Trinetix FLOW (Functional Learning and Operational Workflows) — for
the browser extension and embed runtime.
Version 1.0 as of August 1, 2026
Trinetix Inc. a Wyoming corporation, with its principal place of business at 30 N Gould St STE 4722, Sheridan, WY 82801, USA and its affiliated companies (if any) (herein together referred to as “Trinetix”, “Company”, “we”, or “us”) welcomes you. We provide our customers (the “customer”) and their users with our Trinetix FLOW browser extension and embed runtime (together, the “FLOW runtime”).
This Privacy Notice explains how we as a data controller process personal data in connection with FLOW runtime, as well as its general overview when the FLOW runtime operates on the web applications used within your organization (the “organization”) – our customer.
We act as data controller with respect to business-contact data through direct communications, limited operational data that the FLOW runtime generates to run and bill the service, such as aggregate token-usage counts and masking counts; this operational data contains no page content and no free text.
We act as a data processor when we engaged by our customer – data controller. As data controller, our customer determines the purposes and means of processing personal data. If you are a user of one of our customer’s services, please refer to the applicable customer and its privacy notice for information about how your personal data is collected, used, and managed within FLOW runtime. If you have any questions regarding this Privacy Notice, please refer to the Contact Information section below.
When you contact us as a representative of our customer, when our customer provides you with access within their tenant you become a user (the “user”, “you”).
The FLOW runtime displays in-application guidance, including guided tours, tooltips, pop-ups, a launcher, a resource center and, where enabled, an artificial-intelligence assistant, on top of the web applications you use. All such content is configured by our organization through the FLOW runtime. Your organization determines which guidance is published and whether artificial-intelligence features described below are enabled.
“Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations.
Please note that we as a data controller DO NOT collect personal data that is, by its nature, particularly sensitive. Sensitive personal data refers to information such as genetic data, biometric data, data revealing racial or ethnic origin, information about political opinions, sex life, sexual orientation, religion or other beliefs, data concerning health, trade union membership or other sensitive information. Trinetix does not sell personal data and does not use it for advertising purposes.
When we act as a data processor, the FLOW runtime may process the following data:
Data the FLOW Runtime Collects
The only free-text value transmitted through analytics is the text you enter into the Resource Center search box. It is limited to two hundred characters, is not further masked, and is transmitted only if you use the search function; it also helps identify searches that returned no results.
“Device type” is recorded as a category (desktop, tablet, or mobile) derived from your window width; exact screen dimensions are not transmitted.
Data the FLOW Runtime Does Not Collect
The FLOW runtime is designed to minimize the information it collects. Specifically:
Service Requests. To load content and verify eligibility, the FLOW runtime transmits a public site key or a signed session token. The signed session token encodes the relevant system and environment, is never transmitted as separate fields, and is used to derive your organization on the server. For eligibility checks, the runtime additionally transmits a stable internal identifier derived from your system and organization; this identifier is not personal, and no personal data is transmitted.
The browser extension additionally transmits the website’s domain (the origin only, not the full URL) to verify whether your organization has published guidance for that website and requests the list of registered domains on starting. To perform these functions, the extension operates on the websites you visit; on websites for which your organization has published guidance, it removes that website’s content-security-policy response headers (including any report-only policy) so the guidance can load.
Information Stored Solely on Your Device. Tour progress (enabling the “resume where you left off” function) and “already shown” and frequency-cap flags are stored locally within your browser and are not transmitted. The anonymous identifiers described above are likewise stored locally but, as noted, are transmitted together with analytics data.
Page URLs Used for AI Features. To generate assistance, the full-page URL — including any query string and fragment — is transmitted and stored within the AI “content gap” record. Analytics data, by contrast, retains only the domain and path. Because a query string may contain sensitive values, you should avoid including personal data in URLs on pages where the AI assistant is enabled.
How the AI Assistant Works. The AI assistant is available only if your organization has enabled it and set up an AI key within your organization’s FLOW tenant. It starts working in one of two ways:
In both cases, the assistant also sends the page address (URL) and the CSS selector of the relevant on-screen element. This helps it identify the right guidance to give you.
Sending Information to the AI Model. When AI features are used, the masked question or error text is sent to an AI model provider to generate a response. The specific model and key are set up separately for each organization. To help find the most relevant guidance, the masked question is also turned into a numeric vector (a string of numbers) by the platform’s embeddings provider, such as Microsoft Azure OpenAI. In both cases, masking is applied before any information is sent.
