Privacy Policy
Version 1.0, effective September 22, 2026
This Privacy Policy explains how Filohealth Software, Inc., registration number 10746556, a Delaware corporation with its registered address at 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States, operating the website https://filo.inc and https://meetfilo.io ("Filo", "we", "us", "our"), handles personal data when you visit our websites, book a demo, create an account, or use the Filo services. It covers the data we handle as a controller, and it explains where we act only as a processor for a customer. It is written to meet the GDPR and UK GDPR, the Swiss FADP, and United States state privacy laws, and it tells people in other countries what rights they have here.
1. Who we are and what this policy covers
The controller for the data described in this policy is Filohealth Software, Inc., registration number 10746556, 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States. You can reach us, including our data protection contact, at daniel@meetfilo.io. We have not appointed a statutory Data Protection Officer, because we are not required to, and that address reaches the person responsible for data protection at Filo.
This policy applies to our marketing websites, to the demo booking on them, to the Filo product, and to the emails and support we send you. It does not apply to the personal data that a customer puts into its own workspace, such as its patients' messages: for that data the customer is the controller, we are its processor, and the customer's own privacy notice applies. The roles section below explains the difference.
In short:
- We do not sell personal data, and we never have.
- We do not use anyone's personal data, or any customer content, to train AI models, and our AI providers are contractually forbidden from doing so.
- Product data is hosted in the European Union.
- Analytics and advertising cookies on our marketing websites run only after you accept them, and a Global Privacy Control signal counts as a refusal. Inside the product we use sign-in cookies and product analytics, described below.
- You can ask for a copy of your data, a correction, or deletion at any time by emailing us, and we answer within 30 days.
- Health information only ever reaches us inside a customer's workspace, where we act on that customer's instructions under a Data Processing Agreement.
2. The data we collect
We collect the following categories of personal data, and no more than we need for the purpose it was collected for:
- Account data: your name, email address, password (stored hashed, never in readable form), profile photo where you set one, language, workspace membership, and role.
- Business data: the business details, brand information, goals, and settings you add to your workspace, including the website address you ask us to scan.
- Billing data: billing name, address, VAT identification number, plan, invoices, and payment records. Card and bank details are entered directly with our payment provider and never reach our servers.
- Connected accounts: when you link a WhatsApp, Instagram, Facebook, Meta Ads, TikTok, or Google account, the account's name and identifiers, the access tokens (stored encrypted), and the data those platforms provide to us, described in the next section.
- Content you create: the posts, captions, images, ad creatives, offers, and media you or the services produce in your workspace.
- Usage and technical data: log data and product events describing how the services are used, IP address, browser and device type, operating system, referring page, timestamps, and error reports. On our own systems this is used to run, secure, and debug the services.
- Approximate location: a country and city estimated from your IP address by our analytics and hosting providers. We do not collect GPS or precise location.
- Records of consent: the version of the Terms of Service and Privacy Policy you accepted, when you accepted them, and the IP address and browser string at that moment, kept as proof of acceptance.
- Demo bookings: when you book a demo, your first and last name, email address, website, chosen time and time zone, the UTM parameters and any advertising click identifier in your visit, and the meeting created for you.
- Communications: the messages you send us, such as support requests, sales emails, and anything you write in a form, together with our replies.
- Waitlist and signup source: where signup is limited, your email address, the campaign or link you arrived from, and whether you have been admitted.
3. Data from connected platforms (Meta and TikTok)
When a customer links an account from their workspace, Filo connects to the WhatsApp Business Platform, Instagram, Facebook Messenger and Pages, and Meta Ads, operated by Meta Platforms ("Meta"), and to TikTok. We use the platforms' official interfaces (the Meta Graph API, the WhatsApp Business Platform, the Meta Marketing API, and the TikTok Login Kit and Content Posting API) and request only the permissions the services need. This section describes the data we receive from those platforms, how we use it, and how it is deleted. The customer who connects an account is the controller of the messages, contacts, and content in it, and Filo processes that data as the customer's processor under our Data Processing Agreement.
Messaging (WhatsApp, Instagram, Messenger). We receive the messages exchanged with the connected WhatsApp Business number, Instagram professional account, or Facebook Page, including attachments, the sender's profile name, username, or platform ID, the sender's phone number on WhatsApp, timestamps, and delivery status. We use this data to show the conversation in the customer's inbox, to send the replies the customer or its team write, to draft or send replies generated by AI where the customer has enabled that, and to keep the conversation history for the customer. For WhatsApp campaigns we also receive the customer's approved message templates and the delivery status of each message sent.
