Privacy Policy

Version 1.1 · Effective from 31 July 2026
Controller:
SDT SYSTEMS d.o.o.
Čevljarska ulica 16
1230 Domžale
Slovenia
Contact: info@sdtsystems.eu

1. Introduction

This Privacy Policy explains how SDT SYSTEMS d.o.o. processes personal data in connection with:

  1. the Workflow AI website;
  2. meeting bookings and inquiries;
  3. the Workflow AI mobile application;
  4. the Workflow AI web platform;
  5. free, demo, trial and paid access;
  6. customer support;
  7. marketing and business communication;
  8. artificial intelligence functionalities;
  9. translation and speech recognition;
  10. images, audio and video;
  11. connected and wearable devices; and
  12. related services.

Workflow AI is a software, technological and service solution intended to support operational work across different departments and industries.

It may include a mobile application, web platform, artificial intelligence, large language models, a voice assistant, speech recognition, translation, work instructions, onboarding, task guidance, communication, reporting, analytics, connected devices and wearable devices.

This Privacy Policy applies to:

  1. Website visitors;
  2. persons submitting inquiries;
  3. persons booking meetings;
  4. persons registering for Workflow AI;
  5. Users of free, demo, trial or paid services;
  6. representatives of customers and potential customers;
  7. Administrators; and
  8. End Users using Workflow AI through an Organisation.

2. Who We Are

The provider of Workflow AI is:

SDT SYSTEMS d.o.o.
Čevljarska ulica 16
1230 Domžale
Slovenia
E-mail: info@sdtsystems.eu

Unless a data protection officer is appointed and separately published, this e-mail address also serves as the general contact point for privacy matters.

3. When We Act as Controller and Processor

Depending on the circumstances, SDT SYSTEMS d.o.o. may act as either a controller or a processor.

3.1 When We Act as Controller

We generally act as controller when we process personal data for our own purposes, including when:

  1. you visit our Website;
  2. you submit an inquiry;
  3. you book a meeting;
  4. you communicate with us;
  5. you register directly for a demo or free account;
  6. we provide customer support;
  7. we manage sales and customer relationships;
  8. we conduct B2B marketing;
  9. we secure and improve our own services;
  10. we manage billing and accounting;
  11. we protect legal claims; or
  12. we comply with our legal obligations.

3.2 When We Act as Processor

Where an Organisation uses Workflow AI for its employees, workers, contractors, agency workers, trainees or other End Users, that Organisation usually determines:

  1. why Workflow AI is used;
  2. which functionalities are enabled;
  3. which individuals use the system;
  4. which data are entered;
  5. how data are used;
  6. who may access data; and
  7. what work-related consequences may follow.

In such cases, the Organisation is usually the controller and SDT SYSTEMS d.o.o. acts as processor.

The Organisation is responsible for:

  1. determining the legal basis for processing;
  2. informing End Users;
  3. ensuring compliance with employment law;
  4. ensuring compliance with occupational health and safety rules;
  5. adopting internal policies where required;
  6. managing access rights;
  7. assessing the use of cameras and microphones;
  8. assessing workplace monitoring;
  9. performing a data protection impact assessment where required; and
  10. ensuring lawful use of Workflow AI.

If you use Workflow AI through your employer or another Organisation, questions about mandatory use, workplace monitoring, legal basis and work-related consequences should generally be directed to that Organisation.

4. Personal Data We Process

The personal data we process depends on how Workflow AI is used.

4.1 Website Visitors

We may process:

  1. IP address;
  2. browser type and version;
  3. device type;
  4. operating system;
  5. technical identifiers;
  6. pages visited;
  7. date and time of access;
  8. clicks and interactions;
  9. referral source;
  10. advertising or campaign source;
  11. cookie identifiers;
  12. approximate location derived from technical data;
  13. security logs; and
  14. server logs.

4.2 Inquiries, Meetings and Sales Communication

We may process:

  1. name and surname;
  2. business e-mail address;
  3. phone number;
  4. company or Organisation name;
  5. job title or role;
  6. country;
  7. language;
  8. time zone;
  9. meeting details;
  10. calendar information;
  11. inquiry content;
  12. communication history;
  13. information about interest in Workflow AI;
  14. meeting or call notes;
  15. follow-up activities; and
  16. sales status.

4.3 Registration and User Accounts

We may process:

  1. name and surname;
  2. e-mail address;
  3. phone number, where provided;
  4. Organisation;
  5. department;
  6. user role;
  7. permissions;
  8. authentication data;
  9. User ID;
  10. account ID;
  11. session ID;
  12. language settings;
  13. country settings;
  14. registration date;
  15. login history;
  16. device information;
  17. account settings;
  18. accepted versions of the General Terms;
  19. acknowledged versions of the Privacy Policy; and
  20. other confirmations.

