Legal

Privacy Policy

Effective: 19 August 2026 · Last updated: 19 August 2026

This policy explains what personal data ChapFlow handles, why we handle it, who we share it with, how long we keep it, and the rights you can exercise under the Personal Data Protection Act, 2022 of the United Republic of Tanzania.

In short

  • ChapFlow is a product of The Site Weavers, which is the data controller behind the platform and the entity that invoices you.
  • We are the data controller for account, billing and website data, and a data processor acting on our customers' instructions for everything inside their workspace.
  • We do not sell personal data, and we do not use customer workspace content to train artificial-intelligence models.
  • Each customer workspace runs on its own separate database, and access is limited by roles, permissions and plan entitlements.
  • You can ask us to access, correct, restrict, erase or stop processing your personal data, and you can complain to the Personal Data Protection Commission.
  • Some of our sub-processors operate outside Tanzania, so we rely on the transfer safeguards required by Part V of the Personal Data Protection Act, 2022.

1. Who we are

ChapFlow is a product of The Site Weavers (https://www.siteweavers.co.tz), a company established in the United Republic of Tanzania. The Site Weavers operates the ChapFlow business operating platform, this website and our related applications and interfaces (the Service), and is the data controller responsible for it. In this policy ChapFlow, we and us mean The Site Weavers.

All ChapFlow subscriptions are contracted, invoiced and collected by The Site Weavers, so that is the name that appears on your invoices, on the payment pages you are sent to, and on your card or mobile-money statement.

  • Data controller: The Site Weavers
  • Registered office: Dar es Salaam, United Republic of Tanzania
  • Data Protection Officer: reachable at support@chapflow.com

We have appointed a Data Protection Officer as required by section 27(3) of the Personal Data Protection Act, 2022 (Cap. 44) (the PDPA), and we maintain registration as a data controller and a data processor with the Personal Data Protection Commission in accordance with Part III of the PDPA and the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023. A copy of our current certificate of registration is available on request.

2. Scope of this policy

This policy applies to personal data we handle when you:

  • visit our marketing website or request a demonstration;
  • create or administer a ChapFlow workspace, or are invited into one as a user;
  • are recorded inside a customer workspace as a contact, lead, employee, supplier or document signatory; or
  • contact our support, sales or security teams.

It does not cover third-party websites or services you reach through ChapFlow, or the independent privacy practices of the integrations you choose to connect. It is read together with our Terms of Service and our Security page.

Alongside the PDPA and its regulations, our handling of personal data is shaped by Tanzanian law of wider application, including the Electronic Transactions Act, 2015 (Cap. 442), the Cybercrimes Act, 2015, the Electronic and Postal Communications Act, 2010, and the record-keeping duties imposed by the Tax Administration Act, 2015 and the Companies Act, 2002.

3. Our two roles: controller and processor

The PDPA distinguishes a data controller, who determines the purpose and means of processing, from a data processor, who processes personal data on a controller's behalf and under its instructions. ChapFlow occupies both positions, and which one applies determines who you should approach to exercise your rights.

Situation Our role Who to contact first
Website visits, demo requests, support enquiries, user accounts, authentication, billing, security logs Data controller Our Data Protection Officer
Records our customers create inside their workspace, CRM contacts, leads, employees, attendance, documents, marketing audiences, uploaded files Data processor for that customer The customer that operates the workspace, as controller

Where we act as processor, we process personal data only to deliver the Service, to keep it secure and available, to provide support at the customer's request, and where Tanzanian law compels us. Our processing is governed by a written contract associating us with the controller, as required by section 27(4) of the PDPA. If you approach us directly about workspace content, we will refer your request to the responsible customer and assist them in answering it, unless the law requires us to respond ourselves.

4. Personal data we collect as controller

Account and identity data

Your name, work email address, organisation name, workspace address, role and permissions, preferred language and time zone, and an optional profile photograph. Passwords are stored only as a one-way hash, never in readable form. If you enable two-factor authentication we store an encrypted secret and your recovery codes. If you sign in through Google or LinkedIn we store the provider name and the identifier that provider assigns to you, not your password with them.

