RapidWorkflow Privacy Policy

Effective date: 1 June 2026

This policy explains how RapidWorkflow collects, uses and protects personal information when you visit our website, contact us, book a call, receive business communications from us or use our services.

1. Who we are

RapidWorkflow is a trading name of Rapid Documents Ltd. In this policy, “RapidWorkflow”, “we”, “us” and “our” refer to Rapid Documents Ltd trading as RapidWorkflow.

Our registered/contact address is: 199 Field End Road, C/O Lotuswise, Eastcote, Pinner, Middlesex, England, HA5 1QZ.

For privacy or data protection questions, please contact us at: info@rapidworkflow.ai.

We are the controller of personal information that we collect and use for our own business purposes, such as operating our website, responding to enquiries, managing sales conversations and providing our services. Where we process personal information only on behalf of a client as part of a client project, we may act as a processor and the client will normally be the controller.

2. What this policy covers

This policy applies to personal information processed in connection with:

  • visits to rapidworkflow.ai and any related landing pages;
  • enquiries, contact forms, emails and discovery calls;
  • Calendly or other appointment bookings;
  • business-to-business outreach and follow-up communications;
  • proposals, contracts and client project delivery;
  • use of workflow automation, AI, CRM, analytics and operational tools in our business.

This policy does not cover third-party websites that we may link to. Those websites will have their own privacy policies.

3. Personal information we collect

Information you give us

We may collect information that you provide when you complete a form, email us, book a call, speak with us or become a client. This may include:

  • name, job title, company name and business contact details;
  • information about your business, workflows, documents, systems and operational challenges;
  • meeting notes, call recordings or transcripts where these are used and you are informed;
  • proposal, contract, billing and payment-related information;
  • any other information you choose to send to us.

Information we collect automatically

When you use our website, we may collect limited technical and usage information such as IP address, device/browser type, pages visited, referral source, date/time of visit and website interaction data. This may be collected through analytics, cookies or similar technologies.

Information from third-party sources

For business-to-business outreach and sales, we may collect or verify business contact information from publicly available sources, business directories, LinkedIn, company websites, professional databases or approved lead/data providers. This may include your name, role, company, work email address, business phone number, company website and relevant business context.

4. How we use personal information

We use personal information to:

  • operate, maintain and improve our website and services;
  • respond to enquiries and manage discovery calls;
  • understand a business’s workflow, admin and document-related bottlenecks;
  • prepare proposals, quotes and project recommendations;
  • deliver workflow mapping, automation, client portal, dashboard and AI workflow projects;
  • manage client relationships, support requests, billing and administration;
  • send relevant business-to-business communications about our services where lawful;
  • monitor campaign performance and manage opt-outs;
  • protect our business, systems, clients and users from misuse, fraud or security threats;
  • comply with legal, tax, accounting and regulatory obligations.

5. Our lawful bases for processing

Depending on the situation, we rely on one or more of the following lawful bases under UK data protection law:

  • Contract: where processing is needed to take steps before entering into a contract or to provide services under a contract.
  • Legitimate interests: where we have a reasonable business interest in operating and improving our services, responding to business enquiries, carrying out B2B marketing, managing client relationships, preventing misuse and developing our business, provided those interests are not overridden by individual rights and interests.
  • Consent: where we ask for consent, for example for certain cookies, newsletters or call recordings where consent is required.
  • Legal obligation: where we need to process information to comply with legal, tax, accounting or regulatory requirements.

Where we rely on legitimate interests for business-to-business outreach, we aim to contact people in a relevant professional context, provide clear information about who we are, and make it easy to opt out.

6. Business-to-business outreach and marketing

We may contact business contacts by email or other professional channels where we believe our services may be relevant to their organisation or role. We do not intend to send marketing emails to personal consumer addresses such as Gmail, Yahoo, Hotmail or similar personal accounts.

If you receive a marketing or outreach email from us and do not want to hear from us again, you can use the unsubscribe or opt-out option in the message or contact us directly. We will maintain a suppression list to help ensure we do not contact you again for marketing purposes.

