ReviewFlow

Privacy Policy

Effective date: 11 August 2026

This Privacy Policy explains how ReviewFlow handles personal data when businesses use our platform, when their customers respond to feedback requests and when prospective businesses submit pilot or business enquiries.

1. Who we are

ReviewFlow is a customer feedback, reputation and service-recovery platform operated by Kayus Systems, a Nigerian registered business (CAC BN 9759219). ReviewFlow helps businesses request feedback from genuine customers, collect ratings and comments, manage service-recovery cases and monitor reputation activity.

Privacy or data-protection enquiries can be sent to [email protected].

2. Information we process

Depending on how ReviewFlow is used, we may process:

  • Business account information, such as an account holder's name, email address, business name, category, review destination and service configuration.
  • Pilot and business-enquiry information, such as a contact name, business name, sector, location, email address, phone number if supplied, approximate customer-interaction volume, a recovery-audit score if attached, and the business challenge entered in a pilot or enquiry form.
  • Customer contact information supplied by a business using ReviewFlow, such as a display name, phone number, email address and external customer reference.
  • Feedback information, including ratings, comments, response timestamps and public-review-link click activity.
  • Service-recovery information, such as case status, follow-up notes, issue categories and actions recorded by the business in response to customer feedback.
  • Messaging and delivery information, such as request status, delivery status, provider message identifiers, attempts and related timestamps.
  • Technical and security information needed to operate and protect the service, including session information, audit records, request metadata and diagnostic information.

ReviewFlow is not designed to collect diagnoses, treatment details, medical records, payment-card data in feedback fields, or other unnecessary sensitive information. Businesses must not place such information in customer, feedback or recovery records.

3. Why we process information

We process information to:

  • provide, secure and maintain ReviewFlow;
  • authenticate users and manage business workspaces;
  • evaluate and respond to founding-pilot applications and business enquiries;
  • send customer feedback requests on behalf of businesses;
  • collect and display customer feedback to the relevant business;
  • create and manage service-recovery workflows;
  • calculate product and usage metrics needed to operate the service;
  • prevent abuse, investigate failures and maintain auditability;
  • provide support and service communications; and
  • meet applicable legal, regulatory or contractual obligations.

4. Businesses, customers and data-protection roles

A business using ReviewFlow decides which genuine customers it adds, what customer contact information it supplies and when it sends a feedback request. For personal data that ReviewFlow handles solely on that business's instructions, the business is generally the data controller and Kayus Systems acts as a service provider or processor.

Kayus Systems may act as a controller for information it needs for its own account administration, security, fraud prevention, legal compliance and service operations. Each business remains responsible for having an appropriate lawful basis for the customer information it uploads and for respecting applicable customer rights.

ReviewFlow does not use a customer's rating to decide whether the customer receives a configured legitimate public-review opportunity.

5. WhatsApp, Meta and service providers

ReviewFlow is designed to support business messaging through the WhatsApp Business Platform. When messaging is enabled, information reasonably required to deliver a message may be transmitted to Meta, WhatsApp and approved messaging or solution providers used to provide that function.

We also use service providers for hosting, databases, transactional email, application monitoring, source-code operations and secure backup/recovery. Providers receive only the information reasonably necessary for the service they perform and may process it under their own applicable terms and privacy notices.

6. When we disclose information

We may disclose personal data:

  • to service providers that help us operate ReviewFlow;
  • to Meta, WhatsApp and approved messaging providers when required for messaging;
  • to payment providers when paid billing functionality is used;
  • to professional advisers, regulators or authorities when reasonably necessary to comply with law, protect rights or investigate abuse;
  • in connection with a lawful merger, acquisition, restructuring or transfer of the ReviewFlow business, subject to appropriate safeguards.

We do not sell personal data to advertisers.

7. Data minimisation and retention

We aim to collect and retain only information relevant to the purposes for which ReviewFlow is provided. Customer contact information and its linked feedback-request, feedback and service-recovery history are normally retained for 12 months after the last relevant customer activity.

After that period, inactive customer records and their interaction history are deleted when they are no longer required. If a customer has opted out of future messaging, ReviewFlow may retain only the minimum suppression information needed to prevent accidental re-contact while the business remains active, while removing other customer identifiers and old interaction history.

Audit records, in-app notifications and processed messaging-webhook records are normally retained for 12 months. If a business closes its ReviewFlow account, its tenant data is scheduled for deletion after a 30-day grace period, unless a documented legal, security, dispute or investigation requirement requires preservation for longer.

Founding-pilot applications and direct business enquiries are handled separately from tenant customer records. We retain that correspondence only as long as reasonably necessary to evaluate or respond to the enquiry, manage legitimate business communications and meet applicable legal or dispute-handling needs.

A valid deletion request may be handled earlier where applicable. Encrypted disaster-recovery backups follow a separate short technical lifecycle and may contain an older copy until those backup artifacts expire. If an older backup is restored, completed privacy deletions are re-applied before normal operation resumes. Billing or tax records, if commercial billing is introduced, may have a separate legally required retention period.

8. Security

We use administrative and technical safeguards designed to protect ReviewFlow data, including authenticated access, tenant-scoped authorization, secure session handling, encrypted transport where supported by our infrastructure, audit controls, restricted production credentials, monitoring and recovery procedures.

No internet service can guarantee absolute security. Businesses using ReviewFlow are also responsible for protecting credentials and limiting access to authorised personnel.

9. Cookies and similar technologies

ReviewFlow uses essential cookies or similar technologies needed for authentication, session management, security and core application functionality. ReviewFlow does not use those technologies to decide whether a customer receives a public-review opportunity.

10. Your choices and rights

Depending on applicable law and your relationship with ReviewFlow, you may have rights to be informed, request access or correction, request deletion or restriction, object to certain processing, request data portability, withdraw consent where consent is relied upon, and make a complaint to the relevant supervisory authority.

If you received a ReviewFlow message from a business, the fastest way to exercise rights concerning that business's customer records is usually to contact the business directly. You may also contact us at [email protected], and we will assist as appropriate.

11. International processing

ReviewFlow and its service providers may process information in countries different from the country where a user or customer is located. Where required, we use appropriate contractual, technical or organisational safeguards for cross-border processing.

12. Children

ReviewFlow is a business service and is not directed to children. We do not knowingly invite children to create ReviewFlow business accounts. Businesses are responsible for ensuring their use of customer contact information is appropriate and lawful for their customers.

13. Nigerian data-protection framework

ReviewFlow is operated from Nigeria and is designed to follow applicable Nigerian data-protection requirements, including the Nigeria Data Protection Act 2023, alongside other laws that may apply to a particular business or customer relationship.

14. Changes to this policy

We may update this Privacy Policy as ReviewFlow develops or as legal and operational requirements change. Material updates will be published on this page with a revised effective date.