Curly Curly

Privacy Policy

Effective date: 13 August 2026

This Privacy Policy explains how Foundasys ("Curly", "we", "us") collects, uses, and protects personal data when you use the Curly add-in (for Microsoft Word, Word on the web, Google Docs, OnlyOffice, and Euro-Office), the Curly dashboard, and the curly.io website (together, the "Service"). The Word add-in is listed on Microsoft AppSource as "Curly Pro", and the Google Docs add-on on the Google Workspace Marketplace as "Curly".

We are the data controller for the personal data described below.

Curly's core privacy principle: the content of your documents is processed within your Office or editor environment and is never transmitted to or stored on Curly's servers. The data we do collect is limited to what's needed to run your account, licence, and team — described in full below.


1. Who we are

Controller Foundasys
Address Mina Krusemanstraat 299, 7513 HJ Enschede, The Netherlands
Chamber of Commerce (KvK) 42092371
VAT (BTW-id) NL005494168B57
Contact [email protected]

For any privacy question or to exercise your rights (Section 8), contact us at [email protected].


2. What data we collect

a. Account data — when you create an account or are invited to a team: your name, email address, and preferred language (locale). Curly is passwordless — you sign in with a one-time code sent to your email address or a secure single-use sign-in link, so we never ask for, see, or store a password.

b. Team & licence datateam name, membership and role, pending invitations (the invited email + role), and licence details (status, trial dates, seat allocation, and the identifiers of your subscription with our payment provider).

c. Device / activation data — when you activate the add-in on a device, we record: a device label (derived from your browser's user-agent string plus a randomly generated device identifier), the host application (e.g. Word, Word on the web, Google Docs, OnlyOffice, Euro-Office), an approximate country (a two-letter country code derived from your IP address at our network edge — we do not store your IP address with this record), and activation/last-seen timestamps.

d. Trial sign-up data — when you request an in-add-in trial code: your email, locale, and your IP address at the time of the request, retained for a limited period and used only to prevent abuse and rate-limit requests.

e. Billing data — payments are processed by our payment provider, Lemon Squeezy (a Stripe company), acting as Merchant of Record. We do not receive or store your full payment-card details; Lemon Squeezy does. We store your subscription/licence status and the provider's customer and subscription identifiers.

f. Communications — transactional emails we send (verification, trial reminders, invitations, billing notices) and any messages you send us for support.

g. Document content — NOT collected. When you use the add-in to scan or fill placeholders, your document is read and modified within your Office/editor environment. Document content is not transmitted to or stored on Curly's servers.

We do not use advertising trackers, sell personal data, or build advertising profiles.


3. How we use your data, and our legal bases

Purpose Legal basis (GDPR Art. 6)
Provide and operate the Service (accounts, licences, teams, activations) Performance of a contract
Process payments and manage subscriptions Performance of a contract
Send transactional/service emails Performance of a contract
Authenticate you and secure the Service Legitimate interests
Prevent fraud and abuse (e.g. trial-code rate limiting) Legitimate interests
Understand aggregate, cookieless website usage Legitimate interests
Monitor errors and performance to keep the Service reliable Legitimate interests
Comply with legal/accounting obligations Legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights. You may object at any time (Section 8).


4. Who we share data with (processors / sub-processors)

We use a small number of carefully chosen service providers ("processors") to run the Service. Each processes data only on our instructions; their locations are listed below.

Provider Purpose Location
Laravel Cloud (on AWS) Application hosting EU — eu-central-1 (Frankfurt)
Neon Database (your account/team/licence data) EU
Lemon Squeezy (a Stripe company) Payments & Merchant of Record United States (acts as Merchant of Record; EU VAT handled); safeguarded by Standard Contractual Clauses
Resend Sending transactional email EU region
Flare (Spatie) Error & performance monitoring EU — Belgium
Google Cloud Translation Translating Curly's own interface text (not your data) Google Cloud (global endpoint)
Cloudflare Content delivery, security, edge country lookup, and privacy-friendly, cookieless website analytics (Cloudflare Web Analytics) Global edge network

Note on Google Translate: it receives only Curly's user-interface strings so we can show the app in your language. It does not receive your documents, your account data, or any personal data.

We will keep this list current. We do not share your personal data with any other third party except where required by law.


5. International transfers

Our application and database are hosted in Frankfurt, Germany (eu-central-1). Some of our providers operate in other regions — Lemon Squeezy (United States) and Cloudflare (global edge network). Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Google Cloud Translation receives only interface strings, not your personal data.


6. Cookies

Curly uses a minimal set of strictly necessary cookies and similar browser storage only:

Our website analytics (Cloudflare Web Analytics) are cookieless and collect no personal data. The Curly add-in itself uses no analytics and no tracking cookies. We do not use advertising or third-party tracking cookies.


7. How long we keep your data

We keep personal data only as long as necessary for the purposes above — generally for as long as your account is active, and for up to 90 days after you close it. Device activations are kept until the device is deactivated or the membership is removed. Billing records are kept as long as required by law (typically 7 years for tax/accounting in The Netherlands). When you close your account, we delete or anonymise your personal data except where we must retain it to meet a legal obligation.


8. Your rights

Under the GDPR you have the right to: access your data, rectify inaccuracies, request erasure, restrict or object to processing, request data portability, and withdraw consent where processing is based on consent. To exercise any of these, email [email protected] — we will respond within the legally required timeframe.

You also have the right to lodge a complaint with your supervisory authority. In The Netherlands this is the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).


9. How we protect your data

We use TLS/SSL encryption for data in transit, rely on passwordless authentication (one-time email codes and signed single-use sign-in links) so there is no password to be stolen or reused, and limit access to personal data to what is necessary to operate the Service.


10. Children

The Service is intended for business and professional use and is not directed at children under 16. We do not knowingly collect personal data from children.


11. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Effective date" above and, for material changes, notify you by email or an in-app notice.


12. Governing law

This Privacy Policy is governed by the laws of The Netherlands.


Questions? Contact us at [email protected].