Legal
Política de privacidad
This Privacy Policy explains how Felagar (“we”, “our”, or “us”) collects, uses, and shares information when you use Felagar (the “Service”). By using the Service you agree to the practices described below.
These practices apply to the hosted Felagar product operated by us. If you run a self-hosted instance, you (or your organisation) are the controller for that deployment; this policy does not govern self-hosted operators except where we provide optional hosted components.
1. Who we are
Felagar is a hosted workspace for agencies and freelancers: projects and Kanban, design approvals, chat, tickets, company CRM, sales pipeline, time and budgets, a client portal, and MCP for AI agents. Felagar is a product of Athom.Agency. Our registered address and data controller details are available on request at legal@felagar.com.
2. Information we collect
2.1 Information you provide
- Account information - name, email address, and password when you register.
- Profile information - optional profile photo, phone, timezone, language, and display preferences.
- Workspace content - projects, boards, cards, comments, designs and versions, files, tickets, chat messages, companies, deals, time entries, notes, and other data you create in the Service.
- Client and team data - information about staff and client users you invite (such as name and email), and company CRM records you maintain.
- Payment information - billing details processed by Stripe when you subscribe. We do not store full card numbers; Stripe handles PCI compliance on our behalf.
- Support communications - messages you send to our support or legal email addresses, and ticket-related email when inbound email is enabled.
2.2 Information we collect automatically
- Usage data - pages visited, features used, and actions taken within the dashboard and portal.
- Log data - IP address, browser type, operating system, referring URL, and timestamps of requests.
- Cookies and local storage - see our Cookie Policy for details.
2.3 Information from third parties
- Google OAuth - if you sign in with Google we receive your name and email address from Google to create or log into your account.
- Styrar - when you connect Styrar for social planning, we receive OAuth tokens and related connection metadata needed to operate the integration on your behalf.
- MCP / OAuth clients - when you connect Cursor, Claude, or other MCP clients, we receive the credentials and scopes you authorise so agents can act under your permissions.
3. How we use your information
- Provide, operate, and improve the Service.
- Authenticate your identity and maintain your session.
- Deliver workspace features (projects, approvals, chat, tickets, CRM, pipeline, time, files, MCP).
- Process billing and send receipts via Stripe.
- Send transactional emails (invites, verification, password reset, approvals, ticket updates) via Sequenzy or, for some self-host deployments, Resend.
- Enable optional audio/video huddles and meetings in chat via Cloudflare RealtimeKit.
- Detect fraud, abuse, and security threats.
- Comply with legal obligations.
We do not sell your personal data. We do not use your content to train AI models.
4. Legal basis for processing (GDPR)
If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases:
- Contract performance - processing necessary to deliver the Service you have signed up for.
- Legitimate interests - security, fraud prevention, and service improvement, balanced against your interests.
- Legal obligation - where required by applicable law.
- Consent - for optional cookies and marketing communications, where applicable.
5. Sharing your information
We share your information only in the following circumstances:
- Service providers - we engage sub-processors to operate the Service, including Cloudflare (CDN, DNS, and RealtimeKit for audio/video calls), Stripe (payments), Sequenzy (transactional email on hosted), S3-compatible object storage for files and designs, and database/cache infrastructure. Each sub-processor is bound by data processing agreements where required.
- Calling & huddles - when you start or join an audio/video huddle, your connection is routed through Cloudflare's RealtimeKit infrastructure. Cloudflare processes call metadata and relays encrypted audio/video streams needed to run the call; it does not receive your other workspace content.
- Integrations you enable - Styrar, Google, MCP clients, and similar connections receive only what is needed for the integration you authorised.
- Team members and clients - within your agency, staff and invited clients see content according to the permissions and portal visibility you configure.
- Legal requirements - if required by law, court order, or to protect the rights, property, or safety of Felagar, our users, or the public.
- Business transfers - in the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity, subject to the same privacy commitments.
6. Data retention
We retain your data for as long as your account is active or as needed to provide the Service. When you delete your agency or account:
- Personal profile data and workspace content are removed according to our deletion process.
- Aggregated, anonymised analytics data may be retained for up to 2 years for product improvement.
- Billing records are retained for 7 years to comply with financial regulations.
- Backup copies may persist for up to 90 days in encrypted storage before being purged.
7. Security
We use industry-standard security measures including HTTPS encryption in transit, bcrypt-hashed passwords, AES-256-GCM encrypted secrets, TOTP two-factor authentication, and HTTP-only session cookies. Despite these measures no system is perfectly secure; we encourage you to use a strong password and enable two-factor authentication.
8. International transfers
Our infrastructure is hosted primarily in the EU/EEA via Cloudflare and related providers. If data is transferred outside the EEA we rely on Standard Contractual Clauses or other appropriate safeguards as required by applicable law.
9. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access - request a copy of the personal data we hold about you.
- Rectification - request correction of inaccurate or incomplete data.
- Erasure - request deletion of your personal data, subject to legal retention requirements.
- Portability - request your data in a structured, machine-readable format.
- Restriction / objection - request that we restrict or stop processing your data in certain circumstances.
- Withdraw consent - where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise these rights, email legal@felagar.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16 without parental consent, we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. Continued use of the Service after that date constitutes acceptance of the updated policy. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact
For privacy-related enquiries, contact us at legal@felagar.com.