4.4 Application and Platform Use

We may process:

  1. usage data;
  2. activity logs;
  3. features used;
  4. Credits allocated and consumed;
  5. tasks;
  6. procedures;
  7. work instructions;
  8. comments and confirmations;
  9. questions and answers;
  10. support interactions;
  11. uploaded files;
  12. AI Outputs;
  13. summaries;
  14. reports;
  15. usage analytics;
  16. error logs;
  17. crash logs;
  18. diagnostic data; and
  19. system configuration data.

4.5 Artificial Intelligence and Large Language Models

Depending on the functionality used, we may process:

  1. prompts;
  2. questions;
  3. answers;
  4. source documents;
  5. procedures;
  6. instructions;
  7. text submitted for analysis;
  8. generated content;
  9. translated content;
  10. summaries;
  11. recommendations;
  12. reports;
  13. conversation context;
  14. metadata; and
  15. other data necessary to provide the requested AI functionality.

4.6 Translation and Speech Processing

We may process:

  1. voice input;
  2. audio recordings;
  3. speech-to-text transcripts;
  4. detected languages;
  5. translations;
  6. generated speech;
  7. speaker-related technical data;
  8. audio quality data; and
  9. session metadata.

Depending on the technical configuration, audio may be processed temporarily without long-term storage, or may be stored where this is necessary for the agreed functionality, support, documentation or another lawful purpose.

The applicable Organisation is responsible for configuring and communicating the intended use.

4.7 Images and Video

Where enabled, we may process:

  1. photographs;
  2. video recordings;
  3. individual video frames;
  4. objects appearing in images;
  5. work areas;
  6. equipment;
  7. documents visible in images;
  8. persons incidentally captured;
  9. image metadata;
  10. time and device information;
  11. image interpretations; and
  12. generated reports.

4.8 Workplace and End User Data

Depending on the Organisation’s configuration, we may process:

  1. name and surname;
  2. contact details;
  3. employee or contractor role;
  4. department;
  5. team;
  6. work location;
  7. preferred language;
  8. task allocation;
  9. task status;
  10. task completion information;
  11. work instructions;
  12. communication with supervisors;
  13. translations;
  14. feedback;
  15. reports;
  16. usage logs;
  17. device information; and
  18. work-related content.

4.9 Wearable Devices and Connected Equipment

We may process:

  1. device identifier;
  2. device status;
  3. connection data;
  4. headset use;
  5. microphone use;
  6. speaker use;
  7. camera-related data;
  8. audio, image or video captured through the device;
  9. battery and diagnostic data;
  10. maintenance data; and
  11. security logs.

4.10 Special Categories of Personal Data

Workflow AI is not designed to intentionally collect special categories of personal data unless a specific use case requires such processing and the Organisation has ensured an appropriate legal basis and safeguards.

Depending on the environment, images, audio, video or uploaded documents may incidentally contain:

  1. health information;
  2. biometric characteristics;
  3. religious information;
  4. political opinions;
  5. trade union information;
  6. racial or ethnic information; or
  7. other sensitive data.

Users and Organisations should not upload or record sensitive data unless this is necessary, lawful and appropriately protected.

5. How We Collect Personal Data

We may collect personal data:

  1. directly from you;
  2. from your Organisation or employer;
  3. automatically through the Website, Application, Platform or devices;
  4. through cookies and similar technologies;
  5. from third-party meeting, communication, support or security tools;
  6. from integrations enabled by an Organisation; or
  7. from publicly available B2B sources where permitted by law.

6. Purposes of Processing

6.1 Website and Online Services

We process data to:

  1. operate the Website;
  2. provide Website functionality;
  3. ensure security;
  4. prevent misuse;
  5. analyse Website use;
  6. improve user experience; and
  7. manage cookies.

6.2 Inquiries, Meetings and Sales

We process data to:

  1. respond to inquiries;
  2. organise meetings;
  3. provide presentations;
  4. prepare offers;
  5. manage customer relationships;
  6. maintain communication records; and
  7. conduct follow-up activities.

6.3 Accounts and Access

We process data to:

  1. create accounts;
  2. authenticate Users;
  3. manage permissions;
  4. connect Users with Organisations;
  5. enable free or paid access;
  6. allocate Credits;
  7. record acceptance of contractual documents; and
  8. secure accounts.

