Legal
Privacy Policy
Effective July 15, 2026 · Last updated July 15, 2026
This policy explains what personal information Workflow Reliance handles and why. We wear two hats: we are the controller of our own site and account data, and a processor operating on our clients’ behalf. Section 2 explains which one applies to you — and, if you received a message sent through the platform, where to direct your requests.
1. Introduction, Entity, and Scope
This Privacy Policy (“Policy”) explains how Workflow Reliance LLC, a Colorado limited liability company doing business as “Workflow Reliance” (“Workflow Reliance,” “WR,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information.
This Policy applies to:
- Our website, https://www.workflowreliance.com and its subdomains (the “Site”); and
- The Workflow Reliance platform — the custom operations and automation software we build and operate for our business customers (the “Platform,” and together with the Site, the “Services”).
What Workflow Reliance is. WR is a software platform and independent software vendor (ISV). We design, build, and operate custom operations platforms for service businesses (“Clients”). Depending on the build, a Client’s platform may include AI-assisted communications: it drafts messages with the assistance of artificial intelligence, routes each draft through a human approval gate before anything is sent, delivers approved messages by email and SMS, captures replies, and helps book meetings — alongside scheduling, reporting, and related back-office automation. WR bills Clients under an order form or statement of work.
Important — please read Section 2 first. WR wears two different hats depending on whose data is involved, and your rights and the correct point of contact depend on which hat applies. If you are a person who received an email or text message that was sent using the Platform, the message was sent by, and on behalf of, one of our Clients — not by WR for its own purposes — and Section 2 explains where to direct your requests.
2. Our Two Roles: Controller and Processor
Data-protection laws distinguish between a controller (the party that decides why and how personal data is processed) and a processor (the party that processes personal data on behalf of, and under the instructions of, a controller). WR acts in both capacities, depending on the data:
(a) WR as Controller. For personal information relating to our own Site visitors and our Client account holders — for example, contact-form submissions, marketing inquiries, Client administrator and user account details, and billing relationships — WR is the controller. This Policy governs that processing, and you may exercise your rights directly with WR under Section 8.
(b) WR as Processor. For end-recipient data that WR processes on a Client’s behalf — the names, email addresses, mobile/phone numbers, message content, engagement events (such as opens, clicks, replies, and delivery/consent records) of the candidates, prospects, customers, and contacts our Clients message through the Platform — WR is a processor (a “service provider” under U.S. state law). In this context:
- The Client is the controller and the “sender of record” for all messages sent through the Platform. The Client decides who is contacted, what is sent, and on what legal basis, and the Client is responsible for obtaining any required consent.
- WR processes this data only on documented instructions from the Client, under a data processing agreement / service-provider terms, and for the purpose of operating the Services.
- Direct end-recipient rights requests to the relevant Client. If you received a message through the Platform and want to access, correct, delete, opt out of, or otherwise exercise rights over your personal information, please contact the business that sent you the message (the sender of record). WR will assist and support that Client in responding to your request as required by law and our contract, but WR does not independently determine outcomes for data it processes on a Client’s behalf. If you contact WR directly, we will, where we can identify the responsible Client, forward your request to that Client and/or direct you to them.
3. Categories of Personal Information We Collect
3.1 Website Visitor Data (WR as Controller)
- Contact-form fields you submit — such as name, business email address, company, and the content of your message or inquiry.
- Cookies and analytics data — see Section 10.
- Technical/device data — IP address, browser type, device and operating-system information, referring/exit pages, and similar log data generated when you use the Site.
3.2 Client Account Data (WR as Controller)
- Account and contact details for Client administrators and users — name, business email address, job title, login credentials, and account configuration.
- Billing information — plan, billing contact, and payment status. Payments are processed by Stripe. WR does not store full payment card numbers; card data is handled by Stripe under its own security and compliance controls, and WR receives only limited billing metadata (e.g., last four digits, card brand, transaction status).
3.3 End-Recipient Data Processed on Clients’ Behalf (WR as Processor)
Data our Clients load into or generate on the Platform about the people they contact, including:
- Contact identifiers — names, email addresses, and phone/mobile numbers.
- Message content — drafts and sent messages, and captured replies.
- Engagement events — sends, deliveries, opens, clicks, reply status, meeting bookings, and similar activity.
- Consent records — the consent source, the exact disclosure text shown at the point of capture, timestamps, and opt-out (STOP) status, retained to demonstrate consent and to enforce opt-outs and suppression.
