top of page
feedfrwd-transparent-with-text-dark-gray (1).png
LoginBook a demoJoin the beta

Privacy Policy

Effective Date: Sept 1st, 2026
Last Updated: Sept 1st, 2026

1.  Who We Are and What This Policy Covers

FeedFrwd, Inc. (“FeedFrwd,” “we,” “us,” or “our”) is a Delaware corporation operating the FeedFrwd platform — an AI-powered feedback intelligence engine that helps organizations turn customer feedback into prioritized, actionable decisions. We are headquartered in the United States and serve customers globally.

 

Legal entity: FeedFrwd, Inc.

Website: feedfrwd.ai

Privacy contact: privacy@feedfrwd.ai

This policy applies to:

  • visitors to our website at feedfrwd.ai (the “Site”);

  • individuals who register for, administer, or use the FeedFrwd platform (the “Service”); and

  • individuals whose feedback is processed through the Service by our customers (“End Users”).

It does not apply to our customers’ own websites, products, or privacy practices, or to third-party services you connect to FeedFrwd.

Related documents. This policy should be read together with the FeedFrwd Terms of Service (feedfrwd.ai/legal/terms), the Cookie Policy (feedfrwd.ai/legal/cookies), the AI Supplementary Terms (feedfrwd.ai/legal/ai-terms), the Data Processing Agreement (feedfrwd.ai/legal/dpa), and the Subprocessor List (feedfrwd.ai/legal/subprocessors).

2.  Our Two Roles: Controller and Processor

Understanding which role we are playing determines who is responsible for your data and who you should contact about it.

 

When we act as a controller: We decide why and how data is processed. This covers data about our own users and visitors: account registration, billing, support conversations, marketing, Site analytics, and security logs. This policy governs that processing.

 

When we act as a processor: We process data on a customer’s behalf and under their instructions. This covers the feedback data, signals, and End User records our customers import into or connect with the Service. Our customer is the controller; the FeedFrwd Data Processing Agreement governs that processing.

 

If you are an End User — someone whose review, support ticket, or survey response was analyzed in FeedFrwd by a company you dealt with — that company controls your data. Please direct access, correction, and deletion requests to them. If you contact us instead, we will forward your request to the relevant customer and let you know we have done so, but we cannot act on it directly.

3.  Information We Collect

3.1  Information you provide directly

  • Account registration: name, work email address, password or federated login identifier, job title, and company name.

  • Profile information: profile photo, display name, notification preferences, and interface settings.

  • Billing information: billing contact name, billing address, tax identifiers, and payment card details. Card details are collected and stored by our payment processor; we do not store full card numbers.

  • Communications: the content of support requests, sales enquiries, survey responses, and other correspondence with us.

  • Trial, demo, and event requests: name, email, company, role, and use-case details you provide when requesting a trial, a demonstration, or access at an event.

 

3.2  Information generated through use of the Service

  • Customer Data and signals: the feedback records our customers upload, import, or connect — reviews, support tickets, survey responses, interview notes, transcripts, app store reviews, and similar content, together with any metadata attached to them.

  • Derived insights: themes, clusters, sentiment classifications, impact and priority scores, recommendations, and actions generated by the Service from Customer Data.

  • Usage data: feature interactions, pages viewed, actions taken, imports run, session duration, timestamps, and referring pages.

  • Integration data: data exchanged when a customer connects FeedFrwd to a third-party system, together with the connection metadata and access tokens needed to maintain that connection.

  • Configuration data: workspaces, teams, tags, labels, categories, scoring weights, workflow rules, and other settings.

3.3  Information collected automatically

  • Device and technical data: IP address, browser type and version, operating system, device identifiers, language, time zone, and screen resolution.

  • Security and audit logs: authentication events, administrative actions, and access records retained for security and accountability.

  • Cookies and similar technologies: as described in Section 8 and in our Cookie Policy.

