feesz
// Legal

Privacy Policy

Last updated: April 12, 2026. We treat privacy as a feature, not a checkbox. This policy explains how we collect, use and protect personal data.

Plain-language summary

We collect the minimum personal data needed to deliver the Services, never sell it, never train third-party models with customer content, and give you full control to access, export or delete your data.

1. Scope of this policy

This Privacy Policy explains how FEESZ collects, uses, shares and protects information when you visit feesz.com, use the FEESZ console, integrate our APIs, or interact with our team. It applies to personal data we process as a data controller. Where FEESZ acts as a processor on behalf of a customer, the customer's privacy notices apply first.

2. What we collect

We collect information you provide directly (such as account details, billing information and support requests), data generated through your use of the Services (logs, device information, in-product events) and limited data from third parties (such as our identity provider when you log in). For the content you submit to the Services, we process metadata and fingerprints — not the underlying creative content for any purpose other than providing the Services.

3. How we use information

We use personal data to deliver and improve the Services, secure our infrastructure, communicate with you, comply with legal obligations and, with your consent, send you marketing communications you can unsubscribe from at any time. We do not sell personal data, and we do not use customer content to train models that benefit third parties.

5. Sharing and disclosure

We share information with vetted sub-processors that support the Services (cloud infrastructure, communication tools, billing). The full list of sub-processors is published in our Trust Center. We may also share information when required by law, to protect FEESZ rights, or in connection with a corporate transaction — in which case we will notify customers in advance.

6. International transfers

FEESZ operates primary regions in EU (Frankfurt) and US (Virginia), with optional residency in Brazil, the UK and Singapore. When personal data is transferred outside the European Economic Area or the UK, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures where appropriate.

7. Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations and resolve disputes. Customer content is deleted within 60 days of contract termination unless legally required to retain it.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise these rights by writing to [email protected] — we respond within 30 days.

9. Security

FEESZ maintains a comprehensive information security program aligned with SOC 2 Type II and ISO 27001. Controls include encryption in transit and at rest, role-based access, continuous monitoring, regular penetration testing and employee security training. Documentation is available upon request under NDA.

10. Contact us

Privacy questions can be sent to [email protected]. Our European representative and Brazilian DPO contact details are published in the Trust Center. You also have the right to lodge a complaint with your local data protection authority.