Privacy Policy

Effective Date: 02-July-2025
Last Updated: 02-July-2025

For individuals in the European Economic Area, United Kingdom, and Switzerland, you can read this version⁠ of our Privacy Policy

The following Privacy Policy governs the online information collection practices of Foyer Technologies Private Limited ("Company," "Foyer," "Merlin," "we," or "us"). This Privacy Policy outlines the types of information that we gather about you while you are using our websites https://merlin.foyer.work/, https://www.getmerlin.in, browser extensions (Chrome, Edge, Firefox, Safari), mobile applications (iOS and Android), the AI Note Taker app, our API services, and any other related services (collectively, the "Services"), and the ways in which we use this information.

Foyer operates Merlin AI, a comprehensive AI-powered assistant that helps users ("User(s)") access state-of-the-art AI models for various tasks including text generation, conversation, document analysis, image generation, web searching, and more. We also enable users to share their content such as information, files, and folders ("Content") and analyze interactions with their customers, prospects, and third parties ("Viewer(s)"). Viewers are non-registered users who may access content shared by our registered Users.

We process your data in accordance with applicable laws and regulations, following industry best practices for data protection and AI safety. This Privacy Policy is designed to help you understand how we collect, use, share, and protect your information.

1. Purpose and Scope

This Privacy Policy applies to information we collect:

This policy does NOT apply to:

2. Information We Collect

2.1 Information You Provide Directly

Account Information: When you create an account, we collect your name, email address, and account credentials.

User Content: We collect the content you provide when using our Services, including:

Payment Information: When you purchase subscriptions or services, we collect payment details (processed securely through third-party payment processors).

Communications: Information you provide when you contact our support team or participate in surveys.

2.2 Information We Collect Automatically

Usage Information: We collect information about how you interact with our Services, including:

Device Information: We collect:

Cookies and Similar Technologies: We use cookies, web beacons, and similar technologies to collect information about your browsing activities. See our Cookie Policy below for details.

2.3 Information from Third Parties

OAuth Providers: When you sign in using Google, Apple, or other OAuth providers, we receive basic profile information.

Cloud Storage Services: When you connect cloud storage accounts (e.g., Google Drive, Dropbox), we access only the files you choose to process.

Analytics Providers: We receive aggregated analytics data about Service usage from our analytics partners.

3. How We Use Your Information

We use the information we collect to:

3.1 Provide and Improve Our Services

3.2 Communicate with You

3.3 Ensure Safety and Security

3.4 Business Operations

3A. Lawful Bases for Processing

We process your personal data only when permitted under applicable data protection laws. Our processing activities are based on one or more of the following lawful grounds:

We rely on your freely given, specific, informed, and unambiguous consent to process your data for:

Performance of a Contract

We process your data to provide the Services you request under our Terms of Service, including:

We may process your data to comply with applicable legal obligations, such as:

Legitimate Interests

We process your data when it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This includes:

Where necessary, we may process your data in connection with the exercise or defence of legal claims, including dispute resolution or investigations.

4. How We Share Your Information

We do not sell your personal information. We share information in the following circumstances:

4.1 Service Providers

We share information with third-party service providers who help us operate our Services, including:

4.2 API and Integration Partners

If you connect third-party services, we may share data as necessary to provide integrated functionality.

We may disclose information if required to do so by law or in response to valid legal requests from public authorities.

4.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

4.5 Safety and Protection

We may share information to:

We may share your information with your explicit consent or at your direction. Where we rely on your consent to process personal data, you may withdraw that consent at any time by updating your account settings or contacting us at support@foyer.work or dpo@foyer.work

4.7 Aggregated or De-identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you. Access to your information is limited to authorized employees, contractors, and service providers who require it to perform their duties. All such individuals are subject to strict confidentiality obligations.

5. Data Retention

We retain your information for as long as necessary to:

Specific retention periods:

6. Your Rights and Choices

6.1 Access and Portability

You can access, download, or export your information through your account settings.

6.2 Correction

You can update or correct your information through your account settings or by contacting us.

6.3 Deletion

You can request deletion of your account and associated data. Some information may be retained as required by law.

6.4 Communication Preferences

You can opt out of marketing communications through the unsubscribe link in emails or account settings.

