Privacy Policy
Last updated: 2026-07-29
This Privacy Policy describes how FYAI B.V. ("we", "us", "FYAI") processes personal data in connection with the FYAI platform.
FYAI acts in two distinct roles under the GDPR:
- Controller for the data of our own customers and their team members, the account holders who use FYAI.
- Processor for the lead data our customers collect through FYAI on their own websites. Our Data Processing Agreement applies additionally to that role.
1. Who we are
- Company
- FYAI B.V.
- Chamber of Commerce
- 42118728
- Registered address
- Gaspeldoorn 8, 4814 NP Breda
- privacy@fuelyour.ai
- Privacy contact
- Lauren Fortes
- Data Protection Officer
- Not appointed. We have no statutory obligation to appoint one. Privacy questions go to the contact above.
2. What personal data we process
2.1 As controller (customer accounts)
When you create an FYAI account or are invited as a team member, we process:
- Identification data: name, email address
- Authentication data: hashed passwords, API tokens, session data
- Team context: team and workspace roles, invitation history
- Communication: emails about your account (transactional only, no marketing unless you opted in)
- Logs: IP address, user agent and timestamps for logins, critical actions such as form activation and exports, and audit events
2.2 As processor (lead data)
When a customer deploys FYAI on their website, we process, on the instruction of that customer, data about visitors to that website:
- Attribution data:
gclid,fbclid,li_fat_id, source URL, timestamps, IP address and user agent - Form data: only after explicit activation by the customer and only for the fields the customer has mapped: name, email address, phone number, company name, address details and any designated custom fields
- Consent snapshot: where the customer sends one
- Lead qualification: labels, quote value and realised revenue entered by the customer
Until a form is activated, only field names are stored, never field values.
3. Purposes and legal bases
| Processing | Legal basis (GDPR) |
|---|---|
| Creating and managing accounts | Performance of a contract (Art. 6(1)(b)) |
| Tracking and logging leads | Processor on behalf of the customer (Art. 28) |
| Security, fraud and abuse detection | Legitimate interest (Art. 6(1)(f)) |
| Billing and accounting | Legal obligation (Art. 6(1)(c)) |
| Product improvement on aggregated, non-identifiable data | Legitimate interest (Art. 6(1)(f)) |
| Service and account communication | Performance of a contract (Art. 6(1)(b)) |
We do not use lead data for our own marketing purposes, and we do not share it with any third party other than the advertising platforms designated by the customer.
4. Sharing with third parties (sub-processors)
We engage the sub-processors listed below.
| Sub-processor | Function | Location |
|---|---|---|
| CONSTRUKT B.V. | Hosting, application servers and databases (Iron Mountain data centre, Haarlem) | Netherlands (EU) |
| Mailgun Technologies, Inc. | Transactional email | European Union (EU region only) |
| Functional Software, Inc. (Sentry) | Error monitoring | EU/US, under SCC |
| Stripe Payments Europe, Ltd. | Billing and payment processing | Ireland (EU), with transfers under SCC |
| Google LLC | Google Ads offline conversions, Google Ads API enhanced conversions for leads, Google Tag Manager API | EU/US, under SCC and supplementary measures |
| Meta Platforms Ireland Ltd. | Conversions API | EU/US, under SCC |
| LinkedIn Ireland Unlimited Company | Conversions API (coming soon) | EU/US, under SCC |
| Microsoft Ireland Operations Ltd. | Microsoft Ads conversions (coming soon) | EU/US, under SCC |
Customers decide per workspace which advertising platforms are activated. Lead data is only forwarded to platforms the customer has explicitly enabled.
5. International transfers
Our hosting, application servers and databases are located in the Netherlands. Some sub-processors, such as Google, Meta and Microsoft, are established in the United States. Those transfers take place under the EU Standard Contractual Clauses (2021/914) and, where applicable, additional organisational and technical safeguards including pseudonymisation and hashing of email addresses and phone numbers for matching.
6. Retention periods
| Category | Retention |
|---|---|
| Account data | Until account termination, plus 12 months |
| Audit logs (form activation, exports) | 24 months |
| CSV export files | Maximum 30 days on disk |
| Customer lead data | Per customer instruction; by default for as long as the workspace is active. Soft-deleted records are permanently removed after 90 days. |
| Billing data | 7 years, statutory tax retention |
7. Security
We take appropriate technical and organisational measures, including:
- TLS encryption on all connections
- Password hashing, and encryption at rest of third-party access tokens
- Hashing of email addresses and phone numbers (SHA-256 over the lowercased, trimmed value) where the conversion matching protocol requires it, for Meta Conversions API and Google Ads enhanced conversions. The plaintext values never leave our infrastructure, only the hashes are forwarded.
- Role-based access control, with multi-tenant isolation per team and per workspace
- Rate limiting on the tracking and export endpoints
- Audit logging of privacy-sensitive actions
- Backups and tested recovery procedures
- Limited internal access on a need-to-know basis
8. Cookies and similar technologies
The FYAI platform itself uses strictly necessary cookies only, session and CSRF. We place no tracking or marketing cookies on our own platform.
On our customers' websites, FYAI may be deployed as a tracking pixel. Placing that pixel and obtaining any required cookie consent is the responsibility of that customer, who is the controller for it.
9. Your rights
Under the GDPR you have the right to:
- Access your data (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Object to processing (Art. 21)
- Data portability (Art. 20)
- Withdraw consent you previously gave
Are you a visitor to a customer's website? Address your request to that customer first: they are the controller. We support them in fulfilling it.
Requests can be sent to privacy@fuelyour.ai. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
10. Deleting data connected through Meta
If you connected a Meta advertising account to FYAI using Facebook Login, you can ask us to delete the data associated with that connection. Send a request to privacy@fuelyour.ai, or remove FYAI from your Facebook account settings, in which case Meta notifies us automatically.
On receiving such a request we delete the stored access tokens and the account connection. You receive a confirmation code with which you can check the status of your request at any time.
11. Data breaches
We comply with the personal data breach notification duty under Art. 33 GDPR. Affected customers are informed without undue delay, in accordance with the Data Processing Agreement.
12. Changes to this policy
We may update this Privacy Policy. Material changes are communicated to account holders at least 30 days in advance, by email or in the application.
13. Contact
FYAI B.V., Gaspeldoorn 8, 4814 NP Breda
privacy@fuelyour.ai