Privacy Policy

Last updated: 2026-07-29

This Privacy Policy describes how FYAI B.V. ("we", "us", "FYAI") processes personal data in connection with the FYAI platform.

FYAI acts in two distinct roles under the GDPR:

  1. Controller for the data of our own customers and their team members, the account holders who use FYAI.
  2. Processor for the lead data our customers collect through FYAI on their own websites. Our Data Processing Agreement applies additionally to that role.

1. Who we are

Company
FYAI B.V.
Chamber of Commerce
42118728
Registered address
Gaspeldoorn 8, 4814 NP Breda
Email
privacy@fuelyour.ai
Privacy contact
Lauren Fortes
Data Protection Officer
Not appointed. We have no statutory obligation to appoint one. Privacy questions go to the contact above.

2. What personal data we process

2.1 As controller (customer accounts)

When you create an FYAI account or are invited as a team member, we process:

  • Identification data: name, email address
  • Authentication data: hashed passwords, API tokens, session data
  • Team context: team and workspace roles, invitation history
  • Communication: emails about your account (transactional only, no marketing unless you opted in)
  • Logs: IP address, user agent and timestamps for logins, critical actions such as form activation and exports, and audit events

2.2 As processor (lead data)

When a customer deploys FYAI on their website, we process, on the instruction of that customer, data about visitors to that website:

  • Attribution data: gclid, fbclid, li_fat_id, source URL, timestamps, IP address and user agent
  • Form data: only after explicit activation by the customer and only for the fields the customer has mapped: name, email address, phone number, company name, address details and any designated custom fields
  • Consent snapshot: where the customer sends one
  • Lead qualification: labels, quote value and realised revenue entered by the customer

Until a form is activated, only field names are stored, never field values.

3. Purposes and legal bases

Processing Legal basis (GDPR)
Creating and managing accounts Performance of a contract (Art. 6(1)(b))
Tracking and logging leads Processor on behalf of the customer (Art. 28)
Security, fraud and abuse detection Legitimate interest (Art. 6(1)(f))
Billing and accounting Legal obligation (Art. 6(1)(c))
Product improvement on aggregated, non-identifiable data Legitimate interest (Art. 6(1)(f))
Service and account communication Performance of a contract (Art. 6(1)(b))

We do not use lead data for our own marketing purposes, and we do not share it with any third party other than the advertising platforms designated by the customer.

4. Sharing with third parties (sub-processors)

We engage the sub-processors listed below.

Sub-processor Function Location
CONSTRUKT B.V. Hosting, application servers and databases (Iron Mountain data centre, Haarlem) Netherlands (EU)
Mailgun Technologies, Inc. Transactional email European Union (EU region only)
Functional Software, Inc. (Sentry) Error monitoring EU/US, under SCC
Stripe Payments Europe, Ltd. Billing and payment processing Ireland (EU), with transfers under SCC
Google LLC Google Ads offline conversions, Google Ads API enhanced conversions for leads, Google Tag Manager API EU/US, under SCC and supplementary measures
Meta Platforms Ireland Ltd. Conversions API EU/US, under SCC
LinkedIn Ireland Unlimited Company Conversions API (coming soon) EU/US, under SCC
Microsoft Ireland Operations Ltd. Microsoft Ads conversions (coming soon) EU/US, under SCC

Customers decide per workspace which advertising platforms are activated. Lead data is only forwarded to platforms the customer has explicitly enabled.

5. International transfers

Our hosting, application servers and databases are located in the Netherlands. Some sub-processors, such as Google, Meta and Microsoft, are established in the United States. Those transfers take place under the EU Standard Contractual Clauses (2021/914) and, where applicable, additional organisational and technical safeguards including pseudonymisation and hashing of email addresses and phone numbers for matching.

6. Retention periods

Category Retention
Account data Until account termination, plus 12 months
Audit logs (form activation, exports) 24 months
CSV export files Maximum 30 days on disk
Customer lead data Per customer instruction; by default for as long as the workspace is active. Soft-deleted records are permanently removed after 90 days.
Billing data 7 years, statutory tax retention

7. Security

We take appropriate technical and organisational measures, including:

  • TLS encryption on all connections
  • Password hashing, and encryption at rest of third-party access tokens
  • Hashing of email addresses and phone numbers (SHA-256 over the lowercased, trimmed value) where the conversion matching protocol requires it, for Meta Conversions API and Google Ads enhanced conversions. The plaintext values never leave our infrastructure, only the hashes are forwarded.
  • Role-based access control, with multi-tenant isolation per team and per workspace
  • Rate limiting on the tracking and export endpoints
  • Audit logging of privacy-sensitive actions
  • Backups and tested recovery procedures
  • Limited internal access on a need-to-know basis

8. Cookies and similar technologies

The FYAI platform itself uses strictly necessary cookies only, session and CSRF. We place no tracking or marketing cookies on our own platform.

On our customers' websites, FYAI may be deployed as a tracking pixel. Placing that pixel and obtaining any required cookie consent is the responsibility of that customer, who is the controller for it.

9. Your rights

Under the GDPR you have the right to:

  • Access your data (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Object to processing (Art. 21)
  • Data portability (Art. 20)
  • Withdraw consent you previously gave

Are you a visitor to a customer's website? Address your request to that customer first: they are the controller. We support them in fulfilling it.

Requests can be sent to privacy@fuelyour.ai. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Deleting data connected through Meta

If you connected a Meta advertising account to FYAI using Facebook Login, you can ask us to delete the data associated with that connection. Send a request to privacy@fuelyour.ai, or remove FYAI from your Facebook account settings, in which case Meta notifies us automatically.

On receiving such a request we delete the stored access tokens and the account connection. You receive a confirmation code with which you can check the status of your request at any time.

11. Data breaches

We comply with the personal data breach notification duty under Art. 33 GDPR. Affected customers are informed without undue delay, in accordance with the Data Processing Agreement.

12. Changes to this policy

We may update this Privacy Policy. Material changes are communicated to account holders at least 30 days in advance, by email or in the application.

13. Contact

FYAI B.V., Gaspeldoorn 8, 4814 NP Breda
privacy@fuelyour.ai