Privacy Policy on the Processing of Personal Data by Cloud Automation Solutions EOOD
1. Introduction
This Privacy Policy (“Policy”) explains how Cloud Automation Solutions EOOD (“we”, “our”, or “us”), operating the Felan AI platform, collects, uses, discloses, and safeguards personal data in connection with the provision of our services.
This Policy applies to the processing of personal data when you:
-
Visit our public website at https://felan.ai or register for the application at https://app.felan.ai
-
Use our AI teammate services for software-delivery work
-
Interact with our company (e.g., support requests, communications)
This Policy does not apply to third-party websites, platforms, or services that are not owned or controlled by us, even if they are accessible through links on our Platform or integrated with our Service. We encourage you to review the privacy policies of any third-party services you access.
The purpose of this Policy is to inform you — as a data subject — about what personal data we collect, for what purposes we process it, on what legal bases, how long we retain it, with whom we share it, and how you can exercise your rights.
This Policy describes our processing under the EU General Data Protection Regulation (GDPR), the Bulgarian Personal Data Protection Act (PDPA), and other applicable data protection laws.
2. Who Are We
Cloud Automation Solutions EOOD is the data controller responsible for the processing of your personal data as described in this Policy.
Company: Cloud Automation Solutions EOOD
Registration Number (EIK): 203094836
Registered Address: Bulgaria, Sofia, 1797, 131-VA str. 1B
Website: https://felan.ai
Data Protection Contact Person:
Milko Slavov
Email: privacy@felan.ai
If you have any questions regarding the processing of your personal data or wish to exercise your rights, please contact our Data Protection Contact Person at the email address above.
By registering an account and/or using any of our services, you acknowledge that you have read and understood this Privacy Policy.
We encourage you to contact us directly at privacy@felan.ai if you have concerns about our data practices before contacting regulatory authorities.
3. Personal Data We Collect and How We Use It
Personal data means any information that describes and can be linked to a specific identifiable individual. We collect and process personal data for the purpose of providing, maintaining, and improving our Service.
3.1 Roles of the Parties
-
When we act as data controller: For Account data (registration, billing, usage data), we determine the purposes and means of processing and act as the data controller.
-
When we act as data processor: For data from the Customer’s systems that we access or process to carry out the Customer’s requests, the Customer remains the data controller and we act as the data processor, processing data on the Customer’s instructions. This relationship is governed by our Data Processing Agreement.
3.2 Account Information
-
Email Address: Professional email address for account creation and communication
-
Name: Name for personalization (if provided)
-
Company Information: Company name and business identification data
-
Authentication Data: Encrypted passwords or OAuth tokens for secure access
3.3 Customer Systems and Content
When the Customer authorizes Felan AI to connect with development tools, we may process:
-
Documentation systems: Product documentation, API docs, README files, and uploaded reference material
-
Issue tracking and test-management systems: Issues, comments, requirements, test cases, and results
-
Communication systems: Messages, threads, support tickets, and event payloads
-
Code repositories: Source files, repository history, branches, pull requests, and related metadata
-
Applications and environments: Customer-authorized application interfaces, environment metadata, and execution inputs
Felan may read from or write to connected systems according to the Customer’s instructions and the permissions granted to the connection. Repository content may be cloned into an isolated agent workspace and modified when authorized. Content needed for sessions, outputs, uploaded knowledge, and durable team memory may be stored as described in this Policy and the DPA.
3.4 Session and Execution Data
-
Session Data: Requests, messages, transcripts, status, and delegated-agent activity
-
Execution Data: Command output, test results, logs, error messages, and resource metadata
-
Visual Evidence: Screenshots and screen recordings when a workflow captures them
-
Artifacts: Files, patches, reports, and other outputs created during a session
3.5 AI-Generated and Agent-Produced Content
-
Plans and Analysis: Product, technical, test, release, incident, and operational work products
-
Repository Artifacts: Code, documentation, tests, reviews, and proposed changes
-
Connected-System Outputs: Issues, comments, reports, and test-management records
In accordance with the EU AI Act, we inform you that Felan AI uses third-party artificial intelligence models to analyze authorized context and produce requested software-delivery work. AI-generated results may contain errors and require human review appropriate to the risk and intended use. The Service does not make automated decisions with legal or similarly significant effects on individuals.