6.4 Providing Workflow AI

We process data to:

  1. generate and adapt work instructions;
  2. provide task guidance;
  3. support onboarding;
  4. provide translation;
  5. provide speech recognition;
  6. process documents;
  7. generate summaries;
  8. generate reports;
  9. support workplace communication;
  10. provide AI-supported answers;
  11. enable connected devices;
  12. enable integrations; and
  13. provide other requested functionalities.

6.5 Support, Maintenance and Security

We process data to:

  1. provide support;
  2. diagnose errors;
  3. maintain the service;
  4. secure accounts and infrastructure;
  5. investigate incidents;
  6. prevent fraud and misuse;
  7. keep audit and security logs; and
  8. protect legal claims.

6.6 Product Improvement

We may process data to:

  1. improve functionality;
  2. improve reliability;
  3. test new features;
  4. improve usability;
  5. analyse system performance;
  6. detect recurring errors;
  7. improve safety; and
  8. develop new use cases.

Where we act as processor, product improvement involving personal data is carried out only where permitted by:

  1. the applicable agreement;
  2. documented instructions;
  3. applicable law;
  4. the technical configuration; or
  5. anonymisation.

6.7 Marketing

We may process data to:

  1. communicate with business contacts;
  2. send information about Workflow AI;
  3. send invitations or offers;
  4. conduct B2B marketing;
  5. measure campaign performance; and
  6. conduct advertising or remarketing where permitted.

6.8 Legal and Administrative Purposes

We may process data to:

  1. comply with legal obligations;
  2. manage accounting and tax records;
  3. respond to authorities;
  4. enforce agreements;
  5. establish and protect legal claims; and
  6. document compliance.

7. Legal Bases

Depending on the context, we may rely on:

7.1 Contract and Pre-contractual Steps

Processing may be necessary to:

  1. respond to a request;
  2. arrange a demonstration;
  3. create an account;
  4. provide Workflow AI;
  5. provide support; or
  6. perform an agreement.

7.2 Legitimate Interests

We may rely on legitimate interests for:

  1. B2B communication;
  2. customer relationship management;
  3. service security;
  4. fraud prevention;
  5. product improvement;
  6. business administration;
  7. analytics;
  8. maintaining records; and
  9. protecting legal claims.

We assess whether our interests are overridden by the rights and freedoms of individuals.

7.3 Consent

We rely on consent where required, including for:

  1. non-essential cookies;
  2. certain marketing communication;
  3. optional analytics or advertising tools;
  4. optional recordings; or
  5. optional functionalities where consent is appropriate.

Consent may be withdrawn at any time.

7.4 Legal Obligation

We process data where necessary to comply with legal, regulatory, accounting, tax or authority requirements.

7.5 Processing on Behalf of an Organisation

Where we act as processor, we process personal data based on the documented instructions of the Organisation.

The Organisation is responsible for determining the relevant legal basis.

8. Artificial Intelligence and Automated Processing

Workflow AI uses artificial intelligence and automated processing to:

  1. generate or adapt instructions;
  2. translate speech or text;
  3. convert speech to text;
  4. analyse documents;
  5. interpret images where enabled;
  6. prepare summaries;
  7. generate reports;
  8. suggest next steps;
  9. support Users during tasks; and
  10. provide operational insights.

AI Outputs may be inaccurate, incomplete, outdated, ambiguous, misleading or unsuitable.

Workflow AI is a support tool and does not replace human judgement.

Workflow AI is not intended to make solely automated decisions producing legal or similarly significant effects for individuals.

Organisations must ensure appropriate human oversight before using AI Outputs for decisions relating to:

  1. employment;
  2. termination;
  3. disciplinary measures;
  4. salary;
  5. promotion;
  6. performance evaluation;
  7. occupational safety;
  8. health;
  9. individual rights; or
  10. other material consequences.

9. Use of External AI and Large Language Model Providers

Workflow AI may use external artificial intelligence, large language model, speech recognition, translation, image processing and AI infrastructure providers.

Depending on the functionality, selected model and technical configuration, data submitted through Workflow AI may be transferred to such providers for processing.

This processing may include:

  1. prompts;
  2. source documents;
  3. text;
  4. transcriptions;
  5. translations;
  6. images;
  7. audio;
  8. relevant conversation context;
  9. metadata; and
  10. generated outputs.

Where Workflow AI is used by an Organisation and we act as processor, we seek to use contractual and technical configurations under which service providers process customer personal data for the purpose of providing, securing and maintaining the relevant service.

The exact contractual and technical arrangement may differ between providers and functionalities.

