Legal

Privacy Policy

How PrimesFlow Ltd ("PrimesFlow", "we", "us") handles data across the PrimesFlow platform, dashboard, website, and monitoring agent.

Last updated: July 22, 2026

01

Introduction

PrimesFlow Ltd ("PrimesFlow", "we", "us", or "our") is a private limited company registered in England and Wales that operates PrimesFlow, a software-as-a-service platform for server monitoring and AI-assisted incident diagnostics. This Privacy Policy explains what information we collect, how we use it, how long we keep it, and the choices you have.

This policy applies to the primesflow.io website, the PrimesFlow dashboard and APIs, and the PrimesFlow monitoring agent installed on your servers (collectively, the "Service"). By creating an account, installing the agent, or otherwise using the Service, you acknowledge that you have read this policy and agree to the practices described in it. If you do not agree, please do not use the Service.

The Service is intended for use by professionals aged 18 or older. Accounts are secured with an email address and a password of your choosing.

02

Account Data

When you register a workspace or are invited to one, we collect the information required to create, secure, and administer your account:

  • Full name
  • Email address (used as your sign-in identifier)
  • Password, stored only as a salted cryptographic hash — we never store or transmit your password in plain text
  • Workspace name
  • Team member email addresses
  • Assigned role for each team member (owner, admin, or member)
  • Notification preferences and timezone

Account records are kept for the life of your account and removed within 30 days after account deletion, subject to the legal and tax exceptions described in Section 06.

03

Billing Data

Payment processing is handled entirely by Stripe, Inc., a PCI DSS Level 1 certified provider. Card details are submitted directly from your browser to Stripe. PrimesFlow never receives or stores full card numbers, CVV codes, or bank account numbers.

The billing metadata we do store includes:

  • Card brand and the last four digits of your card
  • Billing name and billing address
  • Selected plan, billing cycle, and payment history
  • Stripe customer ID and subscription ID

This metadata is used to display invoices, reconcile payments, provide receipts, and meet our tax and accounting obligations.

04

Server & Monitoring Data

The PrimesFlow agent runs as an unprivileged process on the hosts you choose to monitor and transmits a limited set of operational telemetry to PrimesFlow over TLS. Specifically, the agent collects:

  • System metrics — CPU utilization, memory use, disk I/O and capacity, network throughput, load average, and swap activity
  • Process information — top processes by CPU and memory, aggregate process counts, and basic process state
  • Service health — status checks for services such as nginx, PostgreSQL, and Docker, plus TCP port and HTTP endpoint probes you configure
  • System metadata — hostname, operating system and version, kernel version, uptime, and agent version
  • Scoped log snippets — short, contextually relevant excerpts of log output captured only when AI diagnostics are triggered for an incident. PrimesFlow does not continuously stream or ingest your full log files.
  • SSL/TLS certificate metadata — issuer, subject, validity window, and fingerprint for certificates you ask PrimesFlow to monitor

What PrimesFlow does NOT collect

  • The contents of your application databases
  • End-user data flowing through your applications
  • Environment variables, secrets, or API keys
  • SSH keys or credentials of any kind
  • Source code or full file contents from your servers
  • Personal data belonging to your end-users or customers
05

How We Use Your Data

We use the information we collect for the following purposes:

  • Service delivery — running your monitoring workspace, ingesting agent telemetry, rendering dashboards, and delivering alerts
  • Anomaly detection — computing baselines and thresholds against your own telemetry to surface unusual behavior
  • AI-assisted diagnostics — generating assistive incident summaries and probable-cause analysis when you trigger diagnostics for an incident
  • Billing and account management — invoicing, subscription changes, receipts, and support
  • Product improvement — aggregated and anonymized usage patterns to inform product decisions
  • Communications — transactional messages (security notices, billing, incident notifications) and optional product updates. You may opt out of non-essential messages at any time.
  • Legal compliance — meeting our obligations under applicable law and responding to lawful requests

AI model boundary

We do not use customer telemetry to train general-purpose AI models. AI diagnostics run per-account in isolation and are never shared across accounts. Diagnostic outputs are assistive and are not a substitute for engineering judgment.

