1. Introduction
This Privacy Policy explains how Fylos ("Fylos", "we", "us", or "our"), collects and processes personal data when you use our website fylos.io and our application Fylos (collectively, the "Service").
This Privacy Policy applies to visitors, users, and customers of the Service. If you do not agree with this Privacy Policy, please do not use the Service.
Where required by law (e.g., in the EEA/UK), we use a cookie consent banner and honor your consent choices for non-essential cookies and similar technologies.
2. Who We Are (Controller) and Scope
Controller (Data Controller): Frozen Bamboo V.O.F. (brand: Fylos) is the controller for personal data processed for our own business purposes (e.g., accounts, billing, marketing, website analytics).
Business Customer Content: When you use Fylos as part of an organization and upload documents or content that may contain personal data, we generally process that content on behalf of the customer (typically acting as a processor). Our Data Processing Agreement (DPA) will be made available separately.
This Privacy Policy does not cover third-party websites or services that you access through links in our Service.
3. Personal Data We Collect
We collect personal data in the following categories:
3.1 Account and Profile Data
- Name
- Email address
- Organization/workspace information
- Login credentials (stored in a hashed/encrypted form where applicable)
- Account settings and preferences
3.2 Authentication Data (e.g., Google OAuth)
If you sign up or log in via Google, we receive information such as your name, email address, and a Google account identifier, depending on the scopes you authorize.
3.3 Customer Content and Files
Content you upload, create, or store in the Service, which may include personal data depending on what you choose to upload (e.g., documents, contracts, notes).
3.4 Payment and Billing Data
We use third-party payment processors (e.g., Stripe) to handle payments. We do not store full credit card details on our servers. We may receive billing details such as:
- Billing name and address
- Payment status and transaction identifiers
- Subscription information (plan, renewals, invoices)
3.5 Usage and Device Data (Website/App)
- IP address
- Device type, browser type, operating system
- Pages/screens viewed, timestamps, clicks and interactions
- Referral URLs and approximate location derived from IP (country/region)
3.6 Communications Data
- Messages you send to support (email, chat)
- Email delivery and engagement metrics (e.g., opened emails) where enabled and permitted
3.7 Security and Logs
- Audit logs and security events (e.g., login timestamps, IP addresses, device identifiers)
- Two-factor authentication (2FA) events (if enabled)
4. How We Use Personal Data (Purposes)
We process personal data for the following purposes:
4.1 Provide and Operate the Service
- Create and manage accounts and workspaces
- Provide core features (document management, knowledge base features, signing workflows)
- Maintain service functionality and performance
4.2 Authentication and Security
- Authenticate users (including Google OAuth)
- Provide account security and prevent fraud/abuse
- Support two-factor authentication (2FA) via SMS where enabled
4.3 Billing and Payments
- Process subscriptions and payments
- Issue invoices and receipts
- Handle refunds where required by law and manage payment disputes
4.4 Support and Communication
- Respond to support requests
- Send service messages (e.g., verification emails, password resets, security alerts)
- Provide onboarding and product guidance
4.5 Analytics and Product Improvement
- Understand how the Service is used
- Improve features, UX, reliability, and performance
4.6 Marketing and Advertising (Where Permitted)
- Measure conversion performance of ads
- Build and measure remarketing audiences
- Run and optimize advertising campaigns
Marketing and advertising technologies are used only where allowed by law, and in the EEA/UK typically require your consent via our consent platform.
5. Legal Bases for Processing (EEA/UK)
Where GDPR applies, we rely on the following legal bases:
- Contract: to provide the Service you requested (account creation, authentication, billing, support)
- Legitimate interests: to secure and improve our Service, prevent fraud, and understand usage (balanced against your rights)
- Consent: for non-essential cookies and marketing/remarketing technologies (e.g., pixels, CAPI, session recordings), where required
- Legal obligation: to comply with laws (e.g., tax and accounting obligations)
You may withdraw consent at any time through our cookie settings.
8. International Data Transfers
Some of our service providers may process personal data outside the European Economic Area (EEA). Where required, we rely on appropriate safeguards, such as:
- The European Commission's Standard Contractual Clauses (SCCs), and/or
- Other lawful transfer mechanisms under GDPR
You can contact us to request additional information about transfer safeguards.
9. Data Retention
We retain personal data only as long as necessary for the purposes described in this Privacy Policy, including to meet legal, accounting, or reporting requirements.
Typical retention periods (may vary depending on context):
- Account data: retained while the account is active; deleted or anonymized within a reasonable period after account deletion request, unless legally required to keep it
- Billing records: retained as required by tax and accounting laws
- Security logs: retained for a limited period to maintain security and prevent abuse
- Marketing data: retained until you withdraw consent or opt out, where applicable
10. Security
We implement appropriate administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.
No method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your login credentials.
11. Your Rights (EEA/UK and Similar Jurisdictions)
Depending on your location, you may have rights including:
- Access to your personal data
- Correction of inaccurate data
- Deletion ("right to be forgotten")
- Restriction of processing
- Objection to processing (including direct marketing)
- Data portability
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with your local data protection authority
To exercise your rights, contact us at support@fylos.io.
12. Marketing Preferences
You can opt out of marketing emails at any time by using the unsubscribe link in the email, or by contacting us.
Where required by law, marketing cookies and remarketing technologies are used only with your consent and can be disabled via cookie settings.
13. Children's Privacy
The Service is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page. If changes are material, we will provide notice as required by law.
15. Contact
If you have questions about this Privacy Policy or our privacy practices, contact us:
Email: support@fylos.io
Fylos
Gijsbrecht van Amstelstraat 72D, Hilversum
KvK: 94244715
VAT: NL866690335B01
Fylos is a Frozen Bamboo V.O.F. brand.