Technical and security data

Internet Protocol (IP) address, browser and device information, session records, timestamps of sign-in and administrative actions, mobile push notification tokens if you use notifications, and metadata about workspace application programming interface (API) keys such as their prefix and last use. We record this to operate the Service, investigate incidents and demonstrate accountability, and we hold it in audit logs described in section 13.

Billing data

Your plan, subscription status, invoices, amounts, currency, add-ons, usage counters and payment references returned by our payment providers. Billing is carried out by The Site Weavers, which holds these records as controller for invoicing, payment collection, credit control and the tax and accounting duties Tanzanian law imposes. We do not receive or store full payment card numbers. Card and mobile-money details are entered on the hosted pages of PayPal or PesaPal, and we neither store payment instruments nor charge you automatically; we issue an invoice and a payment link.

Sales, support and correspondence

The content of demo and contact forms, including your name, email address, role, organisation size and message; support tickets and their attachments; and our correspondence with you. Where a message fails to send, its contents may appear in our application logs so we can recover and deliver it.

Data we do not collect

The Service is not designed to hold, and we do not ask for, national identity numbers, dates of birth, payroll or salary amounts, bank account numbers, genetic data, or continuous location tracking of individuals. We do not buy personal data from data brokers, and we do not operate advertising networks or sell personal data to anyone.

5. Workspace content we process for customers

Our customers decide what to record in their workspace. Acting as their processor, we may hold the following categories of personal data on their behalf. Each customer is the controller of these records and is responsible for having a lawful basis to collect them.

  • Customer relationship records: names, job titles, email addresses, telephone numbers, postal addresses, company tax and registration identifiers, notes, activities, deals and timelines.
  • Location data: addresses attached to companies, contacts and leads, and the latitude and longitude produced when a customer asks us to geocode those addresses for mapping and visit planning.
  • People and human-resources records: employee names and numbers, work email addresses and telephone numbers, job titles, employment dates, working schedules, photographs, emergency contact names, relationships and telephone numbers, leave requests and balances, timesheets, performance goals, reviews, ratings and manager notes, one-to-one notes, documents such as contracts and policies together with acknowledgements, and assigned equipment.
  • Attendance records: clock-in and clock-out times, work dates and corrections. Where a customer connects a compatible attendance terminal, we receive the identifier that the device assigns to an employee, the punch time and direction, and the raw payload the device sends. We do not receive or store fingerprint, face or other biometric templates, which remain on the customer's device.
  • Marketing records: audience membership, campaign recipients and delivery status, opens, clicks, bounces and complaints, unsubscribe events, campaign-source parameters, referring and landing pages, and the IP address and browser string captured with consent and unsubscribe events as evidence of what was recorded and when.
  • Commercial records: quotations, invoices, payment records and, where the customer enables electronic signatures, signatory names, email addresses and signature audit trails.
  • Files and documents uploaded to workspace storage, together with the identity of the uploader and download statistics.
  • Custom fields that a customer defines, which may contain further personal data of the customer's choosing.

We do not use workspace content for our own purposes. We do not mine it for advertising, we do not share it between customers, and we do not disclose it except as set out in section 11.

6. Sensitive personal data

Section 30 of the PDPA prohibits processing sensitive personal data, which includes genetic and biometric data, data concerning health or sex life, data relating to children or offences, financial-transaction or security-related data, and data revealing racial, ethnic, political, religious or philosophical attributes, affiliation or trade-union membership, without the prior written consent of the data subject, subject to limited statutory exceptions.

ChapFlow does not require sensitive personal data in order to work, and no ChapFlow feature asks for it. If a customer chooses to record sensitive personal data in free-text fields, notes, custom fields or uploaded documents, that customer is responsible for obtaining prior written consent and for restricting who in its workspace can see those records. We ask customers not to place sensitive personal data in the Service unless it is genuinely necessary and lawfully consented to.

7. Purposes and lawful bases

Section 5 of the PDPA requires personal data to be processed lawfully, fairly, transparently and securely, collected for explicit, specified and legitimate purposes, kept accurate and up to date, limited to what is necessary, retained no longer than needed, and protected by appropriate technical and organisational measures. We process personal data for the purposes below and for no incompatible purpose.

