Legal

Privacy Policy

This Privacy Policy explains how ALGOFLOW OÜ, an Estonian private limited company registered under code 17161776, processes personal data in connection with AlgoFlow. It applies to the website, calculator, technical specification forms, account area, course access, homework review, private course materials, support communication, payment pages, and custom software development discussions.

This policy should be read together with the User Agreement and any specific contract, invoice, payment link, technical specification, or NDA agreed for a service. Effective date: 5 June 2026.

Controller And Contact

ALGOFLOW OÜ is the controller for personal data processed through AlgoFlow unless a specific third-party service acts as an independent controller under its own policy. You can contact us about privacy requests through the public contact form or the communication channel published on the website.

We do not appoint a data protection officer unless we later publish a dedicated DPO contact. Privacy requests should include enough information to identify your account, invoice, payment reference, project reference, or course access record. We may need to verify your identity before acting on a request.

Personal Data We Process

Account data may include your name, email address, password hash, account status, locale, email verification and password reset metadata, Google OAuth profile identifiers where used, profile settings, email change history, and session-related metadata.

Project and development request data may include contact details, company or billing context where provided, calculator selections, saved calculations, estimate snapshots, technical requirements, messages, files or links you provide, project notes, status history, admin replies, and support/contact form content.

Course data may include purchased package, course access status, lesson availability, lesson progress, video playback metadata needed for access rules, homework submissions, attachments, admin review decisions, revision comments, private lesson or cheatsheet access, and private Telegram group invite metadata where such invite is generated.

Payment data may include real invoice numbers, payment-link references, provider transaction identifiers, amount, currency, payment method, provider name, transaction status, reconciliation metadata, fraud and chargeback indicators, and limited provider payloads. Card numbers, expiry dates, and CVV/CVC codes are entered directly into secure provider-hosted payment forms such as Revolut Checkout and are processed by the payment provider. We do not store card numbers or card security codes. Depending on the payment method, we may process payment references, expected and observed payment amounts, timestamps, settlement status, and reconciliation details needed to confirm payment and activate access.

Technical and security data may include IP address, user agent, device and browser data, request logs, cookie and local storage identifiers, language and theme preferences, Turnstile challenge metadata, analytics events where analytics is enabled, and diagnostic data needed to secure, debug, and operate the platform.

Purposes And Legal Bases

We process personal data to create and manage accounts, authenticate users, verify email addresses, restore account access, provide the calculator and saved configurations, process project requests, prepare or discuss technical specifications, provide course access, review homework where included, manage admin communication, create payment links, confirm payments, activate paid access, and provide support.

We also process data to protect the platform, prevent abuse and fraud, enforce access rules, debug incidents, maintain logs, preserve evidence of transactions and accepted work, handle disputes, comply with tax, accounting, consumer, company, and legal obligations, and improve the reliability and usability of the service.

The legal bases may include performance of a contract or steps requested before a contract, compliance with legal obligations, legitimate interests in operating, securing, improving, and defending the service, consent where required for optional analytics or marketing communications, and establishment, exercise, or defence of legal claims.

Sources Of Data

Most personal data is provided by you when you register, submit forms, configure a project, send messages, upload or link materials, submit homework, pay an invoice, or communicate with us.

We may also receive data from payment providers, OAuth providers, Turnstile or security services, email and Telegram delivery services, hosting and logging systems, analytics services where enabled, payment confirmation systems, and administrators acting inside the platform.

Processors, Providers, And Recipients

We share personal data only when needed for the service, security, payment, legal, or operational purposes. Recipients may include hosting and database providers, email providers, Telegram bot and messaging infrastructure, Cloudflare Turnstile, analytics providers where enabled, Google OAuth where used, payment providers such as card processors or payment facilitators, provider infrastructure used for payment verification, professional advisers, accountants, and public authorities where legally required.

Payment card details are entered into secure payment-provider forms, including Revolut Checkout where configured, and are processed by the payment provider, not by our own card storage. We retain invoice and transaction records needed for accounting, reconciliation, access activation, dispute handling, and fraud prevention, but not full card numbers or CVV/CVC codes. Third-party providers may process data under their own privacy policies when they act as independent controllers.

If personal data is transferred outside the European Economic Area, we rely on an adequacy decision, standard contractual clauses, provider safeguards, or another lawful transfer mechanism where required by law.

Cookies, Local Storage, And Analytics

We use necessary cookies and similar technologies for authentication, sessions, language selection, theme preference, security checks, checkout state, course access, and other functionality that is needed for the platform to work.

The browser may store local data such as checkout drafts, theme or language preference, course video position, and temporary interface state. This helps keep dynamic app pages usable but does not replace backend-owned payment, access, or account status.

Where Google Analytics or similar optional analytics is configured, analytics helps us understand public page usage and improve the service. Optional analytics or marketing communications are used only where there is a lawful basis and, where required, consent. Turnstile or anti-abuse providers may set or read technical signals needed to distinguish legitimate users from automated abuse.

Retention

We keep personal data only as long as reasonably needed for the purposes described in this policy. Account, course, request, payment, support, and admin records may be retained while your account is active and after closure where needed for legal obligations, accounting, dispute resolution, fraud prevention, security, auditability, or enforcement of agreements. For payments, retained records are invoice numbers, payment-link references, provider transaction identifiers, statuses, amounts, currencies, reconciliation notes, and accounting records, not card numbers or CVV/CVC codes entered into Revolut or other provider-hosted forms.

Verification and reset codes are intended for short-term account security. Technical logs are normally kept for a limited operational period unless needed for security, debugging, legal claims, or abuse investigation. Backups may retain data for a limited time until they are overwritten according to the backup cycle.

Deleting an account may remove or anonymize account-facing data where possible, but we may retain records that must be kept for tax, accounting, payment, fraud, security, legal, or contractual reasons.

Your Rights

Depending on your jurisdiction and the legal basis for processing, you may have the right to request access to your personal data, rectification, erasure, restriction, portability, objection to processing, and withdrawal of consent where processing is based on consent.

Withdrawal of consent does not affect processing that happened before withdrawal and does not affect processing based on another lawful basis. Some requests may be refused or limited where we must keep data for legal obligations, payment records, security, fraud prevention, dispute handling, or legal claims.

We aim to respond to privacy requests within the time required by applicable law. You may also lodge a complaint with the Estonian Data Protection Inspectorate or another competent supervisory authority.

Security

We use technical and organisational measures intended to protect personal data, including access controls, session security, password hashing, server-side payment and access confirmation, Turnstile protection on protected flows, and separation of server-side secrets from the public web client.

No online service can guarantee absolute security. You are responsible for keeping your account credentials private, using a secure email account, and notifying us if you suspect unauthorized account access.

Automated Decisions And Profiling

The platform may automatically calculate estimates, validate inputs, apply course access rules, reconcile payment status, and block clearly invalid or abusive requests. These processes support service delivery and security.

We do not use solely automated decision-making that produces legal or similarly significant effects on users without a meaningful human review path where such review is required by law.

Children

AlgoFlow is not directed to children. If you are under the age at which you can lawfully enter into a contract or give valid consent in your country, you may use paid services only with involvement of a parent or legal guardian where required by law.

Changes To This Policy

We may update this Privacy Policy when the platform, providers, legal requirements, or data practices change. The updated version is published on the website with its effective date. Material changes will be communicated where required by law or where practical for the service context.

Contacts

For privacy questions, data access, correction, deletion, account closure, or consent withdrawal, contact us through the public contact form or the communication channel published on the site.