You can manage cookie preferences through our cookie consent tool or your browser settings.

6.6 Do Not Track

We do not currently respond to Do Not Track browser signals.

6.7 Account Information

You can update account information through your account settings or by contacting support. You can manage cookie preferences through our cookie consent tool or your browser settings.

7. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and any applicable regulators within the timelines prescribed by law.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including:

9. Sensitive Information

We do not intentionally collect sensitive personal information (e.g., health data, religious beliefs, political opinions). If you provide such information in prompts or content, you do so at your own discretion.

10. Children's Privacy

Our Services are not intended for children under 16 (or applicable age of digital consent in your jurisdiction). We do not knowingly collect information from children. If we learn we have collected information from a child without proper consent, we will delete it promptly. Parents or guardians who believe we may have collected information from their child should contact us immediately.

Here's a clear, compliant, and user-friendly privacy policy section you can include to address the feedback regarding account creation and Google login:

11. Account Registration and Login

We offer users the ability to register and log in to our platform either by creating a dedicated account or by using a third-party authentication provider such as Google.

11.1 Standard Registration

When registering using the standard form, the following personal data is collected and marked with an asterisk (*) to indicate that it is required for account creation:

These data fields are mandatory in order to create and maintain a secure user account.

11.2 Login via Google (OAuth)

As an alternative, you may choose to log in using your existing Google account. If you do so, we will receive certain information from Google, specifically:

This data is used solely for authentication and account creation/login purposes. We do not gain access to your Google password or any other data from your Google account beyond what is explicitly authorized.

11.3 Legal Basis

The legal basis for processing your data during registration or login is:

11.4 Data Retention

We retain your registration data for as long as your account remains active. You may request deletion of your account at any time.

12. Data Processing Activities and Legal Bases

Processing ActivityPurposeLegal BasisApplicable Region
Account Registration & User ManagementTo create, manage, and secure your user account, including enabling log-ins via email or third-party providers (e.g., Google).Art. 6(1)(b) GDPR — Performance of a contractEU, UK, Switzerland
Identity Verification (if applicable)To verify your identity for security and fraud prevention when creating or managing your account.Art. 6(1)(c) GDPR — Legal obligation (where required) and Art. 6(1)(f) GDPR — Legitimate InterestEU, UK, Switzerland
Service ProvisionTo deliver the GetMerlin.com services you have requested, including the core AI tools and extensions.Art. 6(1)(b) GDPR — Performance of a contractEU, UK, Switzerland
Email Communications & NotificationsTo send you account-related information (e.g., password resets, service updates).Art. 6(1)(b) GDPR — Performance of a contractEU, UK, Switzerland
Marketing Emails & NewslettersTo send you marketing materials, updates, and offers, if you have opted in.Art. 6(1)(a) GDPR — ConsentEU, UK, Switzerland
Analytics & Performance TrackingTo analyse usage of our website/app, measure performance, and improve our services (e.g., Google Analytics, Googleapis).Art. 6(1)(a) GDPR — ConsentEU, UK, Switzerland
Cookies for Essential FunctionalityTo store your cookie preferences and keep our site secure and functioning properly.Art. 6(1)(f) GDPR — Legitimate InterestEU, UK, Switzerland
Third-Party Content & Plug-insTo display embedded content or enable sharing via social plug-ins/buttons (e.g., YouTube, LinkedIn, Twitter, Instagram).Art. 6(1)(a) GDPR — ConsentEU, UK, Switzerland
CDN & Security ServicesTo deliver website content quickly and securely via services like Jsdelivr CDN.Art. 6(1)(f) GDPR — Legitimate InterestEU, UK, Switzerland
Customer SupportTo respond to your inquiries and resolve any support tickets you submit.Art. 6(1)(b) GDPR — Performance of a contractEU, UK, Switzerland
Legal & ComplianceTo comply with legal obligations, enforce our Terms of Service, or defend our legal rights.Art. 6(1)(c) GDPR — Legal obligation & Art. 6(1)(f) GDPR — Legitimate InterestEU, UK, Switzerland

Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with personal information.

Our website includes icons or buttons that link to our official profiles on social media platforms, including:

X (formerly Twitter) LinkedIn Instagram Youtube

These buttons function solely as external links. When you click on one of these icons, you are redirected to the respective platform. No personal data is transferred to these platforms simply by visiting our website.

