Legal
Privacy Policy
How we handle personal data across the Fluidlee website and platform.
1. Who we are and what this covers
This Privacy Policy explains how Fluidlee Ltd. (“Fluidlee”, “we”, “us”) handles personal data. It is a single notice covering both of our surfaces:
- The website — fluidlee.com, including the contact / early-access form.
- The platform — the Fluidlee dashboard and API (api.fluidlee.com) that account holders sign in to and build on.
For all of the above we are the data controller. There is one important exception: the records your tenants and end users create inside your product are data we process on your behalf — there we act as your processor, governed by our Data Processing Agreement, not this policy. Section 4 explains that split.
2. The personal data we collect
Account data (platform)
- Your name, email address, and company name.
- Authentication credentials — your password is never stored in readable form (see Security).
- Optional profile details you provide: profile image, timezone, and notification preferences.
- Your plan tier and account status.
Billing data (platform, paid plans)
- Billing name, billing address, tax identifier, and billing email addresses.
- A tokenized payment reference held by our payment processor — the card brand, last four digits, and expiry only. Full card numbers never reach Fluidlee.
- Invoices, subscription records, and payment history.
Contact-form data (website)
- The name, email, optional company, and message you submit.
- The IP address and browser user-agent captured with the submission, used to prevent spam and abuse. These messages are delivered to us by email; they are not added to a marketing database.
Technical data
- Standard server logs. IP addresses are used transiently for rate limiting and security.
- We run no analytics, no advertising trackers, and no third-party tracking cookies on the website or in the platform. See Cookies below.
3. How we use personal data, and our legal bases
Under the GDPR and equivalent laws, we rely on the following legal bases:
- To provide the service — create and secure your account, authenticate you, operate the platform, meter usage, and bill paid plans. Basis: performance of a contract.
- To keep the service secure and reliable — prevent fraud and abuse, debug, and improve the product; respond to your support requests. Basis: our legitimate interests.
- Service communications — important notices about your account, security, and changes to these terms. Basis: contract / legitimate interests.
- Marketing communications, where sent — only with your consent, and you can opt out at any time. Basis: consent.
- Legal and accounting obligations — e.g. keeping tax records. Basis: compliance with a legal obligation.
4. Your end users’ data
Fluidlee is a backend for your product. The records your tenants and end users create are your data, held on your behalf. We do not require personal data about your end users — at most an opaque actor identifier you choose to pass so the audit log can record who did what. No names, no emails, no personal data are required by us. We do not sell, mine, or use that data for anything other than serving your API.
For that data, you are the controller and we are your processor. Our obligations are set out in the Data Processing Agreement, and a current list of the subprocessors involved is available on request. Requests from your end users about their data should be directed to you, as controller.
5. Sharing and subprocessors
We share personal data only with the vendors that help us run the service — hosting, email delivery, and (once enabled) payment processing and optional AI features. A current list of these vendors, with each one’s purpose and location, is available on request — email hello@fluidlee.com.
We do not sell your personal data, and we do not “share” it for cross-context behavioral advertising (as those terms are defined under California law). We may disclose data where required by law, to protect our rights or users’ safety, or in connection with a merger or acquisition — in which case we will notify you and this policy will continue to apply.
6. International data transfers
We operate from the State of Israel. Some of our subprocessors are located in the United States or elsewhere, so your personal data may be transferred outside your country. Where the law requires it, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses — for those transfers.
7. How long we keep data
The retention periods below are our proposed defaults, to be confirmed with counsel:
- Account data — for as long as your account is active, then deleted or anonymized within a reasonable period after closure.
- Billing and tax records — retained up to 7 years after the relevant transaction, as required by Israeli tax and accounting law.
- Contact-form messages — kept for up to 24 months, then deleted.
- Backups — rolling backups are overwritten on a short cycle (around 30 days).
- Audit logs on your projects — retained per your plan tier (7 / 30 / 365 days). This is your data under the DPA.
8. Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- EEA / UK (GDPR): access, rectification, erasure, restriction of processing, data portability, objection to processing, and the right to withdraw consent. You may also lodge a complaint with your local supervisory authority.
- Israel (Privacy Protection Law): the right to review the personal data we hold about you and to request its correction.
- California (CCPA/CPRA): the right to know, delete, and correct your personal information, and to opt out of its sale or sharing — noting that we do not sell or share personal information. We honor Global Privacy Control (GPC) signals, and we will not discriminate against you for exercising your rights.
To exercise any of these, email hello@fluidlee.com. We may need to verify your identity first. Where we hold data only as a processor on a customer’s behalf, we will refer your request to that customer.
9. Security
We protect personal data with appropriate technical and organizational measures, including encryption in transit, passwords stored as strong salted one-way hashes, API keys stored only as hashes, logical tenant isolation enforced at the database layer (with dedicated databases available on Enterprise), strict access controls, and audit logging. You can read more on our security page. Detailed technical measures are available to enterprise customers under NDA on request. No method of transmission or storage is ever 100% secure, and we cannot guarantee absolute security.
10. Cookies and tracking
The marketing site sets no cookies and runs no analytics or trackers. It does load web fonts from Google Fonts, which means your IP address is exposed to Google when a font is fetched, but no cookie is set. The platform uses only strictly necessary authentication tokens to keep you signed in — never advertising or cross-site tracking cookies. Because we use no non-essential cookies, no consent banner is required and there is no separate cookie policy.
11. Children
Fluidlee is a business tool that is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the date above, and we will give notice of material changes where required.
13. Contact
Fluidlee Ltd.
Timna 1, Hafetz Haim Israel
Questions about this policy or your data:
hello@fluidlee.com.