Privacy Policy
Last updated: 26 July 2026
Katteli Inc. (“Katteli,” “we,” “us,” or “our”)
This Privacy Policy explains how we collect, use, share, and protect personal information when you use TestFlows™ Machine websites, APIs, clients, and related services (the “Services”). See also our Terms of Service.
This Policy covers account, billing, and control-plane data. It does not
govern data inside your virtual machines or workloads (“Customer Content”).
You are the controller of Customer Content. For a processor relationship under
a Data Processing Addendum, contact privacy@testflows.com.
1. Information we collect
- Account: email (required), account identifiers and status, authentication tokens. Standard accounts do not require a legal name, postal address, or phone number.
- Service use: session and machine metadata, usage and credit events, API and control-plane logs (including IP addresses), and abuse-prevention signals.
- Website / client: IP address, user-agent, language, referral URLs, and cookies or similar technologies (see Section 6).
- Communications: support correspondence and transactional email; optional marketing email if you opt in (you may unsubscribe anytime).
- Payments: card numbers and payment credentials are collected by Stripe. When Managed Payments applies, Stripe (via Link) is merchant of record. We receive billing metadata (customer and order identifiers, amounts, tax, payment status), not your full card number. See Stripe’s privacy policy.
The Services are for business use by adults and are not directed to minors. We do not knowingly collect personal information from anyone under 18.
2. How we use information
We use personal information to provide, operate, secure, and improve the Services; authenticate users; prevent abuse and fraud; meter usage and bill; send transactional messages; respond to support; comply with law and enforce our Agreement; and, with consent where required, send product updates or marketing.
We do not sell personal information or share it for third-party marketing.
Where GDPR or UK GDPR applies, we process data under contract, legitimate interests (security, fraud, product improvement), legal obligation, and consent (optional marketing and non-essential cookies). You may object to processing based on legitimate interests where that right applies.
3. How we share information
We share personal information with:
- Service providers that help us run the Services (payments, email delivery, hosting, observability), under confidentiality and data-protection terms;
- Stripe / Link for checkout, tax, receipts, disputes, and Managed Payments;
- Authorities or others when we believe disclosure is reasonably necessary to comply with law, enforce our Agreement, or protect rights and safety;
- A buyer or successor in a merger, acquisition, or asset sale, with notice where required;
- Parties you direct us to share with.
4. International transfers
We are a Canadian company. To operate the Services we may process and store information outside your country, including in the European Union and other places where we or our providers operate. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses).
5. Retention
We retain personal information while your account is open and as needed to provide the Services. After closure, we generally retain account and billing history for legal, tax, accounting, fraud, and dispute purposes. Where law requires erasure, we will anonymize the account email and revoke tokens after verification, while retaining de-identified usage and billing records as permitted. Logs and security data are kept for a limited operational period unless needed longer for an investigation or legal hold.
6. Cookies
We use essential cookies and local storage for authentication, security, and load balancing. Optional analytics on marketing pages, if enabled, are for aggregate traffic only. Where required, we ask consent before non-essential cookies. Browser controls may block cookies; blocking essential cookies may break login.
7. Security
We use administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is completely secure. If a personal-data breach requires notice under applicable law, we will notify affected users and regulators as required.
8. Your rights
Depending on your location, you may have rights to access, correct, delete or anonymize, object to or restrict processing, portability, withdraw consent, opt out of marketing, and lodge a complaint with a supervisory authority. These rights may be limited by law. We will not discriminate against you for exercising privacy rights available to you.
To exercise rights, email privacy@testflows.com from the email on your
account. We may verify your identity and will respond as required by law.
9. Changes
We may update this Policy by posting a revised version and changing the “Last updated” date. Material changes will be notified by email or prominent notice where required.
10. Contact
Katteli Inc.
Privacy: privacy@testflows.com
Legal: legal@testflows.com
Website: https://testflows.com