GenticFlow
For IT TeamsFor MSPsHow It WorksMobile AppPricing

Privacy Policy

Last updated: July 2026

1. Introduction

GenticFlow Ltd. ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our IT support platform and services.

2. Data Controller and Processor

When you use our Service, you (the customer) are the Data Controller for your Customer Data and Device Diagnostic Data. GenticFlow Ltd. acts as Data Processor on your behalf, processing data only according to your instructions to provide the Service. This includes personal data of your employees and end users who interact with the Service on your behalf, for example through end-user chat or the client portal.

For certain processing we act as a Data Controller in our own right: account and billing information, marketing communications, security monitoring of our platform, and aggregated usage and performance telemetry used to administer, secure, and improve the Service.

For detailed information about our data processing obligations, subprocessors, and international transfers, please refer to our Data Processing Agreement (DPA).

3. Information We Collect

3.1 Information You Provide

  • Account information (name, email, company details)
  • Sign-in information from your organization's identity provider when single sign-on is enabled (such as name, email, and profile attributes)
  • Contact information for support requests
  • Payment and billing information (full payment card details are processed by our payment processor and are never stored on our systems)
  • User-generated content (support tickets, chat messages, and uploaded documents and knowledge content)

3.2 Information Collected Automatically

  • Endpoint diagnostic data (system logs, hardware info, software inventory)
  • Remote support session details (session times, participants, and command and file transfer activity)
  • Usage data (feature usage, session duration, interaction patterns), including data on user interaction with AI features and automation workflows
  • Technical data (IP addresses, browser type, device information)
  • Mobile app data (device identifiers and push notification tokens) when you use our mobile applications
  • Performance and error logs

4. How We Use Your Information

We use collected information to:

  • Provide and maintain our IT support services
  • Gather real-time endpoint diagnostics for troubleshooting
  • Process payments and send billing notifications
  • Respond to support requests and improve customer service
  • Analyze usage patterns to enhance platform functionality, including improving how the Service uses AI models, such as prompt selection and routing, response quality and error-rate measurement, and system performance; this does not involve training AI models on your Customer Data or building fine-tuning datasets from it
  • Comply with legal obligations and enforce our terms

5. Legal Basis for Processing (GDPR)

We process personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service you have subscribed to, including its AI-assisted support features
  • Legitimate Interest: Security monitoring, fraud prevention, service improvements, and analytics
  • Legal Obligation: Tax records, regulatory compliance, and responding to lawful requests
  • Consent: Marketing communications (where applicable)

6. AI and Machine Learning

GenticFlow Ltd. uses AI and machine learning, including large language models operated by third-party providers, to deliver the Service's support features, such as issue investigation, recommended fixes, and end-user chat. AI processing is an integral part of the Service:

  • Data relevant to a support case may be processed by AI models to generate findings, responses, and recommendations
  • Sensitive values such as email addresses, national identifiers, payment card numbers, phone numbers, and API credentials are detected and redacted from prompts before they are sent to AI providers
  • We use third-party AI providers (listed in our DPA) under strict data processing agreements
  • We do not use your Customer Data to train our own AI models. We select third-party AI providers whose commercial API terms state that data submitted through their APIs is not used to train their models; the providers we currently use are listed in our DPA

7. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit using TLS for all connections
  • Application-layer encryption of sensitive fields with per-tenant key separation
  • Role-based access controls with custom roles
  • Two-factor authentication with TOTP and FIDO2 passkeys
  • Endpoint agents run with the permissions necessary for support functions, with audited command execution
  • Complete command history with outputs, approvals, and verification results for endpoint operations

8. Data Sharing and Disclosure

We do not sell your personal information. We may share data with:

  • Service Providers: Cloud hosting, payment processing, analytics (under strict confidentiality agreements)
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with merger, acquisition, or asset sale

9. Aggregated and Anonymized Data

We may create aggregated, anonymized, or de-identified data from your information. This data cannot reasonably be used to identify you. We may use and share aggregated data for analytics, benchmarking, product improvement, and industry reports without restriction.

