Kissflow

Privacy Policy

01.09.2026

Effective date: 01 September 2026.
For the prior version, please click here.

This Privacy Policy (the “Policy”) describes how Kissflow collects, uses, discloses and otherwise processes information, including Personal Data (as defined below), in connection with your interactions with us. It applies to (a) individuals who visit the website or any of Kissflow's other web properties, blogs, landing pages, demos, event registrations or forums; (b) account administrators, billing contacts, support contacts and other named contacts of organisations that subscribe to the Kissflow services (each, a “Subscriber”, and each such individual, an “Authorised User Contact”); (c) recipients of Kissflow's marketing communications and other individuals who contact Kissflow to request information, support, a demo or a proposal; (d) individuals whose personal data is collected through cookies and similar tracking technologies on Kissflow's web properties; and (e) job applicants who apply for, or express interest in, a role with Kissflow or any of its group entities. Such individuals are referred to collectively as “you”.

This Policy does not apply to (a) the content that Subscribers and their end-users upload, submit, integrate or otherwise process while using the Kissflow platform (“Customer Data”), which Kissflow processes only on the Subscriber's behalf as a data processor under the applicable Kissflow Data Processing Addendum (the “DPA”); (b) employees and former employees of Kissflow, who are covered by Kissflow's internal Employee Privacy Notice; and (c) any hosted application, workflow or workspace built by a Subscriber on the Kissflow platform, which is governed by the Subscriber's own privacy notice.

This Policy is drafted in the terminology of the Digital Personal Data Protection Act, 2023 of India (the “DPDPA”). Data Fiduciary and Data Controller refer to the same role under the DPDPA and the EU and UK General Data Protection Regulations respectively; Data Principal and Data Subject refer to the same person; and Personal Data has the meaning given to it under the applicable law.

1. Types of Data We Collect

1.1 Non-Personal Data means information that does not identify you and that we cannot reasonably use to identify you, including aggregated, anonymised or de-identified information (for example, device and browser type, operating system, pages viewed and interaction frequency). We may use Non-Personal Data for any lawful purpose and will not attempt to re-identify de-identified data.

1.2 Personal Data means information that identifies you or that may, with reasonable effort, be used to identify you. Any Non-Personal Data connected or linked to Personal Data shall be treated as Personal Data for so long as such connection or linkage exists.

Depending on how you interact with Kissflow, we collect Personal Data from the sources set out below.

Source

What we collect

Directly from you

(a) When you subscribe to any of our services and agree to the applicable Terms of Service, we collect your name, email address, geolocation and contact details; (b) when you submit web forms on our web properties or use interactive features (including providing feedback or suggestions, making requests, or participating in surveys, contests, webinars, events, podcasts, promotions or sweepstakes, requesting customer support or otherwise communicating with us); (c) when you provide testimonials, forms or information to us in other contexts; and (d) when you authorise us to connect with a third-party service, we access and store the Personal Data that the third-party service makes available to us, which may include your email address, location or profile information.

Automatically through our web properties and platform

(a) When you access or use our services, we automatically collect information on the type of device you use and the operating system version, to perform our agreement with you; (b) online identifiers, service usage and telemetry data generated when you visit our web properties or use the Kissflow services; and (c) information collected via your browser's cookies, as further described in Section 3.

From third parties

(a) Marketing lists, databases and social media, but only where we have checked that those third parties either have your consent or are otherwise legally permitted or required to disclose your Personal Data to us; (b) business or channel partners through whom you create or access your account; (c) publicly available sources; (d) email add-ons and other tools; (e) lead-enrichment and business-intelligence providers; (f) recruitment platforms; and (g) third-party log-in services that share information with us.

Our web properties may include social media features and widgets that are hosted by third parties or embedded directly on our web properties. Your interaction with those features is governed by the privacy notice of the company that provides them. You should review your privacy settings on those third-party services to understand and manage the information sent to us through them.

2. Personal Data Sets We Process & Purpose of Collection and Use

The table below sets out, for each purpose for which we process Personal Data, (a) the categories of Personal Data processed, (b) the purpose and processing operations and (c) the lawful basis under the DPDPA, the GDPR / UK GDPR and the CCPA (and other applicable US state privacy laws). Retention is dealt with separately in Section 5.

Personal Data set

Purpose and operations

Lawful basis

Prospect and Website Visitor Data: online identifiers (IP address, cookie ID and unique identifiers), approximate geographic location, browsing and interaction data, and, where you voluntarily provide it, contact information (name, business email, job title, company, country and phone number).

To operate our web properties, understand how they are used, engage with prospective customers, respond to inquiries and demo requests, deliver marketing communications and measure the effectiveness of our marketing.

DPDPA: Legitimate Use under Section 7 for security and operation of the web properties; Consent under Section 6 for direct marketing.

