Back to home
Foundworks Logo

Privacy Policy

v1.0 · last updated May 2026 · we'll email registered users about material changes

1. Introduction

This Privacy Policy explains how Foundworks ("we," "us," "our") collects, uses, and protects your personal data when you use our platform. We are committed to GDPR compliance and transparent data practices. Foundworks, established in the Netherlands, is the data controller for the processing described in this policy (contact details in section 10).

We process personal data on these legal bases: performance of a contract (providing the Service — account, businesses, agents, billing), legitimate interest (security, abuse prevention, audit logging, service improvement), consent (newsletter, optional integrations you connect), and legal obligation (tax and bookkeeping records).

2. Data We Collect

We collect the following categories of data:

  • Account data: Name, email address, and a login identifier from our authentication provider Clerk. Passwords and social sign-ins are managed by Clerk — we never store your password.
  • Business and department data: The business name, mission, brand voice, target customer (ICP), and any instructions or files you or your AI agents produce. Stored as Markdown files in our virtual filesystem.
  • Agent execution data: Task records, event logs, approval queue items, cost-tracking rows per LLM call.
  • Technical data: IP address, browser type, access timestamps, request audit logs.
  • Connected integrations (only if you choose to connect them): Encrypted OAuth tokens or API keys for any integration you connect (e.g. Microsoft Outlook, Google Gmail, Slack, Linear, HubSpot, GitHub), used so your agents can act through your own accounts under your grant. We never store the passwords for those accounts.
  • Newsletter (only if you sign up): Email address and the source you signed up from. Confirmed via a double-opt-in link.
  • Billing data (paid tiers only): Mollie customer + subscription identifiers and invoice records. Card details are handled directly by Mollie and never touch our servers.
  • Optional data: Third-party LLM API keys (stored Fernet-encrypted with an app-level key).

3. How We Use Your Data

  • To provide and operate the Service (running your agents, storing their outputs, surfacing them in the UI).
  • To authenticate your identity and secure your account (sign-in is handled by Clerk — see sub-processors).
  • To process your business and department instructions and deliver outputs.
  • To send transactional emails: account welcome, weekly digest of your team's activity, approval reminders, budget-threshold warnings, and newsletter confirmations / broadcasts (if you opted in).
  • To bill you (paid tiers) via Mollie.
  • To monitor service health, enforce rate limits, and prevent abuse.

4. Data Storage and Security

Your application data (businesses, agent memory, files, billing records) is stored on Azure infrastructure in the European Union (Azure West Europe and North Europe regions). Authentication data is handled by Clerk in the United States under EU Standard Contractual Clauses (see sub-processors). We use industry-standard security measures including:

  • Encryption in transit (TLS) and at rest
  • Authentication, credential storage, and MFA handled by Clerk (SOC 2 Type II)
  • Fernet encryption for stored API keys
  • Isolated sandbox environments for agent execution

5. Data Sharing (Sub-processors)

We do not sell your personal data. We process data through these third-party services, each contractually bound to protect it:

  • Clerk — authentication & user management (sign-up/in, social logins, sessions, MFA). Stores your name, email, and login identifiers; processed in the United States under EU Standard Contractual Clauses.
  • Microsoft Azure — hosting, Azure SQL database, Azure Blob storage (EU regions: West Europe and North Europe).
  • Azure AI / OpenAI — processes your instructions to drive the agent loops. Inputs and outputs transit Azure AI but are not used to train shared models.
  • Azure Communication Services Email — sends transactional email from us to you (welcome, digest, newsletter confirmations, broadcasts, budget warnings).
  • Connected integration providers — only for integrations you connect: Microsoft Graph (Outlook mail), Google (Gmail), Slack, Linear, HubSpot, GitHub. Your agents act through your own accounts under your OAuth grant; content you ask them to send goes to the respective provider.
  • Sandbox providers — Sprites/Fly.io (default) or E2B for isolated agent execution.
  • Web search providers (Tavily / Brave) — when an agent runs a web search, the search query (which can contain business context) is sent to the search provider.
  • Vercel — only if you publish an agent-built website via Vercel; the site content is uploaded for hosting.
  • Mollie — payment processing for paid tiers. Card data goes directly to Mollie; we only see customer/subscription/invoice identifiers.
  • Cloudflare — DNS + edge routing for our domain.

6. Your Rights (GDPR)

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Port your data to another service
  • Object to processing of your data
  • Withdraw consent at any time

You also have the right to lodge a complaint with your national supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

To exercise any of these rights, email us at [email protected].

7. Data Retention

We retain your account data for as long as your account is active. Business + department data (instructions, agent outputs, memory files, event logs) lives for the lifetime of the business. When you delete a memory file the row is soft-deleted with a 30-day grace window; after 30 days it's hard-purged from the database. Archiving a business stops its agents and removes it from your dashboard. Deleting your account (from Settings) irreversibly erases your personal data — name, email, login identifiers, and connected-integration tokens — and archives your businesses; some financial records (e.g. invoices) may be retained where tax law requires. Newsletter subscribers can unsubscribe one-click via the link in every newsletter; we keep the row marked unsubscribed (for audit) until you ask us to delete it. You may request full data deletion at any time.

8. Cookies and Tracking

Authentication is handled by Clerk, which sets a strictly-necessary session cookie on our domain (no consent banner required); the app sends a short-lived token to our API. We use no third-party tracking or analytics cookies. During the Outlook OAuth flow we briefly carry a signed CSRF token in the URL; it expires after 10 minutes.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Continued use of the Service after changes constitutes acceptance.

10. Contact (Data Controller)

Data controller: Foundworks, established in the Netherlands. For privacy-related inquiries, contact us at [email protected].