Privacy Policy
This policy explains how Behavly handles personal data: the data of the people who hold an account, and the data of the End Users our customers track and email through the Service. It describes only what Behavly actually does.
Last updated 6 September 2026
1.Who we are and how to reach us
Behavly is a product of FoundryX (“Behavly”, “we”, “us”). For every question, request or complaint about personal data, write to hello@behavly.io. Capitalised terms have the meaning given in the Terms of Service.
2.Two roles: controller and processor
For account holders — the people who sign up and use the application — Behavly decides why and how data is processed and is therefore the controller.
For End Users— the people whose activity a customer records with the Snippet and who receive a customer’s emails — the customer decides why and how data is processed and is the controller. Behavly processes that data on the customer’s instructions as a processor. If you are an End User, the company whose website or product you use is your first point of contact; we will assist them with your request and will forward any request you send us.
3.Data we process and where it comes from
Account data (controller: Behavly)
- Email address, password hash, name and profile picture. With Google or Microsoft sign-in, the name, email and picture the provider shares.
- Workspace membership, role, invitations you send and accept, and the settings you choose, including the Workspace’s AI and privacy settings.
- Brand profile: company name, description, colours, logo, tagline, contact details and website content extracted for the profile.
- Email templates, images you upload, campaign briefs, saved segments, feedback posts, and the questions you ask the in-app assistant.
- Connected Mailbox credentials (SMTP and IMAP host, port, username, password), encrypted before storage.
- Security and audit records: who changed what in a Workspace, and every use of an AI Feature with its purpose and model. IP address and browser details in server logs.
End User data (controller: the customer)
- Activity recorded by the Snippet on the customer’s own website or product: pages viewed, clicks, scroll depth, cursor movement used for heatmaps, form-interaction signals, time on page, and the browser and device type. The Snippet assigns a random identifier stored in the browser; it does not set cookies.
- The link between that identifier and the End User’s email address, made when the customer’s application identifies the user.
- A behaviour profile derived from the activity, including a short plain-language summary.
- Email engagement: sends, opens (via a tracking image), clicks (via a redirect link), bounces, replies and unsubscribes.
- The emails written and sent to the End User, and replies the End User sends to the customer’s Connected Mailbox, including attachments.
- Consent and opt-out signals: the Global Privacy Control and Do Not Track browser signals, and consent recorded through the Snippet.
4.Why we process it and on what basis
- To provide the Service you signed up for — creating and securing your account, running your Workspace, sending the emails you ask for, reading your Connected Mailbox for replies and bounces, and showing you insights. Basis: performance of a contract.
- To operate the Service on behalf of our customers— recording End User activity, building profiles, writing and sending follow-ups. Basis: the customer’s instructions under our processor commitments; the customer is responsible for its own lawful basis towards End Users.
- To keep the Service secure and to prevent abuse — logs, audit records, rate limiting, suppression of addresses that have unsubscribed or bounced. Basis: our legitimate interest in a secure and lawful service.
- To communicate with you — replies to your messages, Workspace invitations, notices about changes to the Service or to these documents. Basis: performance of a contract and legitimate interest.
- To comply with the law — for example, honouring data-subject requests and keeping records of consent. Basis: legal obligation.
We do not use personal data for advertising, we do not build profiles of account holders, and we do not sell personal data.
5.How AI is involved
The AI Features described in the AI Termssend prompts to Anthropic and, for images, to OpenAI. Before a prompt leaves Behavly it passes through a privacy boundary: email addresses and other direct identifiers are replaced with pseudonyms, sensitive fields are dropped, and in the Workspace’s strict mode all free text is removed. Only a first name is retained where an email greeting needs it. Our providers process prompts to return a response and, under the terms of their business APIs, do not use them to train their models. Every AI use is recorded in the Workspace’s AI access log, and a Workspace owner can switch the AI Features off entirely.
7.International transfers
Data at rest is stored in the European Union. Some providers listed above process data in the United States or other countries. Where personal data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses together with the pseudonymisation and encryption described in this policy.
8.How long we keep data
- End User activity events: deleted automatically after 90 days by default; a Workspace can shorten this window. Derived profiles are refreshed from the remaining events.
- AI access records: 1 year. Workspace audit records: 2 years.
- Campaigns, sent emails, replies and engagement data: for as long as the Workspace exists, so the history remains available to the customer.
- Unsubscribed and bounced addresses: kept in a suppression list for as long as the Workspace exists, so they are never emailed again.
- Account data: for the life of the account. When an account or Workspace is deleted, its data is removed from the live database promptly and from backups within the backup cycle, unless the law requires us to keep it longer.
9.How we protect data
- All traffic between browsers, the Snippet, the application and our providers is encrypted in transit.
- Connected Mailbox credentials are encrypted with AES-256-GCM before storage, with support for key rotation. They are decrypted only at the moment of sending or reading mail.
- Every database table that holds customer data is protected by row-level access rules, so a Workspace can only ever read its own data.
- Prompts to AI providers are pseudonymised as described in section 5.
- Administrative changes are written to an audit log that Workspace owners can review and export.
No system is perfectly secure. If we learn of a breach affecting your data, we will inform you without undue delay and, where we act as processor, assist the customer with its own notification duties.
10.Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy in a portable format, to restrict or object to its processing, to withdraw consent where processing is based on consent, and to complain to a supervisory authority.
Account holders can update their profile and Workspace settings in the application and can request anything else at hello@behavly.io. End Users should contact the customer whose site or product they use; if you write to us instead, we will pass your request on and help the customer fulfil it. We answer requests within one month.
Opt-out signals. The Snippet stops recording when a browser sends the Global Privacy Control or Do Not Track signal, and every email sent through Behavly carries an unsubscribe link that takes effect immediately.
11.Children
The Service is for businesses and is not directed at children. We do not knowingly process the personal data of anyone under 16, and customers agree not to use the Snippet on properties directed at children.
13.Changes to this policy
We will update this policy when the Service or the law changes. Material changes are announced in the application or by email before they take effect, and the date at the top of the page always shows the current version.
14.Contact
For anything related to personal data: hello@behavly.io.