GDPR / UK GDPR: Article 6(1)(f) legitimate interests for operation, security and non-marketing analytics; Article 6(1)(a) consent for direct marketing and non-essential cookies.

CCPA / other US state laws: Business Purpose for operation, security and debugging; consent-based or opt-out for marketing and cross-context behavioural advertising.

Communications Data: any communication between you and Kissflow by email, phone, video call, chat, in-product messaging or otherwise, which may be processed, recorded, stored, summarised and transmitted, including support ticket metadata and attachments.

To provide the response, information or support you have requested; to maintain and improve the quality of our services; to train our personnel and AI-enabled tools (including recorded or monitored calls); and to establish, exercise or defend legal claims.

DPDPA: Legitimate Use under Section 7 for provision of the services and internal recordkeeping; Section 7(a) where necessary for a contract.

GDPR / UK GDPR: Article 6(1)(b) for the contract; Article 6(1)(f) for quality assurance and training. Where required by applicable law, call recording is subject to notice and, where required, consent.

CCPA / other US state laws: Business Purpose for provision of the services, quality assurance and legal claims.

Subscriber Account Data: name, business email, job title, organisation, account credentials, billing contact and billing address of Authorised User Contacts. Full payment-card numbers are processed by our payment processor and are not retained by Kissflow.

To create, administer and support the Subscriber's Kissflow tenant; to manage billing, invoicing and payments; to send service-related communications; and to send Direct Marketing to Authorised User Contacts, subject to their preferences.

DPDPA: Section 7(a) for a contract; Section 7(g) for legal obligation (taxation, accounting); Section 6 Consent for direct marketing.

GDPR / UK GDPR: Article 6(1)(b) for the contract; Article 6(1)(c) for statutory recordkeeping; Article 6(1)(f) or Article 6(1)(a) for direct marketing depending on local law.

CCPA / other US state laws: Business Purpose for provision of the services and statutory recordkeeping; consent-based or opt-out for marketing.

Service Usage and Telemetry Data: online identifiers, access logs, duration of use, click-stream and session data, service and platform interaction data, analytics and login data.

To understand how the Kissflow services are used and to operate, maintain, improve and develop them; to troubleshoot technical issues; and to support product planning and the development of new features.

DPDPA: Legitimate Use under Section 7.

GDPR / UK GDPR: Article 6(1)(f) legitimate interests.

CCPA / other US state laws: Business Purpose.

Security and Audit Data

To secure the Kissflow services and our web properties, prevent fraud and misuse, detect and investigate security incidents and enforce our terms.

DPDPA: Section 7(c) and Section 7(g).

GDPR / UK GDPR: Article 6(1)(c) and Article 6(1)(f).

CCPA / other US state laws: Business Purpose.

Recruitment Data: name, contact details, curriculum vitae, employment history, education, references, application status, interview notes and right-to-work information where permitted by applicable law.

To assess your application, take steps prior to entering an employment contract, and, with your consent, retain your details for future opportunities. If your application is successful, your data is transferred to the employee record.

DPDPA: Section 6 Consent and Section 7(a).

GDPR / UK GDPR: Article 6(1)(b) and Article 6(1)(f); Article 6(1)(a) for future-opportunities retention.

CCPA / other US state laws: Applicant notice under the applicable state law.

Compliance Data: records demonstrating our compliance with this Policy, applicable data protection law and any regulator or court order.

To evidence compliance with legal, regulatory and contractual obligations; to respond to law-enforcement, regulatory and court requests; and to establish, exercise or defend legal claims.

DPDPA: Section 7(g).

GDPR / UK GDPR: Article 6(1)(c).

CCPA / other US state laws: Legal obligation.

For data subjects or Data Principals located in jurisdictions not expressly identified above, we collect and use Personal Data only where we have a lawful basis to do so under the applicable local law. Such a basis may include the performance of a contract, compliance with legal obligations, our legitimate interests (where not overridden by your rights) or your consent, as required under the applicable regime.

Transfers of Personal Data to third countries, as further detailed in Section 7, are based on the same lawful basis set out above. We will not use your Personal Data for any purpose materially different from the purposes above, save as authorised by you or required by applicable law.

3. Cookies & Tracking Technologies

Cookies are small text files placed on your device to collect standard internet log and visitor behaviour information. When you visit our web properties, we may automatically collect Personal Data from you through cookies or similar technologies. We use cookies to understand how our web properties are being used, to measure the effectiveness of our marketing campaigns, to personalise your experience and, where applicable, to make advertising more relevant to you. The categories in use are set out below.

Category

Function

Consent required

Strictly necessary

Operates our web properties (session management, security, load balancing, accessibility). Without these the web properties will not function.

