PRIVACY POLICY

Last Updated: November 14, 2025
I

INTRODUCTION AND SCOPE

This Privacy Policy ("Policy") constitutes a binding agreement between Fenurion Inc. ("Fenurion," "we," "us," or "our") and any individual or entity ("User," "you," or "your") accessing or utilizing our website, digital platforms, services, or products (collectively, the "Services"). This Policy delineates our practices concerning the collection, processing, storage, disclosure, and protection of Personal Data and establishes the juridical framework governing data subject rights.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy. Your continued use of the Services following any modifications to this Policy shall constitute acceptance of such modifications.

Governing Legal Framework

This Policy is drafted in accordance with and operates under the following legal authorities:

  • The General Data Protection Regulation (GDPR) (EU) 2016/679
  • California Consumer Privacy Act (CCPA) of 2018 and California Privacy Rights Act (CPRA) of 2020
  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030
  • Electronic Communications Privacy Act (ECPA), 18 U.S.C. § 2510 et seq.
  • Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506
  • ePrivacy Directive 2002/58/EC as amended by Directive 2009/136/EC
  • Applicable state data breach notification statutes
II

DEFINITIONS AND INTERPRETATIONS

For purposes of this Policy, the following terms shall have the meanings ascribed herein:

"Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, IP addresses, device identifiers, biometric data, geolocation data, and online identifiers that can be used alone or in combination with other information to identify, contact, or locate a specific individual.

"Processing" encompasses any operation performed on Personal Data, whether automated or manual, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.

"Data Controller" means Fenurion Inc., the entity determining the purposes and means of Processing Personal Data, except where an Event Creator independently determines the purposes and means of Processing in connection with their own event, in which case the Event Creator acts as an independent Data Controller for that Processing as described in Section X below.

"Data Processor" means any natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Data Controller.

"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

"Event Creator" means any User who creates, hosts, administers, or otherwise controls an event, poll, ticketed experience, voting campaign, or group collection ("Kitty") on the Services, and who determines the eligibility criteria, participation rules, and data collected from participants in connection with that event.

"Sensitive Personal Information" includes racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health information, sexual orientation, Social Security numbers, financial account credentials, and precise geolocation data.

III

INFORMATION WE COLLECT

A. Information You Provide Directly

We collect information that you voluntarily provide when you:

  • Create an account or register for our Services
  • Complete forms, surveys, or questionnaires
  • Make purchases or conduct transactions
  • Communicate with us via email, chat, phone, or other channels
  • Subscribe to newsletters, marketing materials, or notifications
  • Participate in contests, promotions, or community forums
  • Submit user-generated content, reviews, or feedback

Such information may include: full name, postal address, email address, telephone number, date of birth, payment information, account credentials, profile photographs, and any other information you choose to provide.

B. Information Collected Automatically

When you access our Services, we automatically collect certain technical information through cookies, web beacons, log files, and similar tracking technologies, including:

  • Device Information: Hardware model, operating system, browser type and version, unique device identifiers, mobile network information
  • Usage Data: Pages visited, time spent on pages, clickstream data, referring/exit pages, search queries, interaction with features
  • Location Data: IP address-derived approximate location, GPS coordinates (with consent), Wi-Fi access points, cell tower information
  • Network Information: IP address, ISP, connection type, network performance metrics

C. Information from Third-Party Sources

We may receive Personal Data from:

  • Social media platforms when you connect your account or use social login features
  • Business partners, affiliates, and service providers
  • Data analytics providers and advertising networks
  • Public databases and commercially available sources
  • Credit bureaus and fraud prevention services (for transaction verification)

D. Cookies and Tracking Technologies

We employ the following types of cookies:

  • Strictly Necessary Cookies: Essential for website functionality and security
  • Performance Cookies: Collect aggregate data on website usage and performance
  • Functional Cookies: Remember user preferences and personalization settings
  • Targeting/Advertising Cookies: Deliver relevant advertisements based on browsing behavior

You may control cookie preferences through your browser settings. However, disabling certain cookies may limit functionality of the Services.

