Data Privacy Policy
At FoClea, we take transparency seriously. We prioritize the security and confidentiality of your proprietary business data. This policy outlines clearly and openly how we collect, use, and protect your information.
We believe you have the right to know exactly how your data is handled. We are committed to being open about our data practices, avoiding hidden terms, and ensuring you always remain the owner of your strategic business insights.
1. Account Information: We collect your name, email address, and account role (e.g., user, admin) provided through the Base44 authentication system to manage your access to the service.
2. Proprietary Business Data: We collect and store the data you explicitly input into the FoClea application, including but not limited to:
- Strategic plans (Vision, Mission, Values, Goals)
- SWOT and TOWS analyses
- Key Performance Indicators (KPIs) and metrics
- Business health assessments and responses
- Market Intelligence data (Competitors, Trends)
- Generated insight reports and AI sessions
3. Usage Data: We may collect analytical information about how you navigate and use the application to improve our services.
Your information is used solely for the following purposes:
- Service Provision: To provide the strategic planning, monitoring, and assessment tools you use within FoClea.
- AI Insights: To generate personalized strategic advice, predictive trends, and reports using our AI integrations.
- Communication: To send you critical alerts, scheduled reports, and important service updates.
- Security: To verify your identity and prevent unauthorized access to your proprietary data.
We do not sell your personal or proprietary business data. We only share information in the following limited circumstances:
- AI Integrations: Specific data points (e.g., SWOT entries, KPI trends) are sent to secure Large Language Model (LLM) providers solely to generate the AI responses and insights you request. These providers are not permitted to use your data for training their public models.
- Service Providers: We may use trusted third-party providers for hosting (Base44), database management, and email delivery. These providers are bound by strict confidentiality agreements.
- Legal Requirements: If required by law, we may disclose information to comply with legal processes.
Security Measures: Your data is secured using industry-standard encryption protocols, both in transit (TLS) and at rest. FoClea is built on the Base44 platform, whose infrastructure is independently certified to SOC 2 Type II and ISO 27001 standards.
Per-User Data Isolation: We enforce Row-Level Security so that each user can only access their own records. Your plans, KPIs, assessments, and reports are isolated from other customers and restricted to your authenticated account.
Data Retention & Right to Deletion: We retain your business data for as long as your account is active. You can delete specific data points (e.g., Plans, KPIs) directly within the app at any time. You also have the right to request full deletion of your account and all associated data (the "right to be forgotten") by emailing support@movingforwardsmallbusiness.com; we will process such requests promptly.
To further safeguard your data, FoClea leverages Base44's robust application security features:
- Built-in Security Checks: Base44's platform automatically identifies and alerts us to potential vulnerabilities such as exposed sensitive data, leaked API keys, and misconfigured access controls.
- Role-Based Access Control (RBAC): Access to features and data is strictly controlled based on user roles (e.g., admin, user), ensuring that users only have the permissions necessary for their functions.
- Row Level Security (RLS) & Field Level Security (FLS): We implement granular data access controls, allowing us to define exactly which data rows and specific fields users can view or modify. This ensures that personal and proprietary information remains isolated and secure.
- Secure Backend Functions: Sensitive business logic and critical code are run on secure backend functions, protecting them from client-side exposure.
- Secrets Management: API keys and other credentials are securely managed, preventing unauthorized access.
- Server-side Validation & Rate Limiting: All data inputs are rigorously validated on the server, and rate limiting is applied to protect against abusive behavior and ensure system stability.
We are committed to ensuring digital accessibility for people with disabilities. For more information about our efforts and standards, please view our Accessibility Statement.
You have the right to:
- Access the personal and business data we hold about you.
- Correct or update inaccurate information through your account settings.
- Delete your data or your entire account.
- Export your strategic plans and reports.
For any privacy-related questions or to request data actions not available in the UI, please contact us at support@movingforwardsmallbusiness.com.
