Privacy Policy
sufox.com
How KeepFlow L.L.C-FZ handles personal data on sufox.com: what is gathered, what it is used for, who receives it, and how it is safeguarded.
Operator: KeepFlow L.L.C-FZ · Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Licence / Formation No. 2646796.01 / 2646796 · Effective date: 19 March 2026
Website: https://sufox.com
Primary contact: support@sufox.com
Drafted and published in English as the working text for sufox.com.
This page covers the privacy practices of KeepFlow L.L.C-FZ (“KeepFlow”, “we”, “our”, or “us”): which categories of personal data we handle around sufox.com, the platform, its integrations, our support and marketing activity, and related services; where that data comes from; the reasons and legal grounds for holding it; the recipients it may reach; how long it stays with us; and the rights you can exercise under the data protection rules that apply to you.
Where this policy applies, and our role
The policy governs personal data gathered via the Website, demo enquiries, sign-up and registration steps, invoicing and contracting, support exchanges, and the day-to-day running of the Services. It equally covers situations where you write to us, opt in to our updates, take part in a webinar or event we run, or deal with us in any other professional setting.
Our role changes with the situation. For some processing we decide the purposes ourselves and act as an independent controller. For other processing we act as a processor/service provider for a business customer. Where a customer runs support conversations, tickets, knowledge-base files, end-user messages, or similar working material through the Services, it is usually that customer who determines the purpose and manner of the processing: the customer is then the primary controller, and we handle the data under its instructions and under our agreements with it.
Are you an End User writing to a business that runs its support on our Services? Then questions about the content of that conversation belong, in the first instance, with that business. Where appropriate, we help our customer answer such requests.
The data we work with
- Identity and contact details — name, employer, role or job title, email, phone, postal address, and comparable business contact information.
- Account and profile records — username, sign-in identifiers, authentication metadata, assigned role and permissions, organisation information, and saved preferences.
- Billing and transaction records — billing address, plan and subscription details, invoices, payment status, tax information, and the limited payment data our payment processors pass to us.
- Technical and device information — IP address, browser and operating system, device identifiers, session identifiers, timestamps, rough location derived from IP, and diagnostic logs.
- Usage and analytics signals — pages opened, features used, clicks and navigation, connection settings, volumes of use, event records, and aggregate statistics about the Services.
- Support and correspondence — messages addressed to us, notes from calls, email threads, feedback, survey answers, demo enquiries, and support tickets.
- Customer Content and operational material — tickets and conversations, prompts and instructions, attachments, helpdesk metadata, knowledge sources, and other material passed into or through the Services.
- Marketing preferences — subscription choices, consent records, and how you engage with what we send.
- Cookie and similar data — covered in detail by our Cookie Policy.
Where the data comes from
- You give it to us — opening an account, booking a demo, subscribing, writing in, joining an event, filling in a form, wiring up an integration, or uploading material.
- It is captured automatically — while you use the Website and Services: cookies, server logs, APIs, device signals, and other telemetry and diagnostics.
- Customers and their users supply it — adding colleagues to an account, connecting data sources, sending team invitations, setting up integrations, or raising support requests.
- Third parties pass it on — payment processors, analytics vendors, cloud and infrastructure suppliers, communication tools, integration partners, resellers, identity providers, and open business sources.
Why we use it, and on what legal grounds
Every use of personal data rests on a legal ground recognised by the law that applies. Depending on context that ground is the performance of a contract, a legal duty we must meet, our legitimate interest in running and developing the business, consent you have given, or another basis the applicable law allows. We use personal data:
- to open and manage accounts, verify who is signing in, apply access controls, and make the Services available;
- to take in, store, search, analyse, and produce Outputs from Customer Content, so the Services can run for our customers;
- to collect payments, run subscriptions, issue invoices, keep accounting records, and stop payment fraud;
- to watch performance, fix faults, keep the platform secure, spot abuse, audit usage, and raise the quality and reliability of the Services;
- to run customer and technical support, onboarding, training, and account management;
- to reach you about your account and subscription, service updates, legal notices, and changes to our policies;
- to send marketing where the law allows and your preferences permit, and to see how well those messages perform;
- to meet legal duties, enforce our contracts, bring or defend claims, protect our rights, and answer lawful demands from courts, regulators, and public bodies;
- to support corporate transactions, internal reporting, due diligence, financing, and similar legitimate business steps, with lawful safeguards in place.
