Privacy Policy.
Last updated: September 2026 · Last reviewed: September 2026 · Next scheduled review: September 2027
Who we are
Foyla, Inc. ("Foyla", "we", "us") is a Delaware corporation that designs, builds, and delivers custom software and AI systems for businesses, and operates the website you are on now. This policy covers what we collect, why, and what your rights are, and serves as our California "Notice at Collection."
When this policy applies
This policy applies when Foyla is the controller of your personal data: for example, when you visit our website, book a call, or exchange email with us.
It does not apply when Foyla is a processor acting on behalf of a client: for example, when a system we are building for your employer processes data about you. In that case your employer (or other Foyla client) is the controller, their privacy policy governs, and our obligations are set out in our DPA with that client. If you are unsure which situation applies to you, contact [email protected] and we will help you route the request.
What we collect
Information you give us
- Name, work email, company, and any notes you add when you book a call or contact us.
- Information you share with us during an engagement to define requirements: process descriptions, sample documents, system access. This is client data under the DPA once an agreement is signed.
Information we collect automatically
- Server-side access logs and aggregate page metrics for the website (pages viewed, referrer, rough location from IP). We do not use cross-site advertising trackers or behavioral advertising cookies. If we add a third-party analytics provider in future, we will update this policy to name it.
- Our scheduling page is hosted by Microsoft Bookings. When you book, Microsoft processes your booking details under its own privacy terms and passes them to us.
Sensitive personal information
We do not collect or process "sensitive personal information" as defined under CPRA (such as government identifiers, precise geolocation, racial or ethnic origin, union membership, genetic or biometric data, health data, or the contents of mail, email, and text messages other than as needed to respond to you).
How we use it
We use your data to:
- prepare for and hold the call you booked, and respond to your inquiries;
- scope, propose, and deliver software development work you ask us for;
- maintain the reliability and security of our website and internal systems;
- communicate about our work and, where permitted, send updates you can opt out of at any time;
- meet our legal, tax, and regulatory obligations.
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use client data to train models for other clients or for Foyla.
Financial incentives
We do not offer financial incentives, price differences, or service differences in exchange for the retention or sale of personal information, within the meaning of Cal. Civ. Code §1798.125.
Who we share it with
Only the subprocessors we need to run our business: cloud infrastructure, foundation-model providers, business productivity and scheduling tools, and website hosting. The current list lives on our Subprocessors page. Every subprocessor is bound by written data-protection terms at least as strict as ours.
Where your data lives
By default, data is processed in the United States. For EU/UK residents, transfers out of the EEA/UK are governed by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, or an equivalent approved mechanism.
How long we keep it
We retain personal data only as long as needed for the purposes above or as required by law. Specifically:
- Business-contact information: for the duration of the relationship plus up to 3 years, to answer follow-up questions and meet tax or statutory record-keeping rules.
- Requirements material and client data shared during an engagement: for the life of the engagement plus 30 days, after which it is deleted or returned on request, per the DPA.
- Server-side access logs and aggregate site metrics: 13 months.
- Marketing contacts: until you unsubscribe or ask for deletion; we honor opt-outs immediately and remove you from active lists within 30 days.
- Legal and compliance records (contracts, DPAs, security incident records): as required by applicable statutes of limitation.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or limit the use of your personal data, and to opt out of certain processing. This includes residents of California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, and other US states with comprehensive privacy laws, as well as the EU/UK (GDPR). We do not sell personal information and do not engage in cross-context behavioral advertising. Email [email protected] and we will handle your request within the timeframe required by applicable law (typically 30 to 45 days).
Your Privacy Choices
Foyla does not sell your personal information and does not share it for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share" signal we need to act on for those purposes.
You can still exercise your state-law rights at any time:
- Access, delete, correct, or port your data: email [email protected] with "Privacy Request" in the subject line. On portability requests, we will provide your personal data in a commonly used, machine-readable format such as JSON or CSV.
- Opt out of targeted advertising or profiling: not applicable, we do neither.
- Authorized agents: you can designate an agent to submit a request on your behalf; we will verify the agent's authority before acting.
- Appeals (Colorado, Connecticut, Virginia): if we deny your request, you may appeal by replying to our response; we will review within 45 days.
Foyla honors the Global Privacy Control (GPC) browser signal as an opt-out of sale or sharing where applicable. We do not currently respond to browser Do Not Track (DNT) signals; GPC is the mechanism we use.
California Shine the Light
California residents may request information about any personal information we disclosed to third parties for their own direct-marketing purposes during the prior calendar year, under Cal. Civ. Code §1798.83. We do not disclose personal information for third-party direct marketing; to confirm or request details, email [email protected].
Security
A full write-up lives on our Security page. The short version: least-privilege access, encryption in transit and at rest, an audit log on every production action, and human review built into the systems we deliver.
Contact
Privacy questions and data-subject requests: [email protected]
All other legal matters: [email protected]