How Sensitive Information Is Masked. Sensitive information is masked before any request reaches an AI model or is stored.
On your device, email addresses, long number sequences (seven digits or more), and recognizable patterns for secrets, payment-card numbers, and social security numbers are masked first.
On the server, which is the authoritative source, phone numbers, any keywords on a denylist your organization has defined, and any other patterns your organization has specified are additionally masked.
If this server-side masking cannot be applied for any reason, no request is sent to the AI model and no data is stored. This is a “fail-closed” approach: when in doubt, nothing goes out.
Please note that the page URL and the element selector are intentionally not masked. Please see the relevant section for more detail.
What Is Stored on the Server for AI Purposes (Where Enabled). Where AI features are enabled, the following is stored:
When we act as a data controller, we collect and process your personal data for a variety of purposes. These purposes are tailored to meet our business needs and to ensure that we fulfill our obligations to you in a lawful and transparent manner.
First, we use your data to communicate with you about FLOW runtime. This includes informing you about services. We also use your data to respond to inquiries or requests and provide updates regarding any changes that could affect you.
We process data of our customers and vendors to manage and administer contractual relationships, ensuring that obligations are met and communications are clear throughout the duration of our collaboration.
We also process personal data to comply with legal obligations, such as tax, compliance or regulatory requirements, and to protect the vital interests of our users, partners, or the public.
When we act as a Data Controller, we rely on several lawful bases for processing personal data depending on the nature of the data and the purpose of processing.
We may receive some personal data from third parties. The amount of data collected, the purposes, and the lawful bases for processing are determined by the respective privacy documents of these parties.
We may share your personal data with a range of recipients to facilitate the delivery of our services and to support the operations of FLOW runtime. These recipients include:
When we act as data controller, we do not make decisions that produce legal effects concerning individuals, or similarly significantly affect them, solely through automated processing. You have the right to opt-out from such processing and, we will provide additional information in case the automated decision-making will be used in connection with your personal data.
As a global Company, it is sometimes necessary for us to transfer your personal data to other countries where Trinetix affiliate companies, customers, or service providers are located, including countries outside the European Economic Area (EEA), such as the United States, Ukraine, and Argentina.
In all cases, we take measures to ensure that your data is protected in accordance with applicable data protection laws. These measures may include:
In cases where none of these mechanisms are available, we will not transfer your personal data to third countries unless an alternative lawful basis is available, and we have ensured that your rights and freedoms are adequately protected.
Where we act as data controller, we ensure that the personal data are not retained longer than necessary in relation to the purpose for which they are processed or to comply with applicable legal obligations, resolve disputes, or enforce our agreements. To ensure compliance with this principle, we define the retention periods applicable to each processing operation. The following elements are considered when determining the retention period: legal obligations; recommendations of supervisory authorities; best practices; our operational needs.
When we act as data processor FLOW runtime keeps analytics events and artificial-intelligence records for as long as your organization’s FLOW tenant and the corresponding system remain active. These records are deleted when your organization’s tenant or that system is deleted, and Trinetix will delete or return them earlier at your organization’s request, ordinarily within one month. Session recordings captured to help author artificial-intelligence knowledge are deleted automatically after sixty days. Because the runtime identifies end-users only by random identifiers, deletion requests are handled at the level of your organization’s data rather than an individual end-user. For more details on data retention please contact your organization.
To protect your personal data, we have implemented comprehensive organizational, technical, and security measures. These include, but not limited to: Strict Content Security Policy, HTTP Strict Transport Security, penetration testing, data encryption in transit and at rest; Access controls to ensure only authorized personnel can access your data; Systems that comply with industry standards and legal requirements.
Please note that FLOW runtime is not designed for, nor intended to be used by children. When we act as a data controller, we do not knowingly collect or process personal data from children under the age of 13, or under the age of 16, depending on the jurisdiction within the European Union (the “EU”) or other applicable regions. If we become aware that child’s personal data has been provided to us, please contact us using the details provided in the Contact Information section.
Your principal privacy rights include the right to be informed about collection and use of personal data, right to access your personal data, right to rectification, right to erasure, right to restrict processing, right to object to processing, right to data portability, right to complain to a supervisory authority and right to withdraw consent.
While you may have the rights described above, they may not always apply in full and can be subject to certain legal conditions or exceptions.
To exercise your rights, please see Contact Information section this is free of charge. However, we reserve the right to charge a reasonable fee where requests are unfounded or excessive, due to their repetitive nature.
