Home Legal Privacy Policy

Privacy Policy

How we collect, process, protect, and respect your personal data and Webflow CMS content across the globe.

Effective Date: September 16, 2026 Worldwide Coverage (GDPR & CCPA Compliant)
Privacy First Architecture: AEOFlow is built specifically for Answer Engine Optimization. We strictly collect only data essential for provisioning accounts, processing payments through certified Merchant of Record partners, and synthesizing structured JSON-LD schemas. We never sell your personal information or use your CMS articles to train public foundation models.

1. Introduction & Overview

This Privacy Policy describes how AEOFlow, maintained by Neeraj Mukta ("AEOFlow", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you visit our website, register for an account, or interact with our software, APIs, and Webflow optimization tools (collectively, the "Services").

We are committed to safeguarding the privacy and security of your data in accordance with international data protection regulations, including the European Union General Data Protection Regulation (EU GDPR), the United Kingdom Data Protection Act 2018 (UK GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).

2. Identity of Data Controller

For the purposes of applicable data protection law, the Data Controller responsible for your personal information is:

AEOFlow, maintained by Neeraj Mukta

Registered Address: Zulelal Colony, fulchur peth, Gondia, Gondiya, Maharashtra - 441601, India

Data Protection Officer (DPO) / Privacy Lead: hello@tryaeoflow.com

3. Personal Information We Collect

We collect information in the following categories:

  • Account & Profile Information: When you register or configure an account, we collect your full name, business email address, company or agency name, password hash, and communication preferences.
  • CMS Configuration & API Credentials: When you connect your Webflow workspace or submit content for analysis, we collect Webflow collection IDs, site identifiers, and encrypted API access tokens necessary to retrieve posts and sync generated JSON-LD scripts.
  • Customer Content for Optimization: Blog post text, headings, meta descriptions, author profiles, and publish dates parsed from your designated CMS URLs to perform entity extraction and Schema.org generation.
  • Technical & Telemetry Data: IP address, device type, browser specifications, operating system, time zone, referring URLs, API request logs, and error diagnostic metrics.
  • Customer Support & Communications: Records of communications, questions, bug reports, or feedback submitted via email or support forms.

4. Payment Data & Merchant of Record (Dodo Payments)

To provide secure checkout and seamless international tax compliance, all payment processing, invoicing, and subscription billing are conducted in partnership with our authorized Merchant of Record (MoR):

PCI-DSS Level 1 Payment Handling:

When you purchase a subscription or credits on AEOFlow, your payment details (such as credit card numbers, expiration dates, CVV/CVC codes, and billing postal codes) are collected directly by Dodo Payments (or other designated payment gateway partners). Dodo Payments operates as the Merchant of Record and complies with Level 1 PCI-DSS standards.

AEOFlow never accesses, receives, or stores raw payment card numbers on its servers. We receive only non-sensitive transaction confirmation metadata, such as transaction IDs, subscription tier, billing period, and country code to activate and manage your workspace tier.

5. How We Use Your Information

We process personal data for specific, lawful purposes:

  • Service Delivery: To provision your account, maintain your workspace, and operate our structured data generation engine;
  • CMS Synchronization: To authenticate with Webflow CMS endpoints and deploy generated JSON-LD structured schemas to your sites;
  • Billing & Invoicing: To facilitate payment verification, issue receipts, and manage subscription renewal statuses via Dodo Payments;
  • Customer Support: To troubleshoot issues, answer inquiries, and provide technical guidance;
  • System Reliability & Security: To detect abuse, prevent denial-of-service attacks, investigate fraud, and ensure network resilience;
  • Product Improvement: To evaluate aggregated, de-identified platform metrics and optimize schema extraction accuracy.

6. Legal Bases for Processing (GDPR)

If you reside in the European Economic Area (EEA) or the United Kingdom, we process personal data under the following legal bases:

  • Performance of a Contract (Art. 6(1)(b) GDPR): Processing is necessary to provide the Services you requested under our Terms of Service;
  • Legitimate Interests (Art. 6(1)(f) GDPR): Processing is necessary for our legitimate interests in securing our infrastructure, preventing fraud, and enhancing service quality, provided these interests do not override your fundamental rights;
  • Legal Obligation (Art. 6(1)(c) GDPR): Processing is necessary to comply with applicable tax, accounting, and regulatory requirements;
  • Consent (Art. 6(1)(a) GDPR): Where you have provided specific consent (such as opting in to marketing communications), which you may withdraw at any time.

