01Our roles
FohBoh as controller/business.
We determine the purposes and means of processing account, website, sales, event, billing, security, and business-contact information used to operate FohBoh’s business.
FohBoh as processor/service provider.
When we process Customer Data on behalf of an enterprise customer to provide MGE, Sentry, Cortex, CAAR, connector, or API services, the customer generally determines the purposes and means of that processing and FohBoh acts on documented instructions. The customer’s privacy notice and our DPA govern that processing. Individuals should ordinarily direct requests about Customer Data to the relevant customer.
FohBoh for Certification Records and IUM.
We determine the purposes and means of processing FohBoh-owned certification and uncertified logs, security and operational telemetry, usage and IUM measurements, and related integrity records when used to operate, secure, verify, protect, and improve our certification infrastructure. Where those records contain personal information, this Policy, applicable privacy law, confidentiality duties, and the customer agreement continue to apply regardless of ownership.
Customers are responsible for providing required notices and obtaining required rights or permissions for personal information they make available through the Services.
02Personal information we collect
| Category | Examples | Typical source |
|---|---|---|
| Identifiers and account data | Name, business email, telephone number, login identifier, organization, role, authentication and account settings. | You, your employer/customer, identity provider. |
| Commercial and relationship data | Subscription, order, billing, pilot, partner, support, meeting, and communication records. | You, customer administrators, sales/support interactions. |
| Internet and device activity | IP address, browser, device, pages viewed, referring URLs, session events, feature usage, logs, cookie or similar identifiers. | Your device, website and service telemetry. |
| Professional information | Employer, title, work location, franchise or business affiliation, permissions, and role-based access. | You, your organization, integrations. |
| Customer operational data | Transaction, order, delivery, processor, vendor, contract, inventory, labor, payroll, royalty, supply-chain, or location records that may contain employee, customer, vendor-contact, or other personal information. | Customer uploads; POS, payroll, DSP, processor, vendor and other authorized systems. |
| Credentials and integration data | API keys, OAuth tokens, connector identifiers, service-account metadata and system permissions. | You, administrators, enabled integrations. |
| Certification and evidence metadata | Certified and uncertified logs, rule and KPI versions, mappings, rule execution or failure, Trust Scores, certification status, source references, timestamps, hashes, signatures, exceptions, approvals, override records, CAAR, lineage, provenance and audit metadata. | MGE/Sentry processing and authorized users. |
| Cortex content | Prompts, queries, voice or text input, responses, feedback, approved context and related telemetry. | Authorized users and configured services. |
| Inferences and analytics | Product usage trends, fraud/security signals, service health, support needs, and account-level operational patterns. | Derived from the information above. |
The Services are not designed to receive full payment-card numbers, CVVs, Social Security numbers, protected health information, biometric identifiers, precise geolocation, or other regulated sensitive personal information unless a written agreement expressly authorizes the data and safeguards. Please do not upload such information without authorization.
03How we use personal information
- provide, authenticate, configure, support, and improve the Services;
- ingest, normalize, reconcile, govern, certify, score, and document authorized Customer Data through MGE and Sentry;
- generate, preserve, deliver, and verify CAARs, evidence references, audit trails, integrity metadata, and related artifacts;
- create and maintain FohBoh Certification Records and IUM; verify certification activity; preserve rule-performance and certification history; and develop non-customer-specific methods and operational know-how;
- provide Cortex prompts, responses, summaries, and other AI-assisted features;
- operate APIs, connectors, tenant isolation, access controls, logging, monitoring, incident response, and abuse prevention;
- measure subscription, certification-event, API, location, feature, and IUM usage as defined by an applicable agreement;
- administer billing, pilots, customer relationships, training, communications, and legal notices;
- comply with law, enforce agreements, protect rights and safety, resolve disputes, and establish or defend legal claims;
- create aggregated or de-identified information for service analytics, capacity planning, benchmarking, and product improvement, subject to contractual restrictions and commitments not to re-identify it.
04Certification Records, IUM, human activity, and AI
MGE and Sentry use deterministic rules for variance calculations; the same governed inputs and rule version are intended to produce the same calculation. Authorized people may enter contract terms, validate mappings, approve exceptions, or invoke governed overrides. We may record those actions as evidence, security, or audit metadata.
FohBoh owns Intelligence Under Management (“IUM”) and the certified and uncertified logs generated by MGE, Sentry, and headless trust-layer processing (“FohBoh Certification Records”), including certification events, rule-execution history, certification status, Trust Score history, exceptions, overrides, hashes, signatures, lineage, provenance, operational telemetry, usage measurements, and the compilation and structure of those records. Customer retains ownership of Customer Data and the readable content of its source records. FohBoh’s ownership does not eliminate privacy rights, confidentiality restrictions, security obligations, or contractual limits applicable to information contained in a log.
