Foundry · Legal

Data Treatment & Privacy Policy

How Foundry collects, uses, protects, returns, and deletes your data, and why the intelligence you build here belongs to you.

Your data is yours. What Foundry learns about your firm is also yours. We never sell it, never share it across customers, and never use it to benefit anyone but you. When you leave, your raw data comes home and your Intelligence Brain is switched off and permanently deleted.

Version 1.0 · Last updated August 9, 2026 · Effective August 9, 2026 · atfoundry.dev

Important. This Policy makes binding commitments about sensitive data and is incorporated into the Foundry Terms of Service. A Data Processing Addendum covering GDPR / UK GDPR obligations is available on request at privacy@atfoundry.dev.

The whole idea, in one paragraph

Your data is yours. What Foundry learns about your firm from your data is also yours. Foundry never sells it, never shares it with another customer, and never uses it to benefit anyone but you.

The more you use Foundry, the smarter Foundry gets for you specifically, and that accumulated intelligence, your "Intelligence Brain," belongs to you. It lives and works inside Foundry. When you leave, your raw data comes home with you, and your Intelligence Brain is switched off and permanently deleted. Foundry does not keep it, sell it, or reuse it. The sections below make that commitment precise and legally operative.

1. Scope

This Data Treatment & Privacy Policy ("Policy") describes how Foundry Technologies, LLC ("Foundry," "we") collects, uses, stores, protects, and returns or deletes data in connection with the Foundry Services. It is incorporated into and forms part of the Foundry Terms of Service ("Terms"). Capitalized terms not defined here have the meanings given in the Terms. This Policy covers:

  • Customer Content, the data your organization puts into Foundry.
  • The Intelligence Brain, the derived intelligence layer Foundry generates from your use.
  • Account and usage data, information about how the Services are accessed and operated.
  • Personal data, where any of the above includes information relating to identifiable individuals.

2. Roles: who controls what data

Because Foundry serves business customers, data roles matter:

  • For Customer Content, your organization is the controller (or business) and Foundry is the processor (or service provider). We process Customer Content on your behalf and under your instructions, as set out in the Terms and any Data Processing Addendum ("DPA").
  • For limited account and operational data we need to run and secure the Services (billing contacts, login records, audit logs), Foundry may act as a controller for those specific, limited purposes.

For customers with EU or UK data subjects, Foundry makes a Data Processing Addendum, incorporating the applicable Standard Contractual Clauses, available on request at privacy@atfoundry.dev.

3. What data we collect

3.1 Customer Content

Whatever you and your Authorized Users submit or generate in the Services, for example: deal records, documents (offering memoranda, rent rolls, financials, legal documents), notes, transcripts you choose to ingest, communications within the platform, financial assumptions, and decisions. Foundry does not choose what Customer Content you submit; you do.

3.2 The Intelligence Brain (derived)

Foundry generates a Customer-specific derived layer from your Customer Content and usage: learned patterns, preferences, relationships, embeddings, and historical decision context. This is derived from your data and is treated as your data. See Section 6.

3.3 Account and usage data

Information needed to operate the Services: account and user identifiers, authentication and access logs, device and connection metadata, billing information, support communications, and product telemetry (such as feature usage and error logs). We use this to provide, secure, bill for, and improve the operation of the Services.

3.4 What we do not do

We do not purchase Customer Content about you from data brokers, and we do not scrape third-party sources to enrich your Intelligence Brain unless you direct us to connect a source you control.

4. How we use data

We use data for these purposes only:

  • To provide the Services. Hosting, processing, and displaying your Customer Content; running AI features; generating and operating your Intelligence Brain for your benefit.
  • To secure the Services. Authentication, fraud and abuse prevention, monitoring, and incident response.
  • To operate and bill. Account management, support, and invoicing.
  • To maintain and improve platform operations. Using account and usage data (not your Customer Content or Intelligence Brain, except as narrowly stated in Section 5) to keep the Services reliable and to improve general platform functionality.
  • To comply with law, where processing or retention is legally required.

We do not use your Customer Content or your Intelligence Brain for advertising, and we do not sell it. See Sections 5 and 6.

5. Cross-customer use, model training, and AI providers

This section is the heart of the trust commitment. Read it carefully.

5.1 No cross-customer use

Your Customer Content and your Intelligence Brain are siloed to your organization. Foundry does not expose, share, pool, or make them available to any other customer, and does not use them to benefit any other customer. One customer's Intelligence Brain is never used to answer, inform, or improve another customer's experience.

5.2 No training of shared or general models on your data

Foundry does not use your Customer Content or Intelligence Brain to train, fine-tune, or improve any model that is shared across customers or that serves anyone other than you. Any model tuning that occurs from your data is confined to your own instance and operates solely for your benefit.

5.3 No aggregate learning across customers (current commitment)

At present, Foundry does not perform aggregated or cross-customer learning of any kind, including from anonymized or de-identified data. Each customer's intelligence is fully siloed.

5.4 Third-party AI subprocessors

Foundry uses third-party AI model providers to deliver certain features. Foundry engages such providers under contractual terms that prohibit them from using your Customer Content to train their general or foundation models, and that limit their processing to delivering the feature back to you (for example, zero-data-retention or no-training configurations where available). Foundry uses enterprise and business-tier API arrangements configured for no-training and, where offered, zero data retention. A current list of subprocessors is available on request at privacy@atfoundry.dev, and Foundry will provide notice of material changes as described in the DPA.

5.5 The standard we follow

Foundry's data handling follows the enterprise and business-tier model of AI data protection: your business data is not used to train shared models, is not sold, and is not exposed to other customers. It does not follow the consumer-grade model in which user inputs may be used to train shared models by default.

