Privacy Policy

Last updated September 15, 2026

This page is an honest, accurate description of what this system actually does, written by the team that built it. It is not legal advice, and it has not yet been reviewed by a lawyer — treat it as the correct starting draft for that review, not as a substitute for it.

1. Who we are

Floxify (“Floxify”, “we”, “us”) is operated by Serpex, a sole proprietorship (Udyam UDYAM-GJ-22-0534867), registered at B-116, Tirupati Society, Yogichowk, Surat, Gujarat 395010, India. We can be reached for any privacy question or request at support@floxify.ai.

Floxify is a business-to-business (B2B) sales-intelligence platform. Our customers are companies looking for prospective buyers; the records they search hold information about other businesses and about business professionals who work at them. This policy covers both: the account data we hold about you if you are our customer, and the business and business-contact data we hold about others if you are the subject of a record in our system.

2. What we collect, and where it comes from

Account data. If you sign up, we hold your name, work email, and password (hashed, never stored in plain text), plus workspace and usage data needed to run the product. This comes directly from you.

Company data and signals. Firmographic data about companies (size, industry, location, technology, funding) is compiled from publicly available sources, together with signals we generate ourselves. Self-generated signals come only from crawling public company web pages — never from logging into any platform, and never from any password-gated website. See our crawler information page for exactly how that crawl behaves.

Business-contact data. Records about individual professionals — name, job title, employer, and career history — are compiled from publicly available professional sources. This is business/professional information (comparable to what appears on a business card or a public professional profile), not data about our own customers.

On-demand contact reveal. Floxify is designed to let a customer request a verified email or phone number for a specific contact, on demand, through a specialised third-party verification provider, one request at a time. This feature is not live yet. When it ships: each reveal is scoped to the requesting customer only, is never cached or resold across customers or workspaces, and is excluded from data exports — a structural rule enforced in how contact records are modelled, not a policy we could quietly change later.

Your search queries. When you describe an ideal customer profile in plain English, that text may be sent to a configured third-party AI/large-language-model provider (OpenAI, Anthropic, or OpenRouter, depending on how the environment is configured) purely to translate it into structured search filters. It is not used to train any model on our behalf, and it is not linked to the business-contact records described above.

3. What we do not do

  • We do not scrape login-gated platforms, social networks, or paywalled aggregators. Every signal we generate ourselves comes from a public company homepage that would appear the same way to any visitor.
  • We do not cache or resell third-party contact-reveal results (email/phone lookups). Each is scoped to the customer who requested it.
  • We do not sell raw, unbounded datasets to third parties. Any bulk export from the product is capped at 500 rows per export — see our Terms of Service for why.

4. Lawful basis for processing (GDPR)

For business-contact records about professionals who are not our customers, our lawful basis is legitimate interest: the data is business-context information (name, title, employer) processed for B2B prospecting, a purpose the individual would reasonably expect given their public professional role, and we provide a route to object at any time (Section 7). For account data belonging to our own customers, our lawful basis is performance of a contract — we need it to provide the service you signed up for.

5. Retention and deletion

Account data is kept for as long as your workspace is active, and deleted on request or account closure, subject to what we must keep for legal, tax, or security-log purposes.

Business-contact records are refreshed from our sources on an ongoing basis and kept while they remain part of our product. Our data model supports removing an individual’s personal identifiers (name, title, employer contact) from a record on request while retaining the anonymous, company-level fact it contributed to (for example, “this company added a VP of Sales in March”) — this is a deliberate design choice, not a workaround: it lets us honour deletion requests without destroying a company-level signal that was never about any one individual.

6. Who we share data with

Sub-processors and categories of third party we currently use or plan to use:

  • AI/LLM provider (OpenAI, Anthropic, or OpenRouter, depending on configuration) — processes your natural-language search text into structured filters. Not used against business-contact records.
  • Contact-reveal verification provider(s) — not yet integrated. This section will name the specific provider(s) before that feature goes live.
  • Infrastructure. The product runs on servers we operate ourselves rather than a third-party cloud data-processing sub-processor.

We do not sell business-contact data to data brokers, and we do not make it available to the general public through an unauthenticated API. If that ever changes for a given data category, this policy and our regulatory registrations will be updated first.

7. Your rights

Depending on where you or the data subject are located, applicable law (including the EU/UK GDPR and the California Consumer Privacy Act) may provide the right to: access the personal data we hold, correct inaccurate data, request erasure, object to processing, and opt out of the “sale” or “sharing” of personal information as those terms are defined by California law.

To exercise any of these rights — whether you are our customer or a person whose business-contact record appears in our system — use our data-request page or email support@floxify.ai directly. We will verify and respond to requests within the timeframe applicable law requires.

8. International transfers

Our infrastructure is located in Germany (European Union). If you are accessing Floxify from a different jurisdiction, your data may be processed there.

9. Changes to this policy

We will update the “last updated” date above whenever this policy changes, and for material changes we will make a reasonable effort to notify active customers directly.