Contents
  1. Who We Are
  2. What Personal Data We Collect
  3. How We Use Your Data
  4. Third Parties We Share Data With
  5. Data Retention
  6. Your Rights
  7. UAE PDPL — Residents of the UAE
  8. GDPR — Residents of the European Economic Area
  9. CCPA — Residents of California, USA
  10. Security
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact Us

Envisioned Flow™ is committed to protecting your personal data. This policy explains what we collect, why, how we store it, and your rights — across all of our digital properties including envisionedflow.com, aiready.envisionedflow.com, and governance.envisionedflow.com.

1. Who We Are

Envisioned Flow™ is a brand of Biztech Consulting FZ-LLC, a company registered in the United Arab Emirates. We provide AI governance advisory, digital transformation strategy, and diagnostic assessment tools for enterprise organizations.

For the purposes of this policy, we are the data controller — meaning we determine how and why your personal data is processed.

Contact: hello@envisionedflow.com

2. What Personal Data We Collect

Information you provide directly

When you submit a form on any of our properties, we may collect:

Information collected automatically

We use Plausible Analytics, a privacy-first analytics tool that does not use cookies, does not collect personally identifiable information, and does not track you across websites. Plausible collects aggregate data only — page views, referrer sources, and general geographic region (country level). No personal data is stored.

Payment information

If you purchase a paid service, payment is processed by Stripe. We do not store your card details. Stripe's privacy policy governs the handling of your payment data.

3. How We Use Your Data

We use the personal data you provide for the following purposes:

We do not sell your personal data. We do not use your data for automated decision-making that produces legal or similarly significant effects without human review.

4. Third Parties We Share Data With

We share personal data only with the following service providers, and only to the extent necessary to deliver our services:

Netlify

Our websites are hosted on Netlify (Netlify, Inc., USA). Form submissions are processed and stored by Netlify. Netlify is compliant with GDPR and maintains appropriate data processing agreements. Netlify Privacy Policy →

Resend

We use Resend to deliver transactional emails, including report delivery notifications to our team. Personal data submitted in forms (name, email, organization, role, assessment results) is transmitted via Resend. Resend Privacy Policy →

Anthropic

Our AI Governance Readiness Assessment uses Anthropic's API to generate personalized reports. Your assessment responses are transmitted to Anthropic's API for processing. Anthropic does not use API inputs to train its models by default. Anthropic Privacy Policy →

Stripe

Payment processing for paid services is handled by Stripe (Stripe, Inc., USA). We do not receive or store full payment card details. Stripe Privacy Policy →

Plausible Analytics

We use Plausible Analytics for website traffic measurement. Plausible does not use cookies and does not collect personally identifiable information. Plausible Privacy Policy →

We do not share your data with any other third parties, advertisers, or data brokers.

5. Data Retention

We retain personal data submitted through our assessment tools and contact forms for a maximum of 24 months from the date of submission. After this period, data is deleted from our active systems.

You may request deletion of your data at any time before this period expires by contacting us at hello@envisionedflow.com.

Payment records may be retained for longer periods where required by UAE tax and financial regulations.

6. Your Rights

Regardless of your location, you have the following rights with respect to your personal data:

To exercise any of these rights, contact us at hello@envisionedflow.com. We will respond within 30 days.

7. UAE PDPL — Residents of the UAE

UAE PDPL

This section applies to residents of the United Arab Emirates and is provided in accordance with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).

As a UAE-registered entity, Envisioned Flow™ (Biztech Consulting FZ-LLC) acts as a Data Controller under the PDPL. We collect and process personal data on the lawful basis of legitimate interest — specifically, to deliver the services you request and to follow up on your inquiry.

UAE residents have the right to access, correct, and request deletion of their personal data. To exercise these rights, contact us at hello@envisionedflow.com.

International Data Transfers

Some of the third-party service providers we use — including Netlify, Resend, Anthropic, and Stripe — are headquartered in the United States and may process personal data on servers located outside the UAE. As a result, your data may be transferred internationally as part of delivering our services.

We address this in the following ways:

By using our services, you acknowledge that your data may be processed in the United States or other jurisdictions as described above. If you have concerns about international data transfers, please contact us at hello@envisionedflow.com.

8. GDPR — Residents of the European Economic Area

GDPR

This section applies to residents of the European Economic Area (EEA) and is provided in accordance with the General Data Protection Regulation (EU) 2016/679.

Our lawful basis for processing your personal data is legitimate interest (Article 6(1)(f) GDPR) — we have a legitimate interest in following up with individuals who voluntarily submit their information to receive an assessment report or make a business inquiry.

EEA residents have the following additional rights under GDPR:

Where we transfer personal data outside the EEA (for example, to Netlify, Resend, Anthropic, or Stripe servers in the USA), we rely on appropriate safeguards. Our service providers maintain Standard Contractual Clauses (SCCs) and Data Processing Agreements that provide the legal basis for such transfers under GDPR Article 46. Links to each provider's DPA and transfer mechanisms are available in Section 4 of this policy.

To exercise your GDPR rights, contact us at hello@envisionedflow.com.

9. CCPA — Residents of California, USA

CCPA / CPRA

This section applies to residents of California and is provided in accordance with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

In the past 12 months, we have collected the following categories of personal information: identifiers (name, email), professional information (organization, role), and inferences drawn from assessment responses (maturity score, risk profile).

We do not sell or share your personal information with third parties for cross-context behavioral advertising.

California residents have the right to:

To exercise your California privacy rights, contact us at hello@envisionedflow.com. We will respond within 45 days as required by law.

10. Security

We take reasonable technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:

No method of transmission over the internet is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security.

11. Children's Privacy

Our services are intended for business professionals and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us at hello@envisionedflow.com and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this policy periodically. Continued use of our services after any changes constitutes acceptance of the updated policy.

13. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:

Envisioned Flow™

Biztech Consulting FZ-LLC

Dubai, United Arab Emirates

Email: hello@envisionedflow.com

Subject line: Privacy Request — [Your Name]

We aim to respond to all privacy-related requests within 30 days.