Skip to content
Privacy

Privacy policy

This policy explains how Lovelyflows AB collects, uses, and protects personal data in connection with our AI customer-support platform.

Who we are

Lovelyflows AB is a company registered in Sweden. We operate an AI customer-support platform accessible at lovelyflows.ai, app.lovelyflows.ai, api.lovelyflows.ai, and cdn.lovelyflows.ai. References to 'we', 'us', or 'Lovelyflows' in this policy refer to Lovelyflows AB. Our contact address for data-protection matters is admin@lovelyflows.ai.

Our roles under GDPR

The General Data Protection Regulation (GDPR) distinguishes between a controller, who determines the purposes and means of processing, and a processor, who processes data on the controller's behalf. Both roles apply to Lovelyflows depending on whose data is involved. Lovelyflows as controller. We determine how to process personal data relating to our own clients: the organisations, users, and members who hold accounts on app.lovelyflows.ai, and visitors who interact with our marketing site at lovelyflows.ai. We process this data on the legal bases described in the sections below. Lovelyflows as processor. When a client embeds the Lovelyflows widget on their website, their end-visitors interact with an AI agent hosted by us. In that context the client is the data controller and Lovelyflows is the processor acting on the client's instructions. The client is responsible for ensuring their own website's privacy notice covers the widget and its data flows. We process end-visitor data only to deliver the service and as directed by the client.

Data we collect about clients and their team members

When a client organisation is created on our platform we collect and store: - Organisation details: name, slug identifier, subscription plan, billing interval, Stripe customer identifier, and locale preference. - User accounts: name, email address, hashed password (where applicable), OAuth token identifiers (where social login is used), email-verification status, and account creation timestamps. - Team memberships: which users belong to which organisation and their assigned role (owner, admin, editor, or member). - Session data: IP address, user-agent string, and session token for authenticated sessions. - Billing events: payment status, subscription changes, and invoicing metadata received from Stripe. We collect this data because it is necessary to perform the service contract (Article 6(1)(b) GDPR) and, where applicable, to comply with legal obligations such as invoicing requirements (Article 6(1)(c) GDPR).

End-visitor data processed on behalf of clients

When visitors interact with a client's embedded chat widget, the following data is collected and stored as processor on the client's behalf: - Contact identifiers: name and email address, where provided by the visitor via the pre-chat form or shared during a conversation. - Device and context signals: country derived from IP address, browser name, operating system, and device type. The raw IP address is not stored. - Conversation content: the full text of messages exchanged between the visitor and the AI agent, including AI-generated responses and any conversation summary generated to support ongoing handling. - Interaction metadata: timestamps, chat status (active, resolved, abandoned), resolution classification, customer-satisfaction score and comment where submitted, and language detected. - Knowledge queries: the search queries issued internally when the AI retrieves information from the client's knowledge base, stored in a search log to support quality improvement. Clients determine the purposes for which this data is collected and must ensure their own privacy notices cover it. For each client organisation, Lovelyflows records the lawful basis the client declares, as controller, for this end-visitor processing. The basis currently declared for all clients is legitimate interest (Article 6(1)(f) GDPR) in providing customer support to their own visitors. Lovelyflows processes end-visitor data only on the basis the client has declared, consistent with our role as processor described above under 'Our roles under GDPR'.

AI processing and model providers

To deliver AI-generated responses, Lovelyflows sends conversation content to large-language-model providers via Vercel AI Gateway. The model providers currently in use include xAI (for conversational and reasoning processing) and OpenAI (for fast classification tasks and text embeddings). These providers process the data under their own terms; Vercel AI Gateway acts as an intermediary. The list of providers may be updated as the platform evolves; we will reflect any material changes in this policy. Conversation content sent to model providers is limited to what is necessary to generate a response in that turn. We do not send raw visitor data to model providers for training purposes. AI-generated responses may be inaccurate or incomplete. Clients configure the scope of topics the AI addresses and bear responsibility for reviewing that configuration. A human escalation path (handoff to a team member) is available and can be triggered by the visitor or the AI agent.

How we use data we control

For data processed as controller (client and team member data, and marketing-site visitor data), our purposes and lawful bases are: - Providing and operating the platform: performance of the contract with the client (Article 6(1)(b)). - Authentication and security: legitimate interest in protecting accounts and preventing fraud (Article 6(1)(f)), and performance of contract. - Billing and invoicing: legal obligation under applicable accounting law (Article 6(1)(c)) and performance of contract. - Transactional communications (account verification, password reset, service notifications): performance of contract and legitimate interest in operational communication (Article 6(1)(b) and (f)). - Platform analytics and quality improvement (PostHog): legitimate interest in understanding how the platform is used to improve it (Article 6(1)(f)). Analytics on the marketing site require your consent (Article 6(1)(a)), which you can grant or withdraw via the cookie consent banner. - Error monitoring and logging (Sentry, Logtail, BetterStack): legitimate interest in maintaining platform reliability (Article 6(1)(f)).