IV

LEGAL BASIS AND PURPOSE OF PROCESSING

We Process Personal Data only where we have a lawful basis, including:

A. Contractual Necessity (GDPR Art. 6(1)(b))

Processing necessary for performance of our contract with you, including:

  • Account creation and authentication
  • Service delivery and customer support
  • Transaction processing and order fulfillment
  • Billing and payment administration

B. Legitimate Interests (GDPR Art. 6(1)(f))

Processing necessary for our legitimate business interests, subject to balancing against your rights:

  • Fraud detection and prevention
  • Network and information security
  • Internal analytics and business intelligence
  • Product development and improvement
  • Direct marketing to existing customers

C. Legal Obligation (GDPR Art. 6(1)(c))

Processing required to comply with legal obligations, including:

  • Tax reporting and financial record-keeping
  • Compliance with lawful law enforcement requests
  • Regulatory reporting and auditing requirements
  • Data breach notification obligations

D. Consent (GDPR Art. 6(1)(a) and Art. 9(2)(a))

Where required, we obtain your explicit consent for:

  • Marketing communications beyond existing customer relationships
  • Processing of Sensitive Personal Information
  • Non-essential cookies and tracking technologies
  • Sharing data with third parties for their marketing purposes

You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

V

DATA SHARING AND DISCLOSURE

A. Service Providers and Processors

We engage third-party service providers who Process Personal Data on our behalf under strict contractual obligations, including:

  • Cloud hosting and infrastructure providers
  • Payment processors and financial institutions
  • Customer relationship management platforms
  • Email delivery and marketing automation services
  • Analytics and data intelligence providers
  • Cybersecurity and fraud prevention services

All Processors are bound by data processing agreements requiring compliance with applicable data protection laws and implementing appropriate technical and organizational measures.

B. Business Transfers

In connection with any merger, acquisition, asset sale, reorganization, or bankruptcy proceeding, Personal Data may be transferred to successor entities. You will be notified via email and/or prominent notice on our website of any such change in ownership or control.

C. Legal Disclosures

We may disclose Personal Data when required by law or in good faith belief that such disclosure is necessary to:

  • Comply with legal process (subpoenas, court orders, warrants)
  • Enforce our Terms of Service or other agreements
  • Investigate potential violations of law or our policies
  • Protect against fraud, security threats, or technical issues
  • Protect the rights, property, or safety of Fenurion, our users, or the public

We will assess the validity and scope of any legal demand before disclosure and will provide notice to affected users unless legally prohibited.

D. Aggregate and De-identified Data

We may share aggregate statistical data and de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, and other purposes.

VI

INTERNATIONAL DATA TRANSFERS

Fenurion operates globally and may transfer Personal Data to countries outside your jurisdiction. Where we transfer Personal Data from the European Economic Area (EEA) to third countries, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs): European Commission-approved contractual templates
  • Adequacy Decisions: Transfers to jurisdictions deemed adequate by regulatory authorities
  • Binding Corporate Rules: Internal policies approved by data protection authorities
  • Consent: Your explicit consent for specific transfers where other mechanisms are unavailable

We conduct transfer impact assessments and implement supplementary measures where necessary to ensure data protection equivalent to that required within the EEA.

VII

DATA RETENTION

We retain Personal Data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. Retention periods are determined based on:

  • The nature and sensitivity of the data
  • Contractual obligations and legitimate business needs
  • Legal, regulatory, tax, accounting, or reporting requirements
  • Statute of limitations for potential legal claims

Upon expiration of applicable retention periods, we will securely delete or anonymize Personal Data in accordance with our data retention schedule and applicable legal requirements.

Standard Retention Periods

  • Account Data: Duration of account plus 7 years (for legal compliance)
  • Transaction Records: 10 years (tax and financial regulations)
  • Marketing Communications: Until withdrawal of consent or 3 years of inactivity
  • Technical Logs: 90 days to 2 years (security and operational purposes)
  • Customer Service Records: 6 years from last interaction
VIII

SECURITY MEASURES

Fenurion implements industry-standard technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, including:

Technical Safeguards

  • End-to-end encryption for data in transit (TLS 1.3 or higher)
  • AES-256 encryption for data at rest
  • Multi-factor authentication for administrative access
  • Regular vulnerability assessments and penetration testing
  • Intrusion detection and prevention systems
  • Secure software development lifecycle practices
  • Automated backup and disaster recovery systems

Organizational Safeguards

  • Access controls based on least privilege principles
  • Employee confidentiality agreements and security training
  • Data processing agreements with all third-party processors
  • Incident response and breach notification procedures
  • Regular security audits and compliance assessments

⚠ Security Disclaimer

While we employ commercially reasonable security measures, no electronic transmission or storage system is completely secure. We cannot guarantee absolute security of your Personal Data. You are responsible for maintaining the confidentiality of your account credentials and for all activities under your account.

