Privacy Policy
Last updated: May 2026
1. Who We Are
Foixar Corporation (“Foixar”, “we”, “our”) is a United States company based in Texas. We operate the Foixar platform at foixar.com and app.foixar.com. This policy explains how we collect, use, and protect personal data when you visit our website, request a trial, connect developer systems, or use the Foixar platform.
2. Data We Collect
We collect data in the following ways:
- Lead, trial, and account data — name, work email, company name, contact messages, invite status, tenant membership, and trial provisioning details.
- Authentication data — identity claims from Microsoft Entra ID or federated identity providers configured through Microsoft identity services.
- Customer content — connected repositories, pull requests, diffs, feature briefs, generated specifications, generated code artifacts, business context uploads, captured decisions, governance reports, and audit trails.
- Integration data — configuration and metadata for connected systems such as GitHub, Azure DevOps, Microsoft Teams, tenant-selected AI model providers, and tenant-selected storage providers.
- Usage data — platform interactions, feature runs, governance reviews, rule activity, decision lifecycle activity, and audit logs.
- Technical data — IP address, browser type, device information, and cookies.
- Communications — messages you send us via contact forms or email.
3. How We Use Your Data
- To provide, maintain, and improve the Foixar platform.
- To authenticate users and enforce tenant isolation.
- To provision trials, process lead enquiries, and support customer onboarding.
- To run AI-assisted specification, code generation, governance, audit, and decision-memory workflows using the tenant's configured resources.
- To send transactional communications (platform alerts, run notifications).
- To respond to enquiries and support requests.
- To comply with legal obligations.
4. Tenant Data Isolation
All customer data is scoped to its originating tenant. No tenant can access data belonging to another tenant. Tenant identity is derived from validated authentication tokens — never from request payloads.
5. Data Storage and Security
Foixar-operated platform services run on Microsoft Azure. Tenant-connected resources, including AI model endpoints and storage, may reside in the cloud provider, region, and account selected by the tenant. We use Azure Key Vault for Foixar-managed secrets, Microsoft Entra ID for identity, tenant-scoped authorization checks, and TLS 1.2+ for data in transit. We do not store provider secrets in application configuration files.
6. Cookies
We use essential cookies for authentication and session management, and analytics cookies (Google Analytics) to understand how visitors use our site. You can control non-essential cookies via your browser settings.
7. Third-Party Services
We use the following third-party services and integrations to operate the platform or to connect systems selected by a tenant:
- Microsoft Azure — hosting, storage, identity
- Cloudflare — CDN, WAF, and DDoS protection
- Google Analytics — anonymised usage analytics
- Azure DevOps — integration for customers who connect their ADO organisation
- GitHub — repository, pull request, check run, issue, and GitHub Projects integration for customers who install the Foixar GitHub App
- Microsoft Teams — bot and decision capture workflows where enabled
- Tenant-selected AI and storage providers — such as Azure OpenAI or Azure AI Foundry, AWS Bedrock, Google Vertex AI, Azure Blob Storage, Amazon S3, or Google Cloud Storage, depending on tenant configuration
8. Your Rights
Under GDPR and applicable data protection law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data (“right to be forgotten”).
- Object to or restrict processing.
- Request portability of your data.
To exercise any of these rights, email us at privacy@foixar.com.
9. Retention
We retain lead and trial data for as long as needed to respond to the enquiry, administer the trial, and maintain sales and compliance records. Customer Data is retained for the duration of your contract or trial, unless deleted earlier through the platform or under a written agreement. Chat/session data and operational logs are retained for 90 days by default. Governance audit logs, decision history, and compliance records may be retained for up to 7 years. Data stored in tenant-selected resources is subject to the tenant's own retention settings with that provider.
10. Contact
For any privacy enquiries, contact our Data Protection team at privacy@foixar.com.