup copies expire automatically within a further maximum of 35 days.

Backups are encrypted, access-restricted and used only for disaster recovery and service continuity.

Deleted data is not restored for ordinary business use. If a backup must be restored following a technical incident, applicable deletion instructions are reapplied.

A deletion request cannot override statutory retention duties or the need to preserve limited information for legal claims. In such cases, the affected data is restricted and used only for the relevant legal purpose.

15. Security

We apply technical and organisational measures appropriate to the processing risk, including, where applicable:

  • encryption in transit and at rest;

  • role-based access controls;

  • multi-factor authentication for administrative access;

  • least-privilege access;

  • tenant and environment separation;

  • logging and monitoring;

  • secure secrets and credential management;

  • vulnerability and dependency management;

  • encrypted backups;

  • retention and deletion controls;

  • incident-response procedures;

  • confidentiality obligations and staff access restrictions;

  • periodic review of security measures.

No internet-based system can be guaranteed to be completely secure. We regularly review our safeguards and adapt them to relevant risks and the state of the art.

16. Website analytics, cookies and similar technologies

We use Framer to host and deliver our website. Framer may process technical information necessary to deliver and secure the website.

We use Framer’s built-in, cookie-free analytics. According to Framer, this analytics function does not use cookies or persistent identifiers. It uses a daily rotating value to calculate aggregated daily visitor statistics.

We do not currently use non-essential advertising or cross-site tracking cookies. Therefore, a cookie-consent banner is not required for the website in its current configuration.

If we introduce non-essential analytics, advertising, embedded media or tracking technologies, they will be blocked until any legally required consent has been obtained. This Privacy Policy and any cookie settings will be updated accordingly.

Website fonts are delivered through our website or hosting infrastructure without intentionally causing a separate connection to an external font provider.

17. Provision of personal data

You are not generally required to provide personal data merely to visit our website.

Certain information is required if you wish to:

  • contact us;

  • receive a proposal;

  • enter into or perform a contract;

  • use an AI demonstration or agent;

  • connect an external service;

  • receive customer support.

If required information is not provided, we may be unable to provide the requested service.

18. Your GDPR rights

Subject to the applicable legal conditions, you have the right to:

  • receive information about our processing;

  • obtain access to your personal data;

  • have inaccurate data corrected;

  • have incomplete data completed;

  • request deletion;

  • request restriction of processing;

  • receive applicable data in a structured, commonly used and machine-readable format;

  • object to processing based on legitimate interests;

  • object at any time to direct marketing;

  • withdraw consent at any time;

  • request human intervention where Article 22 GDPR applies;

  • lodge a complaint with a supervisory authority.

Requests may be sent to info@enterflow.ai.

We normally respond within one month. This period may be extended by up to two additional months where permitted under Article 12 GDPR.

We may request information necessary to verify the requester’s identity. Information collected for identity verification will be used only to process and document the request.

19. Children

Our website and services are intended for organisations and adults.

We do not knowingly offer the public demonstration directly to children or intentionally collect children’s personal data.

Customers deploying agents in contexts involving children must implement the additional notices, legal bases, age-verification and consent arrangements required for that use.

20. Changes to this Privacy Policy

We may update this Privacy Policy when our services, service providers, technical configurations or legal obligations change.

The current version and its effective date will be published on our website.

If a change materially affects an ongoing processing activity, we will provide additional notice where required.

Contact us

info@enterflow.ai

EnterFlow AI empowers you to unlock your business potential with AI Voice Agents

Vienna, Austria

Contact us

info@enterflow.ai

EnterFlow AI empowers you to unlock your business potential with AI Voice Agents

Vienna, Austria

Contact us

info@enterflow.ai

EnterFlow AI empowers you to unlock your business potential with AI Voice Agents

Vienna, Austria

EnterFlowAI. All right reserved. © 2026

EnterFlowAI. All right reserved. © 2026

EnterFlowAI. All right reserved. © 2026