3.6 Usage and Technical Data
-
Public Website Browser Analytics: Pseudonymous visitor and session identifiers, page URLs and titles, referrers, timestamps, traffic sources, browser and device information, locale, screen and viewport dimensions, IP-derived information, and company or professional visitor information where made available by Ploy’s visitor-identification service, collected only after analytics consent
-
Application Browser Analytics: Features used, page views, frequency of use, and browser performance data collected by PostHog only after analytics consent
-
Server-Side Application Events: Limited messaging, payment, and survey events sent to PostHog from Felan’s servers; these events do not use browser cookies
-
Technical Information: IP address, browser type, device information
-
Integration Credentials: Encrypted API keys for third-party integrations
3.7 Data Voluntarily Provided
Personal data that you voluntarily provide when using our services, such as information included in support requests, communications with our team, or content uploaded to the Platform.
4. Methods of Data Collection
We collect personal data through the following methods:
-
Directly from you: When you register an account, configure the Service, submit support requests, or otherwise communicate with us.
-
Through third-party integrations: When you authorize Felan AI to connect with your development and communication tools (GitHub, Slack, Jira, etc.), we receive data through API interfaces as configured by you.
-
Automatically: Strictly necessary technical and security data is collected when you access the Website or application. The Ploy-hosted public Website and the application use optional browser analytics only after the shared analytics consent choice. Felan also sends the server-side application events described in Section 3.6; those events do not use browser cookies.
5. Purposes of Data Processing
We process your personal data for the following purposes:
5.1 Service Delivery
-
Account creation and management
-
Processing requests and authorized Customer context in traceable sessions
-
Planning, implementing, reviewing, testing, documenting, and investigating software-delivery work as instructed
-
Running authorized repository, command-line, browser, and integration operations
-
Delivering session results, generated artifacts, screenshots, videos, reports, and connected-system updates
-
Managing integrations with third-party development tools
5.2 Communication
-
Informing you about new features, improvements, and service updates
-
Alerting you to requested results, failures, findings, or system issues
-
Responding to your questions and providing support
5.3 Service Improvement
-
Understanding public Website performance and audience engagement through Ploy browser analytics only after analytics consent
-
Understanding application usage through PostHog browser analytics only after analytics consent and through limited server-side messaging, payment, and survey events
-
Using anonymized, non-personalized data for monitoring and improving system reliability and cybersecurity — a requirement for trustworthy AI
5.4 Security and Legal Compliance
-
Detecting and preventing fraud, abuse, and security threats
-
Meeting our obligations under Bulgarian and EU law
-
Maintaining records as required by applicable legislation
We do not: Sell your data to third parties, use your data for unrelated marketing, or share your confidential business information.
6. Legal Bases for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
-
Performance of a contract (Art. 6(1)(b)): Processing necessary for the performance of our agreement with you or to take steps at your request prior to entering into a contract (e.g., account registration, service delivery, integration management).
-
Pre-contractual measures (Art. 6(1)(b)): Processing necessary to take steps at your request before entering into a contract (e.g., account setup, trial period).
-
Legitimate interest (Art. 6(1)(f)): Processing necessary for our legitimate interests, provided these are not overridden by your rights (e.g., security monitoring, service communications, fraud prevention).
-
Legal obligation (Art. 6(1)(c)): Processing necessary to comply with legal obligations to which we are subject (e.g., retention of financial records under Bulgarian tax law, responding to lawful government requests).
-
Consent (Art. 6(1)(a)): Processing based on your explicit consent, which you may withdraw at any time (e.g., Ploy and PostHog browser analytics and marketing communications if applicable).
7. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes described in this Policy and to meet our legal obligations. All retention periods run from the date of collection of the personal data, unless otherwise specified below:
| Data Type | Retention Period | Reason |
|---|---|---|
| Active Account Data | Duration of service use | Service provision |
| Deleted Account Data | 30-day recovery period before operational deletion | Recovery period |
| Backup Data | Maximum 90 days | Disaster recovery |
| Sessions, Team Knowledge, and Agent Outputs | Duration of service use or configured retention period | Service continuity and requested work |
| Test and Execution Results | 1 year by default, where configurable | Historical analysis |
| Execution Logs | 90 days | Debugging and support |
| Security Logs | 1 year | Security auditing |
| Financial Records | 5 years | Bulgarian tax law |
| Ploy Public-Website Browser Analytics | According to the active Ploy configuration | Website measurement with consent |
| PostHog Messaging, Payment, Survey, and Browser Analytics Events | Up to 1 year under the current application configuration | Product improvement; browser analytics require consent |
Account Deletion: When a team is deleted, we mark it for deletion and apply a 30-day recovery period. After that period, deletion from active systems and service artifacts is handled operationally. Permanent-deletion automation and cross-storage verification are being implemented. Backup copies expire through backup rotation within a maximum of 90 days after removal from active systems. Data that must be retained by law, such as financial records, remains for the legally required period.
Right to Deletion: You can request deletion of your data at any time by contacting privacy@felan.ai. We will respond to the request within the period required by applicable law and provide information about the applicable deletion schedule.
In the event of a documented security breach involving personal data, we will notify the Bulgarian CPDP and affected data subjects as quickly as possible, in accordance with GDPR requirements.
8. AI and Data Minimization
8.1 AI Processing
Felan AI uses third-party artificial intelligence models to interpret requests, analyze authorized context, coordinate tools, and produce requested outputs. Data sent to an AI provider is limited to the context reasonably necessary for the requested work.
8.2 No Model Training
Managed AI providers are configured under commercial terms that exclude Customer data from model training. Current providers and contractual safeguards are listed in our sub-processor disclosures.
8.3 Automated Decision-Making
The Service does not make automated decisions with legal or similarly significant effects on individuals. All AI-Generated Content is intended to assist human decision-making and must be reviewed by a qualified person before being acted upon. Data subjects retain all rights under GDPR, including the right to human intervention.
9. Data Sharing and Sub-Processors
9.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing or any other purposes.
9.2 Sharing for Service Provision
We may share minimal personal data with:
-
Sub-processors engaged to help us provide the Service (see Section 9.3)
-
Payment providers (banks, payment institutions, electronic money institutions) as necessary for processing payments
-
Companies or organizations with your explicit consent, where you have authorized sharing
9.3 Service Providers and Sub-Processors
We use service providers and sub-processors to operate the public Website and provide the Service. The register is:
| Provider | Purpose | Primary Processing Location | Transfer Safeguards and Notes |
|---|---|---|---|
| Ploy, Inc. | Public Website hosting, publishing, browser analytics, and visitor identification | United States; infrastructure and sub-processors may process in the UK, EEA, and United States | Ploy’s published DPA describes SCCs, the UK IDTA, and other approved safeguards |
| Cloudflare, Inc. | Edge delivery, security, and bot management used in Ploy’s delivery of the public Website | Global edge network | Used through Ploy for edge delivery and security |
| Vercel Inc. | Application hosting, edge computing, and related analytics | EU region with global edge processing | DPA and applicable transfer safeguards |
| Supabase Inc. | Database services and authentication | EU, Frankfurt | DPA; EU-hosted project |
| Google LLC | Historical execution-log storage and invoice document delivery | Cloud Storage in the EU; Workspace location follows the configured account | Data-processing terms and SCCs where applicable |
| Daytona Platforms, Inc. | Isolated agent workspace compute and storage | Europe by default; United States entity and control plane | DPA and SCCs for restricted transfers |
| PostHog Inc. | Application browser analytics and server-side messaging, payment, and survey events | EU, Frankfurt | DPA; EU-hosted project; browser analytics require consent |
| Anthropic PBC | Managed AI request processing, generation, analysis, and agent coordination | United States | DPA and SCCs for restricted transfers |
| Stripe Inc. | Payment processing and billing | United States | DPA, SCCs, and PCI DSS controls |
We maintain a register of sub-processors and will notify Customers of intended changes in accordance with the DPA. For the register and change notification process, see our Data Processing Agreement.
