Legal
Privacy & GDPR
Last updated: 27 July 2026
Follo exists to keep agreements — starting with the one about your data: we collect only what the product needs, we never sell it, and you stay in control.
1. Who is responsible
Follo is the data controller for personal data processed in the service. For any privacy matter, contact hello@getfollo.app.
2. What we collect
- Account data: name, email, authentication identifiers.
- Content you submit: captured messages, commitments, updates, evidence and attachments, participant names and contact details you add.
- Usage data: log and device information needed to run and secure the service.
We do not collect data for advertising, and we do not buy data about you from anyone.
3. Why we process it (legal bases)
- Providing the service you signed up for — contract performance (Art. 6(1)(b) GDPR).
- Security, abuse prevention, and service improvement — legitimate interest (Art. 6(1)(f)).
- Legal obligations we are subject to (Art. 6(1)(c)).
- Anything optional — such as sensitive evidence like geolocation — only with your explicit consent (Art. 6(1)(a)), which you can withdraw at any time.
4. AI processing
Content you capture is processed by AI to propose structure (outcomes, owners, deadlines). Every AI run is recorded and attributable. AI proposals are suggestions for humans to confirm — no material decision about you is made solely by automated means.
5. Sharing and subprocessors
Your content is visible only to the people it is shared with: workspace members per their role, and guests via the specific commitments shared with them. We use vetted infrastructure subprocessors (hosting, database, storage, AI processing) bound by data-processing agreements. We never sell personal data.
6. International transfers
Where data is processed outside the EEA, we rely on adequacy decisions or standard contractual clauses as required by chapter V of the GDPR.
7. Retention
We keep data for as long as your account or workspace needs it. Commitment histories are kept because an audit trail is the product; workspace admins can export data or request deletion, after which data is removed within a reasonable period except where law requires retention.
8. Your rights
- Access your data, and receive a portable copy (Art. 15, 20).
- Rectify inaccurate data (Art. 16).
- Erase data ("right to be forgotten", Art. 17).
- Restrict or object to processing (Art. 18, 21).
- Withdraw consent at any time, without affecting prior processing (Art. 7(3)).
- Complain to your supervisory authority (Art. 77).
To exercise any of these, email hello@getfollo.app — we respond within the statutory one month.
9. Security
Workspaces are strictly isolated with row-level security; privileged operations run server-side under least privilege; attachments are served via signed URLs; material actions are recorded in an immutable audit trail. Details are on the Security & privacy page. Report vulnerabilities to security@getfollo.app.
10. Changes
If this policy changes materially, we will notify you in the product or by email before the change takes effect.