Controller:
SDT SYSTEMS d.o.o.
Čevljarska ulica 16
1230 Domžale
Slovenia
Contact: info@sdtsystems.eu
1. Introduction
This Privacy Policy explains how SDT SYSTEMS d.o.o. processes personal data in connection with:
the Workflow AI website;
meeting bookings and inquiries;
the Workflow AI mobile application;
the Workflow AI web platform;
free, demo, trial and paid access;
customer support;
marketing and business communication;
artificial intelligence functionalities;
translation and speech recognition;
images, audio and video;
connected and wearable devices; and
related services.
Workflow AI is a software, technological and service solution intended to support operational work across different departments and industries.
It may include a mobile application, web platform, artificial intelligence, large language models, a voice assistant, speech recognition, translation, work instructions, onboarding, task guidance, communication, reporting, analytics, connected devices and wearable devices.
This Privacy Policy applies to:
Website visitors;
persons submitting inquiries;
persons booking meetings;
persons registering for Workflow AI;
Users of free, demo, trial or paid services;
representatives of customers and potential customers;
Administrators; and
End Users using Workflow AI through an Organisation.
2. Who We Are
The provider of Workflow AI is:
SDT SYSTEMS d.o.o.
Čevljarska ulica 16
1230 Domžale
Slovenia
E-mail: info@sdtsystems.eu
Unless a data protection officer is appointed and separately published, this e-mail address also serves as the general contact point for privacy matters.
3. When We Act as Controller and Processor
Depending on the circumstances, SDT SYSTEMS d.o.o. may act as either a controller or a processor.
3.1 When We Act as Controller
We generally act as controller when we process personal data for our own purposes, including when:
you visit our Website;
you submit an inquiry;
you book a meeting;
you communicate with us;
you register directly for a demo or free account;
we provide customer support;
we manage sales and customer relationships;
we conduct B2B marketing;
we secure and improve our own services;
we manage billing and accounting;
we protect legal claims; or
we comply with our legal obligations.
3.2 When We Act as Processor
Where an Organisation uses Workflow AI for its employees, workers, contractors, agency workers, trainees or other End Users, that Organisation usually determines:
why Workflow AI is used;
which functionalities are enabled;
which individuals use the system;
which data are entered;
how data are used;
who may access data; and
what work-related consequences may follow.
In such cases, the Organisation is usually the controller and SDT SYSTEMS d.o.o. acts as processor.
The Organisation is responsible for:
determining the legal basis for processing;
informing End Users;
ensuring compliance with employment law;
ensuring compliance with occupational health and safety rules;
adopting internal policies where required;
managing access rights;
assessing the use of cameras and microphones;
assessing workplace monitoring;
performing a data protection impact assessment where required; and
ensuring lawful use of Workflow AI.
If you use Workflow AI through your employer or another Organisation, questions about mandatory use, workplace monitoring, legal basis and work-related consequences should generally be directed to that Organisation.
4. Personal Data We Process
The personal data we process depends on how Workflow AI is used.
4.1 Website Visitors
We may process:
IP address;
browser type and version;
device type;
operating system;
technical identifiers;
pages visited;
date and time of access;
clicks and interactions;
referral source;
advertising or campaign source;
cookie identifiers;
approximate location derived from technical data;
security logs; and
server logs.
4.2 Inquiries, Meetings and Sales Communication
We may process:
name and surname;
business e-mail address;
phone number;
company or Organisation name;
job title or role;
country;
language;
time zone;
meeting details;
calendar information;
inquiry content;
communication history;
information about interest in Workflow AI;
meeting or call notes;
follow-up activities; and
sales status.
4.3 Registration and User Accounts
We may process:
name and surname;
e-mail address;
phone number, where provided;
Organisation;
department;
user role;
permissions;
authentication data;
User ID;
account ID;
session ID;
language settings;
country settings;
registration date;
login history;
device information;
account settings;
accepted versions of the General Terms;
acknowledged versions of the Privacy Policy; and
other confirmations.
4.4 Application and Platform Use
We may process:
usage data;
activity logs;
features used;
Credits allocated and consumed;
tasks;
procedures;
work instructions;
comments and confirmations;
questions and answers;
support interactions;
uploaded files;
AI Outputs;
summaries;
reports;
usage analytics;
error logs;
crash logs;
diagnostic data; and
system configuration data.
