Privacy Policy
Effective date:
Table of contents
This document describes how Folk (hereinafter “We”, “Us”) collects, uses, stores, and protects the personal data (“Personal Data”) You, or your employees using the Platform (the “Users”) provide to Us through the platform “Folk” (the “Platform”).
We are committed to comply with the provisions of the General Data Protection Regulation (GDPR).
By accessing the Platform and using the Services, You and the Users acknowledge that You and the Users have read this privacy policy (the “Privacy Policy”). The Privacy Policy applies to the processing of personal data performed when using the Platform and Services.
The Privacy Policy supplements the Platform's terms of service (“TOS”). Capitalized terms not defined in the Privacy Policy have the meaning given to them in the TOS.
By using the Platform and the Services, the Users and You are bound by the Privacy Policy, which can be modified or updated at any time. Any modification will be posted on the Platform. If the modifications or updates concern elements for which Your consent of was required, We will inform You in order to obtain Your consent again.
1. Data Controller
We, Folk Inc., a Delaware corporation, whose registered office is located at 1209 North Orange Street, Wilmington, Delaware 19801, is the Data Controller, within the meaning of the GDPR, of Your personal data, as well as the Users’ Personal Data.
For any question or request relating to this Privacy Policy or to the processing of Your or the Users’ Personal Data, You can contact Us at the following address: privacy@folk.app
2. Conditions for processing Your personal data
We collect and use Personal Data that You have spontaneously transmitted to Us, which is necessary to subscribe to the Services and to receive emails containing information from Us (newsletters).
You must provide accurate, true, and correct personal details and information and update these data and information whenever necessary so it remains true and complete.
We collect and process Your Personal Data in a fair and lawful manner, while respecting Your rights.
Under no circumstances do We (i) sell Your Personal Data and (ii) use Your Personal Data to train AI models.
3. Information collected
We collect information about You and the Users including information that You and the Users provide in connection with the Service, information from Third Parties, and information that is collected automatically such as through cookies and other technologies:
- personal information including, but not limited to, full names, postal address, email address;
- payment information, including, but not limited to, payment card number, expiration date, security code and billing address, invoices;
- information that Your and Users’ browser sends whenever the Services and Platform are used;
- third-party services that We use and that collect, monitor and analyze data to provide analytics and other data to help us to improve Our Platform and Services;
- third-party services (including, but not limited to, Microsoft Outlook, Gmail, iCloud) used by You and the Users to import data in the Platform including, but not limited to, Contacts Personal Data (email, name, address, phone number, calendar events, etc.), being specified that We process Contacts Personal Data as Your processor and in compliance with our Data Processing Agreement;
- inquiries and feedbacks provided by You and/or the Users, including contact information and content of the inquiries and feedbacks; and
- Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding an interaction with the Platform.
We requested Your Google data access or Your Microsoft data with the following scope:
- Access to the contacts in Your Google Contacts after you authenticate (auth/contacts);
- Read email resources metadata including Your labels, history records, and email messages (…/auth/Gmail.read-only – or Microsoft);
- Read events in Your calendars (…/auth/calendar.read-only);
- Send emails using Your Gmail account (…/auth/gmail.send).
The only way our Service access Your Google data is after You explicitly accept our Privacy Policy and provide us with the right to access Your Google data, as defined above. We are fully compliant with Google requirements. We will use reasonable efforts to protect Your information collected through Google API and we will not use this data to develop, improve or train generalized AI or LM models.
Folk Mobile Application
When you use the folk mobile application on iOS or Android, we additionally collect:
- Device identifiers including the iOS Identifier for Vendor (IDFV) and an Android Application ID. These are used to associate a session with Your and the Users’ folk account, for crash reporting, and for diagnostics. They are not used for advertising and are not shared with advertising networks.
- Crash and performance diagnostics, including stack traces, operating system version, device model, app version, and anonymized usage events. This data is used solely to identify and fix bugs and to improve mobile app performance.