No

Functional

Remembers your preferences (language, region, login state) to improve the user experience.

Yes

Performance and analytics

Counts visits, measures usage patterns and identifies errors and slow pages (for example, Google Analytics).

Yes

Marketing and advertising

Measures the effectiveness of our marketing campaigns and enables retargeting on third-party platforms (for example, Google Ads, LinkedIn and Meta).

Yes


You may manage your cookie preferences through the cookie banner displayed on first visit, by re-opening the banner from the website footer, or through your browser settings. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.

4. Sharing Personal Data

We share your Personal Data with the categories of recipients set out below. We do not sell your Personal Data in the conventional sense of the term (that is, we do not exchange Personal Data directly for money).

Category of recipient

Purpose of sharing

Group entities and sub-processors

The complete list of Kissflow's group entities and sub-processors together with the applicable data processing terms, are set out in the Kissflow Data Processing Addendum. Please refer to those documents for the complete and current list.

Marketing partners

Social-media platforms, advertising networks and marketing-services operators, for retargeting and analytics purposes, including by way of placing cookies or other tracking technologies on our web properties.

Legal, regulatory and law-enforcement recipients

Where required by applicable law, a binding order, or to establish, exercise or defend legal claims. We will disclose only the minimum Personal Data necessary and, where permitted by law, will notify you before disclosure.

Successors in interest

In the event of a merger, acquisition, financing, reorganisation or sale of substantially all of Kissflow's assets, subject to the same obligations as this Policy.

5. Data Retention

We retain your Personal Data only for so long as is necessary for the purposes for which it was collected, or as required by applicable law.

Specific retention periods are set out in Kissflow's internal Data Retention Policy, which is a confidential internal document. Kissflow will share the retention position applicable to a specific processing activity or engagement on a case-by-case basis, subject to reasonable identity verification and appropriate confidentiality safeguards.

We may retain Personal Data for longer periods where required by legal, regulatory, tax or accounting obligations, to maintain accurate records of dealings with you, or where we reasonably believe there is a prospect of litigation.

6. Security

We implement and maintain physical, technical and administrative security measures that comply with applicable law and prevailing industry standards, including encryption in transit, authentication and access controls, and monitoring. Particulars of Kissflow's security programme are published in the Kissflow Trust Center. If you become aware of a suspected security incident affecting your Personal Data, please contact us at privacy@kissflow.com.

7. Data Transfer

Given the international operations of Kissflow and its group entities, your Personal Data may be transferred to, and processed in, countries other than the country in which you reside. In all cases, we take appropriate measures to ensure that your Personal Data receives an adequate level of protection upon its transfer.

Transfers of Personal Data of Indian Data Principals are made in accordance with Section 16 of the DPDPA. Transfers from the EEA, the UK or Switzerland are made under the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), the UK International Data Transfer Addendum (version B1.0), the Swiss adaptation of those Clauses, or an applicable adequacy decision. For other regimes with transfer restrictions, transfers are made under the transfer mechanism recognised by the relevant regime.

8. Automated Decision-Making and AI Features

The Kissflow services include artificial-intelligence features which a Subscriber, as controller of the workflow data uploaded by it, may elect to enable. The privacy-notice obligations in respect of those AI features are the Subscriber's, and not those of Kissflow under this Policy.

In our own operations (including marketing, sales, customer-relationship and support tools), we may use standard analytics, segmentation, lead-scoring and generative-AI features that involve a degree of automated profiling. We do not make solely-automated decisions that produce legal effects concerning you, or similarly significantly affect you, on the basis of such processing.

9. Notice to End-Users of Subscribers

Where the Kissflow services are made available to an end-user through a Subscriber, the Subscriber is the Data Fiduciary / Data Controller of that end-user's Personal Data. End-users should direct any data-privacy questions or requests to the Subscriber. Where we receive a request directly from an end-user, we will direct the end-user to the Subscriber. We are not responsible for the privacy or security practices of Subscribers, which may differ from this Policy. Links from our web properties to third-party websites are provided for convenience only, and this Policy does not apply to those websites.

10. Your Rights

You are entitled to certain rights in relation to your Personal Data, which may vary depending on your place of residence and the applicable data protection law. The table below summarises those rights.

Jurisdiction

Rights available

India (Digital Personal Data Protection Act, 2023)

If you are a Data Principal (as defined under the DPDPA), you have the right to access information about the processing of your Personal Data (Section 11), the right to correction, completion, updating and erasure of your Personal Data (Section 12), the right to grievance redressal (Section 13), the right to nominate another individual to exercise your rights in the event of your death or incapacity (Section 14), and the right to withdraw consent where processing is based on consent.

