PRIVACY POLICY

The Foundations (“we,” “us,” or “our”) operates thefoundations.co (the “Website”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Website and subscribe to our services.

We are committed to protecting your privacy and ensuring transparency about our data practices. Please read this policy carefully. By accessing or using our Website, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

1. Information We Collect

1.1 Information You PROVIDE

We collect information you voluntarily provide when you register for an account, subscribe to our services, sign up for our newsletter, or contact us. This includes:

• Email address (required for account creation and subscription)

• Name (optional, for personalization)

• Payment information (processed securely through Stripe; we do not store your full credit card details)

• Any other information you choose to provide in communications with us

1.2 Information Collected Automatically

When you access our Website, we automatically collect certain information, including:

• Device information (browser type, operating system, device type)

• Log data (IP address, access times, pages viewed, referring URL)

• Location data (country and region, derived from IP address)

• Cookies and similar tracking technologies (see Section 5)

2. How We Use Your Information

We use the information we collect for the following purposes:

• To provide and maintain our services, including processing subscriptions and delivering content

• To communicate with you about your account, subscription, and our services

• To send you our newsletter and editorial updates (with your consent)

• To process payments and prevent fraud

• To analyze Website usage and improve our content and services

• To comply with legal obligations

• To protect our rights and the security of our Website

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

Contract performance: Processing necessary to provide our subscription services

Consent: Processing based on your explicit consent (e.g., newsletter subscription)

Legitimate interests: Processing necessary for our legitimate business interests (e.g., analytics, fraud prevention)

Legal obligation: Processing required to comply with applicable laws

4. How We Share Your Information

We do not sell your personal information. We may share your information with:

Service providers: Third parties that help us operate our Website and services, including Stripe (payment processing), our hosting provider, and email service providers

Analytics partners: Services that help us understand Website usage (e.g., Google Analytics)

Legal requirements: When required by law, court order, or governmental authority

Business transfers: In connection with a merger, acquisition, or sale of assets

5. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and deliver personalized content. Types of cookies we use:

Essential cookies: Required for Website functionality and authentication

Analytics cookies: Help us understand how visitors interact with our Website

Preference cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling certain cookies may affect Website functionality.

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law. When you cancel your subscription, we retain your account information for a reasonable period to allow for reactivation and to comply with legal obligations. You may request deletion of your data at any time (see Section 7).

7. Your Rights

7.1 Rights Under GDPR (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

• Right to access your personal data

• Right to rectification of inaccurate data

• Right to erasure (“right to be forgotten”)

• Right to restrict processing

• Right to data portability

• Right to object to processing

• Right to withdraw consent at any time

7.2 Rights Under CCPA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

• Right to know what personal information we collect, use, and disclose

• Right to delete your personal information

• Right to opt-out of the sale of personal information (we do not sell personal information)

• Right to non-discrimination for exercising your privacy rights

7.3 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@thefoundations.co. We will respond to your request within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including France (where we are based) and the United States (where some of our service providers are located). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, secure servers, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

10. Children’s Privacy

Our Website and services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will take steps to delete such information.

11. Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our Website and updating the “Last updated” date. Your continued use of our Website after such changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@thefoundations.co

Website: thefoundations.co

Data Controller: The Foundations

For users in the EEA, you also have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.