- In-app activity, such as which screens you visited and which features you used, used to improve the product. This data is associated with Your and the Users’ folk account.
The folk mobile application does not access the contacts stored in your device’s native address book. CRM contacts are imported only from the third-party services you explicitly connect (Google, Microsoft, and the others listed in our List of Sub-Processors).
The folk mobile application does not currently send push notifications and does not collect push notification tokens.
The folk mobile application does not include cross-app advertising or tracking SDKs and does not display third-party advertising. The iOS app does not request App Tracking Transparency permission.
4. Purpose of processing and legal basis
We collect information, including Personal Data, for the purpose following purposes and legal bases:
- deliver the Platform and Services to You and the Users (legal basis: performance of the TOS);
- identifying and communicating with You, including newsletters and marketing materials (legal basis: Our legitimate interests to communicate with You and the Users);
- responding to Your requests, including customer service inquiries (legal basis: performance of the TOS);
- processing Your payments (legal basis: performance of the TOS);
- improving the Services and analyzing Your and the Users’ usage of the Platform and Services (legal basis: Our legitimate interests to improve the Platform and Services); and
- responding to valid legal processes and valid requests from government authorities (legal basis: legal obligation).
The way we use Your and the Users’ data obtained through Google API is explicitly limited to the use defined below:
- Providing the Platform and Service;
- Access to the contacts in Your Google contacts and read resources metadata to synchronize Your contacts and metadata so You can access them on Our Service. Our use of Google data is limited to the practices explicitly disclosed in this Privacy Policy. We must obtain Google’s express consent for using Google data beyond the limits set in this Privacy Policy.
5. Recipient of Personal Data and transfer outside European Union
Within the framework of the management of the Platform and Services, We may transmit Personal Data to several recipients, in particular:
- Service Providers: We may disclose information we collect about you to our third-party service providers. The categories of service providers to whom we entrust your information include service providers for: (i) the provision of the Services; (ii) the provision of information, products, and other services you have requested, including Non-folk Services as that term is defined in the Agreement; (iii) marketing and advertising; (iv) payment and transaction processing; (v) customer service activities; (vi) the provision of IT and related services; and (vii) fraud prevention and user authentication.
- Advertising Partners: We do not disclose or use your information to advertise any third party’s products or services via the Services. We may disclose your information to third-party advertising partners to market our own Services and grow our Services’ user base, such as to provide targeted marketing about our own Services via third-party services. Please see the “Your Choices” and “Your Rights” sections below for more information and to opt out.
- Disclosures to protect us or others: We may access, preserve, and disclose any information we store in association with you to external parties if we, in good faith, believe doing so is required or appropriate to: (i) comply with law enforcement or national security requests and legal process, such as a court order or subpoena; (ii) protect your, our, or others’ rights, property, or safety; (iii) enforce our policies or contracts; (iv) collect amounts owed to us; or (v) assist with an investigation and prosecution of suspected or actual illegal activity.
- Disclosure in the event of merger, sale, or other asset transfer: If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of some or all assets, or transition of service to another provider, then your information may be sold or transferred as part of such a transaction, as permitted by law and/or contract.