Content (Instagram, Facebook Pages, TikTok). We receive the name, username, and identifiers of the connected account and of the Pages or accounts the customer manages, we publish the posts the customer approves to the account on the customer's behalf, and we read the results of those posts (reach, likes, comments, saves, and shares) to report how they perform. On TikTok we also read the account's posting options, such as the privacy levels available for a post, so the customer can choose them before publishing.
Advertising (Meta Ads). We receive the ad accounts and Pages the customer gives us access to, the campaigns, ad sets, ads, and creatives in them, and their performance data (spend, impressions, reach, clicks, results, and the countries ads were delivered in). We use this data to create and manage campaigns on the customer's instructions and to report their performance. We do not receive information about the individual people who see or click ads.
How we use and share it. We use data from Meta and TikTok only to provide the services described above to the customer who connected the account, to support that customer, and to keep the services secure. We do not use it for our own purposes: we do not sell it, do not use it to advertise to anyone, do not share it with data brokers or advertising networks, do not use it to build profiles of the people who message our customers outside the customer's own inbox, and do not use it to train or improve AI models. We share it only with the customer, with the subprocessors that host and operate the services, listed at the Filo Trust Center, under data protection agreements that restrict their use of it, with the platform itself when delivering the messages, posts, and ads the customer directs, and where the law requires. Our use of Meta data complies with the Meta Platform Terms and Developer Policies and, for WhatsApp, the WhatsApp Business Terms of Service. Our use of TikTok data complies with the TikTok Developer Terms of Service.
Storage and retention. Platform data is stored on servers in the European Union and encrypted in transit and at rest, and access tokens are stored encrypted. We keep it for as long as the account stays connected and the workspace is active, subject to the retention periods in the Retention section and in our Data Processing Agreement, and delete it on the timelines set out there when the workspace is closed.
Disconnecting and deleting platform data. You can remove Filo's access and have platform data deleted at any time:
- Disconnect the account in your workspace under Settings, Integrations. We delete the access tokens and the conversations and posts stored for that account, and stop receiving data from it.
- Remove Filo in the platform's own settings: on Facebook and Instagram under Settings, Business integrations, and on TikTok under Settings and privacy, Security and permissions, Manage app permissions. The platform then revokes our access.
- Email daniel@meetfilo.io from the email address on your account to ask us to delete the data we hold from a connected platform, or all of your workspace data. We confirm the request and complete the deletion within 30 days.
- If you are a person who messaged one of our customers and want your data deleted, contact that customer, who is the controller, or email daniel@meetfilo.io and we will pass your request to the customer and assist with it.
4. Our two roles: controller and processor
Controller. For the people who visit our websites, book a demo, create an account, pay us, or write to us, Filo decides why and how the data is handled, so we are the controller and this policy is your notice.
Processor. For the personal data inside a customer's workspace, including the messages, calls, contacts, and files of that customer's patients and clients, the customer decides why and how the data is handled. The customer is the controller, we are its processor, and we act only on its documented instructions. That processing is governed by our Data Processing Agreement, available in an EU version meeting Article 28(3) GDPR and a United States version covering HIPAA and CCPA from the Filo Trust Center, and not by this policy.
If you are a patient or client of a business that uses Filo and you want to see, correct, or delete your data, contact that business first: it holds the relationship and the record. If you write to us instead we will pass your request to it without undue delay and help it answer, as our Data Processing Agreement requires.
Joint controllership. For the Meta Pixel on our marketing website, Filo and Meta jointly decide the purposes of the collection and transmission of the event data, so we are joint controllers with Meta for that step within the meaning of Article 26 GDPR, under Meta's Controller Addendum. Meta's own later processing of that data is its own responsibility. The advertising and measurement section explains what is collected and how to refuse it.
5. How we use data
We use personal data for these purposes, and no others:
- To provide the services: creating and running your account and workspace, connecting the platforms you link, generating and publishing content, handling conversations and calls, and running campaigns.
- To operate and secure the services: monitoring availability, investigating errors, detecting and preventing abuse, fraud, and security incidents, and keeping audit logs.
- To support you: answering your questions, and providing the hands-on assistance described in our Terms of Service, which may involve our staff working inside your workspace.
- To bill you: taking payment, issuing invoices, recovering unpaid amounts, and keeping accounting records.
