Skip to main content

Privacy Policy

Last updated: May 1, 2025

Privacy Policy

This Privacy Policy explains how Startbase LTD ("Startbase", "we", "us", or "our") collects, uses, shares, and protects personal data when you use ActionFlows.ai (the "Service"). Startbase LTD is a company registered in England and Wales under company number 15278821. Our registered office is 24-26 Arcadia Avenue, FIN009, London, England, N3 2JU.

For this Privacy Policy, Startbase LTD is the controller of personal data we process about you as a user of the Service, unless we process data on behalf of an organisation customer under a data processing agreement.

If you do not agree with this policy, do not use the Service.

This policy should be read with:

Questions: [email protected]. Data processing agreement requests: [email protected].

1. What this policy covers

This policy covers personal data processed through our website at ActionFlows.ai, the ActionFlows application, and related support. It does not replace the privacy policies of third-party AI model providers, integrations, or MCP servers that you choose to connect. Those providers process data under their own terms once it leaves our Service.

2. Definitions

Service means the ActionFlows.ai website, application, APIs, and related features operated by Startbase LTD.

Personal data means information relating to an identified or identifiable living person.

Organisation means a workspace or organisation account on the Service, including a personal organisation.

You means a visitor, registered user, or member of an organisation using the Service.

3. Personal data we collect

Data you give us

Depending on how you use the Service, this may include:

  • Name, email address, and password (if you register with email)
  • Organisation or company name and billing details
  • Support messages, feedback, and files you send us
  • Flow designs, workflow configuration, prompts, and other content you create
  • API keys, OAuth tokens, and other credentials you store so that flows can call third-party services
  • Profile details you choose to add

We do not store full payment card numbers on our systems. Payments are processed by Stripe. Stripe's privacy notice is at https://stripe.com/privacy.

Google sign-in

You may create or access an account with Google. If you do, we receive the account identifiers Google provides (typically name, email address, and a provider account id) so we can authenticate you. GitHub and similar providers may be used as integrations inside a flow. They are not currently offered as a sign-in method on the Service.

Data collected automatically

When you use the Service we collect technical and usage data needed to operate, secure, and improve it. This typically includes IP address, browser and device characteristics, approximate location derived from IP address, timestamps, pages and features used, diagnostic logs, and error reports. We do not use GPS or device location permission to track your physical location.

We also use cookies and similar technologies as described in the Cookie Policy.

Data from organisations and administrators

If you join an organisation, administrators can see membership, access, and usage information for that organisation. They may ask us to restrict or delete a member's access.

4. How we use personal data and legal bases

We process personal data to:

  • Create and administer accounts, organisations, and authentication
  • Provide the Service, including running flows, agents, schedules, and APIs you request
  • Process subscriptions, credits, invoices, and tax records through Stripe
  • Provide support and communicate about the Service (security, billing, and material changes)
  • Send marketing only where you have consented or where another lawful basis applies, with an unsubscribe option
  • Maintain security, prevent abuse and fraud, and debug the Service
  • Comply with law, enforce our terms, and protect our legal rights
  • Understand aggregated product usage so we can improve the Service

Where UK GDPR or EU GDPR applies, we rely on one or more of:

  • Contract: to provide the Service you asked for
  • Legitimate interests: to secure, operate, and improve the Service, provided those interests are not overridden by your rights
  • Consent: for non-essential cookies and for marketing where consent is required
  • Legal obligation: for tax, accounting, and regulatory duties

We do not use special category (sensitive) data as a product feature. Do not use the Service to store health, biometric, or similar special category data unless you have a lawful basis and an appropriate agreement with us.

5. Cookies and similar technologies

We use necessary cookies and local storage to run the Service. Analytics and marketing technologies load only with your consent. Details, categories, and how to change your choices are in the Cookie Policy. You can reopen the Privacy preference center from the website footer.

6. How long we keep data

We keep personal data only as long as needed for the purposes above, including:

  • Account and organisation data: while the account is active, then for a limited period needed to close the account, resolve disputes, and meet legal duties (typically up to 30 days after deletion for operational copies, unless a longer legal retention applies)
  • Billing and invoice data: as required by UK tax and accounting rules (generally 6 to 7 years)
  • Support records: typically up to 2 years after the request is closed
  • Security and server logs: typically up to 90 days, unless needed longer for an investigation
  • Marketing preferences: until you opt out or we no longer need them

Backups may retain deleted data for a short additional period until they rotate.

