Legal
Legal Notice & Regulatory Disclosures
This document constitutes the comprehensive Legal Notice, Regulatory Compliance Statement, and Intellectual Property Policy for Buildflow Inc. (“Buildflow”). It provides binding disclosures regarding corporate identity, privacy framework adherence, public web data extraction principles, platform developer program compliance, and security governance.
1. Corporate Identity & Registered Entity Information
- Operating Entity: Buildflow Inc.
- Commercial Classification: Enterprise Business-to-Business (B2B) Software-as-a-Service (SaaS)
- Official Online Domain: https://buildflowhq.com (and authorized subdomains)
- Primary Contact for Legal & Privacy Inquiries: privacy@buildflowhq.com
- Customer Support & Operational Inquiries: support@buildflowhq.com
2. Regulatory & Data Privacy Framework Alignment
General Data Protection Regulation (GDPR) & UK GDPR Compliance
Buildflow operates in full alignment with the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK Data Protection Act 2018:
- Dual Legal Roles: Buildflow acts as a Data Controller for direct customer account records and as a Data Processor for prospect context processed by customers on the platform.
- Data Subject Rights:Data subjects may exercise their rights to access, rectification, erasure (‘right to be forgotten’), data portability, and restriction of processing by contacting privacy@buildflowhq.com. Responses are executed within thirty (30) days.
- International Transfers & Standard Contractual Clauses (SCCs): Cross-border transfers originating from the EEA, United Kingdom, or Switzerland utilize standard contractual clauses approved by the European Commission.
California Consumer Privacy Act (CCPA / CPRA)
Zero Sale of Personal Data: Buildflow does not sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate personal information to another business or third party for monetary or other valuable consideration. Under the California Consumer Privacy Act and California Privacy Rights Act, Buildflow maintains a strict non-sale posture across all services and browser extension workflows.
3. Platform & Browser Extension Compliance
Google Chrome Web Store Developer Program Policies
The Buildflow Chrome Extension operates strictly under Google Chrome Web Store Developer Program Policies:
- Single Purpose Declaration:The extension’s sole functionality is B2B sales enablement: allowing sales reps to capture publicly visible prospect data on professional networking pages and generate contextual outreach.
- Principle of Least Privilege:The extension explicitly foregoes broad browser-level permissions (such as the generic ‘tabs’ permission), operating strictly on defined host permissions (
*://*.linkedin.com/*) and activeTab scopes. - Limited Use Guarantee: Data extracted via the Chrome Extension is never transferred to data brokers, advertising networks, or used for credit evaluation or consumer profiling.
Legality of Public Data Extraction & Prospect Intelligence
Buildflow’s prospect intelligence features extract only information that is made publicly available by users on professional networking platforms. Our technological architecture is engineered in accordance with established international legal precedents governing automated retrieval of public web data (including hiQ Labs, Inc. v. LinkedIn Corp.):
- Public Information Exclusivity: Buildflow does not bypass authentication paywalls, CAPTCHAs, or access-controlled private networks. It reads only what is visible to the authenticated user on public web DOM structures.
- User-Initiated Action: Scraping operations run exclusively upon user navigation or explicit user command, ensuring client-directed agency.
4. Artificial Intelligence Ethics & Safeguards
Buildflow leverages cutting-edge enterprise AI endpoints (including Google Gemini, Anthropic Claude, and OpenAI via secure gateways) to deliver sales synthesis:
- Prohibition of Foundation Model Training: All enterprise agreements and API pipelines guarantee that Customer Content, company feature catalogs, and scraped prospect data are NEVER utilized to train, retrain, or improve public foundation models.
- Ephemeral Inference Processing: Data payloads sent to AI inference endpoints are retained solely for the ephemeral duration required to complete the generation task and verify output integrity, adhering to zero-data-retention standards.
- Encrypted Inter-Service Transit: All API communications between application services, Redis brokers, Celery workers, and external AI providers are secured via TLS 1.3 encryption.
5. Intellectual Property & DMCA Policy
All visual interfaces, design templates (including our 13 proprietary slide families), codebases, logos, and system documentation are the exclusive intellectual property of Buildflow Inc. Buildflow respects third-party intellectual property and complies with the provisions of the Digital Millennium Copyright Act (17 U.S.C. § 512).
DMCA Takedown Notices: If you believe that any content hosted on or generated through Buildflow infringes upon your copyright, please submit a formal notification to our Designated Copyright Agent at privacy@buildflowhq.com with the following details: (a) physical or electronic signature of the copyright owner; (b) identification of the copyrighted work claimed to have been infringed; (c) identification of the material to be removed; and (d) your full contact details.
6. Law Enforcement & Legal Process Guidelines
Buildflow discloses user data to law enforcement or government authorities only when legally compelled by valid, enforceable legal process, such as a search warrant, court order, or subpoena issued by a court of competent jurisdiction. Unless prohibited by applicable law or judicial order, Buildflow will provide advance written notice to affected customers before producing data, allowing the customer an opportunity to seek protective orders.
7. Security Governance & Vulnerability Disclosure
Buildflow is committed to safeguarding customer data through continuous security testing and responsible vulnerability disclosure:
- Infrastructure Security: Multi-stage hardened container builds, non-root runtime environments, and automated SAST/dependency security scans (Bandit, Trivy, GitLeaks, pip-audit).
- Responsible Disclosure: Security researchers who identify potential vulnerabilities are invited to report findings to privacy@buildflowhq.com. We commit to acknowledging reports within 48 hours and will not pursue legal action against researchers acting in good faith under responsible disclosure principles.
8. Legal Directory & Contact Information
- Corporate Counsel & DPO: privacy@buildflowhq.com
- DMCA & Copyright Compliance: dmca@buildflowhq.com (or privacy@buildflowhq.com)
- Security Team: security@buildflowhq.com
- Official Website: https://buildflowhq.com
- Headquarters: Buildflow Inc.
- Acknowledgements delivered within 48 business hours.