Privacy Policy

Last updated: February 18, 2026

1. Introduction

This Privacy Policy explains how Fylos ("Fylos", "we", "us", or "our"), collects and processes personal data when you use our website fylos.io and our application Fylos (collectively, the "Service").

This Privacy Policy applies to visitors, users, and customers of the Service. If you do not agree with this Privacy Policy, please do not use the Service.

Where required by law (e.g., in the EEA/UK), we use a cookie consent banner and honor your consent choices for non-essential cookies and similar technologies.

2. Who We Are (Controller) and Scope

Controller (Data Controller): Frozen Bamboo V.O.F. (brand: Fylos) is the controller for personal data processed for our own business purposes (e.g., accounts, billing, marketing, website analytics).

Business Customer Content: When you use Fylos as part of an organization and upload documents or content that may contain personal data, we generally process that content on behalf of the customer (typically acting as a processor). Our Data Processing Agreement (DPA) will be made available separately.

This Privacy Policy does not cover third-party websites or services that you access through links in our Service.

3. Personal Data We Collect

We collect personal data in the following categories:

3.1 Account and Profile Data

  • Name
  • Email address
  • Organization/workspace information
  • Login credentials (stored in a hashed/encrypted form where applicable)
  • Account settings and preferences

3.2 Authentication Data (e.g., Google OAuth)

If you sign up or log in via Google, we receive information such as your name, email address, and a Google account identifier, depending on the scopes you authorize.

3.3 Customer Content and Files

Content you upload, create, or store in the Service, which may include personal data depending on what you choose to upload (e.g., documents, contracts, notes).

3.4 Payment and Billing Data

We use third-party payment processors (e.g., Stripe) to handle payments. We do not store full credit card details on our servers. We may receive billing details such as:

  • Billing name and address
  • Payment status and transaction identifiers
  • Subscription information (plan, renewals, invoices)

3.5 Usage and Device Data (Website/App)

  • IP address
  • Device type, browser type, operating system
  • Pages/screens viewed, timestamps, clicks and interactions
  • Referral URLs and approximate location derived from IP (country/region)

3.6 Communications Data

  • Messages you send to support (email, chat)
  • Email delivery and engagement metrics (e.g., opened emails) where enabled and permitted

3.7 Security and Logs

  • Audit logs and security events (e.g., login timestamps, IP addresses, device identifiers)
  • Two-factor authentication (2FA) events (if enabled)

4. How We Use Personal Data (Purposes)

We process personal data for the following purposes:

4.1 Provide and Operate the Service

  • Create and manage accounts and workspaces
  • Provide core features (document management, knowledge base features, signing workflows)
  • Maintain service functionality and performance

4.2 Authentication and Security

  • Authenticate users (including Google OAuth)
  • Provide account security and prevent fraud/abuse
  • Support two-factor authentication (2FA) via SMS where enabled

4.3 Billing and Payments

  • Process subscriptions and payments
  • Issue invoices and receipts
  • Handle refunds where required by law and manage payment disputes

4.4 Support and Communication

  • Respond to support requests
  • Send service messages (e.g., verification emails, password resets, security alerts)
  • Provide onboarding and product guidance

4.5 Analytics and Product Improvement

  • Understand how the Service is used
  • Improve features, UX, reliability, and performance

4.6 Marketing and Advertising (Where Permitted)

  • Measure conversion performance of ads
  • Build and measure remarketing audiences
  • Run and optimize advertising campaigns

Marketing and advertising technologies are used only where allowed by law, and in the EEA/UK typically require your consent via our consent platform.

6. Cookies, Pixels, Session Replay, and Consent

We use cookies and similar technologies, including tags, pixels, server-side tracking, and session replay tools.

6.1 Consent Management

We use CookieYes as our Consent Management Platform (CMP) to collect, manage, and store consent preferences where required.

6.2 Website Analytics

  • Google Analytics 4 (GA4) — including server-side implementation for analytics and measurement

6.3 Advertising and Conversion Tracking (Marketing)

We may use the following for conversion measurement and remarketing (subject to your consent where required):

  • Meta Pixel and Meta Conversions API (CAPI)
  • Google Ads Conversion Tracking and Remarketing Tag
  • LinkedIn Insight Tag and LinkedIn Conversions API
  • Zapier (or similar workflow tools) may be used to send server-to-server conversion events and/or offline conversion events to ad platforms

6.4 Session Replay / Behavioral Analytics

  • Microsoft Clarity may collect interaction data such as clicks, scrolling, page navigation, and (depending on configuration) session recordings. Where required by law, this is enabled only with your consent.

You can change your cookie preferences at any time through our cookie settings.

7. Sharing and Disclosure of Personal Data

We share personal data only as needed to operate our business and provide the Service:

7.1 Service Providers (Subprocessors / Vendors)

We use third-party providers for hosting, infrastructure, analytics, communications, and payments. These providers process personal data on our behalf under contractual obligations.

Examples of providers we use include:

  • Stripe (payments and billing)
  • Supabase (backend infrastructure: authentication, database, storage)
  • Netlify (hosting and deployment)
  • Hostinger (DNS/domain services)
  • n8n (workflows/automations)
  • SendGrid (email delivery)
  • Twilio (SMS delivery and 2FA)
  • Google OAuth (login/sign-up via Google)
  • CookieYes (consent management)
  • Google Analytics 4, Meta, LinkedIn, Microsoft Clarity (analytics/marketing as described above)
  • Pabbly Connect (automation for server-to-server conversion events where applicable)

We may update this list as our tooling changes.

7.2 Legal Requirements

We may disclose personal data if required to do so by law, regulation, legal process, or governmental request.

7.3 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be transferred as part of that transaction, subject to applicable law.

8. International Data Transfers

Some of our service providers may process personal data outside the European Economic Area (EEA). Where required, we rely on appropriate safeguards, such as:

  • The European Commission's Standard Contractual Clauses (SCCs), and/or
  • Other lawful transfer mechanisms under GDPR

You can contact us to request additional information about transfer safeguards.

9. Data Retention

We retain personal data only as long as necessary for the purposes described in this Privacy Policy, including to meet legal, accounting, or reporting requirements.

Typical retention periods (may vary depending on context):

  • Account data: retained while the account is active; deleted or anonymized within a reasonable period after account deletion request, unless legally required to keep it
  • Billing records: retained as required by tax and accounting laws
  • Security logs: retained for a limited period to maintain security and prevent abuse
  • Marketing data: retained until you withdraw consent or opt out, where applicable

10. Security

We implement appropriate administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.

No method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your login credentials.

11. Your Rights (EEA/UK and Similar Jurisdictions)

Depending on your location, you may have rights including:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion ("right to be forgotten")
  • Restriction of processing
  • Objection to processing (including direct marketing)
  • Data portability
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with your local data protection authority

To exercise your rights, contact us at support@fylos.io.

12. Marketing Preferences

You can opt out of marketing emails at any time by using the unsubscribe link in the email, or by contacting us.

Where required by law, marketing cookies and remarketing technologies are used only with your consent and can be disabled via cookie settings.

13. Children's Privacy

The Service is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page. If changes are material, we will provide notice as required by law.

15. Contact

If you have questions about this Privacy Policy or our privacy practices, contact us:

Email: support@fylos.io


Fylos

Gijsbrecht van Amstelstraat 72D, Hilversum

KvK: 94244715

VAT: NL866690335B01


Fylos is a Frozen Bamboo V.O.F. brand.