# Privacy Policy.

Last updated: October 2026 · Last reviewed: October 2026 · Next scheduled review: September 2027

> This is a plain-language summary of how Foyla handles your data. If any of it matters to your procurement or legal team, reach out to [legal@foyla.ai](mailto:legal@foyla.ai) and we will walk through it with you.

## Who we are

Foyla, Inc. ("Foyla", "we", "us") is a Delaware corporation that designs, builds, and delivers custom software and AI systems for businesses, and operates the website you are on now. This policy covers what we collect, why, and what your rights are, and serves as our California "Notice at Collection."

## When this policy applies

This policy applies when Foyla is the controller of your personal data: for example, when you visit our website, book a call, or exchange email with us.

It does not apply when Foyla is a processor acting on behalf of a client: for example, when a system we are building for your employer processes data about you. In that case your employer (or other Foyla client) is the controller, their privacy policy governs, and our obligations are set out in our DPA with that client. If you are unsure which situation applies to you, contact [privacy@foyla.ai](mailto:privacy@foyla.ai) and we will help you route the request.

## What we collect

**Information you give us**

- Name, work email, company, and any notes you add when you book a call or contact us.
- If you apply to work with us through this website: your name, email, the message you write, your CV, and your LinkedIn profile if you choose to share it.
- Information you share with us during an engagement to define requirements: process descriptions, sample documents, system access. This is client data under the DPA once an agreement is signed.

**Information we collect automatically**

- Server-side access logs and aggregate page metrics for the website (pages viewed, referrer, rough location from IP). We do not use cross-site advertising trackers or behavioral advertising cookies. If we add a third-party analytics provider in future, we will update this policy to name it.
- The forms on this website (call requests, messages, and applications) are delivered to our Microsoft 365 mailboxes. When you submit a form, Cloudflare, which hosts this website, runs an automated spam check (Turnstile) that processes technical data such as your IP address and browser characteristics.

## Sensitive personal information

We do not collect or process "sensitive personal information" as defined under CPRA (such as government identifiers, precise geolocation, racial or ethnic origin, union membership, genetic or biometric data, health data, or the contents of mail, email, and text messages other than as needed to respond to you).

## How we use it

We use your data to:

- prepare for and hold the call you booked, and respond to your inquiries;
- review your application and contact you about it, if you apply to work with us;
- scope, propose, and deliver software development work you ask us for;
- maintain the reliability and security of our website and internal systems;
- communicate about our work and, where permitted, send updates you can opt out of at any time;
- meet our legal, tax, and regulatory obligations.

We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use client data to train models for other clients or for Foyla.

## Financial incentives

We do not offer financial incentives, price differences, or service differences in exchange for the retention or sale of personal information, within the meaning of Cal. Civ. Code §1798.125.

## Who we share it with

Only the subprocessors we need to run our business: cloud infrastructure, foundation-model providers, business productivity and scheduling tools, and website hosting. The current list lives on our Subprocessors page. Every subprocessor is bound by written data-protection terms at least as strict as ours.

## Where your data lives

By default, data is processed in the United States. For EU/UK residents, transfers out of the EEA/UK are governed by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, or an equivalent approved mechanism.

## How long we keep it

We retain personal data only as long as needed for the purposes above or as required by law. Specifically:

- Business-contact information: for the duration of the relationship plus up to 3 years, to answer follow-up questions and meet tax or statutory record-keeping rules.
- Requirements material and client data shared during an engagement: for the life of the engagement plus 30 days, after which it is deleted or returned on request, per the DPA.
- Server-side access logs and aggregate site metrics: 13 months.
- Job applications: up to 1 year after the hiring decision, unless a longer period is required by law or you ask us to delete them sooner.
- Marketing contacts: until you unsubscribe or ask for deletion; we honor opt-outs immediately and remove you from active lists within 30 days.
- Legal and compliance records (contracts, DPAs, security incident records): as required by applicable statutes of limitation.

## Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or limit the use of your personal data, and to opt out of certain processing. This includes residents of California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, and other US states with comprehensive privacy laws, as well as the EU/UK (GDPR). We do not sell personal information and do not engage in cross-context behavioral advertising. Email [privacy@foyla.ai](mailto:privacy@foyla.ai) and we will handle your request within the timeframe required by applicable law (typically 30 to 45 days).

## Your Privacy Choices

Foyla does not sell your personal information and does not share it for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share" signal we need to act on for those purposes.

You can still exercise your state-law rights at any time:

- Access, delete, correct, or port your data: email [privacy@foyla.ai](mailto:privacy@foyla.ai) with "Privacy Request" in the subject line. On portability requests, we will provide your personal data in a commonly used, machine-readable format such as JSON or CSV.
- Opt out of targeted advertising or profiling: not applicable, we do neither.
- Authorized agents: you can designate an agent to submit a request on your behalf; we will verify the agent's authority before acting.
- Appeals (Colorado, Connecticut, Virginia): if we deny your request, you may appeal by replying to our response; we will review within 45 days.

Foyla honors the Global Privacy Control (GPC) browser signal as an opt-out of sale or sharing where applicable. We do not currently respond to browser Do Not Track (DNT) signals; GPC is the mechanism we use.

## California Shine the Light

California residents may request information about any personal information we disclosed to third parties for their own direct-marketing purposes during the prior calendar year, under Cal. Civ. Code §1798.83. We do not disclose personal information for third-party direct marketing; to confirm or request details, email [privacy@foyla.ai](mailto:privacy@foyla.ai).

## Children

The website is intended for businesses and is not directed to children under 13 (or under 16 where applicable). We do not knowingly collect personal information from children.

## Changes to this policy

We may update this policy as our website or practices change. The date at the top of this page shows when it was last updated.

## Security

A full write-up lives on our Security page. The short version: least-privilege access, encryption in transit and at rest, an audit log on every production action, and human review built into the systems we deliver.

## Contact

Privacy questions and data-subject requests: [privacy@foyla.ai](mailto:privacy@foyla.ai) All other legal matters: [legal@foyla.ai](mailto:legal@foyla.ai)

Source: https://foyla.ai/legal/privacy/