European Economic Area (EU GDPR)

If you are a data subject residing in the EEA, you have the right of access, correction, deletion / erasure, restriction of processing, objection to processing, data portability and withdrawal of consent.

United Kingdom (UK GDPR and Data Protection Act 2018)

If you are a data subject residing in the United Kingdom, you have the right of access, correction, deletion / erasure, restriction of processing, objection to processing, data portability and withdrawal of consent.

Switzerland (Swiss FADP)

If you are a data subject residing in Switzerland, you have the right of access, correction, deletion, objection to processing and withdrawal of consent.

California (CCPA / CPRA)

If you are a consumer (as defined under the CCPA / CPRA), you have the right to request disclosure of the categories and specific pieces of Personal Information collected about you, the right to request correction of inaccurate Personal Information, the right to request deletion of Personal Information (subject to exceptions), the right to opt out of the sale or sharing of Personal Information, the right to limit the use of sensitive Personal Information, and the right not to be discriminated against for exercising these rights.

Other jurisdictions

If you are a data subject residing in another jurisdiction, you may have rights which include access, correction, deletion, restriction of processing, objection to processing, portability and withdrawal of consent. We will honour such rights in accordance with the requirements of applicable local law.

To exercise any of these rights, contact us at privacy@kissflow.com. We will verify your identity before acting on your request and will respond within the period required by applicable law. No fee will be charged for a reasonable request.

11. Privacy of Children

We recognise the importance of protecting children's privacy. The Kissflow services and our web properties are intended for use by businesses and their authorised representatives and are not directed at children, and we do not knowingly request or collect Personal Data from children. The age at which an individual is considered a child, and our position in relation to their Personal Data, differs by jurisdiction as set out below.

Jurisdiction

Our position

India (Digital Personal Data Protection Act, 2023)

We do not knowingly collect or process Personal Data of children (individuals under 18 years of age) or of persons with disabilities lacking capacity to consent, except with verifiable parental or guardian consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

European Economic Area (EU GDPR)

We do not knowingly collect Personal Data from children under the age of 16 (or a lower age, not below 13, where permitted by local law under Article 8 GDPR).

United Kingdom (UK GDPR and Data Protection Act 2018)

We do not knowingly collect Personal Data from children under the age of 13.

Switzerland (Swiss FADP)

In the absence of a fixed statutory age under the Swiss FADP, we do not knowingly collect Personal Data from children under the age of 16, aligned with our EU practice.

California (CCPA / CPRA)

We do not knowingly sell or share the Personal Information of consumers under 16 years of age without the required consent. Additional protections apply to consumers under the age of 13 under the US Children's Online Privacy Protection Act.

Other jurisdictions

We apply the age threshold required by applicable local law.

If a parent or guardian becomes aware that a child has provided Personal Data to us, please contact us at privacy@kissflow.com and we will take appropriate steps to erase such Personal Data.

12. Grievance Redressal

If you have a grievance regarding our processing of your Personal Data, please contact the Data Protection Officer / Grievance Redressal Officer at privacy@kissflow.com. We will acknowledge your grievance promptly and seek to resolve it without undue delay.

13. Policy Amendments

Kissflow may amend this Policy from time to time. The most recent version is posted at www.kissflow.com and the date of update is reflected in the “Last Updated” heading above. Where the amendments are material, Kissflow will provide notice by appropriate means and, where required by applicable law, will obtain your consent.

14. Contact Information and Data Controller Information

Kissflow is the trading name of a group comprising OrangeScape Technologies Private Limited (India), Kissflow Inc. and Kissflow FZ LLC (collectively, “Kissflow”, “we”, “us” or “our”). The Data Fiduciary / Data Controller for the processing described in this Policy is identified below.

Data Principal / Data Subject

Data Fiduciary / Data Controller

Individuals located in India

OrangeScape Technologies Private Limited, a company incorporated under the laws of the Republic of India, with its registered office at 1002 and 1003, 10th Floor, Tower-B, World Trade Center, No. 5/142, Rajiv Gandhi Salai (OMR), Perungudi, Chennai - 600096, Tamil Nadu, India, acting as the Data Fiduciary under the DPDPA.

Individuals located outside India

Kissflow Inc., a company incorporated under the laws of the State of Delaware, United States, with its principal place of business at 1000 N West Street, Suite 1200, Wilmington, Delaware, 19801, USA, acting as the Data Controller under the GDPR, UK GDPR, CCPA and other applicable regimes.

The two entities share a single Data Protection Officer and offer a single privacy contact route across all jurisdictions.

Item

Detail

Data Protection Officer


Rini Mathew - privacy@kissflow.com

Grievance Redressal Officer (DPDPA Section 8(10))

Postal correspondence

To the registered office of the applicable Data Fiduciary / Data Controller identified above, marked for the attention of the Data Protection Officer.