GLOBAL DATA PRIVACY & GOVERNANCE

Comprehensive Enterprise Privacy Policy

Effective Date: July 28, 2026 | Last Updated: July 28, 2026 | Document Control Version 3.4

Fraoula LLC ("Fraoula", "we", "us", or "our"), headquartered in Newark, Delaware, USA, is committed to robust data privacy, transparent governance, and stringent information security. This Privacy Policy details our technical data handling, lawful processing foundations, international data transfer safeguards, and user privacy rights across our enterprise platforms.

1. Introduction, Scope & Legal Entity Governance

Fraoula LLC ("Fraoula", "Company", "we", "us", or "our") operates as a global enterprise AI software product company incorporated under the laws of the State of Delaware, United States of America, with primary operational engineering presence across the United States, Europe, and India. This Privacy Policy governs the processing of personal data, technical telemetry, and corporate information collected through our official websites, including www.fraoula.co, our specialized product subdomains including data-audit.fraoula.co (Fraoula Data Auditor) and marketing.fraoula.co (Fraoula Marketing Intelligence Platform), our application programming interfaces (APIs), software development kits (SDKs), cloud connectors, and related enterprise services (collectively, the "Services").

This policy applies to all individuals who visit our digital properties, register for accounts, interact with our enterprise data audit tools, utilize our marketing decision engines, submit corporate inquiries, or participate in our business engagements (collectively, "Users", "Data Subjects", or "You"). Depending on your location and the specific nature of your interaction with Fraoula, Fraoula LLC acts either as a Data Controller (determining the legal purposes and means of processing personal data, such as for website visitors, corporate contact requests, and account management) or as a Data Processor / Service Provider (processing customer data strictly pursuant to executed Data Processing Addenda [DPAs] and Enterprise Service Agreements).

By accessing our Services, establishing an enterprise tenant account, or utilizing our automated data auditing tools, you acknowledge that you have read, understood, and agreed to the data collection, retention, transfer, and security practices described in this Privacy Policy. If you do not agree with any aspect of this Policy, you must immediately cease utilizing our Services and refrain from submitting any personal data or data streams to our endpoints.

2. Categories of Information We Collect

In accordance with global data minimization principles under Article 5(1)(c) of the General Data Protection Regulation () and Section 1798.100 of the California Consumer Privacy Act (/CPRA), Fraoula collects only the minimum personal information required to deliver high-performance, enterprise-grade AI software products. We collect information across three primary operational categories:

A. Technical & Infrastructure Telemetry (Automated Edge Collection)

When your web browser, mobile application, or cloud server establishes a network connection to Fraoula’s edge network (powered by Cloudflare, AWS CloudFront, and GCP infrastructure), our web servers automatically capture standard HTTP/S request metadata. This technical telemetry includes:

  • Network Identifiers: Internet Protocol (IP) address (anonymized or hashed at the edge where required by local law), Autonomous System Number (ASN), geolocation data derived from IP addresses (country, region, city level; zero fine-grained GPS tracking).
  • Device & Browser Specifications: User-agent strings, web browser type and version, operating system architecture, device hardware specifications, screen resolution, preferred language settings, and referrer headers.
  • Session & Performance Telemetry: Connection timestamps, request duration, request headers, Uniform Resource Identifiers (URIs) accessed, HTTP response status codes, payload bytes transferred, and edge network diagnostic logs.
  • Cybersecurity Telemetry: Web Application Firewall (WAF) event logs, TLS handshake parameters, bot scoring metrics, rates of API request execution, and potential malicious attack vectors monitored by our automated Security Operations Center (SOC).

B. Enterprise Customer & Account Identifiers (Directly Submitted Data)

When enterprise users register for production environments, request product demonstrations, configure cloud data warehouse connectors, or communicate with Fraoula engineering support, we collect corporate identity credentials including:

  • Personal & Contact Identifiers: Full legal name, corporate job title, business email address, corporate phone number, company name, primary business location, and enterprise department affiliation.
  • Authentication & Single Sign-On (SSO) Data: OAuth 2.0 / SAML 2.0 identity provider tokens, user ID keys, hashed passwords (utilizing salted Argon2id / bcrypt hashing algorithms; zero plaintext storage), multi-factor authentication (MFA) setup status, and security key credentials.
  • Billing & Commercial Transaction Records: Business credit card details (processed securely via PCI-DSS Level 1 certified processors; Fraoula stores only card brand, last four digits, and expiration date), tax identification numbers, corporate invoicing addresses, purchase order numbers, and contract execution history.
  • Support & Communications Records: Full text of support tickets, technical inquiries, feedback forms, security questionnaire responses, emails exchanged with our team, and transcripts of technical consultations.