Information regarding relevant providers may be made available through:

  1. a data processing agreement;
  2. sub-processor information;
  3. product documentation; or
  4. a reasonable request.

Organisations should not submit information to Workflow AI where they do not have the right to permit the necessary processing.

10. International Processing and Transfers

We primarily seek to use processing locations within the European Economic Area where reasonably possible and appropriate.

However, some cloud, artificial intelligence, large language model, translation, speech recognition, communication, analytics, support or security providers may process, store or access data from countries outside the European Economic Area.

Depending on the functionality, model and technical configuration, personal data or User Content may therefore be processed outside the European Economic Area.

This may include temporary processing necessary to generate:

  1. AI responses;
  2. translations;
  3. transcriptions;
  4. summaries;
  5. image interpretations;
  6. reports; or
  7. other requested outputs.

We cannot guarantee that all processing connected with every Workflow AI functionality will take place exclusively within the European Economic Area.

Where personal data is transferred to or accessed from a country outside the European Economic Area, we take reasonable steps to use an appropriate transfer mechanism and safeguards in accordance with applicable law.

Depending on the provider and destination, these safeguards may include:

  1. an adequacy decision adopted by the European Commission;
  2. Standard Contractual Clauses;
  3. additional contractual safeguards;
  4. organisational safeguards;
  5. technical safeguards; or
  6. another lawful transfer mechanism.

Organisations should take the possible use of non-EEA service providers into account when deciding which documents, recordings and other content may be processed through Workflow AI.

Further information may be provided through the applicable data processing agreement, sub-processor information or upon reasonable request.

11. Recipients and Sub-processors

We may share personal data with:

  1. authorised employees;
  2. contractors and collaborators;
  3. hosting providers;
  4. cloud infrastructure providers;
  5. artificial intelligence providers;
  6. large language model providers;
  7. speech recognition providers;
  8. translation providers;
  9. communication providers;
  10. meeting booking providers;
  11. analytics providers;
  12. support and ticketing providers;
  13. security providers;
  14. development and maintenance providers;
  15. accounting and tax advisers;
  16. legal and professional advisers;
  17. payment providers;
  18. the relevant Organisation; and
  19. courts, regulators or authorities where required.

Where we use sub-processors on behalf of an Organisation, they are subject to appropriate contractual data protection obligations.

A list of key sub-processors may be made available through the Website, Platform, data processing agreement or upon request.

12. Workplace Use

Where Workflow AI is used in a working environment, the Organisation is responsible for ensuring lawful use.

This includes responsibility for:

  1. informing employees and other End Users;
  2. selecting the legal basis;
  3. adopting internal notices and policies;
  4. ensuring compliance with employment law;
  5. ensuring compliance with occupational health and safety rules;
  6. assessing cameras and microphones;
  7. assessing audio, images and video;
  8. assessing monitoring functionalities;
  9. determining access rights;
  10. determining retention periods where applicable;
  11. ensuring human review of AI Outputs; and
  12. handling work-related consequences.

Depending on the configuration, the Organisation may access information about an End User’s use of Workflow AI, including:

  1. assigned tasks;
  2. task status;
  3. work-related communication;
  4. translations;
  5. reports;
  6. feedback;
  7. usage logs; and
  8. operational information.

End Users should contact their employer, Organisation Administrator, HR department, supervisor or data protection contact for information about workplace use.

13. User Content

Users and Organisations may enter, upload or create:

  1. documents;
  2. procedures;
  3. instructions;
  4. images;
  5. audio;
  6. video;
  7. text;
  8. translations;
  9. questions;
  10. answers; and
  11. other data.

The User or Organisation is responsible for ensuring that it has the right to upload and process such content.

We process User Content to:

  1. provide Workflow AI;
  2. generate requested outputs;
  3. maintain the service;
  4. provide support;
  5. ensure security;
  6. troubleshoot issues; and
  7. comply with applicable agreements and law.

Where User Content includes personal data relating to employees, customers, patients, visitors or other individuals, the Organisation must ensure lawful and transparent processing.

14. Cookies and Similar Technologies

We may use cookies and similar technologies for:

  1. essential functionality;
  2. security;
  3. authentication;
  4. remembering preferences;
  5. analytics;
  6. campaign measurement;
  7. advertising; and
  8. remarketing.

Essential cookies may be used where necessary for the service.

Non-essential cookies are used only where permitted and, where required, based on consent.

Additional information may be provided through a Cookie Policy or cookie banner.

15. Data Retention

We retain personal data only for as long as necessary for the relevant purpose, unless a longer period is required or permitted by law.

Typical retention periods may include:

  1. Website logs: for a limited period necessary for security, analytics and troubleshooting;
  2. inquiry and meeting data: generally for up to 24 months after the last relevant communication, unless a longer period is justified;
  3. business contact data: for the duration of the business relationship and a reasonable period afterwards;
  4. active accounts: for the duration of use;
  5. inactive demo accounts: for a reasonable period after inactivity;
  6. free or demo User Content: for the duration of access and a reasonable period afterwards;
  7. technical logs: for a period necessary for security, support and audit purposes;
  8. security logs: for as long as necessary to investigate incidents and protect the service;
  9. support records: for as long as reasonably necessary to provide support and maintain service history;
  10. accounting and tax records: for the period required by law;
  11. contractual acceptance records: for the duration of the contractual relationship and a reasonable limitation period afterwards;
  12. data processed for an Organisation: in accordance with the agreement and documented instructions; and
  13. audio, image or video: according to the relevant functionality, Organisation configuration, agreement and lawful purpose.

We may retain anonymised and aggregated data for longer where it no longer identifies an individual or Organisation.

16. Security

We implement appropriate technical and organisational measures to protect personal data.

These may include:

  1. access controls;
  2. authentication;
  3. permission management;
  4. secure transmission;
  5. encryption where appropriate;
  6. pseudonymisation where appropriate;
  7. backups;
  8. logging;
  9. incident response procedures;
  10. restrictions on internal access;
  11. confidentiality obligations;
  12. security updates;
  13. system maintenance; and
  14. contractual obligations for service providers.

No system can be guaranteed to be completely secure.

Users and Organisations are responsible for:

  1. protecting login details;
  2. managing internal access rights;
  3. securing their devices;
  4. avoiding unnecessary sensitive data; and
  5. promptly reporting suspected security incidents.

17. Your Rights

Depending on the applicable law and context, you may have the right to:

  1. access personal data;
  2. correct inaccurate data;
  3. request erasure;
  4. restrict processing;
  5. object to processing;
  6. receive portable data;
  7. withdraw consent;
  8. object to direct marketing;
  9. request human intervention in certain automated decision-making situations; and
  10. lodge a complaint with a supervisory authority.

Requests may be sent to info@sdtsystems.eu.

To delete your Workflow AI account and the personal data associated with it, you may also use our account deletion page.

We may need to verify your identity.

Where we process personal data on behalf of an Organisation, we may refer the request to the Organisation or ask you to contact it directly.

18. Direct Marketing

You may object to direct marketing at any time.

Marketing e-mails will include an unsubscribe or opt-out mechanism where required.

Service-related and transactional messages may still be sent where necessary.

19. Complaints

Questions or complaints may be sent to:

info@sdtsystems.eu

You also have the right to lodge a complaint with a competent supervisory authority.

In Slovenia, the competent supervisory authority is the Information Commissioner of the Republic of Slovenia.

20. Acknowledgement and Consent

When creating an account, a User may be asked to confirm that they have read this Privacy Policy.

Such acknowledgement does not itself constitute consent to all processing described in this Privacy Policy.

Where consent is required for a particular optional processing activity, we will request it separately.

An Organisation remains responsible for determining the appropriate legal basis for workplace processing.

21. Data Provided by Organisations

An Organisation may provide us with personal data or enable a User’s access to Workflow AI.

Such data may include:

  1. name;
  2. contact details;
  3. role;
  4. department;
  5. language;
  6. permissions;
  7. assigned tasks; and
  8. other work-related information.

The Organisation is generally responsible for informing the individual about this processing.

22. Children

Workflow AI is intended for business and professional use and is not intended for children or persons under the age of 18.

We do not knowingly collect personal data from children.

Where we become aware that such data has been collected without an appropriate legal basis, we will take reasonable steps to delete it.

23. Third-Party Links and Services

The Website, Application or Platform may contain links to third-party websites or services.

We are not responsible for the privacy practices of independent third parties.

Users should review the applicable third-party privacy information.

24. Changes to This Privacy Policy

We may update this Privacy Policy due to:

  1. product development;
  2. new functionalities;
  3. changes to AI providers;
  4. changes to international processing;
  5. changes in law;
  6. security requirements;
  7. new service providers; or
  8. business development.

The updated Privacy Policy will be published through the Website, Application or Platform.

Where required, Users or Organisations may be notified of material changes.

25. Contact

For questions about this Privacy Policy or personal data protection, contact:

SDT SYSTEMS d.o.o.
Čevljarska ulica 16
1230 Domžale
Slovenia
E-mail: info@sdtsystems.eu