Privacy Policy

Foyer Hall holds two kinds of information: the little we need to run accounts, and whatever your firm and its clients choose to put in their workspaces. We do not sell either, and we do not use your content to train models.

Effective 11 September 2026.

What we collect

  • Account details — the email address a person was invited with, and their name if they give one.
  • What your firm puts in — documents, messages, proposals, invoices and the client records your firm creates.
  • A record of actions — who did what in a workspace and when, so a firm can answer that question later.
  • Ordinary server logs — request times, addresses and errors, kept to keep the service up and secure.

Why we hold it

To run the service your firm asked for: to sign people in, to show them their workspace, to send the notifications your firm turns on, to raise and settle invoices, and to keep the whole thing secure and available.

Cookies

Session cookies only, set on the exact address you signed in to, so the portal knows who you are on the next page. There is no advertising cookie, no analytics script and no third-party tracker anywhere on this website or in the portal.

Who else processes it

We use a small number of service providers to run Foyer Hall. They process data on our instructions and for no other purpose:

  • Supabase — the database and sign-in system (United States).
  • Hetzner — the servers the application runs on (United States).
  • Resend — sends the portal's email.
  • Stripe — processes card payments. A firm's clients pay that firm's own Stripe account; their card details go to Stripe and never to us.
  • DocuSeal — handles e-signature on documents sent for signing.

Ask us at [email protected] for the current list; we will tell you before we add one that touches your content.

Artificial intelligence

We do not use your content to train machine-learning models, and we do not hand it to anyone who does. If your firm connects its own AI assistant to the portal, that assistant reads what your firm permits it to read, under your firm's own account with that provider and that provider's terms. Your firm grants those permissions and can withdraw them at any time.

Separation between firms

One firm cannot see another firm's workspaces. That boundary is enforced by the database itself and by the address a person signs in on, not by what a page chooses to display.

How long we keep it

For as long as the firm's account is open. When an account closes we delete its content on request, and otherwise within a reasonable period, apart from records we are required to keep — for example invoices, for tax.

Your rights

Write to [email protected] and we will tell you what we hold about you, correct it, or delete it. If the data sits inside a firm's workspace, we will work with that firm, because the firm decides what belongs in its own records.

Security

Traffic is encrypted in transit. Sign-in is by emailed link or password, and sessions are tied to the single address they were created on. If we ever discover a breach affecting your data, we will tell you what happened and what we did about it.

Changes

If this policy changes in a way that matters, we will email the owner of each firm. The date at the top says when the current version started.