Abilix Digital ← Back to xM-Flow
Legal

Privacy Policy

Effective date: 31 May 2026  ·  Last updated: 31 May 2026  ·  Applies to: xM-Flow and xM-Slab

This Privacy Policy explains how Abilix Digital ("Abilix", "we", "us" or "our") collects, uses, stores, shares and protects information when you use the xM-Flow platform, the xM-Slab application, our websites and related services (together, the "Services"). We built xM-Flow for stone benchtop fabrication businesses, so much of the data in the platform is operational business data that you and your team enter. We treat that data as belonging to you, and we describe below exactly what we do with it.

Contents
  1. Who we are
  2. Information we collect
  3. How we use information
  4. AI features and Alex
  5. Our lawful basis
  6. How we share information
  7. Service providers
  8. Where data is stored
  9. Security
  10. How long we keep it
  11. Your rights and choices
  12. Cookies and tracking
  13. Children
  14. Changes to this policy
  15. How to contact us

1 Who we are

xM-Flow is a product of Abilix Digital, a company based in Rolleston, Canterbury, New Zealand. For the operational business data you load into the platform, you (the customer organisation) are the data controller and we act as your data processor, handling that data on your instructions to provide the Services. For account, billing and website data, we act as the controller. The contact details for any privacy question are in section 15.

2 Information we collect

Account and contact information

When you create an account or a workspace, we collect your name, work email, company name, role, phone number (optional) and the password hash needed to sign you in. For paid plans we collect billing contact details and tax information.

Business data you enter

The platform stores the operational data you and your team create, including customers and leads, quotes, jobs and work orders, slab and offcut inventory, suppliers, calendar and scheduling entries, installation and templating records, finance records, documents and file references, and internal notes. This is your data.

Communications content

If you connect messaging channels such as WhatsApp, webchat or email, we process the messages exchanged with your customers through those channels so the conversation and the AI agent can function inside the platform.

Location and check-in data

If you use the templater GPS check-in feature, the platform processes the device location of the team member at the moment of check-in, compared against the job's registered address, to confirm arrival and build productivity metrics. This is an operational feature controlled by your organisation and its team members.

Usage and device data

We automatically collect technical data such as IP address, browser and device type, pages and features used, timestamps, and diagnostic logs. We use this to keep the Services secure, stable and improving.

Payment data

Card and payment details are collected and processed by our payment provider (Stripe). We do not store full card numbers on our systems. We keep a record of your plan, invoices and payment status.

3 How we use information

We do not sell your personal information, and we do not use the business data inside your workspace to advertise to you or to third parties.

4 AI features and Alex

xM-Flow includes an AI agent called Alex, which uses large language models provided by Anthropic to understand requests and act inside your workspace, such as answering questions, drafting messages, opening jobs or running reports. When you use an AI feature, the relevant content needed to fulfil the request is sent to the AI provider to generate a response.

What this means in practice. AI providers process the request to return a result and, under our agreements, do not use your content to train their general models. Alex acts within the permissions of the signed in user. AI output can be wrong or incomplete, so important actions should be reviewed by a person before they are relied upon.

6 How we share information

We share information only as needed to run the Services:

7 Service providers

We use a small set of trusted providers to deliver the Services. Each is bound by contract to protect your data and to use it only to provide their service to us.

ProviderPurpose
Cloud hosting and application infrastructureRunning the platform and websites
Managed database (Postgres)Storing your workspace records
AnthropicPowering the Alex AI agent
StripePayment and subscription processing
WhatsApp Business and email delivery providersCustomer messaging channels you choose to connect

We can provide the current list of providers on request. We update it as the Services evolve.

8 Where data is stored

xM-Flow is designed as a bridge, not a vault. The cloud database stores your structured records and small metadata such as file names, references, thumbnails, sizes and timestamps.

Your files stay with you

Where your plan and setup use the local storage model, the original files (photos, PDFs, invoices, packing slips, drawings) are kept on your own company network or local server. The cloud platform stores only the reference and a small thumbnail needed to display and link the file. This keeps your large files under your control and within your own infrastructure.

International transfers

Some providers in section 7 operate servers outside New Zealand. Where personal information is transferred overseas, we take reasonable steps to ensure it is protected by comparable safeguards, consistent with the Privacy Act 2020.

9 Security

We protect information using measures appropriate to its sensitivity, including encryption in transit, hashed credentials, access controls, tenant isolation so one organisation cannot see another's data, role based permissions, and audit logging of sensitive actions. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to respond promptly to any incident.

10 How long we keep it

We keep your workspace data for as long as your account is active. After you close your account, we retain data for a limited period to allow recovery and export, then delete or anonymise it, except where we must keep certain records (for example invoices) to meet legal, tax or accounting obligations. You can request earlier deletion as described in section 11.

11 Your rights and choices

Subject to applicable law, you can:

If you are an end user whose data was entered by a customer organisation (for example, you are a customer of a fabricator that uses xM-Flow), please contact that organisation first, since they control that data. We will help them respond.

12 Cookies and tracking

Our websites and app use cookies and similar technologies that are necessary to sign you in, keep your session secure, remember preferences, and understand basic usage so we can improve the Services. You can control cookies through your browser settings. Blocking essential cookies may stop parts of the platform from working.

13 Children

The Services are built for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will remove it.

14 Changes to this policy

We may update this policy as the Services and the law change. When we make material changes, we will update the date above and, where appropriate, notify you inside the platform or by email. Continuing to use the Services after a change means you accept the updated policy.

15 How to contact us

For any privacy question, request or complaint, contact us at hello@abilixdigital.com. We are based in Rolleston, Canterbury, New Zealand. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of New Zealand at privacy.org.nz.