FohBoh.ai / Legal

Privacy Policy

Version 3.1 Effective August 1, 2026 FohBoh.ai, Inc. · Delaware

This Privacy Policy explains how FohBoh.ai, Inc. (“FohBoh,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information through fohboh.ai, the Sentry and Cortex pages and applications, standalone or embedded MGE services, related APIs and connectors, events, communications, and other services that link to this Policy (collectively, the “Services”).

This Policy addresses personal information about identifiable people. It does not govern non-personal business data except where that data is linked or reasonably linkable to a person. A customer agreement, DPA, or employee notice may provide additional or different terms.

01Our roles

FohBoh as controller/business.

We determine the purposes and means of processing account, website, sales, event, billing, security, and business-contact information used to operate FohBoh’s business.

FohBoh as processor/service provider.

When we process Customer Data on behalf of an enterprise customer to provide MGE, Sentry, Cortex, CAAR, connector, or API services, the customer generally determines the purposes and means of that processing and FohBoh acts on documented instructions. The customer’s privacy notice and our DPA govern that processing. Individuals should ordinarily direct requests about Customer Data to the relevant customer.

FohBoh for Certification Records and IUM.

We determine the purposes and means of processing FohBoh-owned certification and uncertified logs, security and operational telemetry, usage and IUM measurements, and related integrity records when used to operate, secure, verify, protect, and improve our certification infrastructure. Where those records contain personal information, this Policy, applicable privacy law, confidentiality duties, and the customer agreement continue to apply regardless of ownership.

Customers are responsible for providing required notices and obtaining required rights or permissions for personal information they make available through the Services.

02Personal information we collect

CategoryExamplesTypical source
Identifiers and account dataName, business email, telephone number, login identifier, organization, role, authentication and account settings.You, your employer/customer, identity provider.
Commercial and relationship dataSubscription, order, billing, pilot, partner, support, meeting, and communication records.You, customer administrators, sales/support interactions.
Internet and device activityIP address, browser, device, pages viewed, referring URLs, session events, feature usage, logs, cookie or similar identifiers.Your device, website and service telemetry.
Professional informationEmployer, title, work location, franchise or business affiliation, permissions, and role-based access.You, your organization, integrations.
Customer operational dataTransaction, order, delivery, processor, vendor, contract, inventory, labor, payroll, royalty, supply-chain, or location records that may contain employee, customer, vendor-contact, or other personal information.Customer uploads; POS, payroll, DSP, processor, vendor and other authorized systems.
Credentials and integration dataAPI keys, OAuth tokens, connector identifiers, service-account metadata and system permissions.You, administrators, enabled integrations.
Certification and evidence metadataCertified and uncertified logs, rule and KPI versions, mappings, rule execution or failure, Trust Scores, certification status, source references, timestamps, hashes, signatures, exceptions, approvals, override records, CAAR, lineage, provenance and audit metadata.MGE/Sentry processing and authorized users.
Cortex contentPrompts, queries, voice or text input, responses, feedback, approved context and related telemetry.Authorized users and configured services.
Inferences and analyticsProduct usage trends, fraud/security signals, service health, support needs, and account-level operational patterns.Derived from the information above.
Please do not upload

The Services are not designed to receive full payment-card numbers, CVVs, Social Security numbers, protected health information, biometric identifiers, precise geolocation, or other regulated sensitive personal information unless a written agreement expressly authorizes the data and safeguards. Please do not upload such information without authorization.

03How we use personal information

  • provide, authenticate, configure, support, and improve the Services;
  • ingest, normalize, reconcile, govern, certify, score, and document authorized Customer Data through MGE and Sentry;
  • generate, preserve, deliver, and verify CAARs, evidence references, audit trails, integrity metadata, and related artifacts;
  • create and maintain FohBoh Certification Records and IUM; verify certification activity; preserve rule-performance and certification history; and develop non-customer-specific methods and operational know-how;
  • provide Cortex prompts, responses, summaries, and other AI-assisted features;
  • operate APIs, connectors, tenant isolation, access controls, logging, monitoring, incident response, and abuse prevention;
  • measure subscription, certification-event, API, location, feature, and IUM usage as defined by an applicable agreement;
  • administer billing, pilots, customer relationships, training, communications, and legal notices;
  • comply with law, enforce agreements, protect rights and safety, resolve disputes, and establish or defend legal claims;
  • create aggregated or de-identified information for service analytics, capacity planning, benchmarking, and product improvement, subject to contractual restrictions and commitments not to re-identify it.

04Certification Records, IUM, human activity, and AI

MGE and Sentry use deterministic rules for variance calculations; the same governed inputs and rule version are intended to produce the same calculation. Authorized people may enter contract terms, validate mappings, approve exceptions, or invoke governed overrides. We may record those actions as evidence, security, or audit metadata.

