Skip to content
KaryaFlow OS

Pre-release legal boundary

Privacy notice

This notice describes the software's data surface and the responsibilities of a self-hosted operator; it is not a managed-service data-processing agreement.

Last updated 22 July 2026

Pre-release scope

This notice describes the categories of data the software can process. It is not a complete privacy notice for a managed service because the public preview does not yet publish an identified service operator, legal address, subprocessors, retention schedule or verified privacy contact.

Use only seed or non-sensitive evaluation data in this preview. In a self-hosted deployment, the deploying business determines the purposes and means of processing and must provide its own notices, lawful basis, rights process, retention rules and processor contracts.

Data we handle

We may handle account details such as your name, work email, business name, role and authentication records. Service use can produce device, session, security, audit and support records.

Business users may add customer, supplier, employee, invoice, payment, compliance and operational information. The exact data depends on which KaryaFlow modules the business enables.

How we use data

  • Provide, secure and maintain a workspace.
  • Authenticate users and support account recovery when delivery channels are configured.
  • Process business actions requested by authorised users.
  • Investigate errors, misuse and security incidents.
  • Send service, security and account communications when an operator configures delivery.
  • Support the operator's documented legal and contractual obligations.

Sharing and service providers

The Community software does not require sale of personal data. A self-hosted operator chooses its hosting, storage, communications, monitoring, AI, payment, tax, bank and signing providers and is responsible for disclosing and governing those transfers.

No list of managed-service subprocessors or cross-border transfer mechanism is claimed on this page because no production managed-service privacy programme is published here.

Retention and security

The software contains operational records, audit trails, backup and export capabilities, but the operator determines and enforces the lawful retention and deletion schedule for its deployment.

Security controls reduce risk but are not a certification or promise of absolute security. Operators must validate transport encryption, access control, secrets, storage, backups and recovery in their environment. See the Security page.

Your choices and rights

Users can correct some account and workspace information through authorised product flows. Applicable law may provide access, correction, deletion, restriction, objection or portability rights.

For self-hosted installations, those requests go to the business operating the deployment. This preview does not claim a central rights-request service.

Contact and complaints

privacy@karyaflow.com is a reserved address, but its receipt path is not yet release-verified and must not be relied on for rights requests or confidential data. A production service must publish its operator identity, legal contact and verified request channel before accepting production data.

For a self-hosted installation, contact the business operating that installation. Do not email passwords, payment credentials or confidential records to an unverified address.

Related information

Read the Terms of Service and our security practices.