Privacy Policy — Coflow
Last updated: 27/08/2026
1. Introduction
SheBossIt (Cyprus) Ltd (hereinafter: "Coflow" or "We"), which operates the Coflow platform for managing the marketing, sales and clients of businesses, personal brands and agencies (the "Platform" or the "Service"), respects the privacy of its users and customers and is committed to protecting the Personal Data collected about them. This privacy policy describes how Coflow collects, uses, retains, discloses, and protects Personal Data when you use the Service, in accordance with the EU General Data Protection Regulation (GDPR) and applicable law.
1.1 Two Capacities — Data Controller and Data Processor
Coflow acts in two distinct capacities with respect to Personal Data, and it is important to distinguish between them:
As a Data Controller — with respect to the Personal Data of the account holders themselves (users who register for the Service). This privacy policy addresses this capacity.
As a Data Processor — with respect to Personal Data that customers enter into the Platform about their own contacts, recipients and leads. In that case the customer is the owner of the database and the controller, and Coflow processes such data solely on the customer’s behalf and instructions. That processing is governed by a separate Data Processing Agreement (DPA), which forms part of the engagement terms, and is not governed by this privacy policy.
2. Information We Collect (as Data Controller)
The information described in this section relates to information Coflow collects in its capacity as Data Controller — that is, about account holders and visitors to the Service.
2.1 Information You Provide Directly
When you open an account and use the Service, we may collect:
Identity and contact details: full name, email address, field of business, and links to the profiles and platforms managed.
Login credentials: email and password, or Google account details where you sign in with Google.
Content and files you choose to upload: brand materials, post media, task attachments, profile pictures, and larger video and audio files; business documents such as price quotes and service descriptions; and personal documents and podcast content you choose to store on the Platform.
2.2 Information from Connected Accounts (Integrations)
Subject to the permission you grant, and using read-only permissions only, we pull information from accounts you choose to connect:
Instagram — basic business profile and posts.
YouTube — channel and video statistics.
Google Calendar — read-only calendar access and the account’s email address, and adding events created through the Service (such as booked calls and meetings). Coflow does not change or delete existing events.
Zoho Books — read-only access to invoices and contacts, to match invoices to brands.
Wix — for customers whose website is built on Wix.
ManyChat — the account’s automation catalogue (flow names and growth tools), to link them to offers.
Rav Messer — the subscribers in the lists you choose to connect, to import them into your Coflow mailing lists.
You may revoke these permissions at any time.
2.3 Payment Information
Subscription details, payment status and service plan. Important Clarification: payments are processed by Stripe, and full credit-card details are not stored on Coflow’s servers.
2.4 Technical Information and Cookies
The Platform uses first-party cookies only, classified as follows:
Essential cookies: required to operate the Service, manage login, identify the current workspace and protect against request forgery when connecting external accounts. This use does not require consent under the GDPR.
Functional cookies: store language and time-zone preferences for correct display.
Affiliate (marketing) cookie: records the partner link through which you arrived (90-day lifetime), to credit affiliates. This cookie is not essential to the Service and is set only subject to your explicit consent through the cookie banner.
Arrival-journey (marketing) cookie: records which channels and links you arrived through (90-day lifetime), to understand which channels bring sign-ups. This cookie is not essential to the Service and is set only subject to your explicit consent through the cookie banner.
Diagnostic cookies: used for troubleshooting and internal testing only, and are not active in production under normal operation.
The Platform does not use third-party cookies for advertising, analytics or user tracking (such as Google Analytics or Meta Pixel).
Note: the marketing website coflow.social is a separate environment from the Platform and uses a single functional cookie only, to remember the language choice.
2.5 Information Generated Through Use
Engagement metrics and follower data collected from connected accounts; basic usage data (signup date, last sign-in, brand name, plan and payment status, and the platforms managed) accessible to Coflow staff for operations and support; and technical log data for security and troubleshooting.
3. Processing by Artificial Intelligence (AI)
Certain Platform features rely on third-party AI engines — OpenAI and Anthropic (Claude). To operate the generation features, content you enter (including brand materials and business text you type) is transmitted to these providers to generate the requested output. Contact records are not routinely transmitted for these features.
The AI providers act as Data Processors on Coflow’s behalf and under contractual commitments. The Platform does not make solely automated decisions producing legal or similarly significant effects concerning you. AI outputs are recommendations only, and reliance on them is at the user’s responsibility.