3.4  Information from third parties

  • Connected systems: where a customer authorizes an integration with a CRM, helpdesk, survey platform, product analytics tool, or app store feed, we receive data from that system within the scope of the authorization granted.

  • Identity providers: where single sign-on is used, we receive the identity attributes the provider releases to us.

  • Publicly available sources: we may supplement business account records with publicly available company information.

  • Partners and referrals: basic referral information where you reach us through a partner.

4.  How We Use Information

4.1  Providing and operating the Service

  • Creating and administering accounts, workspaces, and user access.

  • Ingesting, de-duplicating, analyzing, scoring, and prioritizing feedback, and generating recommendations and actions.

  • Operating integrations and syncing data with systems a customer has connected.

  • Providing support, onboarding, and in-product guidance.

4.2  Maintaining, securing, and improving the Service

  • Monitoring performance, diagnosing errors, and maintaining availability.

  • Detecting, investigating, and preventing fraud, abuse, and unauthorized access, and enforcing usage limits and technical guardrails.

  • Developing new features and improving existing ones, using aggregated or de-identified data.

4.3  Communications

  • Sending service communications such as security alerts, billing notices, and changes to terms. You cannot opt out of these while you hold an account.

  • Sending marketing communications, newsletters, product updates, and event invitations where you have opted in or where permitted by applicable law. You can opt out at any time using the unsubscribe link in any such email or by writing to privacy@feedfrwd.ai.

4.4  Legal and compliance

  • Complying with applicable law, tax obligations, and valid legal process.

  • Establishing, exercising, or defending legal claims, and enforcing our agreements.

  • Protecting the rights, property, and safety of FeedFrwd, our customers, and the public.

 

4.5  Analytics and benchmarking

We generate aggregated and de-identified statistics from use of the Service to understand how it is used, to improve it, and to produce benchmarking or industry insights. Aggregated and de-identified data does not identify any customer, user, or End User, and we do not attempt to re-identify it or publish it in a form that identifies a customer.

5.  Artificial Intelligence

AI is core to how the Service works. We use machine learning and large language models to cluster feedback into themes, classify sentiment, estimate business impact, rank priorities, and draft recommendations and actions.

5.1  Our commitments

  • No training on identifiable customer data without consent. We do not use identifiable Customer Data to train or fine-tune our own foundation or general-purpose AI models without the customer’s prior written consent.

  • AI vendors cannot train on your data. We contractually prohibit the AI providers we use from using Customer Data to train, fine-tune, or improve their own models or services, and we enable zero-retention or minimum-retention settings where a provider offers them.

  • Human oversight. Output is designed to support human decision-making, not to replace it. We do not use automated processing to make decisions about individuals that produce legal or similarly significant effects without human review.

  • Transparency. We will explain, on request, how a particular AI feature works at a level of detail that does not disclose trade secrets.

  • Accuracy. Output is probabilistic and may be incomplete or wrong. It should be reviewed before it is relied on.

5.2  Where to find more

The AI providers we use are named on our Subprocessor List. The contractual terms governing AI features, including any product-improvement licence and the customer’s right to opt out of it, are set out in the FeedFrwd AI Supplementary Terms.

6.  Legal Bases for Processing

If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction requiring a lawful basis, we rely on the following where we act as controller.

 

Performance of a contract: Creating and administering accounts, delivering the Service, processing payments, and providing support.

Legitimate interests: Securing the Service and preventing fraud and abuse; improving and developing our products using aggregated or de-identified data; business analytics; and business-to-business marketing to existing customers. We balance these interests against your rights and you may object at any time.

Consent: Marketing communications to prospects where consent is required; non-essential cookies; and any use of identifiable personal data for AI model training.

Legal obligation: Complying with tax, accounting, and other legal requirements, and responding to valid legal process.

Vital interests / public interest: Rarely, and only where necessary to protect someone’s life or where required in the public interest.

7.  How We Share Information

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose it only in the circumstances below.

