Privacy Policy
Effective date: 22 June 2026
This Privacy Policy explains how Foundasys ("Curly", "we", "us") collects, uses, and protects personal data when you use the Curly add-in (for Microsoft Word, Word on the web, OnlyOffice, and Euro-Office), the Curly dashboard, and the curly.io website (together, the "Service"). The Word add-in is listed on Microsoft AppSource as "Curly Pro".
We are the data controller for the personal data described below.
Curly's core privacy principle: the content of your documents is processed locally inside your Office or editor environment and is never transmitted to or stored on Curly's servers. The data we do collect is limited to what's needed to run your account, licence, and team — described in full below.
1. Who we are
| Controller | Foundasys |
| Address | Mina Krusemanstraat 299, 7513 HJ Enschede, The Netherlands |
| Chamber of Commerce (KvK) | 42092371 |
| VAT (BTW-id) | NL005494168B57 |
| Contact | [email protected] |
For any privacy question or to exercise your rights (Section 8), contact us at [email protected].
2. What data we collect
a. Account data — when you create an account or are invited to a team: your name, email address, and preferred language (locale). Curly is passwordless — you sign in with a one-time code sent to your email address or a secure single-use sign-in link, so we never ask for, see, or store a password.
b. Team & licence data — team name, membership and role, pending invitations (the invited email + role), and licence details (status, trial dates, seat allocation, and the identifiers of your subscription with our payment provider).
c. Device / activation data — when you activate the add-in on a device, we record: a device label (derived from your browser's user-agent string plus a randomly generated device identifier), the host application (e.g. Word, Word on the web, OnlyOffice, Euro-Office), an approximate country (a two-letter country code derived from your IP address at our network edge — we do not store your IP address with this record), and activation/last-seen timestamps.
d. Trial sign-up data — when you request an in-add-in trial code: your email, locale, and your IP address at the time of the request, used transiently to prevent abuse and rate-limit requests.
e. Billing data — payments are processed by our payment provider, Lemon Squeezy (a Stripe company), acting as Merchant of Record. We do not receive or store your full payment-card details; Lemon Squeezy does. We store your subscription/licence status and the provider's customer and subscription identifiers.
f. Communications — transactional emails we send (verification, trial reminders, invitations, billing notices) and any messages you send us for support.
g. Document content — NOT collected. When you use the add-in to scan or fill placeholders, your document is read and modified locally within your Office/editor environment. Document content is not transmitted to or stored on Curly's servers.
We do not use advertising trackers, sell personal data, or build advertising profiles.
3. How we use your data, and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide and operate the Service (accounts, licences, teams, activations) | Performance of a contract |
| Process payments and manage subscriptions | Performance of a contract |
| Send transactional/service emails | Performance of a contract |
| Authenticate you and secure the Service | Legitimate interests |
| Prevent fraud and abuse (e.g. trial-code rate limiting) | Legitimate interests |
| Understand aggregate, cookieless website usage | Legitimate interests |
| Monitor errors and performance to keep the Service reliable | Legitimate interests |
| Comply with legal/accounting obligations | Legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object at any time (Section 8).
4. Who we share data with (processors / sub-processors)
We use a small number of carefully chosen service providers ("processors") to run the Service. Most are based in or host within the European Union. Each processes data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Laravel Cloud (on AWS) | Application hosting | EU — eu-central-1 (Frankfurt) |
| Neon | Database (your account/team/licence data) | EU |
| Lemon Squeezy (a Stripe company) | Payments & Merchant of Record | United States (acts as Merchant of Record; EU VAT handled); safeguarded by Standard Contractual Clauses |
| Resend | Sending transactional email | EU region |
| Flare (Spatie) | Error & performance monitoring | EU — Belgium |
| Google Cloud Translation | Translating Curly's own interface text (not your data) | Google Cloud (global endpoint) |
| Simple Analytics | Privacy-friendly, cookieless website analytics | EU — Netherlands |
| Cloudflare | Content delivery, security, and edge country lookup | Global edge network |
Note on Google Translate: it receives only Curly's user-interface strings so we can show the app in your language. It does not receive your documents, your account data, or any personal data.
We will keep this list current. We do not share your personal data with any other third party except where required by law.
5. International transfers
We aim to process and store personal data within the European Economic Area (EEA). Where a provider operates outside the EEA, or where data may be transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. The providers that may involve a transfer outside the EEA are Lemon Squeezy (United States) and Cloudflare (global edge network); both operate under such safeguards. Google Cloud Translation receives only interface strings, not your personal data.
6. Cookies
Curly uses a minimal set of strictly necessary cookies only:
- A session cookie to keep you signed in to the dashboard.
- Small preference cookies that remember your appearance (light/dark), sidebar state, and chosen language.
Our website analytics (Simple Analytics) are cookieless and collect no personal data. The Curly add-in itself uses no analytics and no tracking cookies. We do not use advertising or third-party tracking cookies.
7. How long we keep your data
We keep personal data only as long as necessary for the purposes above — generally for as long as your account is active, and for up to 90 days after you close it. Device activations are kept until the device is deactivated or the membership is removed. Billing records are kept as long as required by law (typically 7 years for tax/accounting in The Netherlands). When you close your account, we delete or anonymise your personal data except where we must retain it to meet a legal obligation.
8. Your rights
Under the GDPR you have the right to: access your data, rectify inaccuracies, request erasure, restrict or object to processing, request data portability, and withdraw consent where processing is based on consent. To exercise any of these, email [email protected] — we will respond within the legally required timeframe.
You also have the right to lodge a complaint with your supervisory authority. In The Netherlands this is the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).
9. How we protect your data
We use TLS/SSL encryption for data in transit, rely on passwordless authentication (one-time email codes and signed single-use sign-in links) so there is no password to be stolen or reused, host within the EU, and limit access to personal data to what is necessary to operate the Service.
10. Children
The Service is intended for business and professional use and is not directed at children under 16. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the "Effective date" above and, for material changes, notify you by email or an in-app notice.
12. Governing law
This Privacy Policy is governed by the laws of The Netherlands.
Questions? Contact us at [email protected].