WR does not sell this data and does not use it for WR’s own marketing. WR processes it solely to provide the Services to the Client that controls it.
4. How We Use Personal Information
Depending on the applicable role above, we use personal information to:
- Provide, operate, and maintain the Services — including AI-assisted drafting and classification, the human approval workflow, message delivery by email and SMS, reply capture, scheduling, and reporting.
- Authenticate users and secure the Services — account management, access control, fraud and abuse prevention, and monitoring for reliability and security.
- Process billing — via Stripe (WR-as-controller Client data only).
- Provide customer support — responding to inquiries and troubleshooting.
- Communicate with Clients and Site visitors — service and administrative messages and, where permitted, information about the Services.
- Comply with legal obligations and enforce our terms — including recordkeeping for consent/opt-out compliance, responding to lawful requests, and protecting our rights and those of our Clients and users.
- Improve and develop the Services — using aggregated, de-identified, or Client-authorized data, consistent with our contracts and applicable law.
We rely on AI subprocessors (see Section 6) to assist with drafting and classification. Every AI-generated message passes through a human approval gate before it is sent — the Platform does not autonomously send messages that a human has not approved.
5. SMS / Mobile Messaging
This section applies to text (SMS) messaging sent through the Platform. WR is onboarded with our SMS provider (Twilio) as the ISV and registers each Client’s 10DLC brand and campaign; the Client is the sender of record and the party responsible for obtaining consent from each recipient.
Mobile information is never shared for marketing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
- SMS consent is never sold or shared. We do not sell, rent, or share SMS/mobile opt-in data or consent, and we do not disclose it to third parties except the subprocessors strictly necessary to deliver the messages you have asked to receive (for example, the SMS carrier/aggregator that transmits the message) or as required by law.
- Consent. Recipients receive text messages only after opting in (for example, by submitting a mobile number through a Client web form or application containing SMS-consent language, or by giving verbal consent during a phone screen or intake conversation). Consent to receive texts is not a condition of applying for or obtaining any job or service.
- Message frequency varies (messaging is generally conversational and low-volume).
- Message and data rates may apply.
- Opt-out and help. Reply STOP to any message to unsubscribe; you will receive a single confirmation and no further messages. Reply HELP for help, or contact the sender of record. Opt-outs are honored promptly and the number is suppressed.
For the full text-messaging terms and the specific consent language used by a given Client, see that Client’s SMS Terms and Privacy Policy at the point of opt-in.
6. How We Share Personal Information; Subprocessors
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws. We disclose personal information only as described here.
Service providers / subprocessors. We use trusted vendors (“subprocessors”) to provide the Services. Each is bound by contract to protect personal information, to use it only to perform services for WR (or, where WR is a processor, for the Client), and not for their own purposes. The key subprocessors are:
| Subprocessor | Purpose |
|---|---|
| Twilio | SMS message delivery and 10DLC carrier registration |
| Amazon Web Services (AWS), incl. Amazon SES | Cloud hosting/infrastructure and outbound email delivery |
| Supabase | Application database and authentication |
| Anthropic | AI-assisted message drafting and classification |
| Stripe | Billing and payment processing |
| Inngest | Background job orchestration and workflow execution |
| Cronofy | Calendar and meeting scheduling |
| Microsoft (Microsoft Graph) | Capturing replies from Client email inboxes, where the Client connects one |
| Cloudflare | Website delivery, DNS, and security |
We may update our subprocessors from time to time; where WR acts as a processor, changes are governed by the data processing terms with the relevant Client.
Other disclosures. We may also disclose personal information: (i) to comply with applicable law, legal process, or lawful government requests; (ii) to enforce our agreements and terms, or to protect the rights, property, safety, or security of WR, our Clients, users, or the public; (iii) to professional advisors (e.g., lawyers, auditors) under confidentiality; and (iv) in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and, where required, notice.
7. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
- Client account and billing data (WR as controller): retained for the life of the account and as needed thereafter for legal, tax, accounting, and dispute-resolution purposes.
- End-recipient data (WR as processor): retained according to the Client’s instructions and our contract with the Client. On a valid deletion request, or on expiration/termination of the Client relationship, we delete or return the Client’s data as instructed, subject to legally required retention (for example, consent and opt-out records may be retained where necessary to demonstrate compliance and to continue honoring opt-outs).
- Suppression/opt-out records may be retained as long as necessary to ensure we continue to honor a recipient’s opt-out.