- To communicate with you: service messages about your account, changes to these documents, security notices, and, where you have asked for them or the law allows, product and marketing emails you can unsubscribe from in one click.
- To improve the services: understanding which features are used and where people get stuck, using product analytics. This never involves training AI models on your data.
- To measure our marketing: understanding which pages and advertising campaigns lead to a demo booking, where you have accepted analytics and advertising cookies.
- To comply with the law: tax and accounting duties, responding to lawful requests from authorities, and establishing, exercising, or defending legal claims.
6. Legal bases
Under the GDPR and UK GDPR we rely on the following legal bases. Where we rely on a legitimate interest, we have weighed it against your rights and you can object at any time, as set out in the rights section.
- Performance of a contract, Article 6(1)(b): creating and running your account and workspace, providing the services and support, billing, and the demo you booked.
- Legitimate interests, Article 6(1)(f): securing and operating the services, preventing abuse and fraud, product analytics to improve what we build, direct marketing to business contacts about services like the ones they asked about, keeping records to defend legal claims, and the internal notifications that tell our team a signup or booking happened.
- Consent, Article 6(1)(a): analytics and advertising cookies on our websites, the Meta Pixel and the events we mirror to Meta, and marketing emails where consent is required. You can withdraw consent at any time, with no effect on what happened before.
- Legal obligation, Article 6(1)(c): accounting and tax records, and answering lawful requests from authorities.
- We do not rely on consent, or on any other basis, to process special categories of data for our own purposes: we do not collect health data as a controller. Health data reaches us only inside a customer's workspace, where the customer is the controller and its own legal basis under Articles 6 and 9 applies.
7. AI and your data
Parts of the services use artificial intelligence to draft content and images, answer messages, handle calls, transcribe audio, and suggest campaigns. The models are run by providers we engage as processors and list at the Filo Trust Center: OpenAI for language models, Deepgram for speech to text, ElevenLabs for speech synthesis, and LiveKit for real-time audio. Each is bound by a written data protection agreement, each is configured to process in the European Union, and each is contractually prohibited from using the data we send for model training.
No training on your data. Filo does not use personal data, customer content, conversations, calls, or documents to train, fine-tune, or improve any AI model, our own or anyone else's. This also applies to aggregated and anonymized derivatives of that data: we do not build training sets, benchmarks, or prediction models out of it. We keep the settings that enforce this, such as switching off stored responses at OpenAI and opting out of Deepgram's model improvement programme, and we publish each control with the date we last verified it at the Filo Trust Center.
Transparency under the EU AI Act. Filo is the provider of the AI systems in the services and a customer using them is the deployer, within the meaning of Article 3 of Regulation (EU) 2024/1689. Our assistant tells people that they are speaking with an AI assistant, as Article 50(1) requires, and images, audio, and video that the services generate are marked in a machine-readable way where the model provider supports it, as Article 50(2) requires. A customer who publishes AI-generated material has its own disclosure duties under Article 50(4), set out in our Terms of Service.
No decisions made by a machine alone. We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. The services draft and suggest; a person in the business decides. Where a customer switches on automatic replies, the messages that go out are still that customer's responsibility and are not decisions about a person in the sense of Article 22.
Likeness and publicity. We do not use anyone's name, image, voice, or likeness to generate content, and our Terms of Service forbid customers from doing so without the person's consent. If you believe content generated through Filo uses your likeness without your permission, write to daniel@meetfilo.io and we will act on it.
8. Sharing and disclosures
We do not sell personal data, and we do not share it with data brokers. We disclose it only in these situations:
- Processors that run the services for us, under written data protection agreements that limit them to our instructions. The current list, with each one's purpose, location, data categories, and safeguards, is published at the Filo Trust Center. In summary: hosting and infrastructure (Railway, Amsterdam; Amazon Web Services, Frankfurt; Vercel, Frankfurt), AI providers (OpenAI, Deepgram, ElevenLabs, LiveKit, all in the EU), payments (Stripe, United States), email and SMS (Resend, Dublin; Twilio, Ireland), product analytics (PostHog, Frankfurt), demo scheduling and CRM (HubSpot), and internal team notifications (Slack, United States, which receives a signup or booking name and email address, never patient data).
- Platforms you connect yourself, such as Meta and TikTok, when we deliver the messages, posts, and ads you direct through the services. They act under their own terms with you, not as our processors.