4.5 Artificial Intelligence and Large Language Models
Depending on the functionality used, we may process:
prompts;
questions;
answers;
source documents;
procedures;
instructions;
text submitted for analysis;
generated content;
translated content;
summaries;
recommendations;
reports;
conversation context;
metadata; and
other data necessary to provide the requested AI functionality.
4.6 Translation and Speech Processing
We may process:
voice input;
audio recordings;
speech-to-text transcripts;
detected languages;
translations;
generated speech;
speaker-related technical data;
audio quality data; and
session metadata.
Depending on the technical configuration, audio may be processed temporarily without long-term storage, or may be stored where this is necessary for the agreed functionality, support, documentation or another lawful purpose.
The applicable Organisation is responsible for configuring and communicating the intended use.
4.7 Images and Video
Where enabled, we may process:
photographs;
video recordings;
individual video frames;
objects appearing in images;
work areas;
equipment;
documents visible in images;
persons incidentally captured;
image metadata;
time and device information;
image interpretations; and
generated reports.
4.8 Workplace and End User Data
Depending on the Organisation’s configuration, we may process:
name and surname;
contact details;
employee or contractor role;
department;
team;
work location;
preferred language;
task allocation;
task status;
task completion information;
work instructions;
communication with supervisors;
translations;
feedback;
reports;
usage logs;
device information; and
work-related content.
4.9 Wearable Devices and Connected Equipment
We may process:
device identifier;
device status;
connection data;
headset use;
microphone use;
speaker use;
camera-related data;
audio, image or video captured through the device;
battery and diagnostic data;
maintenance data; and
security logs.
4.10 Special Categories of Personal Data
Workflow AI is not designed to intentionally collect special categories of personal data unless a specific use case requires such processing and the Organisation has ensured an appropriate legal basis and safeguards.
Depending on the environment, images, audio, video or uploaded documents may incidentally contain:
health information;
biometric characteristics;
religious information;
political opinions;
trade union information;
racial or ethnic information; or
other sensitive data.
Users and Organisations should not upload or record sensitive data unless this is necessary, lawful and appropriately protected.
5. How We Collect Personal Data
We may collect personal data:
directly from you;
from your Organisation or employer;
automatically through the Website, Application, Platform or devices;
through cookies and similar technologies;
from third-party meeting, communication, support or security tools;
from integrations enabled by an Organisation; or
from publicly available B2B sources where permitted by law.
6. Purposes of Processing
6.1 Website and Online Services
We process data to:
operate the Website;
provide Website functionality;
ensure security;
prevent misuse;
analyse Website use;
improve user experience; and
manage cookies.
6.2 Inquiries, Meetings and Sales
We process data to:
respond to inquiries;
organise meetings;
provide presentations;
prepare offers;
manage customer relationships;
maintain communication records; and
conduct follow-up activities.
6.3 Accounts and Access
We process data to:
create accounts;
authenticate Users;
manage permissions;
connect Users with Organisations;
enable free or paid access;
allocate Credits;
record acceptance of contractual documents; and
secure accounts.
6.4 Providing Workflow AI
We process data to:
generate and adapt work instructions;
provide task guidance;
support onboarding;
provide translation;
provide speech recognition;
process documents;
generate summaries;
generate reports;
support workplace communication;
provide AI-supported answers;
enable connected devices;
enable integrations; and
provide other requested functionalities.
6.5 Support, Maintenance and Security
We process data to:
provide support;
diagnose errors;
maintain the service;
secure accounts and infrastructure;
investigate incidents;
prevent fraud and misuse;
keep audit and security logs; and
protect legal claims.
6.6 Product Improvement
We may process data to:
improve functionality;
improve reliability;
test new features;
improve usability;
analyse system performance;
detect recurring errors;
improve safety; and
develop new use cases.
Where we act as processor, product improvement involving personal data is carried out only where permitted by:
the applicable agreement;
documented instructions;
applicable law;
the technical configuration; or
anonymisation.
6.7 Marketing
We may process data to:
communicate with business contacts;
send information about Workflow AI;
send invitations or offers;
conduct B2B marketing;
measure campaign performance; and
conduct advertising or remarketing where permitted.