C. Automated Data Stream & Marketing Intelligence Telemetry

Fraoula operates two core enterprise software products. The nature of data ingested by these products is strictly demarcated as follows:

  • Fraoula Data Auditor (data-audit.fraoula.co): Ingests enterprise database schema definitions, transaction volume logs, stream timestamps, data type metadata, and zero-trust anomaly flags. Data Auditor is engineered to perform real-time data quality scoring and automated compliance checks (such as PHI exposure detection and data drift). All payload contents are processed ephemerally in-memory within isolated customer Virtual Private Clouds (VPCs); zero raw customer data payload contents are permanently stored on Fraoula disk drives.
  • Fraoula Marketing Intelligence Platform (marketing.fraoula.co): Ingests aggregated digital campaign spend data, server-to-server ad channel API telemetry (Google Ads, Meta Ads, LinkedIn Ads, programmatic DSPs), anonymized conversion events, and probabilistic attribution scores. Personal identifiers ingested through customer tracking pixels are hashed client-side utilizing cryptographic SHA-256 digests prior to network transmission.

3. Methods of Data Collection

Fraoula employs transparent, privacy-by-design collection mechanisms to gather data across our digital ecosystem:

  • Direct User Input: Data provided when completing contact forms, scheduling enterprise consultations, subscribing to research updates, creating user accounts, or submitting support tickets.
  • Automated Edge & Cloud Telemetry: Real-time event logging generated by edge computing nodes, load balancers, container orchestration instances, and serverless runtime environments upon every network request.
  • API & Cloud Warehouse Connectors: Direct server-to-server integrations configured by customer system administrators (e.g., Snowflake Data Sharing, Databricks Unity Catalog integrations, AWS S3 bucket connectors, Azure Blob Storage APIs).
  • Cookies & Local Storage Objects: Essential session storage, security token storage, and privacy-preserving preference cookies detailed in Section 14 below.

4. Lawful Bases for Processing ( Article 6 & International Standards)

Under European Economic Area (EEA), United Kingdom, and Swiss data protection laws, Fraoula relies upon specific, explicit legal bases to process your personal data under Article 6 of the EU and UK :

  1. Contractual Necessity (Art. 6(1)(b)): Processing is strictly necessary to perform our contractual obligations under enterprise software subscription agreements, terms of service, and Data Processing Addenda specifically to provision accounts, authenticate users, execute automated data auditing, calculate attribution metrics, and deliver operational support.
  2. Compliance with Legal Obligations (Art. 6(1)(c)): Processing is required to fulfill our legal, statutory, and regulatory mandates under United States federal/state laws, European Union law, and international tax treaties including maintaining commercial transaction records, fulfilling tax reporting requirements, responding to legal subpoenas, and maintaining audit logs for regulatory compliance.
  3. Legitimate Business Interests (Art. 6(1)(f)): Processing is necessary to pursue our compelling legitimate business interests, provided such interests are not overridden by your fundamental privacy rights. Our legitimate interests include securing our network infrastructure against cyberattacks, preventing fraud, improving product accuracy, optimizing edge delivery speeds, conducting non-invasive B2B analytics, and asserting legal defense claims.
  4. Explicit Consent (Art. 6(1)(a)): Where mandated by applicable law (e.g., for non-essential analytical cookies or direct marketing communications in certain jurisdictions), we process personal data based upon your freely given, specific, informed, and unambiguous consent. You maintain the absolute right to withdraw consent at any time without affecting the lawfulness of prior processing.

5. Purpose of Data Processing

Fraoula utilizes collected personal data and technical telemetry exclusively for legitimate operational, engineering, and enterprise delivery purposes, including:

  • Software Provisioning & Account Management: Authenticating user identity, enforcing Role-Based Access Control (RBAC), provisioning multi-tenant instances, and executing enterprise product subscriptions.
  • Real-Time Data Quality & Anomaly Auditing: Executing automated data stream quality scoring, identifying financial transaction reconciliation discrepancies, detecting out-of-stock inventory risks, and triggering real-time webhooks within customer environments.
  • Infrastructure Resilience & Cybersecurity: Monitoring network traffic patterns, detecting distributed denial-of-service (DDoS) attacks, enforcing Web Application Firewall rules, preventing credential stuffing, and maintaining security audit compliance.
  • Customer Support & Technical Consultation: Resolving user support tickets, providing follow-the-sun engineering assistance across USA, EU, and India regions, and conducting technical platform walkthroughs.
  • Corporate Communications & Product Updates: Transmitting essential service notifications, operational alerts, security advisory bulletins, billing statements, and legal policy updates.
  • Regulatory Compliance & Legal Defense: Demonstrating compliance with , and ISO/IEC 27001 standards, investigating security incidents, and defending legal rights.

