Privacy Policy
Last Updated: June 2026
This Privacy Policy explains how Brain Station 23 Ltd ("we," "us," or "our") collects, uses, and protects information in connection with the NeuraFlow Agentic AI Platform ("Platform").
Data Controller: Brain Station 23 Ltd, Plot 2, Road 12, Block E, Banani, Dhaka 1213, Bangladesh. Email: neuraflow@brainstation-23.com.
1. Information We Collect
- Conversation data: messages exchanged between your customers or employees and NeuraFlow agents, as configured by your organisation.
- Business configuration data: agent settings, knowledge base content, workflow configurations, and integration credentials you provide.
- Usage data: logs, analytics, and performance data generated by the Platform.
- Account data: contact information and billing details for your organisation.
2. How We Use Information
- To deliver the Platform services as configured by your organisation.
- To maintain, improve, and secure the Platform.
- To provide analytics, execution traces, and conversation intelligence features.
- To comply with legal obligations.
- To detect and prevent abuse, fraud, or policy violations.
3. What We Do NOT Do
- We do not use your conversation data to train or fine-tune any machine learning model.
- We do not sell your data to third parties.
- We do not build advertising profiles from Platform usage.
- We do not share your data with other customers.
4. Data Isolation
Each customer deployment is isolated at the tenant level. Your data never touches another customer's environment. Role-Based Access Control (RBAC) ensures that only authorised users within your organisation can access your configuration and conversation data.
5. BYOK: Bring Your Own Key
Customers who use the BYOK option connect their own LLM API key. In this configuration, conversation data is sent directly to your chosen provider and does not pass through NeuraFlow's model layer. You pay your provider directly and retain full control of that data relationship.
6. Data Sharing
We may share data with: your organisation (as the data controller), third-party service providers who support the Platform under appropriate data processing agreements, and legal or regulatory authorities when required by law.
7. Data Retention
Conversation data is retained for the period agreed in your service contract. Retention policies are configurable to match your compliance requirements. Upon termination, data is available for export for a defined period before deletion.
8. Security
- TLS 1.2+ encryption in transit.
- AES-256 encryption for stored credentials.
- Tenant-level data isolation.
- Request logging and security event monitoring.
- RBAC with organisation-level permission management.
9. Your Rights
Depending on your jurisdiction, you or your customers may have rights to access, correct, delete, or port personal data. Contact neuraflow@brainstation-23.com to make a data request. We will respond within the timeframes required by applicable law.
10. International Transfers
The Platform is operated from Bangladesh, with infrastructure in cloud regions selected to match your deployment requirements. International data transfers are conducted in compliance with applicable data protection regulations, including GDPR where applicable.
11. Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Platform with reasonable notice before changes take effect.
12. Contact
For privacy questions or data requests, contact us at neuraflow@brainstation-23.com.