6.8 Legal and Administrative Purposes
We may process data to:
comply with legal obligations;
manage accounting and tax records;
respond to authorities;
enforce agreements;
establish and protect legal claims; and
document compliance.
7. Legal Bases
Depending on the context, we may rely on:
7.1 Contract and Pre-contractual Steps
Processing may be necessary to:
respond to a request;
arrange a demonstration;
create an account;
provide Workflow AI;
provide support; or
perform an agreement.
7.2 Legitimate Interests
We may rely on legitimate interests for:
B2B communication;
customer relationship management;
service security;
fraud prevention;
product improvement;
business administration;
analytics;
maintaining records; and
protecting legal claims.
We assess whether our interests are overridden by the rights and freedoms of individuals.
7.3 Consent
We rely on consent where required, including for:
non-essential cookies;
certain marketing communication;
optional analytics or advertising tools;
optional recordings; or
optional functionalities where consent is appropriate.
Consent may be withdrawn at any time.
7.4 Legal Obligation
We process data where necessary to comply with legal, regulatory, accounting, tax or authority requirements.
7.5 Processing on Behalf of an Organisation
Where we act as processor, we process personal data based on the documented instructions of the Organisation.
The Organisation is responsible for determining the relevant legal basis.
8. Artificial Intelligence and Automated Processing
Workflow AI uses artificial intelligence and automated processing to:
generate or adapt instructions;
translate speech or text;
convert speech to text;
analyse documents;
interpret images where enabled;
prepare summaries;
generate reports;
suggest next steps;
support Users during tasks; and
provide operational insights.
AI Outputs may be inaccurate, incomplete, outdated, ambiguous, misleading or unsuitable.
Workflow AI is a support tool and does not replace human judgement.
Workflow AI is not intended to make solely automated decisions producing legal or similarly significant effects for individuals.
Organisations must ensure appropriate human oversight before using AI Outputs for decisions relating to:
employment;
termination;
disciplinary measures;
salary;
promotion;
performance evaluation;
occupational safety;
health;
individual rights; or
other material consequences.
9. Use of External AI and Large Language Model Providers
Workflow AI may use external artificial intelligence, large language model, speech recognition, translation, image processing and AI infrastructure providers.
Depending on the functionality, selected model and technical configuration, data submitted through Workflow AI may be transferred to such providers for processing.
This processing may include:
prompts;
source documents;
text;
transcriptions;
translations;
images;
audio;
relevant conversation context;
metadata; and
generated outputs.
Where Workflow AI is used by an Organisation and we act as processor, we seek to use contractual and technical configurations under which service providers process customer personal data for the purpose of providing, securing and maintaining the relevant service.
The exact contractual and technical arrangement may differ between providers and functionalities.
Information regarding relevant providers may be made available through:
a data processing agreement;
sub-processor information;
product documentation; or
a reasonable request.
Organisations should not submit information to Workflow AI where they do not have the right to permit the necessary processing.
10. International Processing and Transfers
We primarily seek to use processing locations within the European Economic Area where reasonably possible and appropriate.
However, some cloud, artificial intelligence, large language model, translation, speech recognition, communication, analytics, support or security providers may process, store or access data from countries outside the European Economic Area.
Depending on the functionality, model and technical configuration, personal data or User Content may therefore be processed outside the European Economic Area.
This may include temporary processing necessary to generate:
AI responses;
translations;
transcriptions;
summaries;
image interpretations;
reports; or
other requested outputs.
We cannot guarantee that all processing connected with every Workflow AI functionality will take place exclusively within the European Economic Area.
Where personal data is transferred to or accessed from a country outside the European Economic Area, we take reasonable steps to use an appropriate transfer mechanism and safeguards in accordance with applicable law.
Depending on the provider and destination, these safeguards may include:
an adequacy decision adopted by the European Commission;
Standard Contractual Clauses;
additional contractual safeguards;
organisational safeguards;
technical safeguards; or
another lawful transfer mechanism.
Organisations should take the possible use of non-EEA service providers into account when deciding which documents, recordings and other content may be processed through Workflow AI.
Further information may be provided through the applicable data processing agreement, sub-processor information or upon reasonable request.