FohBoh owns Intelligence Under Management (“IUM”) and the certified and uncertified logs generated by MGE, Sentry, and headless trust-layer processing (“FohBoh Certification Records”), including certification events, rule-execution history, certification status, Trust Score history, exceptions, overrides, hashes, signatures, lineage, provenance, operational telemetry, usage measurements, and the compilation and structure of those records. Customer retains ownership of Customer Data and the readable content of its source records. FohBoh’s ownership does not eliminate privacy rights, confidentiality restrictions, security obligations, or contractual limits applicable to information contained in a log.

In a headless deployment for a data platform, POS provider, or system of record, source data is processed automatically within the authorized technical pathway. FohBoh does not routinely inspect or use readable source data for an independent purpose. Human access, if technically possible, is restricted to authorized support, security or incident response, legal compliance, or another purpose permitted by the applicable agreement. Deployments designated as “no-view” use the technical restrictions defined in their Security Addendum.

Cortex may send authorized prompts and context to approved AI providers to generate responses. MGE certification of a source metric does not make every AI-generated statement certified. We contractually and technically limit provider use where available and as specified in the applicable DPA or enterprise agreement.

We do not use Customer Data to train a general-purpose model for unrelated customers unless the customer expressly authorizes that use in writing. We may use service telemetry and de-identified or aggregated information for security, quality, and improvement as allowed by contract and law.

The Services are not intended to make solely automated decisions that produce legal or similarly significant effects concerning individuals. Customers must provide appropriate human review and comply with laws applicable to their use of outputs.

05Sources of personal information

We collect personal information directly from you; from your organization and its administrators; through your use of the Services; from systems, vendors, and integrations you authorize; from service providers and business partners; and from public or commercially available business sources where lawful.

06How we disclose personal information

We may disclose personal information to:

  • cloud hosting, database, observability, cybersecurity, identity, support, communications, document-generation, and other subprocessors that help provide the Services;
  • AI model and related technology providers when needed for an authorized Cortex feature and subject to applicable provider and contractual controls;
  • POS, payroll, delivery, processor, vendor, storage, analytics, and other integrations enabled or directed by Customer;
  • the applicable headless, reseller, or platform partner, while it remains a partner in good standing, for access to FohBoh Certification Records generated through its authorized deployment and only as permitted by the partner agreement;
  • professional advisers, auditors, insurers, financing sources, and transaction counterparties under appropriate duties or safeguards;
  • government authorities, courts, or other persons when required by law or reasonably necessary to protect rights, security, safety, or the integrity of the Services;
  • an acquirer, successor, affiliate, or other party in a merger, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and commitments.
No sale, no targeted advertising

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or process it for targeted advertising as those terms are defined by applicable U.S. state privacy laws. If our practices change, we will update this Policy and provide required choices before the change applies.

07Cookies and similar technologies

We and authorized providers may use essential cookies and similar technologies for authentication, security, preferences, load balancing, and service operation, and analytics technologies to understand website and product use. Where required, non-essential technologies will be controlled through a consent or preference tool. Browser settings may block some technologies, but essential features may not function.

We do not currently respond to browser “Do Not Track” signals as a universal standard has not been adopted. Where legally required and technically supported, we honor recognized opt-out preference signals for covered sale, sharing, or targeted-advertising activity; we do not currently engage in those activities.

08Legal bases for EEA, UK, and similar jurisdictions

PurposeTypical legal basis
Provide contracted Services and account functionalityPerformance of a contract or steps requested before entering a contract.
Secure, administer, support, measure, and improve the ServicesLegitimate interests in operating a secure and effective B2B service, balanced against individual rights.
Required records, compliance, and legal processCompliance with legal obligations and establishment or defense of legal claims.
Optional marketing or non-essential technologiesConsent where required; otherwise legitimate interests subject to applicable choices.
Customer Data processed for an enterprise customerThe customer determines the legal basis; FohBoh processes on documented instructions under a DPA.

09Data retention

We retain personal information only for as long as reasonably necessary for the purposes described, including to provide Services, preserve security and transaction records, meet contractual evidence and audit requirements, comply with law, resolve disputes, and enforce agreements. Actual periods depend on the data class and applicable agreement.

Data classGeneral retention approach
Account and relationship recordsFor the active relationship and a reasonable period afterward for administration, tax, dispute, and legal needs.
Customer Data and generated outputsDuring the service term and for the return/deletion period stated in the enterprise agreement, DPA, or retention schedule.
FohBoh Certification Records and CAAR evidenceAs configured or contractually required—and as reasonably needed to preserve IUM, rule performance, reproducibility, chain of custody, audit readiness, security, and version history. Partner access may end before FohBoh retention; legal holds may extend retention.
Security, access, API, and audit logsFor periods appropriate to security monitoring, investigation, usage verification, and contracted audit requirements.
Billing and IUM metering recordsFor the contract, billing-dispute, tax, audit, and legal limitation periods.
Website analytics and cookiesAccording to the applicable cookie or analytics setting and provider configuration.

