FOUNDRY

This English version is binding. Wersja polska

Privacy Policy

Effective date 25 September 2026.

Administrator details

The data controller and service provider is VibeDev Krzysztof Borkowski, ul. Duńska 58a/5, 71-795 Szczecin, Poland. NIP 8513344737, REGON 543807357. Registered in CEIDG. Brand name FOUNDRY. Website https://foundryhq.app. For all matters regarding personal data and data deletion, contact us at hello@foundryhq.app.

What is FOUNDRY

FOUNDRY is a B2B service. AI agents help corporate clients run marketing and operations (ad campaigns, analytics, store, content, support). The client voluntarily connects their external accounts via the Connect page using OAuth. Supported platforms include Meta (Facebook, Instagram, ads, pixel, catalog), Google (Ads, Analytics, Search Console, Tag Manager, Merchant Center, YouTube, Sheets, selected Drive files), TikTok (ads, account), Microsoft (Advertising, email, Power BI), LinkedIn, Notion, and other tools.

Processed data

We process the connecting person's account data (name, email, provider account ID), encrypted access tokens, data from connected accounts within the granted permissions (campaign stats and settings, analytics, page and profile content, comments and messages, product catalogs, conversion events), technical logs, and agent activity logs.

Purpose of processing

We use this data exclusively to provide the service requested by the client (analysis, reports, preparation and - upon client instruction - execution of changes in their accounts). Every write action is logged, and the client can review it.

Strict data restrictions

We do not sell data. We do not use your data for advertising. We do not pass data to brokers. We do not combine data across different clients. We do not use data from connected accounts to train general AI models.

Legal basis (GDPR)

We process data based on Art. 6(1)(b) (contract with the client) and Art. 6(1)(f) (legitimate interest: security, pursuing legal claims). For third-party data found in client accounts, FOUNDRY acts as a data processor on behalf of the client (Data Processing Agreement available on request).

Subprocessors and infrastructure

We host our infrastructure on servers in the European Union and use Cloudflare for network and site hosting. AI model providers (Anthropic, OpenAI, Google) process data fragments exclusively to perform tasks under their enterprise terms, without training on your data. Data transfers outside the EEA rely on Standard Contractual Clauses.

Security measures

We secure all data using encryption in transit (TLS) and encrypt tokens at rest. We maintain strict access controls limited to authorized personnel, use separate tokens per client, and maintain an access registry.

Data retention

We keep your data and tokens until you disconnect the account or the contract ends. Upon disconnection, we delete access tokens immediately and other data within 30 days. We retain security logs for up to 12 months.

Your rights

You have the right to access, rectify, delete, restrict, and port your data. You may also object to processing and lodge a complaint with the President of the Personal Data Protection Office (UODO).

Disconnecting accounts

You can disconnect any account at any time within FOUNDRY on the Connect page or directly at the provider: - Meta: Business Settings > Integrations > Connected apps / Facebook Settings > Apps and Websites - Google: https://myaccount.google.com/permissions - TikTok: Authorization settings in TikTok for Business - Microsoft: https://myapps.microsoft.com

Google data usage

FOUNDRY's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We do not use data obtained from Google APIs to train generalized AI or ML models.

Meta data usage

We process data from Meta platforms strictly according to Meta Platform Terms and Developer Policies.