When personal information is no longer needed, we delete it or de-identify it using reasonable measures.
8. Your Privacy Rights
Which law applies and who to contact. Your rights depend on where you live and on WR’s role (Section 2). If your personal information was processed by WR on a Client’s behalf (end-recipient data), please direct your request to the Client that sent you the message; WR will assist that Client. For data where WR is the controller (Site visitors and Client account data), contact us at privacy@workflowreliance.com.
8.1 California (CCPA/CPRA) and similar U.S. state laws
Subject to applicable law and verification, you may have the right to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom it is disclosed;
- Delete personal information we hold about you;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information — note that WR does not sell or share personal information, so there is nothing to opt out of;
- Limit the use and disclosure of sensitive personal information — some information we process (such as account login credentials, and the content of emails or texts where the business is not the intended recipient) may constitute “sensitive personal information” under the CPRA. We use and disclose such information only for the limited purposes permitted under CPRA § 7027(m) (to provide, secure, and support the Services as directed) and not to infer characteristics; these uses do not trigger the right to limit, but you may still submit a limitation request to privacy@workflowreliance.com (or, for end-recipient data, to the sender-of-record Client); and
- Non-discrimination — we will not discriminate against you for exercising your rights.
You may use an authorized agent to submit a request. We will verify requests before acting on them.
Appeals. If we deny a rights request, you may appeal by emailing privacy@workflowreliance.com with the subject line “Rights Appeal.” We will respond within the timeframe required by applicable law (several U.S. state privacy laws — e.g., Virginia, Colorado, and Connecticut — provide a right to appeal a denied request).
8.2 EEA / UK (GDPR and UK GDPR)
Where GDPR or UK GDPR applies, and subject to their conditions, you may have the right to: access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing, and the right not to be subject to solely automated decisions producing legal or similarly significant effects. You may also withdraw consent at any time (without affecting prior processing) and lodge a complaint with your supervisory authority.
Lawful bases. Where WR is a controller, we rely on: performance of a contract (to provide the Services and manage accounts); legitimate interests (to secure, operate, and improve the Services, and for limited business communications, balanced against your rights); consent (where required, e.g., certain cookies/marketing); and legal obligation (to comply with law). Where WR is a processor, the Client determines and is responsible for the lawful basis.
How to exercise your rights. Email privacy@workflowreliance.com (or, for end-recipient data, the sender-of-record Client). We respond within the timeframes required by applicable law.
9. Security
We maintain reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction — including encryption in transit, access controls and authentication, network and application security, and use of reputable infrastructure and subprocessors. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
10. Cookies and Tracking Technologies
The Site uses cookies and similar technologies:
- Essential/strictly necessary — required for the Site and Platform to function (e.g., authentication, security, load balancing). These cannot be disabled through our consent controls.
- Analytics/performance — help us understand how the Site is used so we can improve it.
You can control non-essential cookies through your browser settings and, where offered, through our cookie banner or preference controls. Blocking some cookies may affect Site functionality. We honor applicable browser-based opt-out signals (such as Global Privacy Control) where required by law.
11. Children’s Privacy
The Services are intended for businesses and are not directed to children, and we do not knowingly collect personal information from anyone under the age of 16 (or the minimum age required by applicable local law). If you believe a child has provided us personal information, contact privacy@workflowreliance.com and we will take appropriate steps to delete it.
12. International Data Transfers
WR is based in, and processes personal information in, the United States, and our subprocessors may process data in the United States and other countries. If you access the Services from outside the United States, you understand that your personal information may be transferred to and processed in the United States and other jurisdictions, which may have different data-protection laws than your own. Where required for transfers of EEA/UK personal data, we and/or our Clients rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms.
13. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above and post the new version on the Site. If changes are material, we will provide additional notice as required by law (for example, by email to Client account contacts or a prominent notice on the Site). Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.
14. Contact Us
Workflow Reliance LLC (Workflow Reliance)
- Privacy inquiries and rights requests: privacy@workflowreliance.com
- Legal notices: legal@workflowreliance.com
- Support: support@workflowreliance.com
- Mailing address: 1312 17th Street, Unit 2514, Denver, CO 80202
This Policy is governed by the laws of the State of Colorado, without regard to its conflict-of-laws principles, to the extent permitted by applicable law. If you received a message through the Platform, remember that the sender of record is our Client; please contact that business to exercise rights over the personal information they control, and WR will assist as described in Section 2.