- Meta, for advertising measurement on our marketing website, where you accepted advertising cookies. See the advertising and measurement section.
- Professional advisers, such as lawyers, accountants, and auditors, who are bound by professional confidentiality.
- Authorities, courts, and regulators, where we are legally required to disclose, or where disclosure is necessary to establish, exercise, or defend legal claims. We check that a request is valid, disclose the minimum needed, and tell the customer concerned unless the law forbids it.
- An acquirer, in a merger, acquisition, financing, or sale of assets, under confidentiality, and with notice to you before your data becomes subject to a different privacy policy.
- Anyone you ask us to share with, on your instruction.
9. Cookies and similar technologies
Our websites use three kinds of cookies and similar storage. Nothing but the strictly necessary kind is set before you accept it in the banner.
- Strictly necessary: session and sign-in cookies that keep you logged in to the product and protect the form against abuse, and the cookie that remembers your cookie choice itself. These are exempt from consent because the site cannot work without them.
- Analytics: PostHog, which tells us which pages are visited and where people get stuck. On our marketing websites it runs only after you accept. Inside the product it runs for signed-in users and is described below.
- Advertising and measurement: the Meta Pixel and the _fbp and _fbc identifiers it writes, on the Italian advertising landing page only. These run only after you accept.
10. Your cookie choice, and how to change it
When you first visit one of our marketing websites you are asked whether analytics and advertising cookies may be used. Until you accept, neither the Meta Pixel nor PostHog is loaded at all, no advertising identifier is written, and no event is sent to Meta. Your answer is stored in your browser and in a first-party cookie named filo_consent, so we do not have to ask again for 180 days, and you can change it at any time with the Cookies link in the footer of the site.
If your browser sends a Global Privacy Control signal we treat that as a refusal, do not load analytics or advertising cookies, and do not show you the banner at all. Refusing costs you nothing: every part of the site, including the demo booking, works the same.
Inside the product, at use.filo.inc, we use cookies needed to sign you in and keep your session secure, and product analytics that record how the features are used. Once you sign in, those analytics are linked to your user id, your name, and your email address, so we can tell whether a change actually helped the people using it. Session recording is switched off, and patient data and message content are never sent to analytics. We rely on our legitimate interest in improving the product for this, and you can object at daniel@meetfilo.io.
11. Advertising and measurement
We advertise Filo on Meta's platforms. To know which ads bring demo bookings, our advertising landing page uses the Meta Pixel and, for the same events, Meta's Conversions API, which sends the event from our server instead of your browser. Both run only if you accepted advertising cookies.
What is sent. For a page view: the page address, a random event id, the Meta advertising identifiers in your browser (_fbp and _fbc), your IP address, and your browser string. For a demo booking: the same, plus your email address, first name, last name, and our contact id for you, each hashed with SHA-256 before it leaves our server, so Meta receives a fingerprint rather than readable details. Meta uses these to match the event to an account and to report and optimize our campaigns, as a joint controller with us for the collection and transmission step and as its own controller afterwards.
How to refuse. Decline in the cookie banner, or send Global Privacy Control, and none of this happens: no pixel, no identifiers, and no server-side event, which our server also enforces by checking your stored choice before it sends anything to Meta. You can also control advertising in your own Meta account settings. Meta's handling of the data it receives is described in the Meta Privacy Policy.
Demo bookings. When you book a demo, your name, email address, website, and chosen time are stored in our CRM, HubSpot, which acts as our processor, so that we can hold the meeting and follow up about it. The UTM parameters and advertising click identifier from your visit are stored with the booking so we can tell which campaign it came from, and our team gets an internal notification in Slack with your name and email address. We use these details to prepare and hold the demo and to follow up about Filo; you can ask us to delete them at any time.
12. Social logins and connected accounts
You can create an account or sign in with Google, and you can connect Meta and TikTok accounts to your workspace. When you do, the platform asks you to approve what we may access, and we request the narrowest set of permissions the feature needs. From a sign-in we receive your name, email address, profile picture, and the platform's account identifier, and we use them only to create and secure your Filo account.
We never post, message, or advertise on a connected account except where you have asked us to, through the services. Nothing is published without your approval, unless you have switched on automatic publishing or automatic replies in your workspace settings.
You stay in control. Disconnect an account at any time in your workspace settings, or revoke our access in the platform's own settings, and we stop receiving data from it. The connected platforms section above explains exactly what we then delete and how to ask us to delete more.