Purpose Basis on which we rely
Creating and administering your workspace, authenticating users, and delivering the modules on your plan Performance of our contract with you or your organisation
Invoicing, collecting payment, preventing payment fraud, and keeping tax and accounting records Contract, and compliance with Tanzanian tax and company law
Sending service, billing, security and administrative notices you cannot opt out of while you hold an account Contract
Keeping the Service secure and available, rate limiting, audit logging, abuse prevention, incident investigation and backups Our legitimate interest in a secure service, and our security duty under section 27 of the PDPA
Responding to your demo requests, sales enquiries and support tickets Your request, and our legitimate interest in supporting customers
Understanding aggregate product usage so we can improve the Service Our legitimate interest, using aggregated or de-identified data wherever possible
Sending marketing about ChapFlow to people who asked for it, and placing non-essential cookies Your consent, which you can withdraw at any time without charge or explanation
Processing workspace content on a customer's instruction Our processor contract with that customer, who determines the basis
Answering lawful requests from courts, regulators and law-enforcement authorities Compliance with a legal obligation

8. Artificial-intelligence features

ChapFlow includes optional assistive features, Copilot, drafting, summarising, recommendations and route suggestions. We want you to understand exactly what happens when you use them.

  • Where prompts go. When you run an AI action, the instruction and the minimum context needed to answer it are sent over an encrypted connection to the model provider configured for your workspace. Our current providers are OpenAI, Anthropic and Google.
  • What we log. We record the AI action taken, who ran it, the provider and model used, the input submitted, an excerpt of the response, the tokens and credits consumed, and the outcome. This log lets you audit AI use in your workspace and lets us bill credits accurately and investigate faults.
  • Knowledge indexing. If your administrators enable the knowledge base, ChapFlow creates numerical representations (embeddings) of selected workspace content, such as recent text documents and commercial records, so the assistant can find relevant material. When a file is deleted from your workspace, it is removed from the knowledge index.
  • No model training on your content. We do not use customer workspace content to train our own models, and we contract with providers on terms that instruct them not to use content submitted through our accounts to train their general models.
  • Turning it off. AI features are governed by module entitlements and workspace settings. Administrators can disable them, and the rest of the Service works without them.
  • No solely automated decisions. Section 36 of the PDPA gives a data subject the right not to be subject to a decision that significantly affects them taken solely by automated means. ChapFlow AI produces drafts, scores and suggestions for a person to review; it does not make hiring, disciplinary, credit or other significant decisions on its own. Customers must keep a human decision-maker in the loop, and must tell affected individuals and allow reconsideration if they ever configure a workflow that departs from this.

9. Cookies and similar technologies

Under the PDPA, cookies and trackers that can identify a person involve processing personal data, so non-essential ones require your consent on the basis of clear information. Where our website places non-essential cookies we ask first, and you can change or withdraw that choice at any time.

Technology Category Purpose and duration
Session cookie Strictly necessary Keeps you signed in and separates central and workspace sessions. Its contents are encrypted and it expires after a period of inactivity, by default two hours.
Cross-site request forgery token Strictly necessary Protects forms and interactive pages from forged requests. Lasts for the session.
Cookie preference record Strictly necessary Remembers the choice you made in the cookie banner so we do not ask repeatedly. Stored in your browser.
Product analytics Optional Used only with your consent to understand aggregate feature usage. Our marketing website does not run third-party advertising trackers.

Separately, when a ChapFlow customer sends a marketing campaign, the Service can include a tracking image and rewritten links so that customer can measure opens and clicks. That measurement belongs to the sending customer as controller, and its own privacy notice governs it. Customers who publish landing pages using ChapFlow may also add their own code, and are responsible for obtaining consent for anything they add.

You can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from signing in.

10. Marketing communications

We send marketing about ChapFlow only where you have asked for it or have an existing relationship with us and have not objected. Section 35 of the PDPA entitles you to require us to stop processing your personal data for direct marketing, and we honour that without charge. Every marketing message carries an unsubscribe link, and you can also write to our Data Protection Officer. Service messages about your account, billing, security and material changes to these documents are not marketing, and continue while you hold an account.

Where our customers send campaigns through ChapFlow, they must obtain the recipients' consent as required by the PDPA. The Service records consent, its source and its evidence, refuses to send to recipients without a valid consent record, and processes unsubscribes and complaints reported by the delivery provider as a withdrawal of consent.

