FelanFelan AI
ProductUse casesIntegrationsPricingDocsFAQ
Sign in

Privacy Policy on the Processing of Personal Data by Cloud Automation Solutions EOOD

1. Introduction

This Privacy Policy (“Policy”) explains how Cloud Automation Solutions EOOD (“we”, “our”, or “us”), operating the Felan AI platform, collects, uses, discloses, and safeguards personal data in connection with the provision of our services.

This Policy applies to the processing of personal data when you:

  • Visit our public website at https://felan.ai or register for the application at https://app.felan.ai

  • Use our AI teammate services for software-delivery work

  • Interact with our company (e.g., support requests, communications)

This Policy does not apply to third-party websites, platforms, or services that are not owned or controlled by us, even if they are accessible through links on our Platform or integrated with our Service. We encourage you to review the privacy policies of any third-party services you access.

The purpose of this Policy is to inform you — as a data subject — about what personal data we collect, for what purposes we process it, on what legal bases, how long we retain it, with whom we share it, and how you can exercise your rights.

This Policy describes our processing under the EU General Data Protection Regulation (GDPR), the Bulgarian Personal Data Protection Act (PDPA), and other applicable data protection laws.

2. Who Are We

Cloud Automation Solutions EOOD is the data controller responsible for the processing of your personal data as described in this Policy.

Company: Cloud Automation Solutions EOOD

Registration Number (EIK): 203094836

Registered Address: Bulgaria, Sofia, 1797, 131-VA str. 1B

Website: https://felan.ai

Data Protection Contact Person:

Milko Slavov

Email: privacy@felan.ai

If you have any questions regarding the processing of your personal data or wish to exercise your rights, please contact our Data Protection Contact Person at the email address above.

By registering an account and/or using any of our services, you acknowledge that you have read and understood this Privacy Policy.

We encourage you to contact us directly at privacy@felan.ai if you have concerns about our data practices before contacting regulatory authorities.

3. Personal Data We Collect and How We Use It

Personal data means any information that describes and can be linked to a specific identifiable individual. We collect and process personal data for the purpose of providing, maintaining, and improving our Service.

3.1 Roles of the Parties

  • When we act as data controller: For Account data (registration, billing, usage data), we determine the purposes and means of processing and act as the data controller.

  • When we act as data processor: For data from the Customer’s systems that we access or process to carry out the Customer’s requests, the Customer remains the data controller and we act as the data processor, processing data on the Customer’s instructions. This relationship is governed by our Data Processing Agreement.

3.2 Account Information

  • Email Address: Professional email address for account creation and communication

  • Name: Name for personalization (if provided)

  • Company Information: Company name and business identification data

  • Authentication Data: Encrypted passwords or OAuth tokens for secure access

3.3 Customer Systems and Content

When the Customer authorizes Felan AI to connect with development tools, we may process:

  • Documentation systems: Product documentation, API docs, README files, and uploaded reference material

  • Issue tracking and test-management systems: Issues, comments, requirements, test cases, and results

  • Communication systems: Messages, threads, support tickets, and event payloads

  • Code repositories: Source files, repository history, branches, pull requests, and related metadata

  • Applications and environments: Customer-authorized application interfaces, environment metadata, and execution inputs

Felan may read from or write to connected systems according to the Customer’s instructions and the permissions granted to the connection. Repository content may be cloned into an isolated agent workspace and modified when authorized. Content needed for sessions, outputs, uploaded knowledge, and durable team memory may be stored as described in this Policy and the DPA.

3.4 Session and Execution Data

  • Session Data: Requests, messages, transcripts, status, and delegated-agent activity

  • Execution Data: Command output, test results, logs, error messages, and resource metadata

  • Visual Evidence: Screenshots and screen recordings when a workflow captures them

  • Artifacts: Files, patches, reports, and other outputs created during a session

3.5 AI-Generated and Agent-Produced Content

  • Plans and Analysis: Product, technical, test, release, incident, and operational work products

  • Repository Artifacts: Code, documentation, tests, reviews, and proposed changes

  • Connected-System Outputs: Issues, comments, reports, and test-management records

In accordance with the EU AI Act, we inform you that Felan AI uses third-party artificial intelligence models to analyze authorized context and produce requested software-delivery work. AI-generated results may contain errors and require human review appropriate to the risk and intended use. The Service does not make automated decisions with legal or similarly significant effects on individuals.

