Privacy Policy
Last Updated: 02/04/2026
This policy remains in effect as written until we update it. Any changes will be reflected on this page.
The short version
BurjFlow finds and fixes the constraints limiting your revenue. Doing that well requires data — yours, and in some cases your customers'. We treat both with the same discipline we bring to your funnel: nothing collected without reason, nothing shared without cause, nothing kept longer than it's useful. This policy explains what we collect, why, and what control you have over it.
1. Who this applies to
This policy covers:
- Visitors to burjflow.com
- Prospects who submit forms, book calls, or contact us
- Clients engaged for CRO, sales, or growth advisory work
- Individuals whose data we process on a client's behalf while delivering that work
If you're a client, this policy governs BurjFlow's own use of your business data. Where we process your customers' data on your behalf — inside your CRM, your funnel, your sales systems — a separate Data Processing Agreement (DPA) governs that relationship, and this policy explains our role and safeguards at a high level.
2. What we collect
Information you give us directly
Name, email, company, role, phone number — submitted via forms, discovery calls, or email. Business context shared during scoping or diagnostic work: revenue figures, conversion data, funnel metrics, CRM exports, sales call recordings, and similar performance data you provide so we can find the constraint.
Information collected automatically
IP address, browser, device type, pages visited, referral source, and general usage patterns via analytics and cookies. Interaction data from scheduling tools (e.g., call bookings, timestamps).
Information from third-party tools
Data synced from CRM, analytics, or sales engagement platforms you connect us to for the engagement. Data from integrated tools (e.g., Calendly, HubSpot, Google Analytics) necessary to deliver the work.
We do not collect more than the engagement requires. If a data point doesn't inform a decision, we don't ask for it.
3. Why we collect it
- Respond to inquiries, schedule calls — To take steps at your request before entering a contract
- Deliver CRO, sales, or growth engagements — Performance of a contract
- Analyze site usage, improve our own funnel — Legitimate interest
- Send relevant follow-ups or case studies — Legitimate interest / consent, where required
- Comply with tax, legal, or regulatory obligations — Legal obligation
We do not use your data to train third-party AI models, and we do not sell it. Full stop.
4. Cookies and tracking
We use cookies and similar technologies to: understand how visitors use burjflow.com, measure which channels and pages perform, support essential site functionality. You can control cookies through your browser settings. Blocking them may limit some site functionality but won't affect your ability to contact us.
5. Who we share data with
We share data only where it's operationally necessary:
- Service providers — hosting, analytics, CRM, scheduling, and communication tools that support our operations, bound by confidentiality and data-processing terms
- Subprocessors engaged for client work — disclosed on request or in your DPA
- Legal or regulatory authorities — only when required by law, subpoena, or to protect BurjFlow's rights
- Successor entities — in the event of a merger, acquisition, or asset sale, with notice provided where required
We do not sell, rent, or trade personal data. No exceptions.
6. International data transfers
BurjFlow and its service providers may process data outside your country of residence. Where this involves transfers from the EU/EEA, UK, or other jurisdictions with cross-border transfer restrictions, we rely on appropriate safeguards — including Standard Contractual Clauses — to keep protection intact regardless of where the data sits.
7. Data retention
We keep data only as long as it serves a purpose:
- Prospect data — retained while you're an active lead, deleted or anonymized after a period of inactivity
- Client data — retained for the engagement term plus any period required by contract, tax, or legal obligation
- Site analytics — retained per our analytics provider's standard windows, typically 14–26 months
You can request earlier deletion at any time, subject to legal retention requirements.
8. Security
We apply access controls, encryption in transit, and least-privilege principles to systems holding client and prospect data. No system is unbreakable — we minimize what we hold and control who can reach it, because that's the only honest way to reduce risk. If a breach affects your data, we'll notify you in line with applicable legal timelines.
9. Your rights
Depending on where you're located, you may have the right to:
- Know what personal data we hold about you
- Access, correct, or update it
- Request deletion
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent, where consent is the basis for processing
- Opt out of the sale or sharing of personal data (we don't sell data, so this is moot — but it's your right regardless)
- Not be discriminated against for exercising any of the above
To exercise any of these, contact us at neil@burjflow.com. We'll respond within the timeframe required by applicable law — typically 30 days. If you're in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
10. Children's privacy
BurjFlow is a B2B service. We do not knowingly collect data from anyone under 16. If we learn we have, we'll delete it.
11. Changes to this policy
We'll update this page as our practices evolve. Material changes will be reflected with a new effective date. Continued use of our site or services after an update constitutes acceptance of the revised policy.
12. Contact
Questions, requests, or concerns about this policy:
neil@burjflow.com