11. Disclosures and sub-processors

We do not sell personal data and we do not disclose it for anyone else's marketing. We disclose personal data only in the following circumstances.

  • To sub-processors that help us run the Service, under written contracts requiring confidentiality, security measures at least as protective as our own, processing strictly on our documented instructions, and assistance with data-subject requests and breach notification.
  • To your own connected integrations, limited to what that integration needs, and only after an administrator in your workspace authorises the connection.
  • To professional advisers such as auditors and lawyers, under a duty of confidence.
  • To courts, regulators and law-enforcement authorities where we are legally compelled. We assess each request, decline those that are overbroad or unlawful, disclose no more than is required, and tell the affected customer unless we are prohibited from doing so.
  • In a reorganisation, merger or asset sale, where the recipient is bound to protect personal data on terms no less protective than this policy, and where we notify affected customers.

The sub-processors we currently rely on, and what each receives, are listed below. We keep this list current.

Function Provider Personal data involved
Application hosting, databases and backups Our infrastructure provider, identified on request All Service data, encrypted in transit
File and object storage Cloudflare R2 or Amazon Web Services S3, depending on deployment Uploaded files, documents, images and their metadata
Transactional and campaign email Mailgun and the configured mail relay Recipient name and email address, message content, delivery events
Subscription payments PesaPal, PayPal Billing contact details, amounts and payment references; card and mobile-money details go to the provider directly, not to us
Assistive artificial intelligence OpenAI, Anthropic, Google The prompt and the context needed to answer it
Mapping, geocoding and routing Google Maps, OpenStreetMap and its routing service Addresses and coordinates submitted for geocoding or route planning
Push notifications Google Firebase Cloud Messaging, Expo Device push token and notification content
Electronic signatures, where enabled DocuSign Signatory name and email address, document and signature audit trail
Social publishing, where connected Meta (Facebook, Instagram), LinkedIn, X, TikTok, YouTube, Pinterest Connected account identifiers and the content you publish
Single sign-on, where used Google, LinkedIn Name, email address and provider account identifier
Currency exchange rates Open Exchange Rates No personal data

12. Transfers outside Tanzania

Part V of the PDPA restricts transborder flows of personal data. A transfer outside Tanzania is permitted where the recipient country offers protection essentially equivalent to Tanzania's or provides appropriate safeguards, requires a prior evaluation of the necessity of the transfer, and requires a permit from the PDPC.

Several providers in section 11 operate global infrastructure outside Tanzania. Where personal data leaves Tanzania, we:

  • assess in advance whether the transfer is necessary and record that assessment;
  • put contractual safeguards in place with the recipient, obliging it to protect the data to PDPA standards and to allow the necessity of the transfer to be verified afterwards;
  • obtain the permit required by the PDPC before transferring, and follow any guidelines issued by the Minister responsible for information, communication and information technology; and
  • transfer only the minimum personal data needed for the function concerned.

Customers with data-residency obligations should contact us before storing regulated records in the Service, so we can confirm the current hosting arrangements in writing.

13. Retention and deletion

Section 28 of the PDPA requires that personal data be kept in an identifiable form no longer than is necessary. We apply the retention periods below, then delete or irreversibly de-identify the data.

Data How long we keep it
Workspace content and user accounts For as long as the workspace is open, and then as described below
Sign-in sessions Expire after inactivity, by default two hours
Data export packages you generate Deleted automatically seven days after creation
Temporary links to private files Expire by default after one hour
Support-access authorisations Single use, valid for five minutes
Workspace audit and activity logs Kept for the life of the workspace; high-volume system entries are pruned daily
Platform administration audit logs Kept for the life of the account and for any statutory record-keeping period that applies
Workspace suspended for non-payment Retained for 365 days from suspension, then marked eligible for deletion
Before permanent deletion We give 14 days' notice and generate an export package first, so the customer can retrieve its records
Infrastructure backup records 30 days
Invoices, payments and tax records For the period Tanzanian tax and company law requires, generally five years
Marketing consent and withdrawal records Kept while needed to prove that consent was given or withdrawn

When a workspace is deleted, its dedicated database is dropped and the associated central records are purged. Copies may persist briefly in backups and then age out on the schedule above. We may retain the minimum data needed to enforce a legal claim, comply with a statutory duty or resolve a dispute, and we isolate that data from ordinary use.