06

Data Retention

We retain data only as long as necessary for the purposes described in this policy or as required by law.

Data categoryRetention
Account informationLife of account + 30 days after deletion
Billing recordsRetained for applicable tax and legal periods
Server telemetryHobby 7 days · Pro 30 days · Team 90 days (rolling)
Incident reports & AI summariesSame window as the underlying telemetry plan
Support tickets2 years after resolution
Audit logs1 year

When you delete your account, permanent deletion of associated data begins within 30 days, except for records we are required to retain for tax, accounting, fraud prevention, or other legal reasons.

07

Security Practices

Security is central to how PrimesFlow is built and operated. Our program includes:

  • Encryption in transit — all traffic between the agent, the dashboard, our APIs, and your browser is encrypted with TLS 1.2 or higher
  • Encryption at rest — stored data is encrypted at rest using AES-256
  • Access control — multi-factor authentication and least-privilege access controls for production systems, with access limited to authorized personnel
  • Tenant isolation — customer workspaces are logically isolated so one account cannot access another account's data
  • Ongoing review — periodic security reviews, dependency scanning, and infrastructure hardening
  • Breach notification — in the event of a personal data breach affecting your account, we will notify affected customers within 72 hours of confirmation

No system is perfectly secure. We work continuously to reduce risk and encourage responsible disclosure of any suspected vulnerability to contact@primesflow.io .

08

Third-Party Sub-processors

To deliver the Service, PrimesFlow uses a small number of carefully chosen sub-processors. Each sub-processor is bound by contractual data-protection obligations.

ProviderPurposeData shared
StripePayment processingBilling information and payment method
Hetzner / AWSCloud infrastructure and hostingAll service data (encrypted)
PostmarkTransactional email deliveryEmail address, alert and notification content
OpenAIAI diagnostics engineAnonymized telemetry snippets, only when diagnostics are triggered
Plausible AnalyticsWebsite analyticsAnonymous page views, no cookies, no PII

We do not sell, rent, or trade your data to any third party for advertising or marketing purposes.

09

Cookies & Analytics

PrimesFlow uses a deliberately small set of cookies:

  • Session cookie — a secure, HTTP-only cookie that keeps you signed in. It expires when you sign out or after 7 days of inactivity.
  • Preferences cookie — a first-party cookie that stores lightweight preferences such as your dashboard layout and timezone.

We do not use third-party tracking cookies, advertising pixels, or browser fingerprinting. Website analytics are provided by Plausible, which is cookie-free and does not collect personally identifiable information.

10

Your Rights

PrimesFlow Ltd is a UK-based controller and processes personal data under the UK GDPR and the Data Protection Act 2018. Depending on where you live, you may have some or all of the following rights with respect to your personal data:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete information
  • Delete your personal data
  • Portability — receive an export of your data in a machine-readable format (JSON or CSV)
  • Restrict or object to certain processing
  • Withdraw consent where processing is based on consent

You can exercise any of these rights by emailing contact@primesflow.io or calling +44 7446 385946. We aim to respond within 30 days. Account and telemetry exports are also available directly inside the PrimesFlow dashboard.

If you are in the United Kingdom and believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would appreciate the chance to address your concerns first.

11

Children's Privacy

PrimesFlow is a professional tool and is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such information, we will delete it. If you believe a minor has provided personal data to us, please contact contact@primesflow.io.

12

International Data Transfers

PrimesFlow is operated by PrimesFlow Ltd from the United Kingdom, and personal data is handled under the UK GDPR. If you access the Service from outside the United Kingdom, your information may be transferred to, processed in, and stored in the United Kingdom or in other countries where our sub-processors operate.

Where personal data leaves the UK, we rely on appropriate safeguards recognised under UK data protection law — such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — together with technical measures like encryption in transit and at rest.

13

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify workspace owners by email or by posting a prominent notice inside the PrimesFlow dashboard at least 14 days before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14

Contact Information

For privacy questions, data requests, or any other matter covered by this policy, please contact us:

PrimesFlow Ltd

20 Wenlock Road, London, N1 7GU, United Kingdom

Email: contact@primesflow.io

Phone: +44 7446 385946