13. Google user data
Filo's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice:
- We request only non-sensitive scopes: your basic profile and email address for sign-in, and, where a booking feature needs it, access to the specific calendar you point us at.
- We use Google user data only to provide and improve the feature you asked for, never for advertising, and never to build a profile of you.
- We do not sell Google user data and do not transfer it to others, except as needed to provide the feature, to comply with the law, or as part of a merger where you are given notice.
- No human at Filo reads your Google user data, except with your consent, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymized.
- You can revoke our access at any time in your Filo profile settings or at myaccount.google.com under third-party access, and you can ask us to delete what we hold by emailing us.
14. Design and media tool integrations
Where the services offer an integration with a third-party design, media, or stock content tool, we receive only what is needed to import into your workspace what you choose to import: the files themselves and the identifiers and tokens that allow the import. We do not read your other projects or files in that tool, we keep the imported material inside your workspace under the same protection as the rest of your data, and we return, delete, or stop using it when you disconnect the integration or close your workspace. Import and usage limits set by us or by that tool may apply, and its provider's own privacy notice covers what it does with your data. Where an integration partner requires it, we notify that partner of a security incident affecting data shared through the integration within 48 hours of becoming aware of it, in addition to the notifications described in the security section.
15. AI assistants and connectors
Inside the product, the advertising assistant ("Ask Filo") answers questions about your connected ad account. When you ask it something, your question and the ad account data needed to answer it are sent to our language model provider, and account queries run against Meta's hosted advertising connector using the access token you granted when you connected the account. No new provider is involved beyond the ones listed at the Filo Trust Center, and no patient conversation is sent to that connector.
The assistant reads and drafts. Creating, changing, or launching anything in your ad account needs your approval in the product, and every action we take is written to the workspace's activity log with who asked for it and when, kept as an operational record.
If we later offer a connector that lets a third-party AI assistant reach your Filo workspace, it will be off unless you switch it on, will use OAuth with PKCE so that you approve it in Filo and can revoke it at any time, will be limited to the scopes you approve, and will give the assistant no access to anything outside them. The provider of the assistant you choose is not our processor: what it does with what you send it is governed by its own privacy policy.
16. How long we keep data
We keep personal data only as long as we need it, and then delete it or make it permanently anonymous. The periods below apply unless the law requires us to keep something longer, or a legal claim is pending.
- Account and workspace data: for as long as the account is open. When a workspace is closed we return or delete Customer Data as set out in the Data Processing Agreement, and no later than 30 days after you ask us to delete it.
- Call recordings and call audio: 30 days from the call. Call transcripts: 12 months from the call.
- Files sent by your patients and clients in a conversation, such as photos, voice messages, videos, and documents: 90 days from when they arrive. The text we derived from a file, such as a description or a transcript, stays with the message.
- Contact lists uploaded for a messaging campaign, both the file as uploaded and the cleaned recipient list: 12 months from the upload. The messages sent stay in the conversation history.
- Access tokens for connected platforms: until you disconnect the account or close the workspace, and then deleted.
- Billing records, invoices, and tax documents: for the period tax and accounting law requires, up to 10 years.
- Records of which policy version you accepted, with the timestamp, IP address, and browser string: for as long as the account exists and then for the period in which a claim about the agreement can still be brought.
- Demo bookings and sales correspondence: up to 24 months after our last contact, unless you become a customer or ask us to delete them sooner.
- Support emails: up to 24 months after the request is closed.
- Website and product analytics events: up to 12 months.
- Security and access logs: up to 12 months, longer only where an incident is being investigated.
- Backups: encrypted backups run on a rolling cycle and expire automatically, so deleted data disappears from them when the cycle completes rather than immediately.
17. Security
We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit with TLS 1.2 or higher and at rest with AES-256, role-based access on a least-privilege basis, multi-factor authentication and single sign-on for administrative access, private networking between the application and the database, encrypted daily backups with tested restores, dependency and vulnerability scanning, code review before deployment, audit logging, and confidentiality obligations and security training for everyone with access. The full list is published at the Filo Trust Center and annexed to our Data Processing Agreement.
No system is perfectly secure, and we cannot guarantee that data will never be compromised. If a personal data breach does happen, we notify the competent supervisory authority within 72 hours of becoming aware of it where Article 33 GDPR requires, notify affected customers without undue delay and within 24 hours under our EU Data Processing Agreement so they can meet their own duties, notify affected individuals where the risk to them is high under Article 34 GDPR, and give the notices that United States state breach laws require within their deadlines.