In a headless deployment for a data platform, POS provider, or system of record, source data is processed automatically within the authorized technical pathway. FohBoh does not routinely inspect or use readable source data for an independent purpose. Human access, if technically possible, is restricted to authorized support, security or incident response, legal compliance, or another purpose permitted by the applicable agreement. Deployments designated as “no-view” use the technical restrictions defined in their Security Addendum.
Cortex may send authorized prompts and context to approved AI providers to generate responses. MGE certification of a source metric does not make every AI-generated statement certified. We contractually and technically limit provider use where available and as specified in the applicable DPA or enterprise agreement.
We do not use Customer Data to train a general-purpose model for unrelated customers unless the customer expressly authorizes that use in writing. We may use service telemetry and de-identified or aggregated information for security, quality, and improvement as allowed by contract and law.
The Services are not intended to make solely automated decisions that produce legal or similarly significant effects concerning individuals. Customers must provide appropriate human review and comply with laws applicable to their use of outputs.
05Sources of personal information
We collect personal information directly from you; from your organization and its administrators; through your use of the Services; from systems, vendors, and integrations you authorize; from service providers and business partners; and from public or commercially available business sources where lawful.
06How we disclose personal information
We may disclose personal information to:
- cloud hosting, database, observability, cybersecurity, identity, support, communications, document-generation, and other subprocessors that help provide the Services;
- AI model and related technology providers when needed for an authorized Cortex feature and subject to applicable provider and contractual controls;
- POS, payroll, delivery, processor, vendor, storage, analytics, and other integrations enabled or directed by Customer;
- the applicable headless, reseller, or platform partner, while it remains a partner in good standing, for access to FohBoh Certification Records generated through its authorized deployment and only as permitted by the partner agreement;
- professional advisers, auditors, insurers, financing sources, and transaction counterparties under appropriate duties or safeguards;
- government authorities, courts, or other persons when required by law or reasonably necessary to protect rights, security, safety, or the integrity of the Services;
- an acquirer, successor, affiliate, or other party in a merger, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and commitments.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or process it for targeted advertising as those terms are defined by applicable U.S. state privacy laws. If our practices change, we will update this Policy and provide required choices before the change applies.
07Cookies and similar technologies
We and authorized providers may use essential cookies and similar technologies for authentication, security, preferences, load balancing, and service operation, and analytics technologies to understand website and product use. Where required, non-essential technologies will be controlled through a consent or preference tool. Browser settings may block some technologies, but essential features may not function.
We do not currently respond to browser “Do Not Track” signals as a universal standard has not been adopted. Where legally required and technically supported, we honor recognized opt-out preference signals for covered sale, sharing, or targeted-advertising activity; we do not currently engage in those activities.
08Legal bases for EEA, UK, and similar jurisdictions
| Purpose | Typical legal basis |
|---|---|
| Provide contracted Services and account functionality | Performance of a contract or steps requested before entering a contract. |
| Secure, administer, support, measure, and improve the Services | Legitimate interests in operating a secure and effective B2B service, balanced against individual rights. |
| Required records, compliance, and legal process | Compliance with legal obligations and establishment or defense of legal claims. |
| Optional marketing or non-essential technologies | Consent where required; otherwise legitimate interests subject to applicable choices. |
| Customer Data processed for an enterprise customer | The customer determines the legal basis; FohBoh processes on documented instructions under a DPA. |
09Data retention
We retain personal information only for as long as reasonably necessary for the purposes described, including to provide Services, preserve security and transaction records, meet contractual evidence and audit requirements, comply with law, resolve disputes, and enforce agreements. Actual periods depend on the data class and applicable agreement.
| Data class | General retention approach |
|---|---|
| Account and relationship records | For the active relationship and a reasonable period afterward for administration, tax, dispute, and legal needs. |
| Customer Data and generated outputs | During the service term and for the return/deletion period stated in the enterprise agreement, DPA, or retention schedule. |
| FohBoh Certification Records and CAAR evidence | As configured or contractually required—and as reasonably needed to preserve IUM, rule performance, reproducibility, chain of custody, audit readiness, security, and version history. Partner access may end before FohBoh retention; legal holds may extend retention. |
| Security, access, API, and audit logs | For periods appropriate to security monitoring, investigation, usage verification, and contracted audit requirements. |
| Billing and IUM metering records | For the contract, billing-dispute, tax, audit, and legal limitation periods. |
| Website analytics and cookies | According to the applicable cookie or analytics setting and provider configuration. |
Deletion may not remove records that must be retained by law or agreement, are subject to legal hold, reside in protected backups until ordinary rotation, or consist of limited integrity, security, billing, or audit metadata. A cryptographic hash may remain personal information if it can reasonably be linked to a person; we do not treat hashing alone as anonymization.