7.1  Service providers and subprocessors

We use vendors to host, secure, and operate the Service, including cloud infrastructure and database providers, AI providers, authentication, payment processing, transactional email, support tooling, and analytics and error monitoring. Each is bound by written data protection terms, may use data only to provide services to us, and is listed by name at feedfrwd.ai/legal/subprocessors. Customers may subscribe there to be notified before we add or replace one.

7.2  Integration partners

When a customer authorizes an integration, data is exchanged with that system as needed to operate the connection. Those systems are controlled by their own providers and governed by their own privacy policies.

7.3  Within a customer’s workspace

Information you contribute to a workspace — your profile, comments, assigned actions, and activity — is visible to other authorized users of that workspace and to the customer’s administrators.

7.4  Professional advisors

We may disclose data to our auditors, lawyers, insurers, and financial advisors where necessary and subject to confidentiality obligations.

7.5  Corporate transactions

If FeedFrwd is involved in a merger, acquisition, financing, reorganization, insolvency, or sale of assets, data may be transferred as part of that transaction. We will notify affected individuals by email or prominent notice before their data becomes subject to a materially different privacy policy.

7.6  Legal requirements and protection

We may disclose data where necessary to comply with applicable law or valid legal process, to enforce our agreements, or to protect against fraud, security threats, or illegal activity. We assess each request, challenge those that are unlawful or overbroad where we have a reasonable basis to do so, disclose only the minimum required, and notify the affected customer unless legally prohibited.

7.7  With your consent

We may share data for any other purpose with your explicit consent.

8.  Cookies and Tracking

We use cookies and similar technologies on the Site and within the Service for authentication and security, to remember preferences, and to understand usage. Non-essential cookies are set only with your consent where applicable law requires, and you can change your choices at any time through the cookie preferences control on our Site. We honor the Global Privacy Control signal.

Full details, including the categories we use and how to manage them, are in the FeedFrwd Cookie Policy at feedfrwd.ai/legal/cookies.

9.  Data Retention

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

Account and profile data: For the life of the account, then up to twenty-four (24) months after closure, unless earlier deletion is requested.

Customer Data and derived insights: For the term of the customer agreement, then handled as set out in the Data Processing Agreement: a thirty (30) day export window, followed by deletion within ninety (90) days.

Billing and transaction records: Seven (7) years, to meet tax and accounting requirements.

Security and audit logs: Twelve (12) to twenty-four (24) months, depending on log type and security need.

Support correspondence: Twenty-four (24) months after the request is closed.

Marketing contact data: Until you opt out or withdraw consent, then on a suppression list so we do not contact you again.

Backups: Encrypted backups are purged on their ordinary cycle; deleted data may persist in backups until that cycle completes.

Legal hold: Longer where required for ongoing legal proceedings, regulatory obligations, or the establishment or defence of claims.

When a retention period ends, we delete the data or irreversibly de-identify it so that it can no longer be associated with an individual.

10.  International Transfers

We are based in the United States and process data on servers in the United States and, through our subprocessors, in the jurisdictions listed on our Subprocessor page. If you access the Service from outside the United States, your data will be transferred to and processed in countries whose data protection laws may differ from those where you live.

Where required, we implement appropriate safeguards for these transfers:

  • the European Commission’s Standard Contractual Clauses for transfers from the EEA;

  • the UK International Data Transfer Addendum for transfers from the United Kingdom;

  • the Standard Contractual Clauses as adapted for Switzerland under the FADP; and

  • other legally recognized transfer mechanisms as they become available and applicable.

The transfer terms applicable to customers are set out in the FeedFrwd Data Processing Agreement. For a copy of the safeguards we rely on, write to privacy@feedfrwd.ai.

11.  Security

We maintain administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These include:

  • Encryption — TLS 1.2 or higher in transit, and AES-256 or equivalent at rest.

  • Access control — least-privilege, role-based access with multi-factor authentication for administrative access, reviewed periodically and revoked promptly on departure.