11. Recipients and Sub-processors
We may share personal data with:
authorised employees;
contractors and collaborators;
hosting providers;
cloud infrastructure providers;
artificial intelligence providers;
large language model providers;
speech recognition providers;
translation providers;
communication providers;
meeting booking providers;
analytics providers;
support and ticketing providers;
security providers;
development and maintenance providers;
accounting and tax advisers;
legal and professional advisers;
payment providers;
the relevant Organisation; and
courts, regulators or authorities where required.
Where we use sub-processors on behalf of an Organisation, they are subject to appropriate contractual data protection obligations.
A list of key sub-processors may be made available through the Website, Platform, data processing agreement or upon request.
12. Workplace Use
Where Workflow AI is used in a working environment, the Organisation is responsible for ensuring lawful use.
This includes responsibility for:
informing employees and other End Users;
selecting the legal basis;
adopting internal notices and policies;
ensuring compliance with employment law;
ensuring compliance with occupational health and safety rules;
assessing cameras and microphones;
assessing audio, images and video;
assessing monitoring functionalities;
determining access rights;
determining retention periods where applicable;
ensuring human review of AI Outputs; and
handling work-related consequences.
Depending on the configuration, the Organisation may access information about an End User’s use of Workflow AI, including:
assigned tasks;
task status;
work-related communication;
translations;
reports;
feedback;
usage logs; and
operational information.
End Users should contact their employer, Organisation Administrator, HR department, supervisor or data protection contact for information about workplace use.
13. User Content
Users and Organisations may enter, upload or create:
documents;
procedures;
instructions;
images;
audio;
video;
text;
translations;
questions;
answers; and
other data.
The User or Organisation is responsible for ensuring that it has the right to upload and process such content.
We process User Content to:
provide Workflow AI;
generate requested outputs;
maintain the service;
provide support;
ensure security;
troubleshoot issues; and
comply with applicable agreements and law.
Where User Content includes personal data relating to employees, customers, patients, visitors or other individuals, the Organisation must ensure lawful and transparent processing.
14. Cookies and Similar Technologies
We may use cookies and similar technologies for:
essential functionality;
security;
authentication;
remembering preferences;
analytics;
campaign measurement;
advertising; and
remarketing.
Essential cookies may be used where necessary for the service.
Non-essential cookies are used only where permitted and, where required, based on consent.
Additional information may be provided through a Cookie Policy or cookie banner.
15. Data Retention
We retain personal data only for as long as necessary for the relevant purpose, unless a longer period is required or permitted by law.
Typical retention periods may include:
Website logs: for a limited period necessary for security, analytics and troubleshooting;
inquiry and meeting data: generally for up to 24 months after the last relevant communication, unless a longer period is justified;
business contact data: for the duration of the business relationship and a reasonable period afterwards;
active accounts: for the duration of use;
inactive demo accounts: for a reasonable period after inactivity;
free or demo User Content: for the duration of access and a reasonable period afterwards;
technical logs: for a period necessary for security, support and audit purposes;
security logs: for as long as necessary to investigate incidents and protect the service;
support records: for as long as reasonably necessary to provide support and maintain service history;
accounting and tax records: for the period required by law;
contractual acceptance records: for the duration of the contractual relationship and a reasonable limitation period afterwards;
data processed for an Organisation: in accordance with the agreement and documented instructions; and
audio, image or video: according to the relevant functionality, Organisation configuration, agreement and lawful purpose.
We may retain anonymised and aggregated data for longer where it no longer identifies an individual or Organisation.
16. Security
We implement appropriate technical and organisational measures to protect personal data.
These may include:
access controls;
authentication;
permission management;
secure transmission;
encryption where appropriate;
pseudonymisation where appropriate;
backups;
logging;
incident response procedures;
restrictions on internal access;
confidentiality obligations;
security updates;
system maintenance; and
contractual obligations for service providers.
No system can be guaranteed to be completely secure.
Users and Organisations are responsible for:
protecting login details;
managing internal access rights;
securing their devices;
avoiding unnecessary sensitive data; and
promptly reporting suspected security incidents.
17. Your Rights
Depending on the applicable law and context, you may have the right to:
access personal data;
correct inaccurate data;
request erasure;
restrict processing;
object to processing;
receive portable data;
withdraw consent;
object to direct marketing;
request human intervention in certain automated decision-making situations; and