HadesFlow Logo HadesFlow
Home About Services Pricing Blog Contact
HadesFlow Logo HadesFlow
Home About Services Pricing Blog Contact

Privacy Policy

HadesFlow Ltd., Bulgaria
contact@hadesflow.com
Last updated: November 2025

1. General information

At HadesFlow, we value your privacy and are committed to protecting the personal data you entrust to us. This Privacy Policy explains how we collect, use, and safeguard your information when you use our website, services, and AI automation solutions. This information is provided to inform visitors and users of the website about the types, scope, and purposes of personal data processing when accessing the site or using its services. We also explain the rights individuals have regarding the processing of their data. You can visit the website without us collecting any personal data. However, to access certain services on the site, processing personal data may be necessary. This processing is carried out in accordance with legal authorization, in line with the General Data Protection Regulation (EU) 2016/679

2. Owner of the Application

The owner of the HadesFlow ("Owner"), is HadesFlow Ltd. - UIC 208438230, with its headquarters at Sofia, Bulgaria, contact@hadesflow.com.

3. Administrator and Processor of Personal Data

For the purposes of providing the HadesFlow services, the administrator and the processor of personal data ("Administrator") is the owner of the website - HadesFlow Ltd. - UIC 208438230, with its headquarters at Sofia, Bulgaria, contact@hadesflow.com

4. Data Collection and Information

When using HadesFlow services, general data and information are collected and stored in log files on our server. This includes data as follows:

  • Contact Information: Name, email address, phone number, company name.
  • Business Data: Use cases, project goals, technical requirements.
  • Technical Data: Browser type, device, IP address (for analytics and security).
  • Support Data: Chat logs, service tickets, feedback.
  • Payment Data: (For billing purposes – processed via secure third-party platforms like Stripe or PayPal).

We do not collect or store sensitive data unless explicitly required and agreed upon for a project.

4.1. Data Storage and Security

Cloud Accounts (Recommended for starters): For faster setup and improved user experience, we now recommend clients to create a Cloud account. This allows for reliable, GDPR-compliant orchestration of workflows and integrations without needing server provisioning. You remain the owner of your data within the cloud server, and we assist only with workflow configuration if authorized.

For Self-Hosted Clients: You retain full control over your infrastructure. We do not access or store your data unless explicitly granted for setup or support.

All systems and third-party tools are selected with GDPR compliance and security as top priorities. We apply strong encryption, secure credentials storage, and access controls throughout all deployments. For more questions regarding hosting options, please contact us via the contact form or via email to: contact@hadesflow.com.

4.2. Contact via the Website

Visitors and users have the option to contact us through the website. When you use our contact form or reach out via email, the personal data you provide is automatically stored. The data is processed solely for the purpose of handling the contact request and is generally not shared with third parties unless sharing is necessary to process the inquiry.

4.3. Routine Deletion and Blocking of Personal Data

Personal data is stored only for as long as necessary to fulfill the purpose of processing or as required by law.

Once the purpose has been achieved or the legal retention period has expired, the personal data is routinely deleted in accordance with the legal regulations. If the intended purpose of the processing has been fulfilled but the data cannot yet be deleted due to legal requirements, it will be blocked instead.

4.4. AI-Powered Chat Assistant

The chat widget available on this website is an AI-powered assistant, not a human agent. In line with the transparency obligations of the EU AI Act (Regulation (EU) 2024/1689), Article 50, we want you to know that you are interacting with an automated system when you use it.

When you send a message, the text you enter is processed by an automated workflow that relies on a third-party large language model (LLM) provider to generate replies. Chat inputs and the resulting conversation logs may be temporarily stored to operate the service, respond to your request, maintain quality, and improve our assistant. Please do not share sensitive personal data, passwords, or payment details in the chat. AI-generated responses may occasionally be inaccurate or incomplete and should not be treated as professional, legal, or financial advice; for anything important, please verify with us directly.

The assistant does not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 of the GDPR. You can always reach a human by emailing contact@hadesflow.com or using our contact form.

5. Right to Access and Correction

Individuals whose data is being processed have the legal right to request information, correction, and deletion of their personal data. These rights can be exercised at any time by submitting a request via our contact form or by sending an email to contact@hadesflow.com.

5.1. Right to Erasure

If an erasure request is made, personal data must be deleted immediately if any of the following apply:

  • The data was collected or processed for purposes that are no longer necessary.
  • The data was collected based solely on the individual's consent, which has since been withdrawn.
  • The individual has objected to processing under Article 21 of the GDPR, and there are no overriding legitimate grounds for continuing the processing.
  • The personal data was processed illegally.
  • Deletion is required by law.