IX

YOUR RIGHTS AND CHOICES

Depending on your jurisdiction, you may have the following rights regarding your Personal Data:

A. Right of Access (GDPR Art. 15)

You have the right to obtain confirmation whether we Process your Personal Data and to receive a copy of such data along with supplementary information about the Processing.

B. Right to Rectification (GDPR Art. 16)

You may request correction of inaccurate Personal Data and completion of incomplete Personal Data.

C. Right to Erasure / "Right to Be Forgotten" (GDPR Art. 17)

You may request deletion of your Personal Data where:

  • The data is no longer necessary for the purposes collected
  • You withdraw consent and no other legal basis exists
  • You object to Processing and no overriding legitimate grounds exist
  • The data was unlawfully Processed
  • Legal obligations require erasure

D. Right to Restriction of Processing (GDPR Art. 18)

You may request limitation of Processing where accuracy is contested, Processing is unlawful, or you have objected to Processing pending verification of legitimate grounds.

E. Right to Data Portability (GDPR Art. 20)

You have the right to receive Personal Data you provided in a structured, commonly used, machine-readable format and to transmit such data to another controller.

F. Right to Object (GDPR Art. 21)

You may object to Processing based on legitimate interests or for direct marketing purposes, including profiling. We will cease Processing unless we demonstrate compelling legitimate grounds that override your interests.

G. California-Specific Rights (CCPA/CPRA)

California residents have additional rights including:

  • Right to Know: Categories and specific pieces of Personal Information collected
  • Right to Delete: Deletion of Personal Information subject to exceptions
  • Right to Opt-Out: Sale or sharing of Personal Information (we do not sell Personal Information)
  • Right to Correct: Inaccurate Personal Information
  • Right to Limit Use of Sensitive Personal Information
  • Right to Non-Discrimination: Equal service and pricing regardless of privacy rights exercise

H. Exercising Your Rights

To exercise any of these rights, please submit a verifiable request through:

  • Email: privacy@fenurion.com
  • Privacy Request Portal: fenurion.com/privacy-request
  • Mail: Fenurion Inc., Attn: Privacy Officer, [Complete Address]

We will respond to verified requests within the timeframes required by applicable law (generally 30 days for GDPR requests, 45 days for CCPA requests, with possible extensions).

I. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work, or place of alleged infringement.

X

CHILDREN'S PRIVACY

Fenurion's Services are designed primarily for use by adults. However, we recognize that certain events, polls, ticketed experiences, and group collections hosted on our platform by independent Event Creators may be directed at or open to participation by minors under the age of 18 (including children under 13, or under 16 in the European Economic Area, as applicable under COPPA and GDPR Art. 8 respectively). Fenurion does not prohibit such participation, provided the requirements of this Section are satisfied.

A. Mandatory Parental or Guardian Consent

Where an Event Creator's event, poll, voting campaign, ticketed experience, or Kitty is directed at, marketed to, or reasonably likely to be accessed by a child under the age of 13 (or under 16 within the EEA), the Event Creator, and not Fenurion, bears sole and exclusive responsibility for:

  • Determining whether any prospective participant is a minor requiring parental or guardian consent under applicable law;
  • Obtaining verifiable parental or guardian consent, consistent with the standard required under COPPA § 6502(b)(1)(A)(ii) and, where applicable, GDPR Article 8(1)–(2), before any Personal Data of a child is collected, processed, or submitted through the Services in connection with that event;
  • Retaining documented evidence of such consent for the duration required by applicable law and producing it to Fenurion or a competent regulatory authority upon request;
  • Ensuring that the scope of data collected from a child participant is limited to what is reasonably necessary for participation in the specific event, in accordance with the data minimization principle under GDPR Article 5(1)(c); and
  • Honoring any request from a parent or guardian to review, correct, or delete a child's Personal Data collected in connection with the event, consistent with COPPA § 6502(b)(1)(B) and GDPR Article 8 read together with Articles 15–17.