When you send us a request to exercise a right, you are asked to specify as far as possible the scope of the request, the type of right exercised, the personal data processing concerned, and any other useful element, to facilitate the examination of your request. In addition, in case of reasonable doubt, you may be asked to prove your identity.
We will do our best to answer to your requests within in one (1) month or as required by applicable laws and regulations. In case we are complex or many requests the answer may take us long than you might expect. If an extension to the mentioned timeline is necessary, we will inform you and provide the reasons for the delay.
For California and other U.S. states residents please see Notice below. If you are a resident of other jurisdiction, please reach out to us via Contact Information section for more information about your rights or to submit a request.
Please contact us if you have any queries or concerns about our use of your personal data (see below Contact Information section).
If your query is not satisfied or believe your right have been violated, you can submit a complaint to your local data protection authority:
Any compliant to your local data protection authority does not affect your right to pursue legal remedies or seek redress through the courts.
We may update this Privacy Notice periodically to reflect changes in our data practices, legal requirements, or for other operational reasons. Any modifications to this Privacy Notice will be posted and the “last modified” or “latest version” date at the beginning of this document will be updated accordingly.
We encourage you to review this Privacy Notice regularly to stay informed. For significant changes that impact how your personal data is handled, we will make reasonable efforts to notify you directly via email (if we have your contact information) or through other appropriate communication channels.
For any questions described in this Privacy Notice, please contact:
Name: Trinetix Inc.
Postal address: 30 N Gould St STE 4722, Sheridan, WY
82801, USA
Phone: +1 305-833-6680
Email for privacy inquiries:
requests.legal@trinetix.com
Data Protection Officer: Taras Lytovchenko, email:
requests.legal@trinetix.com
Version 1.0 as of July 31, 2026
In addition to the abovementioned, if you are a resident of California, you are entitled to specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). These laws provide you with greater transparency and control over the collection and use of your personal data. The following section outlines your rights and our obligations in relation to your personal data.
Your Rights Under the CCPA and CPRA
As a California resident, you have the following rights concerning your personal data:
Submitting a Verifiable Consumer Request
To exercise any of the rights described above, please submit a verifiable consumer request by contacting us through the Contact Information section below. The request must:
Please note that we may not respond to your request if we cannot verify your identity or authority to make the request. All requests must be labeled as “California Resident Request” in the email subject line or clearly marked as such when submitted through other communication channels.
Verification Process
Upon receiving your request, we will take steps to verify your identity. This may include asking for additional information to confirm that the requestor is the individual whose personal data we have collected or their authorized representative. We will use the personal data provided in a verifiable consumer request solely to verify the requestor’s identity or authority to make the request.
Response Timeline
We will acknowledge your request within 10 business days and aim to respond to verifiable consumer requests within 45 days from the date of receipt. If we require more time (up to an additional 45 days), we will inform you of the reason for the delay and the extension period in writing.
Responses will be delivered electronically, unless you request another format. We will provide the requested information free of charge unless your request is excessive, repetitive, or manifestly unfounded, in which case we may charge a reasonable fee or refuse to comply with your request.
Applicability of Other State Laws
While this section pertains to California residents under the CCPA and CPRA, we are committed to complying with privacy regulations in other US states. If, for example, you are a resident of another state with applicable data protection laws (such as for example Colorado, Connecticut, Montana, Oregon, Texas, Utah, Virginia, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Rhode Island, or Kentucky), please reach out to us to exercise your rights under those state-specific privacy laws.
For more information about your rights or to submit a request, please see our Contact Information section in the Privacy Notice.
Version 1.0 as of August 1, 2026
This document provides information regarding the sub-processors and/or (sub)contractors engaged by the Trinetix Inc. (the “Company”) that may process personal data when the Company acts as a data processor under applicable privacy and data protection laws, including, but not limited to the General Data Protection Regulation (the “EU GDPR”), the California Consumer Privacy Act (the “CCPA”), the California Privacy Rights Act (together with the CCPA, “CPRA”).
| Entity Name | Service Description | Location | Notes |
|---|---|---|---|
| Microsoft Azure | Hosts the FLOW databases, cache and application services. | EU (West Europe region) | This applies to all FLOW customers. |
| Anthropic | Provides the Claude artificial-intelligence model that generates assistant responses. | US | This applies only where customer has enabled the artificial-intelligence assistant. |
| Microsoft Azure OpenAI | Converts the masked question into a numeric vector so that relevant guidance can be found. | EU (Sweden Central region) | This applies only where customer has enabled the artificial-intelligence assistant. |