Deletion may not remove records that must be retained by law or agreement, are subject to legal hold, reside in protected backups until ordinary rotation, or consist of limited integrity, security, billing, or audit metadata. A cryptographic hash may remain personal information if it can reasonably be linked to a person; we do not treat hashing alone as anonymization.

10Security

We use administrative, technical, and organizational safeguards designed for the data and risks involved. Depending on the Service and agreement, these may include encryption in transit and at rest, role-based access, multi-tenant isolation, credential and key controls, logging, monitoring, integrity hashes, digital signatures, vulnerability management, backups, incident response, and personnel controls.

No system is completely secure. Detailed and binding security commitments are contained in the applicable Security Addendum, DPA, and enterprise agreement. Public descriptions do not expand or replace those commitments. Customers share responsibility for endpoint security, identity administration, least privilege, connector configuration, and lawful data handling.

11International data transfers

FohBoh is based in the United States, and information may be processed in the United States and other countries where we or our authorized providers operate. Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses, and contractual and technical supplementary measures. Details may be provided in the applicable DPA.

12Privacy rights and choices

Depending on where you reside and applicable exemptions, you may have rights to request access, correction, deletion, portability, or information about processing; to object to or restrict certain processing; to opt out of covered sale, sharing, targeted advertising, or profiling; to withdraw consent where processing is based on consent; and to appeal a denied request.

Submit a request to privacy@fohboh.ai with the subject “Privacy Request.” We may verify identity and authority and may ask you to identify the relevant FohBoh customer. Authorized agents must provide legally sufficient authorization. We will not discriminate against you for exercising applicable rights.

If your information is contained in Customer Data, FohBoh ordinarily acts for the customer. We may refer the request to that customer or assist it under our DPA. You may also contact the customer directly. Rights are subject to legal limitations, exemptions, and retention obligations.

You may opt out of non-transactional marketing emails through the unsubscribe link. Service, security, legal, billing, and account communications are not marketing and may continue while relevant.

13Children

The Services are business services not directed to children, and users must be at least 18. We do not knowingly collect personal information from children under 13 through the Services. If you believe a child has provided personal information, contact privacy@fohboh.ai.

14Third-party services and links

The Services may link to or integrate with third-party services. Their privacy practices are governed by their notices, not this Policy. Customer administrators decide which integrations to enable and should evaluate the third party’s terms, permissions, and data practices.

15Changes to this Policy

We may update this Policy prospectively. We will post the revised version and effective date and provide additional notice when required by law or contract. We will not quietly or retroactively use previously collected personal information for a materially incompatible purpose without the notice, choice, or authorization required by law and applicable agreements.

16Contact

FohBoh.ai, Inc. is a Delaware corporation. Privacy questions, rights requests, and complaints may be sent to privacy@fohboh.ai. Enterprise customers should also use the contacts and procedures in their DPA or agreement.

AAppendix A — Notice at collection summary

What to knowSummary
Categories collectedIdentifiers/account data; commercial and professional information; device and internet activity; Customer operational data; credentials/integration data; certification/evidence metadata; Cortex content; and derived service analytics.
PurposesProvide, secure, support, certify, document, measure, bill, and improve the Services; operate MGE, Sentry, Cortex, CAAR, APIs, and connectors; communicate; comply with law; and protect rights.
DisclosuresAuthorized service providers, AI providers for Cortex, customer-enabled integrations, advisers, authorities, and transaction parties as described in this Policy.
Sale/sharingWe do not sell personal information for money or share it for cross-context behavioral advertising.
RetentionOnly as long as reasonably necessary for service, security, evidence, contractual, billing, audit, legal, and dispute purposes, subject to the applicable agreement and retention schedule.
Rights contactprivacy@fohboh.ai

BAppendix B — Product-specific notices

SurfaceAdditional notice
FohBoh.ai websitePrimarily processes visitor, business-contact, cookie, event, and communications data. Authenticated account processing is described below.
Sentry / CAARProcesses authorized operational and vendor records through deterministic rules; may record human-entered terms, mappings, approvals, exceptions, and overrides; preserves source references, evidence and integrity metadata.
CortexProcesses prompts and approved context and may disclose them to authorized AI providers. Responses are probabilistic; do not submit unnecessary personal or sensitive information in prompts.
Standalone/headless MGE and APIsProcesses source data automatically within customer-configured scopes; creates FohBoh-owned certified and uncertified logs, calls, certification events, versions, outputs, errors, IUM measures, and security/audit records; provides the authorized partner contract-limited log access while in good standing.