Privacy Policy
This policy explains how AgenticFlow (Pty) Ltd collects, uses, stores, and protects personal information across its AI automation platform and the products built on it — including AgentFlo and PropFlo.
01 Who we are
AgenticFlow (Pty) Ltd (registration number 2026/404680/07) is a South African company that designs, builds, and operates AI automation solutions — including conversational AI agents, workflow automation, and data intelligence — for businesses across South Africa. Our products operate under sub-brands such as AgentFlo (WhatsApp AI for hospitality) and PropFlo (property management).
This policy covers personal information that AgenticFlow processes in two distinct roles under the Protection of Personal Information Act, 2013 (POPIA):
- As responsible partyfor the information of our own business clients and their authorised users — account, billing, and platform-administration data.
- As operatorwhen we process the personal information of a client's end customers (for example, a guest who messages an AgentFlo-powered WhatsApp number) on that client's behalf and under their instructions. In that case the client business is the responsible party for the relationship with their customer.
02 What we collect
We collect only what is needed to provide, operate, and bill for the service.
- Client account informationthe business name, contact person, email address, and phone number provided when a business signs up for or is onboarded onto an AgenticFlow product.
- Service configuration datadetails a client supplies to set up their automation — for example, an AgentFlo guesthouse's property details, room rates, policies, and AI persona settings.
- Billing informationthe records needed to invoice a client (company details, plan, invoice history). We do not store payment card numbers; payments are settled by electronic funds transfer.
- End-customer message contentwhere we operate a conversational agent for a client, the WhatsApp phone number and message content of people who contact that client, processed to generate replies and stored temporarily for session context (see Retention).
- Aggregated usage metricsmessage volumes, response times, and platform-performance counters, which contain no personal identifiers.
We do not collect payment card numbers, identity document numbers, or other sensitive identifiers from end customers. We do not ask for them, and we instruct our AI agents not to request them.
03 How we use it
Your information is used only for purposes directly related to providing the service:
- Operating the automationconversation and configuration data is used to generate relevant AI responses and run the workflows a client has set up.
- Session continuityrecent messages are stored temporarily so a conversational agent remembers context within a conversation.
- Account management & supportclient contact details are used to administer the account, provide support, and send service-related notifications.
- Billingclient and plan details are used to issue invoices and maintain billing records as required by law.
- Notifications & escalationwhere a customer makes an enquiry or a query needs a human, the relevant details are forwarded to the client business so they can follow up.
- Service improvementanonymised, aggregated metrics are used to monitor and improve platform performance. These contain no personal information.
We do not sell personal information, and we do not use it for advertising, third-party profiling, or any purpose unrelated to providing the service.
04 Third-party processors
We use the following sub-processors to deliver the service. Each is bound by data-processing terms consistent with their role:
Some processors are located outside South Africa. Cross-border transfers occur under Section 72 of POPIA, on the basis that adequate protection is in place through contractual measures or the processor's own certifications.
05 Retention
We store as little as possible for as short a time as necessary:
- End-customer conversation history (session)retained for up to 7 days, then automatically deleted from the runtime store.
- Client account & configuration dataretained for the duration of the client relationship and deleted on request after termination, subject to legal retention requirements.
- Billing recordsretained for the period required by South African tax and company law.
- Aggregated usage metricsretained indefinitely in anonymised, non-personal form (message counts, token volumes, timestamps without user identifiers).
No end-customer personal information is retained on AgenticFlow's systems beyond the session window described above. A client business may retain customer details in its own records; that client's privacy practices govern such use.
06 Your rights under POPIA
As a data subject under the Protection of Personal Information Act, 2013, you have the following rights. To exercise any of them, contact us at the address in Section 10.
07 WhatsApp & Meta
Where an AgenticFlow product delivers conversations through the WhatsApp Business API, operated by Meta Platforms, Inc., your messages are also subject to WhatsApp's own Privacy Policy and Meta's data practices.
AgenticFlow is an independent operator using the WhatsApp Business Platform. AgenticFlow (Pty) Ltd is not affiliated with, endorsed by, or a partner of WhatsApp LLC or Meta Platforms, Inc. WhatsApp is a trademark of Meta Platforms, Inc.
Conversations delivered through the WhatsApp Business API are subject to Meta's Business Messaging terms, including the 24-hour messaging window and message-template requirements for business-initiated messages.
08 Children
AgenticFlow's products are intended for use by adults and by businesses. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided personal information through our service, please contact us and we will delete it promptly.
09 Policy changes
We may update this policy from time to time. The effective date at the top of this page will reflect the most recent revision. Material changes will be communicated via the AgenticFlow website or, where appropriate, via direct notification to clients using our platform. Continued use of the service after a change constitutes acceptance of the revised policy.
10 Contact & requests
For privacy-related requests — including access, correction, deletion, or complaints — contact our Information Officer: