Wareflows · Behome
Privacy notice
How Wareflows handles personal data when providing Behome and responding to inquiries.
Who is responsible
Wareflows operates Behome. For platform accounts, security and service administration, Wareflows determines why and how personal data is processed. For property, lead and customer communication data entered by a customer agency, that agency normally determines the purpose of processing and Wareflows processes the data on its behalf.
Privacy questions and rights requests can be sent to info@wareflows.com.
What we collect and why
| Information | Purpose | Legal basis |
|---|---|---|
| Website inquiry details, including your name, email, company and message | To understand and respond to your request | Steps at your request before a contract and our legitimate interests |
| Account, authentication, tenant and office membership details | To provide and secure Behome | Contract and legitimate interests |
| Property, lead, support and security records | To operate, support and protect the service | Contract, legitimate interests and legal obligations |
| Connected-account details, including provider account identifiers, OAuth access tokens and, where supported, refresh tokens, granted permissions, credential expiry and webhook-routing metadata | To provide the requested communication integration | Contract and the customer agency’s documented instructions |
| Communication data, including provider-scoped participant and message identifiers, message text, timestamps, delivery state and attachment type and metadata | To display, send and protect connected communications | Contract and the customer agency’s documented instructions |
Website inquiries are delivered to the Wareflows information mailbox. We do not use inquiry details for unrelated marketing unless you separately ask to receive it.
Where the information comes from
We receive information directly from people who contact Wareflows, from Behome users and their customer agencies, and from connected providers when an authorised user enables an integration. For Meta connections, this includes information Meta makes available through the authorised integration. We also generate limited account, delivery and security records when people use the service. We do not buy contact lists or use public social profiles to enrich customer records.
Meta connections and connected communications
Depending on the Meta service connected and the permissions granted, data may include account and profile identifiers, usernames, permissions, encrypted access credentials and their expiry, provider-scoped participant, conversation and message identifiers, message content, timestamps, delivery state, webhook metadata and attachment metadata. Behome does not infer a participant’s phone number or email address and does not import historical conversations merely because a Meta account is connected.
Where language-model assistance is enabled, it creates private proposals for human review. It does not automatically send messages or change customer records.
Automated decision-making
Behome does not make decisions based solely on automated processing that produce legal or similarly significant effects. Suggested replies and other language-model output require a person to review and choose whether to use them.
Access and sharing
A personal communication connection belongs to its Connection Holder. Agency managers can see limited connection health information and can revoke future access, but they cannot read another holder’s private conversation content. Data is disclosed only to authorised service providers and connected-platform providers to the extent needed to provide, secure, support and maintain the service or carry out a feature enabled by the customer. Optional connected-account and language-model services receive data only when the relevant customer feature is enabled. Recipients are subject to appropriate contractual, confidentiality, data-protection and security obligations. We do not sell personal data.
Where data is processed
Our primary application infrastructure is hosted in the European Economic Area. Some connected providers may process data in other countries. Where required, those transfers rely on an adequacy decision, standard contractual clauses or another lawful safeguard.
Retention and deletion
Website inquiries are kept only while needed to handle the conversation and maintain necessary business or security records. Other data is kept while it is needed to provide the service, satisfy the customer agency’s documented instructions and meet legal or security obligations. Disconnecting a provider removes its access credentials. A permanent provider data-deletion request additionally removes provider identity data and destroys the encryption key for private communication content. Limited content-free audit and deduplication evidence may remain where needed for security and integrity. Recoverable infrastructure backups are retained for 14 days; they are protected and expire through automated retention rather than being used as an active source of customer data.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability, and may complain to your data protection authority. If you contacted a property agency through a Meta service or another channel, the agency is normally the first contact for the customer record it controls. You can also contact us and we will help route the request.
We respond to rights requests without undue delay and normally within one month. Where the law permits more time because a request is complex or numerous, we will explain the extension within the first month. You may lodge a complaint with the data protection authority where you live or work, where the issue occurred, or with the authority responsible for our legal operator.
Changes to this notice
We may update this notice when our processing changes. Material changes will be communicated through the service or directly to affected customers.