← ServiceFlow IQ

Privacy Policy

Last updated 2026-05-20.

What this covers

This policy describes how ServiceFlow IQ ("we") collects, processes, and protects personal information. We act as a data processor for our customers (trade contractors) and as a data controller for our own customers (the operators who sign up for the platform).

What we collect

How we use it

Sub-processors

The full list lives in our developer docs. Notable processors:

Data retention

We retain customer data for as long as the operator's account is active. Upon termination, operators have 30 days to export. After that, data is purged from primary systems within 14 days and from backups within 90 days.

Audit log entries (the activity_log table) are retained for 7 years to meet financial-records-retention obligations.

Your rights (GDPR / CCPA)

Operators may at any time:

Security

We follow the practices documented in our SOC 2 controls mapping: tenant-scoped row-level security on every multi-tenant table, TLS 1.2+ for all transport, HSTS preload, CSP headers, rate limiting, PII redaction in logs, signed customer-portal tokens (HMAC-SHA-256), API key hashing (SHA-256 HMAC).

Children

The Service is not directed at children under 16. We do not knowingly collect personal information from children.

Changes

We will notify operators of material changes to this policy at least 30 days before they take effect.

Contact

Privacy questions or data-subject requests: privacy@serviceflowiq.com.