6. Artificial Intelligence, Data Governance & Strict Non-Training Commitments

As an enterprise AI product company serving Fintech and Healthtech organizations, Fraoula enforces absolute data sovereignty and strict AI data governance principles:

  • ZERO Model Training on Customer Data Payload Contents: Fraoula unequivocally commits that customer data payloads, database contents, transaction records, and Protected Health Information (PHI) processed by Fraoula Data Auditor or Fraoula Marketing Intelligence Platform are NEVER used to train, fine-tune, retrain, or evaluate public foundation models, third-party Large Language Models (LLMs), or shared AI architectures.
  • Ephemeral In-Memory Execution: All automated data auditing, schema verification, and telemetry scoring operations execute strictly in transient RAM memory buffers within customer-dedicated, isolated container environments. Once data processing execution completes, memory buffers are immediately purged.
  • Private Enterprise LLM Infrastructure: Where generative AI features are leveraged within our platforms, models run inside dedicated, sovereign Virtual Private Clouds (VPCs) with zero-data-retention (ZDR) enterprise API agreements with foundational model providers. Customer inputs and outputs remain 100% private to the customer tenant.
  • Zero Automated Decision-Making Producing Legal Effects: Fraoula's automated telemetry engines generate data quality flags, ROAS reallocation recommendations, and security anomaly alerts. Final operational business decisions remain under human control; Fraoula software does not execute automated profiling or decision-making producing legal or similarly significant effects under Article 22.

7. Third-Party Subprocessors & Service Providers

To deliver enterprise cloud performance, Fraoula partners with carefully vetted third-party infrastructure providers ("Subprocessors"). All Subprocessors are bound by strict contractual obligations under Data Processing Addenda (DPAs) requiring adherence to equivalent data protection standards, audits, and certifications:

  • Cloud Infrastructure & Edge Delivery: Amazon Web Services (AWS - USA/EU), Google Cloud Platform (GCP - USA/EU), Microsoft Azure (USA/EU), Cloudflare Inc. (Global Edge CDN & WAF).
  • Data Warehouse & Analytics Connectors: Snowflake Inc., Databricks Inc. (Customer-configured direct database sharing interfaces).
  • Payment Processing & Billing Systems: Stripe Inc., Wix Payments (PCI-DSS Level 1 Certified Financial Gateways).
  • Authentication & Security Services: Auth0 / Okta Inc., Cloudflare Zero Trust Security.

Fraoula maintains a current register of active Subprocessors. Customers may request notification of Subprocessor updates by contacting our Data Protection Officer at info@fraoula.co.

8. International Data Transfers & EU-U.S. Data Privacy Framework (DPF)

Fraoula LLC is headquartered in the United States and operates a global cloud infrastructure. Consequently, personal data collected from data subjects located in the European Economic Area (EEA), United Kingdom (UK), and Switzerland may be transferred to, stored, and processed in the United States or other non-EEA jurisdictions.

To ensure full legal compliance for international data transfers under Article 44 et seq.:

  • Standard Contractual Clauses (SCCs): Fraoula incorporates the European Commission’s Standard Contractual Clauses (Commission Implementing Decision [EU] 2021/914) into all enterprise DPAs with customer data controllers, supplemented by UK Addendum clauses for UK data exports.
  • EU-U.S. Data Privacy Framework Alignment: Fraoula adheres to the Principles of the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework regarding the notice, choice, accountability for onward transfer, security, data integrity, purpose limitation, access, and recourse for personal data transferred from the EEA, UK, and Switzerland to the United States.
  • Supplementary Safeguards: Fraoula implements robust technical safeguards, including end-to-end encryption in transit and at rest, zero-knowledge architecture options, and strict legal challenge protocols against non-EU government data access requests.