6. The Intelligence Brain: ownership, siloing, and lifecycle

6.1 Ownership

As between you and Foundry, you own your Intelligence Brain. Foundry does not own it, does not treat it as Foundry's asset, and does not claim rights to it beyond operating it for you within the Services.

6.2 Foundry cannot profit from it

Foundry will not sell, license, rent, share, expose, or otherwise transfer your Intelligence Brain, in whole, in part, or in any output uniquely derived from it, to any other customer or third party, for any purpose.

6.3 It works only inside Foundry

Your Intelligence Brain is expressed in Foundry's proprietary structures and is a feature of the Foundry environment. It functions only within the Services and is not portable. This does not limit your ownership of, or ability to export, your underlying Customer Content (Section 8). It reflects that the Intelligence Brain is the product working for you, not a separate file that exists independently of the platform.

6.4 Lifecycle on departure

When your subscription ends:

  • Your Customer Content comes home. It remains exportable to you in a machine-readable format for the export window in Section 8.
  • Your Intelligence Brain goes dormant immediately. It stops functioning and stops being used in any way.
  • Your Intelligence Brain is then rendered unusable and permanently deleted within 90 days of the end of the export window, unless a specific, documented legal obligation requires longer retention, in which case the minimum necessary is retained, isolated, and then deleted.

Foundry does not retain your dormant Intelligence Brain indefinitely, does not reactivate it, and does not repurpose it for itself or anyone else. Unlike consumer platforms that keep the personalization they build about you, Foundry deletes it.

7. Security

Foundry implements administrative, technical, and physical safeguards designed to protect data, including:

  • encryption of data in transit and at rest;
  • access controls and least-privilege internal access, with logging;
  • logical separation of customer data (tenant isolation);
  • monitoring, vulnerability management, and incident response;
  • vendor and subprocessor security review.

No system is perfectly secure. In the event of a data breach affecting your data, Foundry will notify you without undue delay, and in any event within 72 hours of confirming a breach affecting your Customer Content, consistent with applicable law and the DPA.

8. Data retention, export, and deletion

8.1 During the subscription

Foundry retains Customer Content and operates your Intelligence Brain for as long as your subscription is active, so the Services function and your intelligence compounds.

8.2 Export

You can export your Customer Content in a machine-readable format at any time during your subscription and for 30 days after termination.

8.3 Deletion of Customer Content

After the export window, Foundry deletes or de-identifies Customer Content within 90 days, except where retention is legally required. Backups are purged on our standard rolling cycle of 35 days.

8.4 Deletion of the Intelligence Brain

Handled as in Section 6.4: dormant on termination, then rendered unusable and permanently deleted.

8.5 Legal holds

Where law requires retention (for example, regulatory or litigation hold), Foundry retains only the minimum necessary, isolates it, restricts access, and deletes it when the obligation ends.

9. Personal data and privacy rights

Where data includes personal information about identifiable individuals (for example, your Authorized Users, or individuals named in your Customer Content), the following apply.

9.1 Individuals' rights

Depending on jurisdiction (for example, GDPR / UK GDPR, CCPA / CPRA), individuals may have rights to access, correct, delete, port, or restrict processing of their personal data, and to object to certain processing.

  • For personal data within Customer Content, your organization is the controller; Foundry will assist you in responding to such requests as processor, per the DPA.
  • For personal data Foundry controls (account and operational data), individuals may contact Foundry at privacy@atfoundry.dev and Foundry will respond as required by law.

9.2 Legal bases (GDPR / UK GDPR)

Where applicable, Foundry processes personal data on the bases of contract performance, legitimate interests (operating and securing the Services), consent (where required), and legal obligation.

9.3 CCPA / CPRA

Foundry does not "sell" or "share" personal information as those terms are defined under the CCPA / CPRA. Foundry acts as a service provider for Customer Content.

9.4 International transfers

Customer Content is hosted in the United States (Section 11). Where data is transferred across borders, Foundry relies on appropriate safeguards, including the Standard Contractual Clauses made available through the DPA.

9.5 Financial and industry-specific data

Customer Content in Foundry may include sensitive financial and real-estate information. Where your organization is subject to obligations such as GLBA or other financial-privacy or confidentiality requirements, the DPA and these terms are intended to support your compliance; you remain responsible for your own regulatory obligations.

10. Subprocessors

Foundry uses vetted subprocessors (for example, cloud hosting, AI model providers, infrastructure, and support tools) to deliver the Services. Foundry maintains a current subprocessor list, available on request at privacy@atfoundry.dev; imposes data-protection obligations on subprocessors consistent with this Policy; and provides notice of material subprocessor changes as set out in the DPA, with an opportunity to object where required.

11. Data hosting and location

Customer Content is hosted on managed cloud infrastructure in the United States. Foundry does not currently offer alternative hosting regions; customers with a regional requirement should contact privacy@atfoundry.dev before onboarding.

12. Changes to this Policy

Foundry may update this Policy. For material changes that reduce your protections or expand our use of your data, Foundry will provide advance notice, and where a change would introduce any new use of your Customer Content or Intelligence Brain (such as any future aggregate-learning feature), such use will be opt-in, not automatic. Notice of material changes is given at least 30 days in advance, by email to account administrators and in the platform, and continued use after the effective date constitutes acceptance of non-material changes.

13. Contact

Privacy and data questions: privacy@atfoundry.dev · Legal notices: legal@atfoundry.dev · Foundry Technologies, LLC · atfoundry.dev

Privacy and data questions can be directed to privacy@atfoundry.dev.