Privacy policy
Last updated 9 September 2026
This policy explains what personal data FoxNetwork collects when you use this site or the FoxNetwork platform, why we hold it, who we share it with, and the rights you have over it. Full details of the company publishing this site are on the Legal notice page.
01Who is responsible
FoxNetwork is the data controller for the personal data described here. Our full company identification is set out on the Legal notice page.
For any question about this policy or to exercise the rights described below, write to contact@foxnetwork.io.
02What we collect
We only collect what the service needs in order to work. In practice that falls into six groups.
- Account data — your name, email address, the role you hold in your organisation, and, if you sign in with Google, the profile picture Google provides.
- Organisation data — your company name, its size, industry and website.
- Site and asset data — the addresses of the sites we maintain, and the name and phone number of the contact person you give us for each one.
- Intervention data — what a technician recorded on site: photographs, measurements, parts used, notes, a signature, the time the visit started and ended, and the GPS coordinates of the device at the moment the report was submitted.
- Documents you upload — standard operating procedures, spare-part records and any files you attach to a request.
- Enquiries — if you ask for a quote we keep your name, email, phone number, company, the region you operate in, your message and the language you wrote in, so we can reply in it.
03Why we hold it, and on what basis
Every use below has a legal basis under Article 6 of the GDPR.
- To provide the service — running your account, dispatching interventions, producing reports and invoicing. Basis: performance of our contract with you.
- To verify work — photographs, timestamps and submission coordinates let us confirm that an intervention happened where and when it was reported. Basis: our legitimate interest in the integrity of the work we invoice for, and yours in not paying for work that did not happen.
- To answer enquiries — replying to a quote request. Basis: steps taken at your request before entering a contract.
- To meet legal obligations — keeping invoices and accounting records. Basis: legal obligation.
- Website measurement — understanding which companies visit our marketing site. Basis: your consent, which you may withdraw at any time.
04Who we share it with
We do not sell personal data and we do not share it for advertising. We use a small number of processors, each acting on our instructions.
- Supabase — database, authentication and file storage, hosted on AWS in Ireland (eu-west-1).
- Vercel — application hosting, served from Dublin.
- Anthropic — we send a company name and the public text of a company website to Claude when enriching a signup, and the contents of a standard operating procedure when converting one into steps. Anthropic does not train its models on this data.
- Postmark — sending transactional email, such as an invitation to join an organisation.
- Google — only if you choose to sign in with Google, in which case Google confirms your identity and gives us your name, email address and profile picture.
- Apollo — identifies the companies visiting our marketing site. This runs on the public site only, never inside your workspace, and only where you have consented.
05Where your data is held
Your data is stored in the European Union. The database and file storage sit in Ireland, and the application runs in Ireland.
Two of our processors are established in the United States: Anthropic and Postmark. Transfers to them are covered by the European Commission's Standard Contractual Clauses.
06How long we keep it
Account and organisation data are kept for as long as your account is open, and for twelve months after it is closed so that the account can be restored if the closure was a mistake.
Intervention records, including photographs and submission coordinates, are kept for five years, because they are the evidence behind an invoice and may be needed if that invoice is disputed.
Invoices and accounting records are kept for ten years, as French commercial law requires.
Quote requests that do not become an account are deleted after three years.
07Your rights
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or send it to another provider in a machine-readable form. You may object to processing we carry out on the basis of legitimate interest, and you may withdraw consent at any time where consent is the basis.
Write to contact@foxnetwork.io. We answer within one month.
If you are not satisfied with our answer you can complain to the CNIL, the French data protection authority, at cnil.fr.
08Security
Access to your data is enforced by the database itself, not only by the application: every table carries row-level security rules that restrict each account to its own organisation's records. Traffic is encrypted in transit, and files are held in private storage that cannot be read without an authenticated request.
No system is perfect. If a breach occurs that is likely to affect your rights, we will notify the CNIL within 72 hours and tell you directly where the risk is high.
09Cookies
The platform sets one cookie, which keeps you signed in. It is strictly necessary for the service to function and cannot be switched off without making sign-in impossible.
The marketing site uses a measurement cookie to identify visiting companies. It is not necessary, and it is only set with your consent.
10Changes
If we change this policy we will update the date at the top. Where a change materially affects how we use your data, we will tell account holders by email before it takes effect.