footr.
DRAFT — this document is under legal review and is not binding until the review is complete.

Privacy Policy

Last updated: 2026-07-16

1. Roles

For data about the customer’s employees (used to populate signatures), the customer organization is the data controller and footr is the data processor.

For the portal’s administrator accounts (email address at sign-in), footr is the data controller.

2. What data is processed

Administrators: email address and name from the Microsoft sign-in. Stored for as long as the account has portal access.

Customer employees: name, title, department, mobile number and email address are fetched from Microsoft Graph the moment an email is composed, used to populate the signature, and never stored by footr.

3. Purposes

Data is processed for two purposes: populating the organization’s email signatures, and authenticating portal administrators. No processing takes place for marketing or profiling.

4. Legal basis

For administrator data, where footr is the data controller, the legal basis is contract (Article 6(1)(b) GDPR) — the processing is required to provide the portal — and legitimate interest (Article 6(1)(f) GDPR) for security and sign-in traceability.

For employee data, footr acts as a data processor and processes it solely on the customer’s instructions. Responsibility for the legal basis rests with the customer as data controller.

5. Retention

Signature templates and rules: until the customer deletes them or the agreement ends. Administrator data: until access is removed. Employee data: not stored.

Deleted records may remain in the database provider’s backups for up to [VERIFY: number of days per Supabase plan] days, after which they are permanently deleted.

6. Sub-processors and location

Storage and processing take place in Stockholm (Supabase AWS eu-north-1 and Vercel arn1 respectively). Sub-processors: Vercel, Supabase and Microsoft. Details are on the security page.

AWS, Vercel and Microsoft are part of US corporate groups. To the extent data is made available from a third country, this is done under the European Commission’s Standard Contractual Clauses (SCC) and/or the EU–US Data Privacy Framework; this is governed in detail by the data processing agreement.

7. Data subject rights

Employees of a customer should primarily contact their employer, which is the data controller for their data. Administrators contact footr directly for access, rectification or erasure.

8. Contact

Questions about personal data processing: security@footr.app. Following an assessment under Article 37 GDPR, footr has not appointed a data protection officer — the service does not process sensitive personal data at scale and does not systematically monitor data subjects.