3.6 Usage and Technical Data

  • Public Website Browser Analytics: Pseudonymous visitor and session identifiers, page URLs and titles, referrers, timestamps, traffic sources, browser and device information, locale, screen and viewport dimensions, IP-derived information, and company or professional visitor information where made available by Ploy’s visitor-identification service, collected only after analytics consent

  • Application Browser Analytics: Features used, page views, frequency of use, and browser performance data collected by PostHog only after analytics consent

  • Server-Side Application Events: Limited messaging, payment, and survey events sent to PostHog from Felan’s servers; these events do not use browser cookies

  • Technical Information: IP address, browser type, device information

  • Integration Credentials: Encrypted API keys for third-party integrations

3.7 Data Voluntarily Provided

Personal data that you voluntarily provide when using our services, such as information included in support requests, communications with our team, or content uploaded to the Platform.

4. Methods of Data Collection

We collect personal data through the following methods:

  • Directly from you: When you register an account, configure the Service, submit support requests, or otherwise communicate with us.

  • Through third-party integrations: When you authorize Felan AI to connect with your development and communication tools (GitHub, Slack, Jira, etc.), we receive data through API interfaces as configured by you.

  • Automatically: Strictly necessary technical and security data is collected when you access the Website or application. The Ploy-hosted public Website and the application use optional browser analytics only after the shared analytics consent choice. Felan also sends the server-side application events described in Section 3.6; those events do not use browser cookies.

5. Purposes of Data Processing

We process your personal data for the following purposes:

5.1 Service Delivery

  • Account creation and management

  • Processing requests and authorized Customer context in traceable sessions

  • Planning, implementing, reviewing, testing, documenting, and investigating software-delivery work as instructed

  • Running authorized repository, command-line, browser, and integration operations

  • Delivering session results, generated artifacts, screenshots, videos, reports, and connected-system updates

  • Managing integrations with third-party development tools

5.2 Communication

  • Informing you about new features, improvements, and service updates

  • Alerting you to requested results, failures, findings, or system issues

  • Responding to your questions and providing support

5.3 Service Improvement

  • Understanding public Website performance and audience engagement through Ploy browser analytics only after analytics consent

  • Understanding application usage through PostHog browser analytics only after analytics consent and through limited server-side messaging, payment, and survey events

  • Using anonymized, non-personalized data for monitoring and improving system reliability and cybersecurity — a requirement for trustworthy AI

5.4 Security and Legal Compliance

  • Detecting and preventing fraud, abuse, and security threats

  • Meeting our obligations under Bulgarian and EU law

  • Maintaining records as required by applicable legislation

We do not: Sell your data to third parties, use your data for unrelated marketing, or share your confidential business information.

6. Legal Bases for Processing

Under GDPR Article 6, we process your personal data based on the following legal grounds:

  • Performance of a contract (Art. 6(1)(b)): Processing necessary for the performance of our agreement with you or to take steps at your request prior to entering into a contract (e.g., account registration, service delivery, integration management).

  • Pre-contractual measures (Art. 6(1)(b)): Processing necessary to take steps at your request before entering into a contract (e.g., account setup, trial period).

  • Legitimate interest (Art. 6(1)(f)): Processing necessary for our legitimate interests, provided these are not overridden by your rights (e.g., security monitoring, service communications, fraud prevention).

  • Legal obligation (Art. 6(1)(c)): Processing necessary to comply with legal obligations to which we are subject (e.g., retention of financial records under Bulgarian tax law, responding to lawful government requests).

  • Consent (Art. 6(1)(a)): Processing based on your explicit consent, which you may withdraw at any time (e.g., Ploy and PostHog browser analytics and marketing communications if applicable).

7. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes described in this Policy and to meet our legal obligations. All retention periods run from the date of collection of the personal data, unless otherwise specified below:

Data TypeRetention PeriodReason
Active Account DataDuration of service useService provision
Deleted Account Data30-day recovery period before operational deletionRecovery period
Backup DataMaximum 90 daysDisaster recovery
Sessions, Team Knowledge, and Agent OutputsDuration of service use or configured retention periodService continuity and requested work
Test and Execution Results1 year by default, where configurableHistorical analysis
Execution Logs90 daysDebugging and support
Security Logs1 yearSecurity auditing
Financial Records5 yearsBulgarian tax law
Ploy Public-Website Browser AnalyticsAccording to the active Ploy configurationWebsite measurement with consent
PostHog Messaging, Payment, Survey, and Browser Analytics EventsUp to 1 year under the current application configurationProduct improvement; browser analytics require consent

Account Deletion: When a team is deleted, we mark it for deletion and apply a 30-day recovery period. After that period, deletion from active systems and service artifacts is handled operationally. Permanent-deletion automation and cross-storage verification are being implemented. Backup copies expire through backup rotation within a maximum of 90 days after removal from active systems. Data that must be retained by law, such as financial records, remains for the legally required period.

Right to Deletion: You can request deletion of your data at any time by contacting privacy@felan.ai. We will respond to the request within the period required by applicable law and provide information about the applicable deletion schedule.

In the event of a documented security breach involving personal data, we will notify the Bulgarian CPDP and affected data subjects as quickly as possible, in accordance with GDPR requirements.

8. AI and Data Minimization

8.1 AI Processing

Felan AI uses third-party artificial intelligence models to interpret requests, analyze authorized context, coordinate tools, and produce requested outputs. Data sent to an AI provider is limited to the context reasonably necessary for the requested work.

8.2 No Model Training

Managed AI providers are configured under commercial terms that exclude Customer data from model training. Current providers and contractual safeguards are listed in our sub-processor disclosures.

8.3 Automated Decision-Making

The Service does not make automated decisions with legal or similarly significant effects on individuals. All AI-Generated Content is intended to assist human decision-making and must be reviewed by a qualified person before being acted upon. Data subjects retain all rights under GDPR, including the right to human intervention.

9. Data Sharing and Sub-Processors

9.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing or any other purposes.

9.2 Sharing for Service Provision

We may share minimal personal data with:

  • Sub-processors engaged to help us provide the Service (see Section 9.3)

  • Payment providers (banks, payment institutions, electronic money institutions) as necessary for processing payments

  • Companies or organizations with your explicit consent, where you have authorized sharing

9.3 Service Providers and Sub-Processors

We use service providers and sub-processors to operate the public Website and provide the Service. The register is:

ProviderPurposePrimary Processing LocationTransfer Safeguards and Notes
Ploy, Inc.Public Website hosting, publishing, browser analytics, and visitor identificationUnited States; infrastructure and sub-processors may process in the UK, EEA, and United StatesPloy’s published DPA describes SCCs, the UK IDTA, and other approved safeguards
Cloudflare, Inc.Edge delivery, security, and bot management used in Ploy’s delivery of the public WebsiteGlobal edge networkUsed through Ploy for edge delivery and security
Vercel Inc.Application hosting, edge computing, and related analyticsEU region with global edge processingDPA and applicable transfer safeguards
Supabase Inc.Database services and authenticationEU, FrankfurtDPA; EU-hosted project
Google LLCHistorical execution-log storage and invoice document deliveryCloud Storage in the EU; Workspace location follows the configured accountData-processing terms and SCCs where applicable
Daytona Platforms, Inc.Isolated agent workspace compute and storageEurope by default; United States entity and control planeDPA and SCCs for restricted transfers
PostHog Inc.Application browser analytics and server-side messaging, payment, and survey eventsEU, FrankfurtDPA; EU-hosted project; browser analytics require consent
Anthropic PBCManaged AI request processing, generation, analysis, and agent coordinationUnited StatesDPA and SCCs for restricted transfers
Stripe Inc.Payment processing and billingUnited StatesDPA, SCCs, and PCI DSS controls

We maintain a register of sub-processors and will notify Customers of intended changes in accordance with the DPA. For the register and change notification process, see our Data Processing Agreement.

