Last updated August 2026
Privacy Policy
Who we are
Followly (“Followly”, “we”, “us”), based in Belgium, operates the Followly follow-up and scheduling software. For most of the data described below, Followly is the data controller under the EU General Data Protection Regulation (GDPR). For one category (your own customers’ records, which you enter into Followly), Followly is instead a data processor, acting only on your instructions. That distinction matters, so we keep it separate throughout this page.
Two kinds of data
Your account data. When you or your team signs up for Followly, we collect the name, email address, and (hashed, never plain-text) password of each person with access, plus your business name and timezone. Followly is the controller for this data.
Your customers’ data. Followly exists to help you manage relationships with your own customers, so you (or we, as part of setup) enter their names, contact details, appointment history, and notes into the product. That data belongs to you, not us. You are the controller for it under GDPR; Followly only processes it on your behalf, to run the product, and never for our own purposes.
What we collect and why
- Account & billing information: to create and secure your account, and to bill your subscription. We use Stripe to process payments; Followly never sees or stores your card details directly.
- Customer & appointment records you enter: to run the follow-up automation you’ve configured. Processed only as needed to provide the service to you.
- Setup information: if you use our white-glove setup, whatever you share with us (e.g. an export from your previous calendar or CRM) so we can import it into your account.
- Basic technical data: things like IP address and request timestamps, kept briefly for security (e.g. rate-limiting abusive login attempts), not for tracking or profiling.
We process this on the basis of performing our contract with you (running the service you signed up for), our legitimate interest in keeping the service secure and working, and, for the setup service, your explicit instruction to import specific data.
Who we share it with
We don’t sell your data, and we don’t share it with advertisers, data brokers, or anyone for marketing purposes. The only outside party involved is Stripe, which processes subscription payments on our behalf as a sub-processor and has its own GDPR-compliant privacy practices (see Stripe’s own privacy policy for details). Stripe may process data outside the EU under its Standard Contractual Clauses.
How long we keep it
We keep account and customer data for as long as your account is active. If you close your account, ask us to delete your data, or stop paying and don’t respond to billing follow-ups, we delete it within a reasonable period rather than holding onto it indefinitely.
Your rights
Under GDPR, for data where Followly is the controller, you can ask us to:
- give you access to the data we hold about you,
- correct it if it’s wrong,
- delete it,
- restrict or object to certain processing, and
- give you a copy in a portable format.
To exercise any of these, email us (see Contact below). If you’re not satisfied with our response, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données).
Security
Passwords are hashed, not stored in plain text. Sessions use signed, httpOnly cookies. We apply rate limiting against brute-force login attempts and standard security headers across the site. No system is unbreakable, but we treat this seriously rather than as an afterthought.
Children
Followly is a business tool and isn’t directed at, or knowingly used by, children.
Changes to this policy
If we materially change how we handle your data, we’ll update this page and change the date at the top.
Contact
Questions about this policy or your data: hello@followly.info.