We may use outreach and CRM tools to manage campaigns, verify business contact details, monitor replies, track opt-outs and improve the relevance of our communications.

7. AI, automation and workflow tools

As a workflow automation business, we may use AI and automation tools to help us provide and improve our services. For example, we may use these tools to summarise notes, classify enquiries, draft workflow documentation, analyse process information, generate draft proposals or support client project delivery.

Where we use AI or automation tools, we aim to use them responsibly. We do not use AI outputs as a substitute for appropriate human review where decisions may affect people or where accuracy is important. We also aim to avoid putting unnecessary or highly sensitive personal information into AI tools unless required and appropriate safeguards are in place.

If we use AI or automation tools as part of a client project, the scope and responsibilities should be set out in the relevant proposal, contract or data processing terms.

8. Cookies and analytics

Our website may use essential cookies and similar technologies needed for the site to function. We may also use analytics tools to understand how visitors use the site and how we can improve it.

Where required, we will ask for consent before setting non-essential cookies. You can also control cookies through your browser settings. If you disable cookies, some parts of the website may not work properly.

9. Who we share personal information with

We may share personal information with trusted suppliers and service providers where needed for the purposes described in this policy. These may include:

  • website hosting and domain providers;
  • email and calendar providers;
  • CRM, outreach, analytics and scheduling tools;
  • workflow automation, AI and software development tools;
  • payment, accounting, bookkeeping and professional advisers;
  • technical delivery partners or freelancers working under appropriate confidentiality arrangements;
  • regulators, public authorities or legal advisers where required by law or to protect our rights.

We do not sell personal information.

10. International transfers

Some of the tools and service providers we use may process or store personal information outside the UK. Where this happens, we will take steps designed to ensure that appropriate safeguards are in place, such as adequacy regulations, standard contractual clauses, the UK International Data Transfer Agreement/Addendum, or other lawful transfer mechanisms.

11. How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purposes described in this policy. The exact period depends on the type of information and our relationship with you.

As a general guide:

  • enquiry and sales records may be kept for as long as needed to manage the enquiry and for a reasonable follow-up period;
  • client project records may be kept for the duration of the relationship and then for a reasonable period afterwards for legal, accounting, support and audit purposes;
  • marketing suppression records may be kept for as long as needed to respect opt-out requests;
  • financial and transaction records are usually kept for at least six years where required for tax and accounting purposes;
  • technical logs and analytics data may be kept for shorter operational periods unless needed for security or legal reasons.

Where we no longer need personal information, we will delete, anonymise or securely archive it where appropriate.

12. Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, password protection, multi-factor authentication, secure cloud services, staff/freelancer confidentiality obligations and appropriate supplier selection. No system can be guaranteed to be completely secure, so we encourage clients and users to avoid sending unnecessary sensitive information unless requested through an appropriate secure process.

13. Your rights

Under UK data protection law, you may have rights in relation to your personal information, including the right to:

  • access a copy of the personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • ask us to delete your information in certain circumstances;
  • ask us to restrict or object to certain processing;
  • ask for portability of information in certain circumstances;
  • withdraw consent where we rely on consent;
  • object to direct marketing at any time.

To exercise your rights, please contact us using the details in section 1. We may need to verify your identity before responding.

14. Complaints

If you have concerns about how we use your personal information, please contact us first so we can try to resolve the issue.

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. The ICO website is www.ico.org.uk.

15. Changes to this policy

We may update this privacy policy from time to time. The latest version will be posted on our website and will show the effective date at the top. If we make material changes, we may take additional steps to bring them to your attention where appropriate.

16. Quick summary

RapidWorkflow collects and uses business contact, website, enquiry and client project information so we can operate our website, respond to enquiries, manage business-to-business outreach, provide workflow automation services and comply with our legal obligations. We use trusted tools and suppliers, do not sell personal information, and give individuals the ability to opt out of marketing and exercise their data protection rights.

RapidWorkflow is a trading name of Rapid Documents Ltd | Privacy Policy | Effective 1 June 2026