9.4 Legal Disclosures
We may disclose your information when required by law:
-
To comply with court orders, subpoenas, or legal processes
-
To enforce our Terms of Service or protect our rights and property
-
To protect the personal safety of users or the public
-
To detect, prevent, or address fraud and security issues
We will notify you of legal requests unless prohibited by law.
9.5 Business Transfers
If Cloud Automation Solutions EOOD is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice and ensure the new entity is bound by this Privacy Policy.
10. Data Storage and Security
10.1 Data Location
Felan’s primary application database and configured application analytics are hosted within the European Union. Other processing depends on the service involved:
-
Ploy: Public Website hosting, consent-based browser analytics, and visitor measurement through Ploy and its published sub-processors
-
Vercel (EU Region): Application hosting and edge computing
-
Supabase (EU Region): Database and authentication
-
Execution and storage providers: Agent workspace execution and file storage as listed in our sub-processor disclosures
-
PostHog (EU Region): Application browser analytics and server-side messaging, payment, and survey events; browser analytics require consent
Where a sub-processor handles data outside the European Economic Area, the applicable transfer mechanism and safeguards are identified in the DPA and sub-processor disclosures.
10.2 Data Breach Notification
In the event of a personal data breach, we will:
-
Notify the Bulgarian CPDP within 72 hours as required by GDPR Article 33
-
Notify affected data subjects without undue delay via email
-
Provide details about the breach, its impact, and remediation steps
-
Take immediate action to contain and resolve the breach
11. International Data Transfers
Our primary application database is hosted within the European Union. Some providers process limited data in the United Kingdom, United States, or other locations under the transfer mechanisms and safeguards identified in the DPA and provider register.
If we need to engage additional processors outside the European Economic Area (EEA) in the future, we will:
-
Notify you in advance
-
Ensure appropriate safeguards are in place in accordance with GDPR Chapter V (adequacy decisions, Standard Contractual Clauses, or other approved mechanisms)
-
Update this Privacy Policy accordingly
12. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
-
Right to Confirmation and Access (Art. 15): You can request confirmation of whether your personal data is being processed and, if so, request a copy of that data. Email privacy@felan.ai and we will respond within the period required by applicable law.
-
Right to Rectification (Art. 16): You can request correction of inaccurate personal data by contacting privacy@felan.ai.
-
Right to Erasure (Art. 17): You can request deletion of your personal data using the account deletion feature in your team settings or by emailing privacy@felan.ai.
-
Right to Restrict Processing (Art. 18): You can request that we limit the processing of your personal data.
-
Right to Data Portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format (JSON/CSV). We will process export requests within 30 days.
-
Right to Object (Art. 21): You can object to the processing of your personal data based on legitimate interest, including analytics.
-
Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you can withdraw it at any time through your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
How to Exercise Your Rights: Contact us at privacy@felan.ai. We will respond within the period required by GDPR. For account deletion and data export, you can also use the features available in your team settings.
Unfounded or Excessive Requests: If requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse to act on the request, in accordance with GDPR Article 12(5).
13. Age Restriction
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from persons under 18 years of age. If we become aware that we have collected personal data from a person under 18 without a valid legal basis, we will take the necessary steps to delete such data without undue delay, unless we are required by law to retain it.
If you become aware that a person under 18 has provided us with personal data, please inform us immediately at privacy@felan.ai.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. We will notify you of material changes by posting the new Privacy Policy on this page and, where appropriate, by email. If we make significant changes, we will provide at least thirty (30) days’ notice before the changes take effect.
15. Supervisory Authority
If you have concerns about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the Bulgarian data protection authority:
Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: https://cpdp.bg
Email: kzld@cpdp.bg
Phone: +359 2 91 53 518
As an EU citizen, you may also contact the data protection authority in your country of residence.
16. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Controller: Cloud Automation Solutions EOOD
Data Protection Contact Person: Milko Slavov
Email: privacy@felan.ai
Last updated: July 29, 2026