10. Third-Party Integrations

When you enable integrations with third-party services (such as Microsoft, Google, or other vendors):

  • Data shared with third parties is governed by their respective privacy policies
  • You control which integrations are enabled and what data is shared
  • We are not responsible for the privacy practices of third-party services
  • Disabling an integration may affect related Service functionality

11. Cookies and Tracking

We use cookies and similar technologies to:

  • Essential Cookies: Required for Service functionality and security
  • Analytics Cookies: Help us understand usage patterns and improve the Service
  • Preference Cookies: Remember your settings and preferences

On our public marketing website at genticflow.com (and only on the marketing website - never inside the authenticated GenticFlow application), we use the following third-party analytics tools. They are loaded only after you accept cookies in regions that require consent:

  • Google Analytics 4: Aggregated page views, traffic sources, and conversion events. Marketing website only.
  • Microsoft Clarity: Session replays and heatmaps to understand how visitors interact with the marketing website. Clarity masks all text inputs and sensitive content by default and does not record personal data entered into forms. Marketing website only - not loaded on any authenticated application page.

You can manage cookie preferences through your browser settings or at any time via the Cookie Preferences link in the website footer, which clears your saved choice and shows the consent banner again. Disabling essential cookies may affect Service functionality.

12. Data Retention

We retain your data only as long as necessary to provide services and comply with legal obligations:

  • Account data: Retained during active subscription + 90 days
  • Endpoint diagnostics: Retained for 90 days
  • Support tickets: Retained for 2 years
  • Billing records: Retained for 7 years (tax compliance)

13. Your Rights (GDPR)

Under GDPR and applicable data protection laws, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Export your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to processing based on legitimate interest
  • Withdraw Consent: Withdraw consent at any time for consent-based processing
  • Automated Decisions: Not be subject to decisions based solely on automated processing that significantly affect you
  • Complaint: Lodge a complaint with your local data protection supervisory authority

For clarity, the platform's automated IT troubleshooting and remediation actions are operational tasks performed on devices under policies configured and authorized by the customer. They are not decisions about individuals that produce legal or similarly significant effects, and they do not constitute profiling or automated decision-making within the meaning of GDPR Article 22.

Contact us at [email protected] to exercise these rights. We will respond without undue delay, and in any event within one month (30 days) of receipt.

14. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the CCPA:

  • Right to Know: What personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information
  • Non-Discrimination: We will not discriminate against you for exercising your rights. We do not offer financial incentives in exchange for retaining or selling personal information.

To exercise CCPA rights, contact [email protected].

15. Marketing Communications

We may send you promotional communications about our services. You can opt out at any time by:

  • Clicking "unsubscribe" in any marketing email
  • Updating your communication preferences in account settings
  • Contacting us at [email protected]

Opting out of marketing does not affect transactional communications (billing, security alerts, service updates).

16. International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards through:

  • Standard Contractual Clauses (EU approved)
  • Data Processing Agreements with all subprocessors
  • Regional data residency options for enterprise customers (use of regional data residency options may be subject to additional fees and contractual terms)

17. Children's Privacy

Our services are not intended for users under 18. We do not knowingly collect information from children. If we become aware that we have collected data from a child, we will delete it promptly.

18. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or platform notification at least 30 days before changes take effect. Continued use of the Service after changes constitutes acceptance. It remains your responsibility to keep your account contact information current and to review this policy periodically.

19. Contact Us

For questions about this Privacy Policy or to exercise your data rights, contact us at [email protected].

For formal Data Protection Officer inquiries: [email protected]

GenticFlow Ltd.
Dublin, Ireland

GenticFlow

GenticFlow is where IT teams and MSPs support and manage endpoints from web or mobile, with live device context, remote control, terminal, file access and endpoint actions. It investigates issues, helps technicians act faster, and verifies the outcome, with or without a ticket.

|
Download on the App StoreDownload on the App StoreGet it on Google PlayGet it on Google Play

Product

  • How It Works
  • Interactive Demo
  • Technician Workbench
  • Mobile App
  • Resolution Playbooks
  • Automation Workflows
  • Incident Intelligence

Resources

  • For IT Teams
  • For MSPs
  • Solutions
  • Compare
  • Pricing

Company

  • About
  • Why GenticFlow
  • Partners
  • Careers
  • Contact

Reference

  • Security
  • Integrations
  • Customer Stories
  • Perspectives

© 2026 GenticFlow Ltd. All rights reserved.

Cookie PolicyPrivacy PolicyTerms of Service