7. Subprocessors & Third-Party Service Providers

We work with trusted third-party service providers (subprocessors) to support our global infrastructure. All subprocessors are bound by data processing agreements requiring stringent confidentiality and security standards:

SubprocessorRole / Service ProvidedLocation
Cloudflare, Inc.Global edge hosting, serverless execution, D1 database & R2 storageGlobal / United States
Dodo PaymentsMerchant of Record, payment processing, global VAT/tax compliance & invoicingUnited States / Global
OpenAI, Inc. / Anthropic, PBC / OpenRouterSemantic entity extraction & schema synthesis (zero data retention API)United States

8. AI Model Inference & Data Privacy

Our entity analysis utilizes state-of-the-art semantic inference APIs. We maintain strict privacy standards regarding AI operations:

  • Customer Content sent for analysis is transmitted via secure, authenticated enterprise API channels;
  • We utilize business enterprise endpoints with contractual zero-data-retention commitments;
  • Your CMS articles, private schema definitions, and blog content are NEVER used to train, retrain, or fine-tune public machine learning models.

9. International Data Transfers

AEOFlow operates globally. Information collected about you may be transferred to, stored, and processed in countries other than your country of residence, including the United States, where our hosting and payment partners maintain infrastructure.

When transferring personal data outside the EEA, UK, or Switzerland, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent UK International Data Transfer Agreements (IDTA).

10. Data Retention & Security Measures

10.1 Retention: We retain personal data only as long as necessary to fulfill the purposes outlined in this policy or to comply with applicable tax, accounting, or legal retention requirements. When your account is deleted, we purge or anonymize your personal data and Webflow access tokens within thirty (30) days, except where legally required to retain transaction records.

10.2 Security Safeguards: We implement administrative, physical, and technical safeguards designed to prevent unauthorized access, loss, or disclosure:

  • Encryption of all data in transit via Transport Layer Security (TLS 1.3);
  • Encryption of sensitive credentials (such as Webflow API tokens) at rest;
  • Strict principle of least privilege for internal administrative access;
  • Distributed Denial of Service (DDoS) mitigation and Web Application Firewall (WAF) via Cloudflare.

11. Your Privacy Rights (GDPR & UK GDPR)

If you reside in the EEA or UK, you enjoy the following statutory rights:

  • Right of Access: Request a copy of the personal data we hold about you;
  • Right to Rectification: Request correction of inaccurate or incomplete information;
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data under certain conditions;
  • Right to Restrict Processing: Request temporary restriction of processing your data;
  • Right to Data Portability: Request transmission of your personal data in a structured, commonly used machine-readable format;
  • Right to Object: Object to processing based on legitimate interests or direct marketing;
  • Right to Withdraw Consent: Withdraw previously granted consent at any time.

To exercise any of these rights, contact us at hello@tryaeoflow.com. We respond to verified requests within thirty (30) days without charge.

12. California Privacy Notice (CCPA / CPRA)

This section applies to California residents pursuant to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020:

  • Right to Know & Access: You have the right to request details on the categories and specific pieces of personal information collected about you in the preceding 12 months;
  • Right to Delete: You have the right to request deletion of your personal data;
  • Right to Correct: You have the right to request correction of inaccurate personal data;
  • No Sale or Sharing of Personal Information: We do not sell personal information, nor do we share personal information for cross-context behavioral advertising. We have not done so in the preceding 12 months;
  • Non-Discrimination: We will never discriminate against you for exercising your privacy rights under California law.

13. Cookie Policy & Tracking Technologies

We use cookies and similar technologies (such as local storage) solely to deliver core website functionality, maintain your login session, and analyze platform traffic:

  • Strictly Necessary Cookies: Essential for user authentication, security, and session management. The platform cannot function properly without these cookies;
  • Functional Cookies: Remember your interface preferences (such as selected language, theme, or workspace ID);
  • Performance & Analytics: Aggregate, anonymized measurements of page load performance and route navigation to optimize platform speed.

You may configure your web browser to block or alert you about cookies. Note that blocking strictly necessary cookies may impact your ability to sign in or use the Services.

14. Children's Privacy

The Services are designed exclusively for businesses, agencies, and adult professionals. We do not knowingly collect personal data from children under the age of 16. If we become aware that personal information of a child has been inadvertently collected, we will take immediate steps to delete such data from our systems.

15. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect enhancements to our platform or evolving regulatory standards. When changes are made, we will update the "Effective Date" at the top. For significant changes, we will provide additional notice via email or a notification in your account dashboard.

16. How to Contact Us & Data Protection Officer

For inquiries, feedback, or to exercise your statutory data privacy rights, please contact our privacy desk:

AEOFlow, maintained by Neeraj Mukta

Registered Address: Zulelal Colony, fulchur peth, Gondia, Gondiya, Maharashtra - 441601, India

Data Protection Officer (DPO) / Privacy Lead: hello@tryaeoflow.com

enesfritde-chnlplruhizh-cnko