Help us keep it secure: use a strong and unique password, turn on multi-factor authentication where it is offered, remove users who no longer need access, and tell us at daniel@meetfilo.io if you think an account has been compromised or you have found a vulnerability. We do not take legal action over good-faith security research reported to us privately.
18. International transfers
Product data is hosted in the European Union: the application, the background workers, and the database run in Amsterdam, the Netherlands, file and media storage runs in Frankfurt, Germany, and our AI providers process in the European Union.
Filo is a United States company, so some personal data reaches the United States: our own staff account for support and the hands-on assistance described in our Terms of Service, our payment provider, and our internal notification tool. Where personal data leaves the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, on the UK International Data Transfer Addendum where the UK GDPR applies, and on the Swiss addendum recognized by the Federal Data Protection and Information Commissioner, together with a transfer impact assessment and the supplementary measures described in our Data Processing Agreement. Where a provider is certified under the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. framework, as Stripe is, we may also rely on the European Commission's adequacy decision of 10 July 2023, which does not replace the Clauses.
You can ask us for a copy of the safeguards that apply to a particular transfer by writing to daniel@meetfilo.io.
19. Your privacy rights and how to use them
Wherever you live, you can ask us to do the following, and we will do it unless the law allows or requires us to refuse, in which case we explain why:
- Access: get confirmation of whether we hold data about you and a copy of it, with the information this policy sets out.
- Correction: have inaccurate data corrected and incomplete data completed.
- Deletion: have your data deleted where we no longer need it, where you withdraw consent and there is no other basis, or where you successfully object.
- Restriction: have processing paused while a correction or an objection is being considered.
- Portability: receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where technically feasible.
- Objection: object at any time to processing based on our legitimate interests, and object absolutely to direct marketing, which we then stop.
- Withdraw consent: withdraw a consent you gave, such as cookies or marketing emails, at any time, without affecting what was lawful before.
- Complain: lodge a complaint with a supervisory authority, without first coming to us.
20. Making a request
Email daniel@meetfilo.io and say what you want. Account holders can also see and edit most of their data in the product at any time, under Settings. We answer within 30 days, and tell you within that period if a complex request needs longer, which the GDPR allows by up to two further months. Requests are free unless they are manifestly unfounded or excessive, in which case we say so before doing anything.
We may ask you for enough information to be sure the request is really yours, especially before we send or delete data. We do not collect extra identification for its own sake: usually answering from the email address on the account is enough. An authorized agent may make a request for you where state law allows, with proof that you authorized them.
If the data is inside a customer's workspace, we are the processor and not the controller. We will forward your request to that customer without undue delay and help it answer, but the customer decides. Tell us the name of the business if you know it, so we can route the request.
If you are unhappy with how we handled a request, write to us again and ask for it to be reviewed; we answer an appeal within 45 days. You can also complain to a regulator, as described in the sections for your region below.
21. Do Not Track and Global Privacy Control
Most browsers can send a "Do Not Track" signal. There is still no agreed standard for what a website must do when it receives one, so, like most operators, we do not respond to it. If that changes we will update this policy.
We do honor Global Privacy Control. A GPC signal from your browser or extension is treated as a refusal of analytics and advertising cookies, and, where the CCPA applies to you, as a valid request to opt out of the sale or sharing of your personal information. No pixel, advertising identifier, or server-side advertising event is created for a visit that carries it, and the consent banner is not shown.
22. EEA, UK, and Switzerland
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection applies to our processing, and the rights in the rights section above are yours under Articles 15 to 22 and 7(3) GDPR and their equivalents.
The controller is Filohealth Software, Inc., 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States, reachable at daniel@meetfilo.io. We have not appointed an Article 27 representative in the Union or the United Kingdom, because our processing of the personal data of people in those territories is occasional, is not large scale, and does not involve special categories of data as a controller. You can raise any question with us directly in your own language at the address above.
You can complain to the supervisory authority of the country where you live or work, or where you think the problem happened, under Article 77 GDPR. For Italy that is the Garante per la protezione dei dati personali, for Spain the Agencia Española de Protección de Datos, for the United Kingdom the Information Commissioner's Office, and for Switzerland the Federal Data Protection and Information Commissioner. You also have the right to an effective judicial remedy under Article 79 GDPR, and to compensation for damage caused by unlawful processing under Article 82.
