Security & Data

Your campaign workspace has boundaries.

How Brandaflow.com separates workspace data, controls access, uses service providers, and approaches backups and retention.

Last updated: September 8, 2026
01Workspace scopedTenant records are linked to a workspace or company.
02Role controlledPages and actions require the relevant permission.
03Provider limitedExternal services receive only the data needed for a task.

Workspace isolation

Brandaflow.com is a multi-workspace application. Tenant-aware records are scoped using a workspace or company identifier, and application queries are expected to enforce that boundary. A user must belong to the relevant workspace and hold the required permission before accessing its operational data.

Workspace isolation reduces accidental cross-account access, but it does not replace careful user administration. Workspace owners should remove people who no longer need access and review client assignments regularly.

Roles and data access

Owners and administrators manage workspace membership and operational permissions. Team members receive access based on their assigned role. Client portal users are limited to campaigns assigned to them and should not receive access to internal creator notes or unrelated campaign records.

Authorized Brandaflow.com personnel may access limited information when required to investigate support, payment, security, or reliability issues. Important product actions are designed to remain traceable through activity and audit records where available.

Authentication and account security

Brandaflow.com uses account authentication, session controls, email verification and recovery flows, temporary login lockouts, and risk-based CAPTCHA checks. Passwords should never be shared, and every team member should use an individual account.

Backups and recovery

Backup coverage is configured at the production infrastructure level and may include application databases and customer-uploaded files. Backup frequency, retention windows, and recovery points depend on the active hosting and storage configuration.

Backups are intended for service recovery, not as a customer-facing archive. Customers should retain source copies of contracts, irreplaceable media, payment records, and other business-critical documents outside Brandaflow.com.

Service providers

Brandaflow.com relies on selected providers for infrastructure, database operations, email delivery, payment processing, monitoring, and public social-data retrieval. A provider receives only the information reasonably needed to complete the requested service.

Payment checkout may be handled through the central Metafora Pay Hub and its enabled payment processors. Public creator or post data may be processed through specialized retrieval providers. Provider availability and data freshness can vary.

Data retention

Workspace data is retained while an account is active and for as long as reasonably needed to provide the service, preserve campaign history, resolve disputes, prevent abuse, and meet legal or financial obligations. Different record types may require different retention periods.

After an approved deletion request, data is removed or de-identified according to operational and legal requirements. Residual copies may remain in restricted backups until those backups rotate out of their configured retention window.

Customer control and deletion requests

Workspace owners control who joins their workspace, which clients can view a campaign, and which operational records their team creates. Requests for account data, correction, export, or deletion can be submitted through customer support and may require ownership verification.

Responsible disclosure and support

If you believe workspace data has been exposed or you identify a security issue, contact Brandaflow.com promptly. Include the affected page, time observed, and a clear description, but do not include passwords, API secrets, or unnecessary personal data.

Contact Brandaflow.com