B. Fenurion's Role and Limitation of Liability

Fenurion acts solely as a technology platform and Data Processor facilitating the Event Creator's collection of Personal Data in these circumstances; Fenurion does not independently verify the age of participants or the existence of parental or guardian consent obtained by an Event Creator, and has no obligation to do so absent actual notice of non-compliance. Consistent with this allocation of responsibility:

  • Fenurion disclaims all liability for an Event Creator's failure to obtain, document, or maintain valid parental or guardian consent as required by this Section or by applicable law;
  • Any Event Creator who collects Personal Data from a child without the requisite verifiable parental or guardian consent does so in material breach of this Policy and our Terms of Service, and assumes sole legal and financial responsibility for any resulting claim, regulatory action, or penalty, including under COPPA, GDPR Article 8, or equivalent state and foreign law;
  • Event Creators agree to indemnify and hold harmless Fenurion, its officers, employees, and affiliates from and against any claim, liability, fine, or expense (including reasonable legal fees) arising out of or related to the Event Creator's failure to comply with the parental or guardian consent obligations set out in this Section; and
  • Fenurion reserves the right, at its sole discretion and without liability, to suspend or terminate any event, remove any content, or restrict any Event Creator's account upon receiving actual notice or credible information indicating that a child's Personal Data has been collected without valid parental or guardian consent.

C. Reporting Non-Compliance

If you are a parent or guardian and believe that your child has participated in an event, poll, ticketed experience, or Kitty on our platform without your verifiable consent, or that an Event Creator has otherwise collected your child's Personal Data unlawfully, please contact us immediately at privacy@fenurion.com with details of the event and the Event Creator involved. Upon verification, we will take appropriate remedial measures, which may include deletion of the relevant data, suspension of the event, and referral of the matter to the appropriate authority where warranted.

D. Fenurion's Own Direct Collection from Minors

Separately from any Event Creator's activity, Fenurion itself does not knowingly collect Personal Data directly from children under 13 (or under 16 in the EEA) for its own platform-level purposes (such as account registration) without verifiable parental or guardian consent obtained by Fenurion. If we learn that we have directly collected such data without valid consent, we will delete it promptly. Parents and guardians may contact us at any time using the details in this Policy to review, request deletion of, or object to further collection of their child's Personal Data held directly by Fenurion.

XI

DO NOT TRACK SIGNALS

Certain web browsers and devices permit you to broadcast a preference that you not be "tracked" online. At present, no uniform technological standard for recognizing and implementing Do Not Track (DNT) signals has been finalized. Accordingly, our Services do not currently respond to DNT browser signals or similar mechanisms.

We will update this Policy if and when a uniform DNT standard is established and adopted by Fenurion.

XII

THIRD-PARTY LINKS AND SERVICES

Our Services may contain links to third-party websites, applications, or services not operated or controlled by Fenurion. This Policy does not apply to such third-party properties. We are not responsible for the privacy practices of third parties, and we encourage you to review their privacy policies before providing any Personal Data.

The inclusion of any link does not imply endorsement by Fenurion of the linked site, its operator, or its content.

XIII

AUTOMATED DECISION-MAKING AND PROFILING

We may use automated processing, including profiling, to:

  • Personalize content and recommendations
  • Assess creditworthiness or fraud risk
  • Optimize marketing campaigns and user experience

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where such processing occurs, you have the right to obtain human intervention, express your point of view, and contest the decision.

XIV

DATA BREACH NOTIFICATION

In the event of a data breach likely to result in a risk to your rights and freedoms, we will:

  • Notify affected individuals without undue delay and, where feasible, within 72 hours of discovery
  • Report the breach to relevant supervisory authorities as required by law
  • Provide information about the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed
  • Offer appropriate mitigation measures, which may include identity theft protection services

We maintain an incident response plan and conduct regular security drills to ensure preparedness for potential security incidents.