10Security
We use administrative, technical, and organizational safeguards designed for the data and risks involved. Depending on the Service and agreement, these may include encryption in transit and at rest, role-based access, multi-tenant isolation, credential and key controls, logging, monitoring, integrity hashes, digital signatures, vulnerability management, backups, incident response, and personnel controls.
No system is completely secure. Detailed and binding security commitments are contained in the applicable Security Addendum, DPA, and enterprise agreement. Public descriptions do not expand or replace those commitments. Customers share responsibility for endpoint security, identity administration, least privilege, connector configuration, and lawful data handling.
11International data transfers
FohBoh is based in the United States, and information may be processed in the United States and other countries where we or our authorized providers operate. Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses, and contractual and technical supplementary measures. Details may be provided in the applicable DPA.
12Privacy rights and choices
Depending on where you reside and applicable exemptions, you may have rights to request access, correction, deletion, portability, or information about processing; to object to or restrict certain processing; to opt out of covered sale, sharing, targeted advertising, or profiling; to withdraw consent where processing is based on consent; and to appeal a denied request.
Submit a request to privacy@fohboh.ai with the subject “Privacy Request.” We may verify identity and authority and may ask you to identify the relevant FohBoh customer. Authorized agents must provide legally sufficient authorization. We will not discriminate against you for exercising applicable rights.
If your information is contained in Customer Data, FohBoh ordinarily acts for the customer. We may refer the request to that customer or assist it under our DPA. You may also contact the customer directly. Rights are subject to legal limitations, exemptions, and retention obligations.
You may opt out of non-transactional marketing emails through the unsubscribe link. Service, security, legal, billing, and account communications are not marketing and may continue while relevant.
13Children
The Services are business services not directed to children, and users must be at least 18. We do not knowingly collect personal information from children under 13 through the Services. If you believe a child has provided personal information, contact privacy@fohboh.ai.
14Third-party services and links
The Services may link to or integrate with third-party services. Their privacy practices are governed by their notices, not this Policy. Customer administrators decide which integrations to enable and should evaluate the third party’s terms, permissions, and data practices.
15Changes to this Policy
We may update this Policy prospectively. We will post the revised version and effective date and provide additional notice when required by law or contract. We will not quietly or retroactively use previously collected personal information for a materially incompatible purpose without the notice, choice, or authorization required by law and applicable agreements.
16Contact
FohBoh.ai, Inc. is a Delaware corporation. Privacy questions, rights requests, and complaints may be sent to privacy@fohboh.ai. Enterprise customers should also use the contacts and procedures in their DPA or agreement.
AAppendix A — Notice at collection summary
| What to know | Summary |
|---|---|
| Categories collected | Identifiers/account data; commercial and professional information; device and internet activity; Customer operational data; credentials/integration data; certification/evidence metadata; Cortex content; and derived service analytics. |
| Purposes | Provide, secure, support, certify, document, measure, bill, and improve the Services; operate MGE, Sentry, Cortex, CAAR, APIs, and connectors; communicate; comply with law; and protect rights. |
| Disclosures | Authorized service providers, AI providers for Cortex, customer-enabled integrations, advisers, authorities, and transaction parties as described in this Policy. |
| Sale/sharing | We do not sell personal information for money or share it for cross-context behavioral advertising. |
| Retention | Only as long as reasonably necessary for service, security, evidence, contractual, billing, audit, legal, and dispute purposes, subject to the applicable agreement and retention schedule. |
| Rights contact | privacy@fohboh.ai |
BAppendix B — Product-specific notices
| Surface | Additional notice |
|---|---|
| FohBoh.ai website | Primarily processes visitor, business-contact, cookie, event, and communications data. Authenticated account processing is described below. |
| Sentry / CAAR | Processes authorized operational and vendor records through deterministic rules; may record human-entered terms, mappings, approvals, exceptions, and overrides; preserves source references, evidence and integrity metadata. |
| Cortex | Processes prompts and approved context and may disclose them to authorized AI providers. Responses are probabilistic; do not submit unnecessary personal or sensitive information in prompts. |
| Standalone/headless MGE and APIs | Processes source data automatically within customer-configured scopes; creates FohBoh-owned certified and uncertified logs, calls, certification events, versions, outputs, errors, IUM measures, and security/audit records; provides the authorized partner contract-limited log access while in good standing. |