FROKO
Features Stats Roadmap Pricing About
Sign in Join Early Access
LEGAL

Privacy Policy

Last updated: September 7, 2026

This policy explains what personal data Froko Technologies, Inc. ("Froko", "we", "us") collects when you use our website and application, why we collect it, who we share it with, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and equivalent laws.

ON THIS PAGE 1. Who we are 2. Data we collect 3. Why we collect it 4. Third-party services 5. Where data is stored 6. How long we keep it 7. Your rights 8. Cookies 9. Security 10. Children's privacy 11. Changes to this policy 12. Contact us

1. Who we are

Froko is an AI-powered front-office assistant for small and local businesses, operated by Froko Technologies, Inc. ("Froko", "we", "us", "our"). We are the data controller for the personal data described in this policy — meaning we decide why and how it's processed.

This policy covers both our marketing website (froko.eu) and our application (the Froko dashboard used by business owners and their customers' contacts).

2. Data we collect

We collect the following categories of personal data:

  • Identity data — your name, and where relevant, the names of your customers or contacts stored in your conversations.
  • Contact data — email address and phone number, for you and for the contacts you communicate with through Froko.
  • Business data — company name, industry, and other details you provide when setting up your account or assistant.
  • Communications content — the calls, SMS, and email messages processed through the platform, so we can display, categorise, and (where enabled) auto-respond to them on your behalf.
  • Usage data — login activity, feature usage, appointment and conversation history, and similar operational data needed to run the service.
  • Payment data — handled directly by our payment processor (Stripe); we do not store full card numbers ourselves.
  • Connected account data — if you choose to connect Gmail, Outlook, Google Calendar, Google Contacts, Google Meet, Microsoft Teams, Zoom, LinkedIn, or a Facebook Page, we access the data in those accounts (e.g. email and calendar content, meeting recordings and transcripts, contacts, or the ability to post on your behalf) only as needed for the specific feature you've enabled, and store the access credentials required to keep that connection working.

3. Why we collect it

We only process personal data where we have a valid legal basis to do so under GDPR Article 6:

  • Performance of a contract — to create your account, run the assistant, and deliver the core service you've signed up for.
  • Consent — for the waitlist/early-access forms on our marketing site, and for any optional communications you opt into.
  • Legitimate interests — to keep the service secure, diagnose issues, and improve the product, balanced against your right to privacy.
  • Legal obligation — where we're required to retain certain records (e.g. billing) by law.

A core part of the service is AI-assisted processing: message content may be sent to our AI providers to categorise conversations and, where you've enabled it, draft or send automatic replies. This only happens for accounts that have those features turned on.

4. Third-party services we use

We use a small number of trusted processors to run Froko. Each only receives the data it needs to perform its specific function, under a data processing agreement.

Supabase

Database, authentication, and file storage for your account and conversation data.

Region: EU
Stripe

Payment processing and subscription billing. We never see or store your full card number.

Region: EU / US (PCI-DSS compliant)
OpenAI

AI-based categorisation of incoming messages, AI-drafted auto-reply generation (used only on accounts that enable this feature), the onboarding chat, and — on accounts with AI phone answering enabled — real-time processing of live call audio.

Region: US — Standard Contractual Clauses apply
Groq

An alternative AI provider used for some of the same message categorisation and reply-drafting processing described above.

Region: US — Standard Contractual Clauses apply
Twilio

Phone calls and SMS text messages, for accounts that enable AI phone/SMS handling — call audio, call metadata, and text message content pass through Twilio to reach our systems.

Region: US/EU — Standard Contractual Clauses apply
ElevenLabs

Text-to-speech voice generation for the AI phone assistant, on accounts using that configuration.

Region: US/EU — Standard Contractual Clauses apply
Meta (Facebook)

For accounts that connect a Facebook Page: we read public Page content to help ground the AI assistant's answers about your business, and — when you choose to publish a post — we publish text updates directly to that Page's feed on your behalf.

Region: US — Standard Contractual Clauses apply
LinkedIn

For accounts that connect LinkedIn: when you choose to publish a post (AI-drafted or your own), we publish it to your own personal LinkedIn profile on your behalf. We never post to a LinkedIn Company Page.

Region: US — Standard Contractual Clauses apply
Google

For accounts that connect Gmail, Google Calendar, Google Contacts, or Google Meet: reads and sends email, manages calendar events, reads your contacts, and reads meeting recordings and transcripts, to power the assistant's inbox, scheduling, and meeting-summary features.

Region: US — Standard Contractual Clauses apply
Microsoft

For accounts that connect an Outlook/Microsoft 365 mailbox or Microsoft Teams: reads and sends email, and reads Teams calendar events and meeting transcripts — the same inbox and meeting-summary features as our Google integration, for accounts that use Microsoft instead.

Region: US — Standard Contractual Clauses apply
Zoom

For accounts that connect Zoom: reads your cloud meeting recordings and transcripts, to summarise customer calls and meetings.

Region: US — Standard Contractual Clauses apply
Nuntly

Delivery of transactional email — appointment confirmations, notifications, and account emails sent by Froko.

Email delivery provider

We do not use Instagram or WhatsApp messaging in the live product today — these remain on our public roadmap but are not yet built. This policy will be updated with the relevant disclosures before either goes live.

5. Where your data is stored

Our primary database runs on Supabase infrastructure hosted in the EU region, so your account and conversation records are stored within the EU by default.

Some processing is performed by the US-based providers listed in Section 4 — our AI providers (OpenAI, Groq), and, for accounts that choose to connect them, providers like Google, Microsoft, Zoom, LinkedIn, and Meta. Where personal data is transferred outside the EEA for this purpose, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards recognised under GDPR Chapter V.

6. How long we keep your data

We keep account and conversation data for as long as your account is active. If you delete a conversation, it moves to a recycle bin and is permanently erased after 14 days unless you restore it sooner. You can permanently delete your entire account and everything in it yourself, at any time, from Settings — this takes effect immediately and cancels any active subscription, except where we're legally required to retain billing records for longer.

7. Your rights under GDPR

If you are located in the EEA/UK (or covered by an equivalent law), you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — delete your personal data yourself at any time from Settings, or ask us to do it for you, subject to legal exceptions.
  • Restriction — ask us to limit how we use your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, including profiling.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.
  • Complain — lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us using the details in Section 12.

8. Cookies

Our marketing website does not use analytics or advertising cookies, and does not set any cookies of its own — because we don't use non-essential cookies here, there's no cookie consent banner to show you.

Our application uses essential session cookies (via Supabase) to keep you signed in securely. These are required for the app to work and cannot be turned off while using the service.

9. How we protect your data

We use industry-standard safeguards including encryption in transit (TLS), encrypted storage at rest, and access controls that limit who inside Froko can view customer data — restricted to what's needed for support and engineering work.

10. Children's privacy

Froko is a business tool intended for use by adults operating a business. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we'll delete it.

11. Changes to this policy

We may update this policy as our product or legal obligations evolve. Material changes will be reflected by updating the "Last updated" date at the top of this page. We encourage you to review it periodically.

12. Contact us

For any question about this policy, or to exercise your data rights, contact us at hello@froko.eu. We aim to respond to all data requests within 30 days, as required by GDPR.

FROKO

Quiet, intentional front office automation for modern trade and local businesses.

PRODUCT Features Roadmap Pricing About
LEGAL Privacy Policy Terms of Service
CONTACT hello@froko.eu Budakalász
© 2026 Froko Technologies, Inc. All rights reserved.
LEGAL

Legal Document