XV

CHANGES TO THIS POLICY

We reserve the right to modify this Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated through:

  • Prominent notice on our website for at least 30 days prior to effective date
  • Email notification to registered users
  • In-app notifications where applicable

The "Last Updated" date at the top of this Policy indicates when it was last revised. Your continued use of the Services after the effective date of changes constitutes acceptance of the modified Policy. If you do not agree to the changes, you must discontinue use of the Services.

We encourage you to review this Policy periodically to stay informed about how we protect your Personal Data.

XVI

SPECIAL NOTICES

A. Notice to Job Applicants

If you apply for employment with Fenurion, we collect Personal Data including resumes, cover letters, references, background check information, and interview notes. This information is used solely for recruitment purposes and is retained in accordance with employment law requirements.

B. Marketing Communications

You may opt out of marketing emails by:

  • Clicking the "unsubscribe" link in any marketing email
  • Adjusting preferences in your account settings
  • Contacting privacy@fenurion.com

Please note that even after opting out of marketing communications, we may still send transactional or service-related messages.

C. Biometric Information

If we collect biometric information (such as facial recognition data), we will:

  • Obtain explicit written consent before collection
  • Inform you of the specific purpose and duration of storage
  • Never sell, lease, or trade biometric data
  • Store biometric data no longer than necessary for the stated purpose or within 3 years, whichever comes first
  • Comply with state biometric privacy laws including Illinois BIPA, Texas Capture or Use of Biometric Identifier Act, and Washington HB 1493
XVII

LEGAL COMPLIANCE AND CERTIFICATIONS

Fenurion maintains compliance with applicable data protection and privacy frameworks, including:

Compliance Frameworks

  • ISO/IEC 27001: Information Security Management
  • ISO/IEC 27701: Privacy Information Management
  • SOC 2 Type II: Security, Availability, and Confidentiality
  • NIST Cybersecurity Framework: Risk Management Standards
  • PCI DSS: Payment Card Industry Data Security Standard (if applicable)

We conduct annual third-party audits to verify compliance with these standards. Certification documentation is available upon request to qualified parties.

XVIII

SEVERABILITY AND ENTIRE AGREEMENT

Severability: If any provision of this Policy is found by a court of competent jurisdiction to be invalid, illegal, or unenforceable, such provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving its intent. If such modification is not possible, the provision shall be severed from this Policy, and the remaining provisions shall continue in full force and effect.

Entire Agreement: This Policy, together with our Terms of Service and any other legal notices published by Fenurion, constitutes the entire agreement between you and Fenurion concerning the subject matter hereof and supersedes all prior or contemporaneous communications and proposals, whether electronic, oral, or written.

Governing Law: This Policy shall be governed by and construed in accordance with the laws of [Jurisdiction], without regard to its conflict of law provisions. However, data protection rights are governed by the applicable laws of your jurisdiction as outlined in this Policy.

Dispute Resolution: Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts of [Jurisdiction], except where mandatory consumer protection laws require otherwise.

XIX

ACKNOWLEDGMENT AND CONSENT

Important Notice

BY ACCESSING OR USING OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO BE BOUND BY ITS TERMS. YOU FURTHER ACKNOWLEDGE THAT YOU HAVE THE RIGHT TO WITHDRAW YOUR CONSENT AT ANY TIME WHERE PROCESSING IS BASED ON CONSENT, WITHOUT AFFECTING THE LAWFULNESS OF PROCESSING BASED ON CONSENT BEFORE ITS WITHDRAWAL.

IF YOU DO NOT AGREE WITH ANY PART OF THIS PRIVACY POLICY, YOU MUST NOT USE OUR SERVICES.

This Privacy Policy represents our commitment to transparency, accountability, and respect for your privacy rights under applicable international, federal, and state laws governing data protection and electronic communications.

Document Version: 4.3
Effective Date: November 14, 2025
Last Reviewed: November 14, 2025

This document has been prepared in accordance with international data protection standards
and reviewed by qualified legal counsel specializing in privacy and technology law.

×
👋

We're here to help!

Chat with our assistant anytime

F

Fenurion Assistant

Online • Always ready to help

F
Hey there! 👋 Welcome to Fenurion Inc. - your partner in digital innovation! How can I help you today?