The recipients of Personal Data are the following:
| Processor | Type of data | Reason | Region | Can opt out |
| TurboPuffer | Contact data | Search | USA | No |
| Apollo.io | Contact data | Enrichment | USA | No |
| AWS | PII, Contact data | Hosting (servers / databases / storage) | USA | No |
| Churnkey | PII | Churn management | USA | No |
| Confluent | Contact data | Event streaming | USA | No |
| Datadog | Diagnostics, logs | Infrastructure monitoring | EU | No |
| Datagma | Contact data | Enrichment | USA | No |
| DropContact | Contact data | Enrichment | EU | No |
| ElevenLabs | Contact data | Note dictation (speech-to-text) | USA | Yes |
| Google Analytics | Cookies | Marketing | USA | Yes (decline cookie banner) |
| Google Workspace | Contact data | Contact and Interactions sync | USA | Yes |
| Intercom | PII | Customer Support | USA | No |
| Linear | PII | Bug tracking | USA | No |
| Make | Contact data | User-configured automations | EU | Yes |
| Microsoft 365 | Contact data | Contact and Interactions sync | USA | Yes |
| OpenAI | Contact data | Enrichment, Formatting | USA | No |
| People Data Labs | Contact data | Enrichment | USA | No |
| Perplexity | Contact data | Enrichment | USA | Yes |
| Prospeo | Contact data | Enrichment | EU | No |
| RevenueCat | PII | Mobile payments / subscription management | USA | No |
| Sendgrid | Contact data | Emailing | USA | Yes |
| Sentry | Technical data | Service quality | ||
| Stripe | PII | Billing | USA | No |
| Stytch | PII | Authentication | USA | No |
| Zapier | Contact data | Automations | USA | Yes |
| Contact data | Contact and Interactions sync | USA | Yes |
We may also share, transmit, disclose, grant access to, make available, and provide Personal Data with and to Third Parties if in accordance with this Privacy Policy. Under no circumstances will We share Your Google data with Third Parties, except in accordance with this Privacy Policy. We commit not to communicate, sell, or transfer Personal Data to Third Parties (aside from Our service providers) without Your express consent, but may communicate them if the law so requires, or upon judicial or government request.
When Personal Data are transferred to countries outside of the European Union, We ensure that the following safeguards are taken:
- Processors are certified under the Data Privacy Framework, which benefit from an adequacy decision from the European Commission pursuant to article 45 of the GDPR and the transfer falls within the scope of such adequacy decision; or
- We have concluded a contract with the recipient of Personal Data that contains the Standard contractual protection clauses adopted by the European Commission pursuant to article 47 of the GDPR.
6. Rights of Data Subjects
Pursuant to GDPR, You and the Users have the following rights:
- The right to access, modify, delete and transfer Personal Data;
- The right to oppose or restrict the processing of Personal Data;
- The right to obtain communication of Personal Data in a structured, commonly-used, readable format (data portability, unless legitimately impossible);
- The right to withdraw consent at any time, when processing relies on consent. In such case, the withdrawal of the consent will not affect the lawfulness of the processing carried out prior to the withdrawal of such consent.
If You are located in the European Union, You also have the right to lodge a complaint with the competent supervisory authority for data protection matters. In France, this is the Commission nationale de l’Informatique et des Libertés (CNIL). You also have the right to define directives pertaining to your digital testament.
You and the Users may exercise these rights by sending an email to privacy@folk.app. We undertake to respond to Your and the Users’ request within thirty (30) days from the receipt of the request. Subject to a possible extension of two additional two months, We reserve the right to object to any requests considered unreasonable due to the repetitive nature thereof.
You may delete your folk account at any time reaching out to support@folk.app. In the folk mobile app (iOS or Android), you can request the deletion by navigating to Settings → Delete account. More information available at https://help.folk.app/en/articles/5701307-how-do-i-delete-my-account
You and the Users are informed that We may, in the event of a doubt as to Your or the Users’ identity, ask for proof of identity in order to prevent any unauthorized access to Personal Data.
7. Communication
We may send You emails to the address associated to Your Account and to the Users’ account, to inform You and the Users of the Services changes or its activities, or to communicate technical or administrative information.
You and the Users may opt out of receiving any, or all, of these marketing communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us. Please note that We may still send You transactional or administrative messages related to the Services even after You have opted out of receiving marketing communications.
8. Data retention, security, and deletion
Personal Data are hosted by Amazon Web Services inside Aurora database that is fully-secured and not accessible outside our servers. Our AWS services are located in the US. We implement technical and organisational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
We are not storing Your Google data except Your Personal Data, including email addresses and Google unique resource IDs.
All data transmitted between your browser, desktop application, or mobile device and folk’s servers is encrypted in transit using TLS 1.2 or higher. Data at rest in our databases and S3 storage is encrypted using AES-256.
