Privacy Policy
Effective Date: April 12, 2026
We are committed to protecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
1. Information We Collect
1.1 Personal Information
We may collect personal information that you voluntarily provide when you:
- Register or create an account on our site
- Subscribe to our newsletters or other communications
- Make inquiries or request information about our services
- Participate in surveys or promotions
Personal information may include your name, email address, phone number, company name, and any other details you provide.
1.2 Collected automatically
Visiting a page on this site records the following, and nothing else:
- The page you viewed and the page that referred you to it
- Your browser and operating system family, for example “Safari on macOS”, not a version fingerprint
- Your country, derived at the network edge. Not your city, and not your IP address, which is used to route the response and is not retained by us
- Page performance timings, so we can tell whether the site is slow for real visitors
These are aggregate counts. There is no identifier tying one page view to another, which means we cannot reconstruct an individual visitor’s path through the site, by design, not by policy.
2. How We Use Your Information
- To answer you. If you send an enquiry, we use what you wrote to reply to it and to prepare for the conversation. That is the only reason we hold it.
- To see which pages are worth keeping. Aggregate page-view counts tell us what people read and what loads slowly. They cannot tell us who, because nothing here identifies a visitor.
- To keep the site up. Abuse prevention and rate limiting at the network edge.
We do not personalise the site to you, do not build a profile from your browsing, and do not sell, rent or share anything with advertisers or data brokers. We are pre-launch and run no marketing list, if that changes, you will be asked to join it rather than added to it.
3. Cookies
This website sets no cookies. There is no consent banner because there is nothing to consent to. The analytics described above are cookieless: no persistent identifier, no device fingerprint, and no ability to follow you to another site.
Two things are kept in your browser’s local storage. Both are settings rather than tracking, and neither is a cookie or is ever sent to us:
- Your light or dark theme preference, so the site does not show you the wrong one on your next visit.
- On password-protected preview pages, a marker for the current tab so you are not asked for the password again on every page. It is discarded when the tab closes.
Clearing site data in your browser removes both, and nothing stops working if you do.
4. Sharing and Disclosure of Information
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except in the following cases:
- Service Providers: We may share your information with trusted third-party vendors and partners who assist us in providing our services.
- Legal Requirements: We may disclose your information if required by law or to protect our rights, property, or safety, or that of others.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new owner.
5. Data Security
We implement a variety of security measures to protect your personal information. These include secure servers, encryption, and restricted access controls. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
6. Your Rights and Choices
You have the following rights regarding your personal data:
- Access: You can request access to the personal information we hold about you.
- Correction: You have the right to correct or update your information.
- Deletion: You can request the deletion of your personal data under certain circumstances.
- Opt-Out: You can opt-out of marketing communications or restrict how we use your data.
To exercise these rights, please contact us at [email protected].
7. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page, and the updated policy will indicate the effective date.
9. GDPR Compliance
If you are located in the European Economic Area (EEA), the following additional provisions apply to the processing of your personal data:
9.1 Legal Basis for Processing
We process personal data under the following legal bases:
- Legitimate Interest: For service delivery, operating Powoflow, and security monitoring necessary to provide our connected operations platform.
- Consent: For marketing communications, newsletters, and optional analytics. You may withdraw consent at any time.
- Contractual Necessity: To fulfill our obligations under your subscription agreement.
9.2 Data Subject Rights
Under the GDPR, you have the right to:
- Access: Obtain confirmation of whether your personal data is being processed and request a copy.
- Rectification: Request correction of inaccurate or incomplete personal data.
- Erasure: Request deletion of your personal data where no compelling reason for continued processing exists.
- Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Restriction: Request limitation of processing under certain circumstances.
- Objection: Object to processing based on legitimate interests or for direct marketing purposes.
9.3 Data Processing Agreements
A Data Processing Agreement (DPA) is available upon request for enterprise and professional tier customers. Contact [email protected] to request a copy.
9.4 International Data Transfers
Powoflow infrastructure is hosted in the United States. For data transferred from the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Copies of the applicable SCCs are available upon request.
10. CCPA/CPRA Compliance
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out: You may opt out of the sale or sharing of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
Do Not Sell or Share My Personal Information
Powoflow does not sell personal information. We do not share personal information for cross-context behavioral advertising. If our practices change, we will update this policy and provide a mechanism to opt out.
Categories of Personal Information Collected
- Identifiers: Name, email address, phone number, company name, IP address.
- Commercial Information: Subscription tier, billing history, service usage records.
- Internet Activity: Browser type, pages visited, interaction data, device information.
- Professional Information: Job title, company affiliation, industry.
- Geolocation Data: Approximate location derived from IP address (precise location only from IoT devices with explicit consent).
11. IoT & Telemetry Data
Powoflow collects and processes telemetry data from IoT devices, sensors, and edge hardware. This section describes how that data is handled.
11.1 Types of Sensor Data Collected
- GNSS Locations: GPS coordinates from fleet trackers and mobile assets.
- Environmental Readings: Temperature, humidity, pressure, wind speed, and other environmental sensor data.
- Device Telemetry: Battery levels, connectivity status, signal strength, firmware versions, and device health metrics.
- Operational Data: Equipment run hours, fuel consumption, vibration readings, and other operational parameters.
11.2 Data Retention
Telemetry data retention periods are configurable per subscription tier:
- Starter: 7 days of raw telemetry, 90 days of aggregated data.
- Professional: 90 days of raw telemetry, 365 days of aggregated data.
- Enterprise: Configurable retention up to 365 days of raw telemetry, with extended archival options.
11.3 Tenant Data Isolation
All customer data is logically isolated by partition key in the record store. Each tenant's data is cryptographically scoped to their organization, ensuring no cross-tenant data access is possible at the infrastructure level.
11.4 Edge Device Data Handling
edge devices process data locally before transmitting to the cloud. Edge AI inference results are processed on-device and only metadata and alerts are transmitted. Raw video streams are not stored in the cloud unless explicitly configured by the customer for recording.
12. Sub-processors
We use the following third-party sub-processors to deliver our services:
- Amazon Web Services (AWS): Cloud infrastructure, compute, storage, and database services (US regions).
- Cloudflare: Content delivery network (CDN), DDoS protection, and edge compute (Workers).
- Auth0: Authentication, identity management, and single sign-on (SSO).
- Mapbox: Mapping, geocoding, and spatial data visualization.
We maintain data processing agreements with all sub-processors and evaluate their security practices regularly.
13. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at: [email protected]
For data protection inquiries, data subject access requests, or DPA requests, email: [email protected]
Last Updated: April 12, 2026