9.4 Legal Disclosures

We may disclose your information when required by law:

  • To comply with court orders, subpoenas, or legal processes

  • To enforce our Terms of Service or protect our rights and property

  • To protect the personal safety of users or the public

  • To detect, prevent, or address fraud and security issues

We will notify you of legal requests unless prohibited by law.

9.5 Business Transfers

If Cloud Automation Solutions EOOD is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice and ensure the new entity is bound by this Privacy Policy.

10. Data Storage and Security

10.1 Data Location

Felan’s primary application database and configured application analytics are hosted within the European Union. Other processing depends on the service involved:

  • Ploy: Public Website hosting, consent-based browser analytics, and visitor measurement through Ploy and its published sub-processors

  • Vercel (EU Region): Application hosting and edge computing

  • Supabase (EU Region): Database and authentication

  • Execution and storage providers: Agent workspace execution and file storage as listed in our sub-processor disclosures

  • PostHog (EU Region): Application browser analytics and server-side messaging, payment, and survey events; browser analytics require consent

Where a sub-processor handles data outside the European Economic Area, the applicable transfer mechanism and safeguards are identified in the DPA and sub-processor disclosures.

10.2 Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the Bulgarian CPDP within 72 hours as required by GDPR Article 33

  • Notify affected data subjects without undue delay via email

  • Provide details about the breach, its impact, and remediation steps

  • Take immediate action to contain and resolve the breach

11. International Data Transfers

Our primary application database is hosted within the European Union. Some providers process limited data in the United Kingdom, United States, or other locations under the transfer mechanisms and safeguards identified in the DPA and provider register.

If we need to engage additional processors outside the European Economic Area (EEA) in the future, we will:

  • Notify you in advance

  • Ensure appropriate safeguards are in place in accordance with GDPR Chapter V (adequacy decisions, Standard Contractual Clauses, or other approved mechanisms)

  • Update this Privacy Policy accordingly

12. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right to Confirmation and Access (Art. 15): You can request confirmation of whether your personal data is being processed and, if so, request a copy of that data. Email privacy@felan.ai and we will respond within the period required by applicable law.

  • Right to Rectification (Art. 16): You can request correction of inaccurate personal data by contacting privacy@felan.ai.

  • Right to Erasure (Art. 17): You can request deletion of your personal data using the account deletion feature in your team settings or by emailing privacy@felan.ai.

  • Right to Restrict Processing (Art. 18): You can request that we limit the processing of your personal data.

  • Right to Data Portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format (JSON/CSV). We will process export requests within 30 days.

  • Right to Object (Art. 21): You can object to the processing of your personal data based on legitimate interest, including analytics.

  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you can withdraw it at any time through your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

How to Exercise Your Rights: Contact us at privacy@felan.ai. We will respond within the period required by GDPR. For account deletion and data export, you can also use the features available in your team settings.

Unfounded or Excessive Requests: If requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse to act on the request, in accordance with GDPR Article 12(5).

13. Age Restriction

Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from persons under 18 years of age. If we become aware that we have collected personal data from a person under 18 without a valid legal basis, we will take the necessary steps to delete such data without undue delay, unless we are required by law to retain it.

If you become aware that a person under 18 has provided us with personal data, please inform us immediately at privacy@felan.ai.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. We will notify you of material changes by posting the new Privacy Policy on this page and, where appropriate, by email. If we make significant changes, we will provide at least thirty (30) days’ notice before the changes take effect.

15. Supervisory Authority

If you have concerns about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the Bulgarian data protection authority:

Commission for Personal Data Protection (CPDP)

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Website: https://cpdp.bg

Email: kzld@cpdp.bg

Phone: +359 2 91 53 518

As an EU citizen, you may also contact the data protection authority in your country of residence.

16. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

Data Controller: Cloud Automation Solutions EOOD

Data Protection Contact Person: Milko Slavov

Email: privacy@felan.ai

Last updated: July 29, 2026

FelanFelan AI

The team layer for AI-native software development.

Product

  • Product
  • Use cases
  • Integrations
  • Pricing
  • Docs
  • FAQ

Agents

  • Bugzy — the QA agent

Company

  • hello@felan.ai

Legal

  • Privacy
  • Terms
  • Cookies
  • DPA

© 2026 Felan