Sharing and subprocessors

We share personal data with the following categories of subprocessors as necessary to deliver the service. Each subprocessor is bound by a data-processing agreement and appropriate contractual safeguards. Hosting and infrastructure: Vercel (hosting, edge functions, blob storage, AI gateway), Neon (PostgreSQL database), Upstash (Redis for rate limiting). Payment processing: Stripe (subscription billing, metered usage billing). Stripe processes payment card data under its own PCI-DSS compliance and acts as an independent controller for payment data. Communication: Resend (transactional email delivery), Knock (in-app and push notifications). Background processing: Trigger.dev (background job queue), Svix (outbound webhook delivery to client integrations). Monitoring and observability: Sentry (error tracking), Logtail and BetterStack (log management). Analytics: PostHog (product analytics, subject to consent on the marketing site). Security: Arcjet (bot protection and rate limiting at the network edge). Real-time collaboration: Liveblocks (presence and cursor features in the dashboard). AI model providers (via Vercel AI Gateway): xAI, OpenAI. We do not sell personal data to third parties.

International transfers

Lovelyflows AB is established in Sweden and operates within the EU/EEA. Several of the subprocessors listed above are established in the United States. Where we transfer personal data outside the EU/EEA, we rely on appropriate safeguards, such as standard contractual clauses (SCCs) approved by the European Commission, or on adequacy decisions where applicable. We assess whether each subprocessor provides an adequate level of protection before transferring data. You may request information about the specific safeguards in place for a particular transfer by contacting us at admin@lovelyflows.ai.

Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, and loss. These measures include encryption in transit (TLS), encryption at rest where supported by our hosting providers, role-based access controls, rate limiting, bot protection, and structured security monitoring. No system is completely secure. If you become aware of a security issue affecting your data, please report it promptly to admin@lovelyflows.ai.

Retention

Client account data (user accounts, organisation records, billing history) is retained for the duration of the active service agreement and for as long as required by applicable law thereafter, including Swedish accounting requirements. End-visitor conversation data processed on behalf of clients is subject to automated retention windows applied platform-wide: chats and their transcripts are automatically deleted 180 days after the last activity on that chat. If a member of the client's team deletes a conversation from the dashboard, it is permanently deleted 30 days after that deletion. A visitor's contact record (name, email address, and associated device and context signals) is automatically deleted once no conversations remain for that visitor and the visitor has had no activity for 30 days. A client's organisation admin or owner can also permanently erase a visitor's contact record and all of that visitor's conversations at any time directly from the dashboard, ahead of the automated windows above. This erasure is immediate and irreversible. Upon termination of a client agreement, their data is deleted or anonymised in accordance with our standard off-boarding process, subject to any overriding legal retention obligations.

Your rights

If you are located in the EU/EEA or the United Kingdom, you have the following rights in relation to personal data we process as controller: - Right of access: to obtain confirmation of whether we process your data and to receive a copy. - Right to rectification: to have inaccurate data corrected. - Right to erasure: to request deletion where the data is no longer necessary, consent has been withdrawn, or processing is unlawful. - Right to restriction: to request that processing be restricted in certain circumstances. - Right to data portability: to receive your data in a structured, machine-readable format where processing is based on consent or contract. - Right to object: to object to processing based on legitimate interests, including profiling. - Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. To exercise any of these rights, contact us at admin@lovelyflows.ai. We will respond within the timeframe required by applicable law (typically one month). If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

Cookies

We use two categories of cookies on our marketing site (lovelyflows.ai). Strictly necessary cookies are required for the site to function and are always active. They include session management and security cookies. No consent is required for these. Analytics cookies (PostHog) allow us to understand how visitors use the site, which pages are most visited, and where improvements can be made. These cookies are only set if you click 'Accept analytics' in the cookie banner. You may decline or withdraw consent at any time using the cookie settings on this page. The dashboard (app.lovelyflows.ai) uses only strictly necessary cookies to maintain authenticated sessions.

Changes and contact

We may update this policy as the platform evolves or as regulatory requirements change. The date at the bottom of this page reflects the most recent revision. We will notify active clients of material changes by email. Contact details for questions about this policy, exercising your rights, or reaching our data-protection contact are below.

Last updated: 31 July 2026

For questions about this policy or to exercise your rights, contact us at admin@lovelyflows.ai or by post to Lovelyflows AB, Sweden.