Administrators can generate a full export of their workspace at any time from Settings → Data & Privacy, and can request permanent deletion of the workspace by contacting us.

14. Your rights

Part VI of the PDPA gives you the following rights, which we honour free of charge:

  • To be informed and to obtain access, to confirm whether we process your personal data, to receive a description of it, the purposes and the recipients, and to be given a copy (section 33).
  • To prevent processing likely to cause you damage or distress (section 34).
  • To stop direct marketing at any time (section 35).
  • Not to be subject to solely automated decisions that significantly affect you, to be told when a decision was taken on that basis, and to require it to be reconsidered (section 36).
  • To rectification, blocking, erasure and destruction of personal data that is inaccurate, out of date, misleading, unlawfully processed or no longer needed, including where you withdraw consent (sections 29 and 38). Where we have disclosed the data to others, we will notify them of the correction or erasure.
  • To restrict processing where it may cause you substantial harm.
  • To withdraw consent at any time, without charge and without giving reasons, where we rely on consent.
  • To compensation for damage suffered through a contravention of the PDPA (section 37).

To exercise a right, write to support@chapflow.com and tell us what you want and which personal data it concerns. We acknowledge requests promptly and aim to respond substantively within 30 days, telling you in advance if a request is complex and needs longer. We may ask for enough information to verify your identity, so that we do not disclose your data to someone else, and we will explain our reasons if an exception under the PDPA means we cannot fully comply.

If your personal data sits in a customer's workspace, for example because you are that organisation's employee, contact or supplier, that organisation is the controller and decides the outcome. Please approach it first. Tell us anyway if you cannot reach it, and we will help route your request.

15. How we protect personal data

Section 27 of the PDPA requires security safeguards appropriate to the state of technology, the cost of implementation, the nature of the data and the risks to data subjects. Each customer workspace runs on its own separate database. Access is controlled by roles, permissions and plan entitlements. Traffic is encrypted in transit, credentials are stored as hashes, and integration tokens and other secrets are encrypted. Sign-in, password reset, API and webhook endpoints are rate limited, administrative actions are recorded in audit logs, and support access to a workspace requires a specific permission, is time-limited, is visible to the workspace, and is logged.

Our Security page sets out these measures in detail, including what we have not yet implemented. No system can be guaranteed impenetrable, so please use strong unique passwords, enable two-factor authentication, grant the least privilege each colleague needs, and review connected integrations periodically.

16. Personal data breaches

We maintain procedures to detect, contain, investigate and record personal data breaches, which include negligent loss and unauthorised alteration, destruction, disclosure, access or processing.

  • As required by section 27(5) of the PDPA, where we are the controller we notify the Personal Data Protection Commission of a security breach affecting personal data without undue delay.
  • Where we act as processor for a customer, we notify that customer without undue delay after becoming aware, give them the information they need to meet their own notification duty, and support their investigation.
  • Where a breach is likely to affect you and we hold your contact details as controller, we will tell you what happened, what data was involved, what we have done and what you should do.

If you believe you have found a security weakness, please report it to support@chapflow.com.

17. Children

ChapFlow is a business tool intended for people aged 18 and over, and we do not knowingly collect personal data from children. The PDPA treats data relating to children as sensitive personal data, and consent must be given by a parent, guardian or other person recognised by law as acting for the child. If you believe a child's personal data has reached us, contact our Data Protection Officer and we will investigate and delete it where required.

18. Changes to this policy

We update this policy when our practices, our sub-processors or the law change. The effective and last-updated dates at the top of the page always show the current version. For changes that materially affect how we handle your personal data, we will give notice by email or in the Service before they take effect, and we will obtain fresh consent where the law requires it. We keep prior versions and will provide one on request.

19. Contact and complaints

Please raise any privacy question or concern with us first. We would rather fix it than have you escalate.

You also have the right to complain to the Personal Data Protection Commission, the authority that supervises the PDPA in Tanzania. Under section 39 of the PDPA the Commission investigates and concludes a complaint within 90 days of receipt, which it may extend by a further period not exceeding 90 days. You can reach the Commission at https://www.pdpc.go.tz. Nothing in this policy limits your right to seek compensation from a court for damage caused by a contravention of the PDPA.