← Foliary

Data Processing Agreement

Last updated 2026-09-21

1. Roles

The Controller is the customer. They decide to capture their conversations, whose conversations those are, and what is done with the result.

The Processor is Belim & Co, acting only on the Controller's instructions.

The data subjects are the Controller, and the people the Controller talks to on Voxer — who are not parties to this agreement and in most cases will not know it exists. The Controller is responsible for having a lawful basis for their data (Terms §3).

For the Controller's own account and billing data, Belim & Co is a controller in its own right and the Privacy Policy governs that, not this agreement.

2. Subject matter, duration, nature and purpose

Subject matterCapturing, transcribing, summarizing, classifying, storing and serving back the Controller's Voxer conversations
DurationFor as long as the subscription is active, plus the retention period in §11
NatureAutomated processing, including automated speech-to-text and AI-generated summaries and classification
PurposeProviding Foliary to the Controller

3. Types of personal data

3.1 ⚠️ Prohibited data

The Controller must not use Foliary to process protected health information (PHI) as defined under HIPAA, or any data subject to HIPAA. Belim & Co is not a HIPAA business associate, will not sign a Business Associate Agreement, and Foliary is not built to HIPAA standards. A Controller whose conversations involve PHI must not connect Foliary.

Conversation content is unstructured and its contents are outside the Processor's control: a coaching conversation may contain health, financial or other sensitive details, and the Processor cannot detect or filter this. The prohibition above is the Controller's responsibility to observe, and the Processor cannot enforce it technically.

4. Categories of data subject

The Controller, and the Controller's clients, team members, partners, mentors and other correspondents on Voxer.

5. Processor's obligations

The Processor shall:

  1. process personal data only on the Controller's documented instructions, which are these terms and the Controller's use of the product, unless required otherwise by law — in which case it will tell the Controller first, unless the law forbids that;
  2. ensure personnel with access are bound by confidentiality;
  3. take the security measures in §6;
  4. not engage a sub-processor except under §7;
  5. help the Controller respond to data-subject requests (§8);
  6. help the Controller with security, breach notification and impact assessments, given the information available to it;
  7. delete or return personal data at the end of the service, per §11;
  8. make available the information needed to show compliance with these obligations, and allow and contribute to audits — see §12.

The Processor does not use the Controller's conversation content to train AI models, and does not permit its sub-processors to do so.

6. Security

7. Sub-processors

The Controller gives general authorization for the sub-processors listed in the Privacy Policy: Supabase, Google Cloud, OpenAI, Vercel, Stripe, Postmark and Cloudflare.

The Processor will give the Controller 30 days' notice before adding or replacing a sub-processor, and the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate and receive a pro-rata refund of any prepaid fees.

Each sub-processor is bound by terms no less protective than these, and the Processor remains liable for their performance.

Voxer is not a sub-processor of Belim & Co. It is the Controller's own supplier and the source of the data.

8. Data-subject requests

The Processor will notify the Controller without undue delay of any request it receives directly from a data subject, and will not respond itself except to confirm the request has been passed on.

The Processor will assist the Controller in accessing, correcting, exporting or deleting a data subject's information. This assistance is provided manually: email support@foliary.co and the Processor will action the request within 30 days. There is no self-service deletion tool.

9. International transfers

All processing takes place in the United States, and Foliary is offered to customers in the United States.

10. Breach

The Processor will notify the Controller within 72 hours of becoming aware of any personal data breach affecting the Controller's data, with the information available at the time and updates as it learns more.

11. Deletion and return

On termination the Controller may request an export of their data, as CSV, by emailing support@foliary.co (Terms §8).

The Processor will delete the Controller's personal data within 30 days of termination, except where law requires it to be kept, and will confirm deletion on request.

Raw incoming message logs are deleted automatically 30 days after receipt, independently of this.

12. Audits

The Processor will answer reasonable written questions about its compliance, at most annually.

Any audit beyond that — including any on-site audit, and any audit required by a supervisory authority — is at the Controller's cost.

13. Liability

Each party's liability under this agreement is subject to the limit in Terms of Service §9: the fees paid in the 12 months preceding the claim.

14. Order of precedence

If this agreement conflicts with the Terms of Service, this agreement prevails for matters of personal data processing.