1. Who is responsible for the data

Foplink, available at foplink.com, is operated by Netinteractive sp. z o.o., with its registered office at ul. Saska 103/1, 03-914 Warsaw, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS 0000612484, NIP 5272766291, VAT ID PL5272766291, REGON 364134276. Netinteractive sp. z o.o. is the controller of account, security, and service administration data. You can contact us about privacy matters at privacy@foplink.com.

When a company or project owner uses Foplink to collect feedback from clients or team members, that organization decides why the project content is processed. In that context, the organization may be the data controller and Foplink acts as its service provider or processor. Reviewers may contact either the organization that sent the invitation or Foplink.

2. Information we process

Account and reviewer identity

The personal identity information requested directly by Foplink is limited to:

  • email address for account access, invitations, and password recovery;
  • an optional name or display name;
  • an automatically generated reviewer name when a guest does not provide one.

Passwords are not stored in readable form. Foplink stores password hashes and security tokens needed to authenticate accounts, guest sessions, invitations, and password resets.

Project and review content

To provide the review service, Foplink also processes content supplied by workspace owners and reviewers, including:

  • organization, workspace, and project names;
  • project URLs and uploaded prototype files;
  • comments, replies, status changes, authorship, and timestamps;
  • the page URL and page title associated with an annotation;
  • CSS selectors, XPath, selected element tag, ID, classes, visible text, selected accessibility attributes, and element position;
  • export files generated at a user’s request.

This review content is not necessarily personal data, but it may contain personal data if a user includes it in a project, page, comment, or selected element.

Technical and security data

Foplink may process standard request information such as IP address, browser type, timestamps, request status, and security events in server logs. The web application uses an essential session cookie. The extension uses local browser storage for account or guest session tokens and preferences.

3. How the Chrome extension works with page data

When the Foplink Reviews side panel is open, the extension reads the active tab URL and title so it can load annotations for that exact page. When a reviewer selects an element and submits a comment, the extension sends the selector and limited element context listed above to Foplink.

The extension does not collect or transmit the reviewed website’s cookies, authentication credentials, complete browsing history, or form values. It does not record screenshots or send the full page source. A user may still include information from a page in a selected element or comment, so reviewers should avoid submitting confidential information that is not needed for the review.

4. Why we process information

Foplink processes information for the following purposes:

  • creating and securing accounts and workspaces;
  • hosting prototypes and connecting live website reviews;
  • displaying, saving, replying to, resolving, deleting, and exporting annotations;
  • sending account access, invitation, and password recovery messages;
  • preventing abuse, diagnosing errors, and maintaining service reliability;
  • responding to support, privacy, and legal requests.

5. Legal bases

Where the GDPR or similar law applies, Foplink relies on:

  • performance of a contract or steps requested before entering a contract to provide accounts, projects, review links, annotations, and exports;
  • legitimate interests in securing, maintaining, and improving the reliability of the service, provided those interests do not override individual rights;
  • legal obligations when processing is required by applicable law;
  • consent where a specific optional use requires it. Consent can be withdrawn at any time.

6. Sharing and disclosure

Foplink does not sell personal data and does not use review data for targeted advertising.

Information may be shared only with:

  • workspace owners, project members, invited reviewers, and other people given access to the relevant project;
  • hosting, infrastructure, database, email delivery, backup, and security providers acting on our instructions;
  • professional advisers or authorities when required to protect rights, investigate abuse, or comply with law;
  • a successor in connection with a merger, acquisition, financing, or transfer of the service, subject to appropriate confidentiality and notice requirements.

7. International transfers

Service providers may process information in countries outside the user’s country. Where personal data is transferred outside the European Economic Area, Foplink uses a legally recognized transfer mechanism or another safeguard required by applicable law.

8. Retention and deletion

Account information is retained while the account is active and for as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes, and protect the service. Project files, annotations, and replies remain available until they are deleted by an authorized user, the project is removed, or the workspace owner requests deletion.

Expired sessions and password reset tokens are removed or become unusable after their validity period. Deleted information may remain temporarily in restricted backups until those backups are overwritten according to the operational backup cycle.

9. Security

Foplink uses HTTPS in transit, password hashing, access controls, scoped project permissions, signed or revocable review links, and limited session tokens. No internet service can guarantee absolute security, so workspace owners should avoid uploading secrets or production data that is not required for a review.

10. Your privacy rights

Depending on applicable law, individuals may have the right to request access, correction, deletion, restriction, portability, or objection to processing. Where processing is based on consent, consent may be withdrawn without affecting processing that occurred before withdrawal.

Send a request to privacy@foplink.com. We may need to verify the requester’s identity and project relationship before disclosing or deleting information. Reviewers may also contact the organization that invited them.

Individuals in the European Economic Area may lodge a complaint with their local data protection authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO).

11. Children

Foplink is a business service and is not directed to children. Workspace owners should not invite children to submit reviews or knowingly upload children’s personal data without an appropriate legal basis.

12. Chrome Web Store Limited Use disclosure

The use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Page and annotation data is used only to provide and secure Foplink’s website review functionality and is not used for advertising or unrelated profiling.

13. Changes to this policy

Foplink may update this policy when the service, legal requirements, or data practices change. The effective date at the top of the page will be updated. Material changes will be communicated through the service or another appropriate channel before they take effect where required.