If the data in question has been made public, appropriate measures will be taken to inform third parties who are processing the data about the deletion request, in accordance with Article 17(1) of the GDPR.

5.2. Right to Restrict Processing

The data subject has the legal right to request the restriction of processing if:

  • The individual disputes the accuracy of personal data.
  • The individual has objected to processing under Article 21(1) of the GDPR.

In these cases, processing must be restricted for the necessary period to verify the accuracy of the data or to determine whether there are valid reasons for continuing the processing that outweigh the individual's interests. Processing should also be restricted if the data is no longer necessary for the purpose it was originally collected, but it must still be retained for legal claims.

5.3. Right to Object

Data subjects have the legal right to object to the processing of their data at any time.

If an objection is raised, the data will no longer be processed unless there are demonstrable, valid legitimate reasons for continuing the processing that outweighs the rights, interests, and freedoms of the individual, or if the processing is necessary for the establishment, exercise, or defense of legal claims.

In the case of objections to processing for marketing purposes, the objection will generally take precedence. The data will no longer be used for these purposes.

5.4. Right to Withdraw Consent

Individuals have the right to withdraw their consent for data processing at any time.

6. Collection and Storage of Personal Data, and Their Purpose

6.1. When Visiting the Website

When you visit our website, the browser on your device automatically sends certain information to the server of our site. This information is temporarily stored in a log file. The following data is collected without your input and stored until it is automatically deleted:

  • IP address
  • Date and time of access

This data is processed for the following purposes:

  • Evaluating system security and stability
  • Error analysis
  • Other administrative purposes

Data that allows identification, such as your IP address, is deleted after a short period of time. If we retain the data beyond this period, it is anonymized so that it can no longer be linked to you.

The legal basis for processing this data is Article 6(1) of the GDPR. Our legitimate interest lies in the purposes listed above. Under no circumstances do we use this data to draw conclusions about your identity.

6.2. Contact Form / Email Contact

We offer a contact form on our website, allowing you to reach out to us at any time. To use the contact form, you must provide a name and a valid email address and phone number (so we know who the request is from and can respond accordingly).

When you submit inquiries via the contact form, the information provided, including your contact details and IP address, will be processed under Articles 6(1)(b) and (f) of the GDPR.

Alternatively, you are welcome to contact us via email using the address provided on our website. In this case, we will store and process your email address and the content of your message according to Articles 6(1)(b) and (f) of the GDPR, in order to respond to your inquiry.

Inquiries and related data will be deleted shortly after unless further retention is required for an ongoing contractual relationship.

7. Transfer of Personal Data

The transfer of personal data also falls under the definition of processing. However, we would like to specifically address the issue of sharing data with third parties. Protecting your data is extremely important to us, and we are very careful when it comes to sharing your information with others.

We only share personal data with third parties when there is a legal basis for doing so. For example, we may share data with individuals or companies who work with us as data processors under Article 28 of the GDPR. A processor is anyone who processes personal data on our behalf, typically within a relationship where we provide instructions and oversight.

In line with GDPR requirements, we get into contracts with all our processors, ensuring they comply with data protection regulations to safeguard your data.

8. Storage Period and Deletion

We only store your personal data for as long as necessary to fulfill the purposes for which it was provided, or as required by law. Once the purpose has been achieved and/or the legal retention period has expired, we will delete or block the data.

9. SSL Encryption

This website uses SSL encryption for security purposes to protect the transmission of confidential information, such as the requests you send to us as the website operator. You can identify an encrypted connection by the address bar changing from "http://" to "https://" and by the lock icon that appears in the address bar in your browser.

When SSL encryption is enabled, any data you send to us cannot be accessed by third parties.

10. Renewal

We periodically revise and update this declaration to ensure it remains clear, accurate, and transparent, reflecting any changes that may have occurred.

Last updated: November 2025.

11. Information on the Competent Supervisory Authority

If you believe that our processing of your data violates the provisions on personal data protection or that your rights under these provisions have been violated in any way, you can contact the competent administrative authority. In the Republic of Bulgaria, this is the Commission for Personal Data Protection.

12. Information not Contained in This Policy

The collection and processing of personal data complies with the provisions of Regulation (EU) 2016/679, as well as the legislation of the Republic of Bulgaria in the field of personal data protection.

Title: Commission for Personal Data Protection

Headquarters and address of management: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov" № 2

Correspondence data: Sofia 1592, Blvd. "Prof. Tsvetan Lazarov" № 2

Phone: +359 2 915 3 518

Email: kzld@government.bg, kzld@cpdp.bg

Website: www.cpdp.bg.

Home About Services Pricing Blog Contact
Terms and Conditions Privacy Policy FAQ

© 2024 HadesFlow AI Automation Agency. All rights reserved.