Who can receive it
Selling personal data, in the usual sense of that word, is not something we do. Data can reach the recipients below — only so far as the purposes above require, and always under suitable contractual and organisational protections:
- companies in our group and our affiliates, where delivery of the service, corporate administration, compliance, finance, or support makes that relevant;
- vendors and subprocessors behind hosting, infrastructure, analytics, security, communications, customer support, payments, identity management, model inference, and other operational work;
- integration providers and outside services you decide to connect, on your instruction;
- professional advisers — lawyers, accountants, insurers, auditors, financing counterparties — bound by confidentiality;
- state bodies, regulators, law enforcement, and tax authorities where the law requires or permits the disclosure;
- current or potential purchasers, investors, merger partners, and similar counterparties during a corporate transaction, under confidentiality protections.
Transfers across borders
Storage and processing can take place in the United Arab Emirates and in any other country where we or our vendors operate. Your data may therefore move to jurisdictions whose privacy rules differ from the ones at home.
Where the applicable law calls for it, we put transfer safeguards in place — contractual clauses, adequacy mechanisms, or other lawful instruments. By handing us personal data and using the Services, you accept that this kind of cross-border handling can happen as set out here.
How we protect it
We keep reasonable administrative, technical, and organisational protections in place against unlawful or unauthorised access, loss, misuse, alteration, and disclosure. Among them: access controls and role-based permissions, logging, encryption in transit and — where fitting — at rest, vetting of suppliers, incident-response procedures, and internal confidentiality rules.
No online transmission and no storage system is ever fully secure, so absolute security is not something we can promise. On your side, use strong credentials, grant access sparingly, configure permissions with care, and keep your own security controls in order while working with the Services.
Should a breach touch personal data under our responsibility, we act as the applicable law and our contracts require — including sending notifications where the law makes them mandatory.
How long we keep it
Data stays with us only as long as the purpose behind it reasonably demands: running the Services, keeping business records, meeting legal duties, settling disputes, enforcing contracts, preventing fraud, and defending our rights and those of others.
The exact period depends on the kind of data, the plan in use, technical and operational needs, and legal or contractual requirements. Once the need has passed, the data is deleted, anonymised, or moved to secure archives, in line with the law and our retention practice.
Your rights and how to use them
Depending on the law that applies and the context of the processing, you may ask to see the personal data we hold on you, have inaccurate or incomplete entries corrected, request deletion, restrict certain processing, receive a portable copy, object to particular uses, and take back consent where consent is what the processing rests on. A complaint to the competent supervisory authority is also open to you.
To use any of these rights, write to support@sufox.com or use the contact routes shown on the Website. Expect us to ask for whatever is needed to confirm your identity and pin down what the request covers. Where our only role is processor for a customer, we may pass your request to that customer, or help them handle it as our contract with them provides.
Exercising a right never leads to worse treatment from us. At the same time, these rights are not unlimited: legal exceptions, technical constraints, and duties to keep certain records can narrow what a request can achieve.
Marketing messages
Where the law permits, we send product news, announcements, event invitations, offers, and the like. Stepping away from non-essential marketing takes one click on the unsubscribe link in any message — or a note to us — at any moment.
An opt-out stops promotion, not administration: messages needed to run your account, deliver the Services, answer support requests, or satisfy a legal duty continue to arrive.
Cookies and similar tools
Together with third-party partners we rely on cookies, local storage, pixels, SDKs, and comparable techniques: they keep the Website and Services running, remember your choices, power analytics, improve features, and — where relevant — assist marketing. The full picture, including the cookie types involved and the controls you have over them, lives in our Cookie Policy.
Links to other services
Links inside the Website and Services can lead to outside sites, documentation libraries, helpdesks, messaging channels, file-storage tools, and similar destinations. How those third parties treat privacy, security, and content is outside our control and responsibility — read their privacy notices before using them or switching on an integration.
Children
The Services are built for business use, not for children, and we never knowingly gather children’s data in breach of the law. If you think a child has passed personal data to us unlawfully, tell us and we will take the appropriate steps.
When this policy changes
Legal, technical, and business developments can require revisions to this Privacy Policy. A materially revised version goes up on the Website, sometimes accompanied by notice inside the Services or by email where that fits. The “effective date” shown at the top tells you when the version you are reading took effect.
How to reach us
Questions about this Privacy Policy or our handling of personal data go to KeepFlow L.L.C-FZ at support@sufox.com, or by post to Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.