7. Where data is processed

We use cloud infrastructure, hosting, databases, object storage, email, error monitoring, and similar processors. We do not currently offer a self-serve control that pins all of your data to a single AWS region. Personal data may be processed in the United Kingdom, the European Economic Area, the United States, and other countries where our providers operate.

When we transfer personal data from the UK or EEA to a country without an adequacy decision, we use appropriate safeguards, typically the applicable standard contractual clauses, unless another lawful transfer mechanism applies.

You choose which AI models and integrations a flow calls. Those providers may process the data you send them in other countries under their own policies.

8. How we protect data

We use technical and organisational measures appropriate to the risk. These currently include access controls, encryption in transit, encryption of stored credentials, backups, and staff access limited to what is needed to do the job.

No internet service is completely secure. You are responsible for your password, organisation invitations, and the credentials you store in the Service.

9. Personal data breach

If a personal data breach must be reported under UK GDPR or EU GDPR, we will notify the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it. We will notify affected individuals without undue delay where the law requires that notice.

10. Children

The Service is not directed at children under 18. We do not knowingly collect personal data from children under 18. If you believe we have done so, contact [email protected] and we will delete the data.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict personal data, to object to certain processing, to withdraw consent, and to data portability.

United Kingdom and European Economic Area. You may also lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO).

United States. If you are a resident of a US state with a consumer privacy law (including California), you may have additional rights to know, delete, correct, or opt out of certain sharing or targeted advertising. We will not discriminate against you for exercising those rights.

To use these rights, email [email protected]. We may need to verify your identity. Organisation administrators can also manage member access inside the product.

You can export flow designs in JSON from the product where that feature is available. You may also request a copy of account data by email.

Marketing

You can opt out of marketing emails using the unsubscribe link or by emailing us. Service messages about your account, security, and billing may still be sent.

Do Not Track

There is no single industry standard for Do Not Track signals. Our cookie banner and Privacy preference center are the controls we provide for analytics and marketing technologies.

12. When we share personal data

We share personal data only as needed:

  • Processors who host, store, send email, process payments (Stripe), provide analytics (Google Analytics, only with consent), or otherwise help us run the Service, under contract
  • Google if you use Google sign-in
  • AI model providers and integrations you configure, for the data a flow actually sends them
  • Organisation members and administrators according to the permissions in that organisation
  • Professional advisers, such as lawyers and accountants, where needed
  • Authorities if required by law
  • A buyer or successor if we sell or restructure the business, with appropriate protections

We do not sell personal data.

13. Third-party integrations and MCP

The Service can connect to third-party tools (for example email, GitHub, Slack, databases, storage, and MCP servers). You decide which connections to enable. We store credentials you provide in encrypted form and use them to run the flows you configure. We do not keep raw third-party payloads longer than needed to run, debug, or secure those flows, except logs described above.

You must have the right to connect each third-party account. Their terms and privacy policies apply to data they receive.

14. Automated processing

We use automated processing to run flows, route jobs, apply rate limits, detect abuse, and suggest product behaviour such as interface state. These operations do not produce legal or similarly significant effects about you as defined in UK GDPR or EU GDPR Article 22. If that changes, we will tell you and provide any required human review.

15. AI and training

We do not use your flows, prompts, or uploaded files to train ActionFlows' own models.

When a flow calls a third-party AI provider you selected, that provider processes the payload under its own terms. We do not claim that every provider has a zero-retention or no-training agreement. Check the provider you configure, and use a provider with a suitable data-processing term if that matters for your use.

16. Organisation access control

Organisation administrators can invite and remove members, limit access to flows, and request deletion of a member's organisation access. To request a full account deletion, use account settings where available or email [email protected].

17. Changes

We may update this policy. The "Last updated" date at the top will change. For material changes we may also email the address on your account or show a notice in the Service. Continued use after the update means you should read the new policy. If you do not agree, stop using the Service and request deletion.

18. Contact

Startbase LTD

24-26 Arcadia Avenue, FIN009

London, England, N3 2JU

United Kingdom

Company number: 15278821

Email: [email protected]

Data processing agreements: [email protected]

Start building AI workflows

Create a free account, open a template or a blank canvas, and run your first ActionFlow.

Newsletter

Get product updates

New nodes, agents, and product notes. We send mail only when we have something worth opening.

Unsubscribe at any time.