Privacy Policy

Privacy Policy

Client Flow Systems (CFS)

Operated by Calogero Mangione

Website: thecfsagency.com | Email: [email protected]

Last updated: June 2026

1. Introduction

Client Flow Systems ("CFS", "we", "us", or "our"), operated by Calogero Mangione, is committed to protecting the privacy and personal information of all individuals who interact with our website, services, and campaigns.

This Privacy Policy explains how we collect, use, store, share, and protect personal information. It applies to:

        Visitors to our website at thecfsagency.com

        Business clients and partners who engage our services

        Contacts in lead databases provided to us by our clients for campaign purposes

We operate across Australia and the United Kingdom. Where applicable, we comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs), the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Spam Act 2003 (Cth), and the Privacy and Electronic Communications Regulations (PECR).

 

2. What Personal Information We Collect

We may collect the following types of personal information:

        Name, phone number, email address, and business details — from clients, partners, and website enquiries

        Lead contact data — names, phone numbers, and email addresses provided by clients for SMS reactivation campaigns

        Industry and business type — collected via our demo request form to tailor AI demos

        Usage data — IP addresses, browser type, pages visited, and time spent on our website

        Communication data — records of SMS conversations conducted via our AI systems on behalf of clients

        Payment information — invoicing details such as business name and ABN/company number (we do not store card details)

 

3. How We Collect Personal Information

We collect personal information in the following ways:

        Directly from you — when you fill out a contact or demo form on our website, sign a partnership agreement, or communicate with us by email or phone

        From our clients — when clients provide us with lead databases for the purpose of running SMS reactivation campaigns

        Automatically — through cookies and tracking technologies when you visit our website

        Through our AI systems — when contacts respond to SMS campaigns operated on behalf of our clients

 

4. How We Use Personal Information

We use personal information for the following purposes:

        To provide and operate our AI automation services on behalf of clients

        To send SMS communications to lead contacts as instructed by our clients

        To respond to enquiries, demo requests, and communications

        To manage client relationships, invoicing, and account administration

        To improve our website and services

        To comply with legal obligations

We do not use personal data for any purpose other than those set out above without prior consent.

 

5. Legal Basis for Processing (UK/EU)

For clients and contacts in the United Kingdom, our legal bases for processing personal data under UK GDPR are:

        Contract — processing necessary to perform our services under a client agreement

        Legitimate interests — operating our business, improving services, and conducting outreach on behalf of clients where there is a pre-existing commercial relationship

        Legal obligation — where processing is required to comply with applicable law

        Consent — where explicitly obtained, such as via opt-in mechanisms

 

6. SMS Campaigns and Third-Party Lead Data

Where CFS conducts SMS campaigns on behalf of clients, the client acts as the Data Controller and CFS acts as the Data Processor. This means:

        The client is responsible for ensuring the lawfulness of the data provided

        The client confirms that contacts have a pre-existing commercial relationship or have otherwise consented to receive commercial messages

        All SMS messages include a functional unsubscribe mechanism (reply DELETE or similar)

        CFS will honour all opt-out requests immediately and update records accordingly

        CFS will not use client-provided lead data for any purpose other than the agreed campaign

 

7. Sharing of Personal Information

We do not sell personal information to third parties. We may share personal information in the following limited circumstances:

        With technology providers — such as GoHighLevel (CRM/SMS platform), Zapier (automation), and Google (email) — who process data on our behalf under appropriate data processing agreements

        With clients — reporting on campaign performance and contact activity relevant to their leads

        With professional advisers — such as accountants or legal advisers, under confidentiality obligations

        Where required by law — in response to lawful requests from regulatory or law enforcement authorities

All third-party service providers are required to handle personal data in accordance with applicable privacy laws.

 

8. Cross-Border Data Transfers

CFS operates remotely and may process data from outside Australia or the United Kingdom. Where personal data is transferred across borders, we take steps to ensure appropriate safeguards are in place, consistent with:

        Australian Privacy Principle 8 (APP 8) — cross-border disclosure of personal information

        UK GDPR Chapter V — transfers to third countries

By engaging our services, clients acknowledge and consent to the cross-border processing of data as described in this policy and any applicable Data Processing Agreement.

 

9. Data Retention

We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by law. Specifically:

        Client and partner data — retained for the duration of the engagement and for 7 years thereafter for legal and tax purposes

        Lead contact data provided by clients — retained only for the duration of the campaign and deleted or returned within 14 days of campaign completion or termination

        Website usage data — retained for up to 12 months

        SMS conversation records — retained for up to 12 months for quality assurance and dispute resolution purposes

 

10. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

        Right to access — request a copy of the personal information we hold about you

        Right to correction — request that inaccurate or incomplete information be corrected

        Right to deletion — request that your personal information be deleted, subject to legal obligations

        Right to object — object to certain types of processing, including direct marketing

        Right to restrict processing — request that we limit how we use your data

        Right to data portability (UK GDPR) — receive your data in a structured, machine-readable format

        Right to opt out of SMS communications — reply DELETE, STOP, or UNSUBSCRIBE at any time

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

 

11. Cookies and Website Tracking

Our website may use cookies and similar tracking technologies to improve your browsing experience and analyse website traffic. Cookies used may include:

        Essential cookies — necessary for the website to function

        Analytics cookies — to understand how visitors use our site (e.g. Google Analytics)

        Marketing cookies — to track the effectiveness of campaigns

You can control cookie settings through your browser. Disabling certain cookies may affect website functionality. Where required by law, we will request your consent before placing non-essential cookies.

 

12. Security

We take reasonable technical and organisational measures to protect personal information from unauthorised access, disclosure, alteration, or destruction. These measures include:

        Secure access controls and password protection on all platforms

        Use of reputable, enterprise-grade software providers with their own security certifications

        Limited access to personal data on a need-to-know basis

        Prompt notification of any data breach to affected parties in accordance with applicable law

No method of transmission over the internet is 100% secure. While we strive to protect personal information, we cannot guarantee absolute security.

 

13. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it.

 

14. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policies of any third-party sites you visit.

 

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The updated policy will be posted on our website with a revised date. We encourage you to review this policy periodically.

For material changes, we will notify existing clients by email where reasonably practicable.

 

16. Complaints

If you have a complaint about how we have handled your personal information, please contact us in the first instance at [email protected]. We will investigate and respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with:

        Australia — Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au

        United Kingdom — Information Commissioner's Office (ICO): www.ico.org.uk

 

17. Contact Us

Client Flow Systems (CFS)

Operated by: Calogero Mangione

Website: thecfsagency.com

Email: [email protected]

For any privacy-related queries, requests, or complaints, please contact us at the email address above.