4. Purposes of Processing and Legal Basis
We process your Personal Data for the following purposes, based on the GDPR legal bases:
| Purpose of Processing | Type of Data | Legal Basis (GDPR) |
|---|---|---|
| Providing the Service and operating the Platform | Account details, content, files | Contract — Art. 6(1)(b) |
| Account management, authentication and security | Login credentials, log data | Legitimate interest — Art. 6(1)(f) |
| AI-based generation features | Content and business text entered | Contract — Art. 6(1)(b) |
| Billing, payments and invoicing | Subscription details, payment history | Legal obligation / Contract — Art. 6(1)(c)/(b) |
| Service and operational communications | Contact details | Legitimate interest — Art. 6(1)(f) |
| Marketing communications from Coflow | Name, email | Consent / Legitimate interest — Art. 6(1)(a)/(f) |
| Affiliate attribution | Affiliate link identifier | Consent — Art. 6(1)(a) |
| Error monitoring and system security | Anonymous user ID, performance data | Legitimate interest — Art. 6(1)(f) |
| Compliance with legal obligations | Accounting data | Legal obligation — Art. 6(1)(c) |
5. Sharing Information with Third Parties
We do not sell your Personal Data. We share information only with the following parties and for the purpose of providing the Service. Our current list of service providers (sub-processors) includes:
Infrastructure and storage: Netlify (hosting and job execution), Supabase (database, storage and authentication), Cloudflare R2 (large-media storage).
Artificial intelligence: OpenAI, Anthropic (Claude).
Payments: Stripe (payment processing), Zoho Books (read-only invoice access on the agency side).
Email and messaging: Resend (system notifications and mailing). Platform data and integrations: Meta/Instagram, Google, Wix, ManyChat, Rav Messer, Apify (collection of publicly available posts for research and metrics).
Monitoring and development infrastructure: Sentry (error monitoring — configured so that no Personal Data is transmitted to it), GitHub (source-code management, no customer data).
Data Processing Agreements (DPAs) are in place with providers that hold or transmit Personal Data. Where a customer grants an agency access to its account, the agency acts as a sub-processor on the customer’s behalf and instructions, and it is the customer who grants and revokes such access — as detailed in the Terms of Use and the Data Processing Agreement.
6. International Data Transfers
Coflow is incorporated in Cyprus (an EU Member State). Information may be transferred for processing between Israel, the European Union and cloud providers operating in the United States.
The European Commission has determined that Israel provides an adequate level of protection for Personal Data (Adequacy Decision). This means that Personal Data may be transferred from the European Union to Israel without the need for additional legal measures.
With respect to providers operating outside the European Economic Area (such as in the United States), transfers are carried out in accordance with recognized transfer frameworks (such as the Data Privacy Framework) or by means of Standard Contractual Clauses (SCC).
7. Data Retention
We retain your Personal Data only for as long as necessary for the purposes set out in this policy:
Operational data: retained for as long as your account is active or as required to provide the Service.
Accounting data: invoices and transaction details are retained for 7 years as required by tax law.
Marketing data: retained until you request removal from the mailing list (Unsubscribe).
System and error logs: retained for a limited period for security and maintenance.
At the end of these periods, the data is deleted or anonymized.
8. Information Security
We take reasonable technical and organizational measures to protect Personal Data, including encryption of data in transit, limiting access to authorized personnel only on a need-to-know basis and in accordance with internal policy, and imposing confidentiality obligations on those with access. The error-monitoring setup is configured so that it does not include Personal Data (anonymous user IDs, scrubbing of email addresses and access tokens, and session recording disabled).
Nevertheless, please note that no security measure provides absolute protection, and transmission of data over the internet is not 100% secure.
9. Your Rights (under the GDPR)
As a Data Subject, you have the following rights:
Right of access — to request a copy of the Personal Data we hold about you.
Right to rectification — to request correction of inaccurate or outdated information.
Right to erasure ("right to be forgotten") — to request deletion of your data.
Right to restriction and to object — including objection to processing for direct-marketing purposes.
Right to data portability — to receive your data in a structured, machine- format.
Right to withdraw consent — where processing is based on your consent, without affecting the lawfulness of processing carried out beforehand.
Right to lodge a complaint — with the competent supervisory authority. The relevant authority for Coflow is the Cyprus data-protection authority (Office of the Commissioner for Personal Data Protection, www.dataprotection.gov.cy).
Rights are exercised by contacting us, and we will respond within the period prescribed by law (generally one month), subject to the provisions of the law.
10. Children’s Privacy
The Service is intended for businesses and users aged 18 and over and is not directed to minors. We do not knowingly collect Personal Data from minors under the age of 18.
11. Changes to this Privacy Policy
We may update this policy from time to time. In the event of a material change, we will post a prominent notice within the Service or send notice by email. Continued use of the Service after the update constitutes acceptance of the updated policy.
12. Contact Us
For questions regarding this privacy policy, or to exercise your rights, please contact us:
Company name: SheBossIt (Cyprus) Ltd
Email: contact@shebossit.com
Address: Ifigenias 8, Livadia, Cyprus