9. Data Retention, Archival & Disposal Schedules

Fraoula enforces strict data lifecycle schedules to prevent excessive data retention, adhering to Article 5(1)(e) storage limitation principles:

  • Customer Account & Identity Identifiers: Retained for the duration of an active commercial subscription plus seven (7) years following contract termination to satisfy corporate tax, financial accounting, and legal audit requirements.
  • Technical Edge Server Logs: Anonymized web server access logs and WAF event logs are retained for thirty (30) days for security telemetry, after which they are automatically purged or aggregated into non-identifiable statistical metrics.
  • Data Auditor Stream Telemetry: Ephemeral in-memory data payload buffers are purged immediately upon execution (within 60 seconds). Aggregate data quality telemetry logs (metadata only) are retained for ninety (90) days for customer reporting dashboards before automated rotation.
  • Support & Communications Records: Retained for three (3) years from the date of ticket closure to maintain technical history and service continuity.
  • Cryptographic Data Disposal: Upon expiry of retention periods, electronic data is destroyed using DoD 5220.22-M compliant cryptographic erasure procedures, rendering files completely unrecoverable.

10. Enterprise Security Governance (, & )

Fraoula maintains an enterprise security program designed to protect personal information and customer data streams against unauthorized access, accidental loss, destruction, alteration, or disclosure:

  • Encryption Controls: All data in transit is encrypted using Transport Layer Security (TLS 1.3) with HSTS preload enabled sitewide. All data at rest across cloud storage repositories is encrypted using AES-256 algorithm keys managed via AWS KMS / GCP Cloud KMS with automatic annual key rotation.
  • Access Control & Authentication: Enforces mandatory Multi-Factor Authentication (MFA) across all employee workstations, strict Role-Based Access Control (RBAC), Principle of Least Privilege (PoLP), and automated session termination.
  • Independent Compliance Audits: Fraoula undergoes annual third-party audits for certification (evaluating Trust Services Criteria for Security, Availability, and Confidentiality) and maintains alignment with ISO/IEC 27001:2022 Information Security Management System standards.
  • Compliance Safeguards: For Healthtech clients, Fraoula executes Business Associate Agreements (BAAs) and implements administrative, physical, and technical safeguards mandated by the Security Rule (45 CFR Part 160 and Part 164, Subparts A and C), including automated PHI redaction and zero-trust masking.
  • Vulnerability Management: Continuous automated vulnerability scanning, quarterly penetration testing by certified external ethical hacking firms, and an active Vulnerability Disclosure Policy.

11. Your Privacy Rights Under U.S. State Laws ( / CPRA, VA CDPA, CO CPA, CT CTDPA, UT UCPA)

Residents of California, Virginia, Colorado, Connecticut, Utah, and other U.S. states with comprehensive privacy legislation possess specific legal rights regarding their Personal Information:

  • Right to Know / Right of Access: You have the right to request that Fraoula disclose the specific pieces of Personal Information we have collected about you, the categories of sources, the commercial purposes for collection, and the categories of third parties with whom we disclose data.
  • Right to Delete: You have the right to request the deletion of your Personal Information held by Fraoula, subject to statutory retention exceptions (such as tax compliance, fraud prevention, or contract completion).
  • Right to Correct Inaccurate Personal Information: You have the right to request that Fraoula rectify inaccurate or outdated Personal Information maintained in our systems.
  • Right to Opt-Out of Sale or Sharing of Personal Information: Fraoula does NOT sell your Personal Information to third parties for monetary compensation, nor do we share your Personal Information for cross-context behavioral advertising. We have not engaged in data sales or cross-context behavioral sharing in the preceding twelve (12) months.
  • Right to Limit Use of Sensitive Personal Information: Fraoula limits the collection of sensitive personal information strictly to what is necessary to perform our business Services. We do not use sensitive personal information for inferring characteristics about consumers.
  • Right to Non-Discrimination: Fraoula will never discriminate against you (e.g., by denying services, charging higher prices, or degrading quality) for exercising any of your statutory privacy rights.

To exercise your U.S. state privacy rights, please submit a verifiable consumer request to info@fraoula.co with the subject line "U.S. Privacy Rights Request". Authorized agents submitting requests on behalf of consumers must provide valid written authorization and verification of identity.

