Cesflo

Legal

Privacy Policy

Effective January 1, 2026

This Privacy Policy describes how TCM Technologies Limited ("Cesflo," "we," "us") collects, uses, and shares information in connection with the Cesflo web and mobile applications (the "Service"). It applies to the organizations that subscribe to Cesflo ("Customers") and the individuals who use the Service on their behalf.

1. Information we collect

We collect the following categories of information:

  • Account and profile information: name, email address, phone number, and role, provided when a workspace is created or a user is invited.
  • Organization and workspace data: the name and identity of the workspace, its configured settings (currency, escalation windows, integrations), and its membership.
  • Operational data Customer submits: process templates, stages, business functions and objectives, process runs, resource library entries and rates, and the actual consumption, cost, and timing data recorded as processes execute. This may include information about Customer's own employees or contractors where Customer chooses to record it (for example, who was assigned to or signed off a stage).
  • Evidence and location data: where a Customer configures a stage to require it, a photo, note, or GPS coordinates captured at the moment of sign-off. This is collected only when a user actively signs off a stage configured to require it, not on an ongoing or background basis.
  • Payment information: our payment processor (Paddle) collects and processes billing and payment card information on our behalf. We do not receive or store full payment card numbers.
  • Usage and device information: log data, device and browser type, IP address, and how the Service is used, collected automatically to operate, secure, and improve the Service.
  • AI-assist input: where an organization enables and uses the optional AI-assisted process drafting feature, the plain-language description entered is sent to our AI provider to generate a draft; this feature is opt-in per organization and off by default.

2. How we use information

  • to provide, operate, and maintain the Service, including the features described in these categories;
  • to process subscriptions, billing, and payments;
  • to send transactional communications: sign-off notifications, escalations, billing receipts, and service updates;
  • to monitor, secure, and troubleshoot the Service, including detecting abuse and rate-limiting;
  • to generate aggregated or de-identified analytics about how the Service is used, to guide what we build; and
  • to comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use Customer Data to train AI models beyond the specific, opt-in AI-assist request it was submitted for.

3. How we share information

We share information with the following categories of service providers, each engaged to provide a specific part of the Service, and bound by contractual confidentiality and data protection obligations:

  • Database, authentication, and file storage: to host Customer Data and manage sign-in.
  • Application hosting: to run and serve the Service.
  • Payment processing: to handle subscription billing (Paddle acts as merchant of record for these transactions).
  • Transactional email delivery: to send notifications and receipts.
  • Push notification delivery: to deliver mobile notifications, where enabled.
  • AI processing: to generate a draft process only when an organization actively uses the AI-assist feature.

We may also disclose information where required by law, to protect the rights, property, or safety of Cesflo, our users, or the public, or in connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply to previously collected information.

4. Data retention

We retain Customer Data for as long as a workspace's subscription is active, and for a reasonable period after cancellation or a payment lapse to allow the organization to export its data or resume service, consistent with Section 11 of our Terms of Service. Historical process run data, including resource rates and costs as they stood at the time a run started, is retained as an immutable record even after the underlying resource or template is later changed, since that is what makes historical reporting accurate. We delete or anonymize information when it is no longer needed for these purposes, unless a longer retention period is required by law.

5. Data security

We use technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, role-based access controls, tenant data isolation between organizations, and audit logging of sensitive administrative actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Your rights & choices

Depending on your location, you may have rights to access, correct, export, or request deletion of your personal information. For information submitted by an organization Customer as part of the Service (such as your name and role within a workspace), we generally act on behalf of that organization, and you should direct requests to your organization's administrator in the first instance; where required by law, we will also respond directly. An organization administrator can manage a user's role and access directly from the workspace's Team page, and can request export or deletion of workspace data by contacting us.

7. Children's privacy

The Service is intended for use by working professionals on behalf of an organization and is not directed to children. We do not knowingly collect personal information from children.

8. International data transfers

We and our service providers may process and store information in countries other than where Customer or its users are located. Where we transfer personal information internationally, we use appropriate safeguards required by applicable law.

9. Cookies & similar technologies

The web application uses essential cookies and local storage to maintain a signed-in session and remember interface preferences (such as light/dark theme). We do not currently use third-party advertising or cross-site tracking cookies on the application itself.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable notice before it takes effect, such as an in-app notice or an email to an organization's administrators.

11. Contact

Questions about this Policy, or requests regarding your personal information, can be sent to info@cesflo.com.