We keep Personal Data as long as Your account remains active.
Your account and the Users’ account will be deleted within one week of the deletion request. However, Personal Data associated with the account will be kept for as long as necessary for the purposes for which they are processed.
Personal Data will be removed:
- from Our databases within 7 days after the deletion request date;
- from Our database backups within 730 days after the deletion request date;
- from Our application logs within a maximum of 930 days after the deletion request date.
Independently from deletion requests, We apply specific retention periods depending on the purposes pursued, in particular: (i) customer account data are kept for the duration of the contractual relationship, then archived for up to five (5) years in intermediate storage for the establishment, exercise or defence of legal claims; and (ii) accounting documents are kept for ten (10) years in accordance with Our legal obligations. At the end of the applicable retention periods, the Personal Data are deleted or irreversibly anonymized.
However, requests to delete Personal Data may be refused, in whole or in part, where such deletion would prevent Us from complying with a legal obligation, or where the processing remains necessary, in particular (i) for the establishment, exercise or defense of legal claims, (ii) for compliance with statutory retention periods (in particular in accounting and tax matters), (iii) for reasons of important public interest (including the detection and prevention of fraud or security incidents), (iv) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, to the extent that the deletion of the data is likely to render impossible or to seriously impair the achievement of the objectives of such processing, or (v), where applicable, comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546).
9. Cookies
A cookie is a file that can be recorded on the hard drive of Your and the Users’ terminals when accessing and using the Platform and Services. Cookies may collect information to improve the Services and Platform. Depending on the purposes of the cookies, consent is necessary for the deposit of cookies.
We use cookies:
- of navigation, which are cookies necessary for the proper technical functioning of the Platform as they allow for the optimization of the display of the content from each terminal and for the application of security parameters (“_cfuid” cookies), which expire when You and the Users close the browser;
- functional cookies, which are not essential to the proper functioning of the Platform but optimize the experience by allowing it to be adapted to You and the User’s terminal and by saving the choice regarding the deposit of cookies. These cookies expire after one year;
- analytics and audience measurement, which allow to follow the navigation of the Users for the purpose of optimization. We use:
- Google Analytics, a web analytics service provided by Google to improve the operation of the Platform. Google Analytics uses the data collected, including the number of visitors, the origin and the details of the pages that were visited, to track and study the use of the Platform, to prepare reports on activities. Google’s privacy policy is available under this link. The main cookies used are the following:
| Name of the cookies | Function, recipient and retention period | Purpose |
| _ga | This cookie is used for Google Analytics. It allows to follow the performance of the pages consulted by the users. This cookie expires after 13 months. | Performance |
- Twilio (Segment)
We do not keep tracking cookies or cookies containing IP addresses for more than thirteen (13) months after their initial deposit on the terminal(s). You and the User may at any time delete cookies from the browser and set it up to block their storage on terminals. We invite You and the Users to refer to the help file of the browser software to establish the appropriate setup.
Rejecting the use of cookies may prevent optimal use of the Platform and Services. Traffic data are generated when the terminal is connected to the internet and the Platform and Services. These data may be used to improve Our Service. We never use personal names in traffic data analyses.
10. Stipulations for US Users
10.1. Children's privacy
Our Services are intended for a general audience and not directed to Users under thirteen (13) years of age (“Children”). We do not intend to collect personal information as defined by the U.S. Children’s Privacy Protection Act (“COPPA”) in a manner that is not permitted by COPPA.
If You are a parent or guardian and believe We have, please contact Us here and We will remove such data to the extent required by COPPA.
For more information on COPPA, click here or visit www.FTC.gov and look for parental guidance on child online safety and privacy.
10.2. Non-Discrimination: we will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you with a different level or quality of goods or services.
- Suggests that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
Any questions?
Questions regarding this policy may be sent to security@folk.app. We also invite you to contact us with suggestions for improvements.