12. European, UK & International Privacy Rights ( / UK / LGPD / PIPEDA)

If you reside in the European Economic Area (EEA), United Kingdom, Switzerland, Brazil (LGPD), Canada (PIPEDA), or Australia, you possess comprehensive statutory data protection rights under applicable law:

  • Right of Access ( Art. 15): Obtain confirmation as to whether your personal data is being processed and receive a copy of your personal data in a readable format.
  • Right to Rectification ( Art. 16): Require the correction of inaccurate or incomplete personal data without undue delay.
  • Right to Erasure / "Right to be Forgotten" ( Art. 17): Request the permanent deletion of your personal data where processing is no longer necessary, consent is withdrawn, or legal grounds for erasure are met.
  • Right to Restriction of Processing ( Art. 18): Request that Fraoula restrict data processing during accuracy disputes or legal claims.
  • Right to Data Portability ( Art. 20): Receive your personal data provided to Fraoula in a structured, commonly used, and machine-readable format (e.g., JSON or CSV) and transmit that data to another controller.
  • Right to Object ( Art. 21): Object at any time to the processing of your personal data based on legitimate interests (Art. 6(1)(f)) or direct marketing.
  • Right to Lodge a Complaint: You maintain the right to submit a complaint directly to your local Data Protection Supervisory Authority (e.g., the Information Commissioner's Office [ICO] in the UK, the CNIL in France, or the BfDI in Germany). However, we encourage you to contact Fraoula first so we may address your concerns directly.

To exercise your international privacy rights, please submit a request to our Data Protection team at info@fraoula.co. We respond to all verifiable data subject requests within thirty (30) days.

13. Children’s Online Privacy Protection Act (COPPA) Compliance

Fraoula’s Services are strictly designed for enterprise, corporate, and B2B professionals. Our websites and software products are not intended for or directed to individuals under eighteen (18) years of age. Fraoula does not knowingly collect, solicit, or market personal information from children under the age of 18 or 16. If we discover that an individual under the age of 18 has submitted personal data to our endpoints, we will immediately execute secure deletion procedures to remove such information from our records. Parents or legal guardians who believe their child has provided personal information to Fraoula should contact us immediately at info@fraoula.co.

14. Cookies, Tracking Technologies & Global Privacy Control (GPC)

Fraoula utilizes minimal, privacy-focused web technologies to ensure network security and user authentication:

  • Essential Strictly Necessary Cookies: Required for fundamental website functionality, single sign-on (SSO) authentication, load balancing, and CSRF security protection. These cookies cannot be disabled in our systems.
  • Preference & Functional Local Storage: Stores user interface state selections (e.g., dark mode preferences, documentation tab states).
  • Zero Non-Essential Advertising Trackers: Fraoula does not employ third-party targeted advertising tracking cookies, behavioral profiling pixels, or cross-site fingerprinting scripts on our primary corporate properties.
  • Global Privacy Control (GPC) & Do-Not-Track (DNT) Signals: Our web infrastructure is configured to recognize and honor Global Privacy Control (GPC) browser signals. When a GPC signal is detected, our servers automatically suppress optional analytics tracking for that session.

15. Business Transitions & Corporate Restructuring

In the event that Fraoula LLC undergoes a business transition such as a merger, acquisition by another enterprise, financing round, corporate reorganization, asset sale, or bankruptcy proceeding your personal data and enterprise account information may be evaluated or transferred as part of the corporate transaction assets.

In any such corporate transition, Fraoula will ensure that the acquiring entity or successor remains bound by the commitments set forth in this Privacy Policy, or will provide advance notice to affected users prior to material policy modifications.

16. Revisions & Material Modification Protocols

Fraoula reserves the right to update or modify this Privacy Policy periodically to reflect technological advances, statutory amendments, legal precedents, or operational changes in our software products. When material updates occur, Fraoula will update the "Effective Date" and "Version" at the top of this document and publish the revised policy at https://www.fraoula.co/privacy. For significant modifications impacting user privacy rights or data processing scope, we will provide additional notice, such as sending a corporate email notification to registered tenant administrators or displaying an overlay alert upon logging into our enterprise consoles.

17. Data Protection Officer & Contact Information

If you have any questions, concerns, feedback, or legal privacy inquiries regarding this Privacy Policy, our data protection practices, or to exercise your statutory rights, please contact our designated Data Protection Officer (DPO) and Legal Governance Team using the credentials below:

  • Legal Entity Name: Fraoula LLC
  • Headquarters Address: Newark, Delaware, United States of America
  • Data Protection Officer (DPO) Email: info@fraoula.co
  • Corporate Website: https://www.fraoula.co

© 2026 Fraoula LLC. All rights reserved. Enterprise AI Products. Built for Scale.