FoundBeforeBack to FoundBefore
Privacy by design

Privacy notice

Version 2026-08-03Effective 2026-08-03

1. Controller and contact

For account, security, product, support and direct marketing processing, the controller is Milos Topic, Belgrade, Serbia, Serbia. Privacy requests: office@foundbefore.com. Registration: Not applicable — individual operator; tax identifier: Not applicable.

2. Scope and customer roles

This notice covers FoundBefore websites, accounts and workspaces. For organisation-controlled business information, the customer may be the controller and FoundBefore may act as processor under the customer agreement. FoundBefore remains controller for its own account, security, billing, abuse-prevention and service-improvement records.

3. Data we collect

  • Identity and contact data: name, work email, authentication identifiers and organisation membership.
  • Business workspace data: profiles, needs, resources, capabilities, constraints, evidence references, documents and user messages.
  • Opportunity data: anonymous responses, questions, consent choices, introductions and outcomes.
  • Commercial data: plan, billing contact, subscription, invoice, refund, campaign and contract records. Full card data is handled by Paddle, not FoundBefore.
  • Technical data: request identifiers, approximate network/security signals, browser preference, audit events and service diagnostics.

4. Purposes and legal bases

We process data to perform the service contract, take requested pre-contract steps, comply with legal obligations, protect legitimate interests in security and service operation, and obtain consent where the law requires it. Consent to identity disclosure inside an opportunity is separate from acceptance of these documents and may be withdrawn for future disclosure.

5. Matching and automated analysis

Rules and assisted analysis may rank compatibility, identify blockers and generate explanations. They do not independently enter contracts, transfer funds or make decisions with legal or similarly significant effects about individuals. Users review outputs and control disclosure. You may request human review of a result affecting your organisation.

6. Sharing

  • Authorised members of your organisation, according to role.
  • Other opportunity participants only after the configured consent requirements are complete.
  • Infrastructure, authentication, storage, email, monitoring and support providers under appropriate terms.
  • Paddle as independent Merchant of Record for buyer, payment, tax, invoice and refund processing.
  • Authorities or professional advisers when legally required or necessary to establish, exercise or defend claims.

7. International transfers

Providers may process data outside Serbia or the EEA. Before production activation, the operator must document provider locations, transfer mechanisms and applicable safeguards, such as adequacy decisions or contractual clauses. Sensitive workspace content is not sent to an optional external AI provider unless that processing is explicitly approved and configured.

8. Retention

Workspace retention is configurable between 30 days and seven years for relevant read notifications and organisation analytics. Unconfirmed extraction source text is minimised after expiry. Organisation deletion has a 30-day recovery period. Billing, acceptance, security and audit records may be retained longer where required for tax, fraud prevention, legal claims or accountability. Data is deleted or anonymised when no longer needed and no lawful hold applies.

9. Security

Controls include platform authentication, tenant isolation, server-side roles, private-by-default visibility, consent-gated disclosure, encryption of queued email content, bounded requests, rate limits and audit trails. No system is absolutely secure; suspected incidents should be reported promptly.

10. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection; withdraw consent; and complain to a competent data-protection authority. Identity verification may be required. We respond within the legally required period and explain any lawful limitation.

11. Cookies, local storage and marketing

Essential storage supports sign-in, active organisation, language and secure invitation flow. Optional first-party attribution is disabled until you choose analytics. FoundBefore does not use third-party advertising cookies in the application. Marketing email requires an applicable legal basis and an unsubscribe mechanism.

12. Children, changes and complaints

FoundBefore is a business service and is not directed to children. Material notice changes will be dated and, when required, presented for renewed acknowledgement. Contact office@foundbefore.com first; you may also contact the Serbian Commissioner for Information of Public Importance and Personal Data Protection or another competent authority.

FoundBefore · Opportunities before search.
PrivacyTermsRefundsAcceptable useCookiesData processingSecurity
A