1. Introduction
ImpactFlow is an enterprise software-as-a-service (SaaS) platform built for organizations that deliver development, humanitarian, conservation, and research programs. Typical customers include:
- Non-governmental organizations (NGOs)
- Governments and public agencies
- Conservation organizations
- Foundations and philanthropic partners
- Development partners and implementing agencies
- Humanitarian organizations
- Research institutions
The platform enables teams to plan and deliver work across:
- Project and program management
- Monitoring and evaluation (MEAL)
- Field operations
- Surveys and forms
- Reporting and dashboards
- AI-assisted analysis
- Workflow automation
- Offline mobile data collection
By creating an account, installing ImpactFlow Field, or using our services, you acknowledge this Privacy Policy. Organization administrators remain responsible for how their workspace configures collection of beneficiary and field data under applicable law and donor requirements.
2. Information We Collect
Information users provide
When you register, join a workspace, or use ImpactFlow features, you or your organization may provide:
- Name
- Email address
- Phone number
- Organization name and type
- Job title and role
- Password (stored only as a secure hash — never in plain text)
- Profile photo
- Survey responses and form submissions
- Beneficiary, household, and community records (as configured by your organization)
- Project, program, indicator, and MEAL information
- Uploaded documents, evidence files, and attachments
Automatically collected information
To operate, secure, and improve the service — including the mobile app — we may automatically collect:
- Browser type and version
- Device type and model
- Operating system
- IP address
- Crash logs and diagnostic data
- Usage analytics (feature usage, performance)
- Authentication and session logs
- API request logs
- Device identifiers used for field-device registration and sync
- Offline sync metadata (timestamps, conflict markers, payload sizes)
Location data
GPS or approximate location is collected only when an organization enables location capture for surveys, field registrations, or evidence geotagging, and when the user grants device permission. Location is not collected continuously in the background for advertising.
Photos and camera
Camera and photo library access are used for evidence collection and documentation (for example attaching images to field records). ImpactFlow does not access the camera or photo library without an explicit user action and the required device permission.
Files
Organizations may upload attachments such as reports, spreadsheets, PDFs, and media. These files are stored in association with the customer tenant and governed by that organization’s access controls.
3. How Information Is Used
We use information to provide and operate ImpactFlow, including:
- Authentication and account security
- Workspace and tenant creation
- Strict tenant isolation between organizations
- Reporting, dashboards, and exports
- Notifications (in-app and email)
- Mobile and web synchronization
- Security monitoring and abuse prevention
- AI assistance features (when enabled for your plan)
- Customer support
- Platform reliability and product improvement
- Billing, invoicing, and subscription management
- Legal compliance and responding to lawful requests
4. AI Services
ImpactFlow includes optional AI-powered features (for example AI Copilot). Depending on your plan and configuration, AI may assist with:
- Report generation and drafting
- Summaries of program or survey content
- Risk detection and anomaly suggestions
- Workflow suggestions
- Knowledge search across permitted organization content
AI never silently changes organization data. Suggestions and generated text should always be reviewed by authorized users before they are relied upon for donor reporting, decisions, or publication.
We do not sell customer data. Where AI processing uses subprocessors, it is performed under contractual safeguards consistent with this policy and applicable data-protection law.
5. Offline Data Collection
ImpactFlow Field may store survey forms, tasks, and captured responses in encrypted local storage on the device while offline. When connectivity is restored, data synchronizes to your organization’s workspace over HTTPS.
Organizations control their own field data, collector assignments, and retention practices. Users should protect devices with OS-level locks and follow their organization’s field-security procedures.
8. Third-Party Services
Depending on configuration, ImpactFlow may rely on third-party services such as:
- Paystack — payment processing
- Google Play — Android distribution and related platform services
- Google Maps or map providers — when location maps are enabled
- Cloud object storage — file and evidence storage
- Email services (for example Resend / SMTP providers)
- Analytics providers — product telemetry (where enabled)
Each provider maintains its own privacy policy and terms. We encourage you to review those policies. Enabling an optional integration may transmit relevant data to that provider under your organization’s instruction.
9. Security
We apply enterprise SaaS security controls designed to protect customer workspaces, including:
- HTTPS / TLS for data in transit
- Encryption for sensitive secrets and appropriate data at rest
- Password hashing (one-way cryptographic hashes)
- Multi-tenant isolation by organization
- Role-based access control (RBAC)
- Audit logs for sensitive administrative actions
- API authentication (tokens / API keys as configured)
- Hardened cloud infrastructure practices
- Operational backups according to platform policies
No method of transmission or storage is perfectly secure. Organizations should apply least-privilege roles, MFA where available, and sound device hygiene for field staff.
10. Data Retention
Organizations own their program and field data within their ImpactFlow tenant. We retain account and workspace data while a subscription (including trial) remains active and as needed to provide the service.
After cancellation or deletion requests, we delete or anonymize personal data within a reasonable period, subject to legal retention duties, security logs, and backup expiry cycles. Organizations may request permanent deletion of a workspace subject to verification and any contractual notice periods.
11. User Rights
Subject to applicable law (including GDPR and the Kenya Data Protection Act), you may request:
- Access to personal data we hold about you
- Correction of inaccurate personal data
- Deletion of personal data
- Export / portability of personal data
- Restriction of processing
- Objection to certain processing
Organization-controlled beneficiary or MEAL records are typically handled by your organization’s administrator first. You may also contact us at chris@impactflow.space.
12. International Transfers
Customer data may be processed in secure cloud infrastructure located outside your country of establishment where permitted by law. Where required, we use appropriate safeguards (such as contractual clauses and provider certifications) for cross-border transfers.
13. Children
ImpactFlow is an enterprise workplace product and is not directed to children. Users must be at least 18 years old, or authorized employees or contractors of a customer organization acting in a professional capacity.
If organizations collect information about minors as part of program delivery, they are responsible for a lawful basis, consent or parental safeguards, and donor/regulatory compliance.
14. Government Organizations
Government and public-sector customers remain responsible for complying with their own national procurement, classification, retention, and data-protection rules. ImpactFlow provides technical and organizational measures; agencies must configure roles, retention, and field collection settings to meet their mandates.
15. Data Protection
We design ImpactFlow with privacy and security principles aligned to:
- GDPR principles (lawfulness, fairness, transparency, purpose limitation, minimization, accuracy, storage limitation, integrity & confidentiality, accountability)
- Kenya Data Protection Act, 2019
- POPIA-aligned principles of lawful processing and security safeguards
- Industry security best practices for multi-tenant SaaS
Customers (controllers) determine much of the purpose and means of processing program data; StemCloud Technologies acts as a processor / operator for platform hosting except where we determine purposes for our own account and billing data.
16. Policy Updates
We may update this Privacy Policy to reflect product, legal, or operational changes. Material changes will be communicated through the product, email, or a notice on this page. The Last Updated date at the top of this page shows when the policy was most recently revised (17 July 2026).
17. Contact
For privacy requests, security concerns, or data-protection inquiries:
- Company
- StemCloud Technologies
- Support email
- chris@impactflow.space
- Website
- https://impactflow.space
- Support portal
- chris@impactflow.space