Please note that once you are on these external sites, their own privacy policies and terms of service apply. We do not control how these platforms collect or process your personal data.

15. Updates to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes through the Services or by email. The "Effective Date" at the top indicates when this Policy was last revised.

16. AI-Specific Privacy Practices

16.1 Your AI Content

16.2 AI Safety and Ethics

We are committed to responsible AI development and deployment:

17. Data Processing for Business Users

If you use our Services on behalf of an organization:

For enterprise customers, we offer Data Processing Agreements (DPAs). Contact dpo@foyer.work to request a DPA.

18. Marketing and Advertising

We may use your information for marketing purposes:

You can opt out of marketing at any time through your account settings or by clicking "unsubscribe" in our emails.

19. Automated Decision Making

We use automated systems for:

You have the right to request human review of significant automated decisions that affect you. If you disagree with our decision on any request, you may appeal by contacting us again at dpo@foyer.work within 30 days of communication of such decision to you.

20. Impact assessment

We conduct privacy and data protection impact assessments where required by law, particularly for high-risk features involving automated decision-making or large-scale processing.

21. Data captured on our mobile apps

We capture the following data across our mobile apps (Merlin AI, Notetaker app, Wallflower)

  1. Firebase analytics – Firebase Analytics help us understand how users interact with our website by collecting information about mouse movements, clicks, and scrolling behavior.
  2. Facebook events – Facebook events helps us measure, optimize, and build audiences for our advertising campaigns. It allows us to track conversions from Facebook ads, Optimize ads based on collected data, build targeted audiences for future ads and remarket to qualified leads who have already taken action on our app.
  3. TikTok events – Tiktok events help us measure, optimize and build audiences for our advertising campaigns on tiktok.
  4. Microsoft Clarity - Microsoft Clarity also help us understand how users interact with our website by collecting information about mouse movements, clicks, and scrolling behavior.

22. Requests and Contact Us

Any request that you may want to share or submit may also be submitted by authorized agents. In such cases, we require signed permission from the data subject.

Contact Us

For questions about this Privacy Policy or our privacy practices:

Data Protection Officer: dpo@foyer.work
Customer Support: support@foyer.work
DPO Phone: Sirsendu Sarkar (+91-8953348922)

Our DPO: Sirsendu Sarkar (+91-8953348922)

EU GDPR Representative:
Rickert Rechtsanwaltsgesellschaft m.b.H.
Colmantstraße 15, 53115 Bonn, Germany
Email: info@rickert.law
Phone: +49 (0)228 74 898 0

UK GDPR Representative:
Rickert Services Ltd UK
PO Box 1487, Peterborough, PE1 9XX
United Kingdom
Email: art-27-rep-foyertech@rickert-services.uk

Mailing Address for DPO: House 721, 6th B Cross Road, Block-3, Koramangala, Bangalore, India 560034

Registered Address and Mailing Address: Foyer Tech Inc 16192 Coastal Highway, Lewes, DE 19958 United States Email: support@foyer.work

California

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, contact us at support@foyer.work.

Other Jurisdictions

If you are located in other jurisdictions with specific privacy laws, you may have additional rights. Contact us to learn more.


Cookie Policy

This Cookie Policy explains how we use cookies on our websites and applications (the "Services"), the types of cookies we use, and your rights regarding cookie management. You can access our cookie policy from here

Browser Help Pages:


End User License Agreement (EULA)

Your use of our applications may be governed by platform-specific End User License Agreements:


Procedure for Data Withdrawal via Erasure and Objection

You have the right to request the withdrawal of your data through erasure of your personal data held by us. This means we will delete all personal data pertaining to you from our systems, subject to any legal obligations for data retention.

To initiate a request for data erasure:

  1. Send an email to support@foyer.work
  2. CC dpo@foyer.work
  3. Include "Data Erasure Request" in the subject line
  4. Provide your account email and any relevant details

We will respond to your request within 30 days and complete the erasure within the timeframes required by applicable law.

You also have the right to object to the processing of your personal data where we rely on legitimate interests or use your data for direct marketing purposes. To exercise this right, contact us at dpo@foyer.work and support@foyer.work