23. United States state privacy rights
If you live in a United States state with a comprehensive privacy law, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and the other states whose laws are in force, you have the right to know what we collect and why, to get a copy of it, to have it corrected, to have it deleted, to opt out of targeted advertising and of the sale or sharing of personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. Use the same address, daniel@meetfilo.io, and we answer within 45 days, extendable once where the law allows. If we refuse, you may appeal by replying to our answer; we decide an appeal within 45 days and tell you how to contact your state Attorney General if you remain unsatisfied.
Categories collected in the last 12 months, in the CCPA's terms: identifiers (name, email address, account and device identifiers, IP address), commercial information (plan, invoices, purchases), internet or network activity (pages visited, product events, interaction with our emails), approximate geolocation derived from an IP address, professional or employment-related information (your role and the business you work for), audio and visual information where a customer's workspace handles calls or images, and the contents of your communications with us. We collect them from you, from your device, from the platforms you connect, and from our advertising and scheduling providers, for the business purposes listed in the "How we use data" section, and we disclose them to the categories of recipient listed in the "Sharing and disclosures" section.
Sale and sharing. We do not sell personal information for money and never have. Where you accept advertising cookies, the Meta Pixel and the events we mirror to Meta may count as "sharing" for cross-context behavioural advertising under the CCPA. Declining in the banner, or sending Global Privacy Control, opts you out, and you can also write to us. We do not knowingly sell or share the personal information of anyone under 16.
Sensitive personal information. We do not collect sensitive personal information as a business for our own purposes, and we do not use or disclose any for purposes that require the right to limit. Health information reaches us only inside a customer's workspace, where we act as that customer's service provider and may use it only to provide the services, which our Data Processing Agreement requires.
California Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to report under California Civil Code section 1798.83, but you may ask us to confirm it at daniel@meetfilo.io.
24. Other countries
Wherever you are, you may use the rights in the rights section above by writing to daniel@meetfilo.io, and we apply them to everyone rather than only where a law compels us. Where your national law gives you more, it applies as well: this includes the Personal Information Protection and Electronic Documents Act in Canada, the Privacy Act 1988 and the Australian Privacy Principles in Australia, the Privacy Act 2020 and its information privacy principles in New Zealand, including the rules on disclosing information outside the country, and the Lei Geral de Proteção de Dados in Brazil. Tell us where you are when you write, so we can apply the right rules and deadlines, and you can always complain to your national privacy regulator.
25. Children and minors
The services are sold to businesses and are not directed at children. You must be at least 18 to accept our Terms of Service or use the services, and we do not knowingly collect personal data from children for our own purposes, which means we do not knowingly collect data from children under 13 in the sense of the Children's Online Privacy Protection Act, or from anyone under 16 in the sense of the state laws that raise the age for advertising and profiling.
If a child's data reaches a customer's workspace, for example because a parent writes to a clinic about their child, the customer is the controller and its own rules and consents apply; we process it only on that customer's instructions.
If you believe a child has given us personal data for our own purposes, write to daniel@meetfilo.io and we will delete it.
26. Review, update, or delete your data
You can see and change most of your data yourself: your name, email address, password, and language under Settings, your business details and brand information under Settings, Brand, your connected accounts under Settings, Integrations, and your billing details and invoices under Settings, Billing. Closing a connected account or deleting content there takes effect immediately.
To receive a copy of your workspace data, or to have your account and everything in it deleted, email daniel@meetfilo.io from the address on the account. We confirm the request, provide the export, and complete the deletion within 30 days, keeping only what the law requires us to keep, such as invoices and the record of the agreement you accepted. Backups holding a copy expire on their own cycle and are not restored to bring deleted data back.
27. Changes to this policy
We update this policy when what we do changes, or when the law does. Where a change is material, for example a new purpose, a new category of recipient, or a new transfer, we tell you in the product or by email at least 30 days before it takes effect, and ask account holders to accept the new version. Smaller changes, such as clarifications and updated references, take effect when published.
The version number and effective date at the top of this document identify the current policy. We keep a record of which version you accepted and when.
28. Contact us
Filohealth Software, Inc., registration number 10746556, 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States. Website: https://filo.inc and https://meetfilo.io. Email: daniel@meetfilo.io for privacy questions, data requests, security reports, and anything else in this policy. Our subprocessor list, our security measures, and our Data Processing Agreement are published at the Filo Trust Center.