  • Tenant isolation — logical segregation of customer data, enforced at the application and data layers.

  • Monitoring and logging — security-relevant events are logged, retained, and monitored, with alerting for suspected incidents.

  • Secure development — peer review, automated testing, dependency vulnerability scanning, and separate development, staging, and production environments.

  • Vendor assessment — subprocessors are assessed before engagement and bound by written data protection terms.

  • Incident response — a documented plan covering detection, containment, recovery, notification, and post-incident review.

We will notify affected customers and, where required, individuals and regulators, in accordance with applicable law and the timelines in our Data Processing Agreement.

No method of transmission or storage is completely secure. While we work to protect your data using commercially reasonable means, we cannot guarantee absolute security. Suspected vulnerabilities can be reported to security@feedfrwd.ai.

12.  Your Privacy Rights

Depending on where you live, you may have some or all of the rights below. We extend them to individuals globally to the extent practicable, regardless of location.

12.1  Rights in the EEA, UK, and Switzerland:

  • Access — obtain a copy of the personal data we hold about you.

  • Rectification — have inaccurate or incomplete data corrected.

  • Erasure — have your data deleted in certain circumstances.

  • Restriction — have processing restricted in certain circumstances.

  • Portability — receive your data in a structured, commonly used, machine-readable format.

  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.

  • Withdraw consent — at any time, without affecting the lawfulness of prior processing.

  • Complain — lodge a complaint with your supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner.

12.2  Rights in California

California residents have the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; to limit the use of sensitive personal information; to opt out of sale or sharing; and not to be discriminated against for exercising these rights.

We do not sell personal information and do not share it for cross-context behavioral advertising. In the preceding twelve months we collected the categories of personal information described in Section 3 for the purposes described in Section 4, and disclosed them for business purposes to the categories of recipients described in Section 7.

We will confirm receipt of a request within ten (10) business days and respond within forty-five (45) days, extendable by a further forty-five (45) days where reasonably necessary. Authorized agents may submit requests with proof of authorization.

12.3  Rights in other U.S. states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. Where a state provides a right to appeal a refused request, you may appeal by replying to our response or writing to privacy@feedfrwd.ai with the subject line “Privacy appeal.” We will respond to appeals within the period required by the applicable law.

12.4  Rights in other jurisdictions

Residents of Australia (Privacy Act 1988 and the Australian Privacy Principles), Brazil (LGPD), Canada (PIPEDA and Quebec Law 25), Japan (APPI), and other jurisdictions may have additional rights under local law. We aim to honor privacy requests from individuals globally.

12.5  How to exercise your rights

Write to privacy@feedfrwd.ai. We may need to verify your identity before acting, and may ask for information sufficient to confirm you are the person the data relates to. We do not charge for reasonable requests, but may charge a reasonable fee or decline where a request is manifestly unfounded or excessive, as permitted by law. We aim to respond within thirty (30) days, or sooner where the law requires.

End Users: if your data is in FeedFrwd because a company you dealt with put it there, please contact that company. See Section 2.

13.  Children’s Privacy

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from individuals under 16 (or a higher age where local law requires). Customers are contractually prohibited from submitting data knowingly collected from children under 16. If we learn that we have collected such data without an appropriate legal basis, we will delete it promptly. Parents and guardians with concerns can write to privacy@feedfrwd.ai.

14.  Changes to This Policy

We may update this policy to reflect changes in our practices, our technology, or the law. When we make material changes, we will update the “Last Updated” date above and notify you by email to the address associated with your account, by prominent notice on the Site, or in-product, in advance of the change taking effect where required. We encourage you to review this policy periodically. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

This version supersedes the FeedFrwd Privacy Policy dated April 14, 2026. Previous versions are available on request.

15.  Contact Us

If you have questions, concerns, or requests about this policy or our data practices:

Privacy questions, data rights requests, DPA requests: privacy@feedfrwd.ai

bottom of page