[Ferrule]

Privacy Policy

Ferrule

Last updated: 26 August 2026 · Version 1.0

1. Who we are and what this policy covers

Ferrule (“Ferrule”, “we”, “us”) operates an action gateway. Agents belonging to our customers call it to perform actions in the customer's own third-party tools, and we risk-score, meter, authorize and log every one of those calls.

Registered at Sveavägen 44, 6 tr, 111 34 Stockholm, Sweden.

This policy explains how we handle personal data in two distinct capacities, which are governed by different rules:

Whose dataOur roleGoverned by
Part AWebsite visitors, prospects, people who contact usController — we decide why and howThis policy
Part BPersonal data inside a customer's connected toolsProcessor — we act only on the customer’s documented instructionsThis policy and the Data Processing Agreement signed with that customer

Where the Data Processing Agreement (“DPA”) and this policy conflict in respect of Part B, the DPA governs.

Part A — When we are the controller

This part covers personal data we collect for our own purposes: running our website, responding to access requests, and communicating with prospective and existing customers.

A.1 What we collect

Information you give us. When you submit the access request form we collect your first name, last name, work email address and company name, together with the fact that you agreed to be contacted. If you email us or talk to us during evaluation or onboarding, we hold the content of that correspondence and any business contact details in it.

Information collected automatically. Our web server records the IP address the request came from, the user agent string, the pages requested, referring URL and timestamp. These logs exist to keep the site available and secure.

We do not knowingly collect special categories of personal data under Article 9 GDPR in this part, and the form should not be used to send us any.

A.2 Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Responding to an access request and evaluating fitForm submissions, correspondenceArt. 6(1)(b) — steps at your request prior to a contract
Administering a customer relationship, billing, supportContact details, correspondenceArt. 6(1)(b) — performance of a contract
Site availability, security, abuse preventionServer logsArt. 6(1)(f) — legitimate interest in operating a secure service
Direct outreach to business contacts about the serviceWork email, companyArt. 6(1)(f) — legitimate interest in B2B marketing, subject to your right to object at any time
Meeting tax, accounting and legal obligationsBilling and contract recordsArt. 6(1)(c) — legal obligation

Where we rely on legitimate interest, we have assessed that interest against your rights and are able to provide the assessment on request.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or UK you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. You may exercise any of these by writing to [email protected]. We answer within one month.

You also have the right to complain to a supervisory authority. If you are in the EEA you may complain to the authority in your country of residence or workplace; our EU representative is identified in section 5.

Part B — When we are the processor

When a customer connects a tool, the actions their agents take through us can touch personal data belonging to that customer's own users, staff or contacts. We act as a processor for that data.

B.1 What we process, and why it is personal data

We process only what an action requires, for as long as the action and its audit record require it.

We do not read a connected tool on our own initiative. Every read is an action a customer's agent asked for, and every action appears in that customer's log.

B.2 What we do with it

Region. Processing stays inside the European Union. Execution, storage and logging run on AWS in eu-north-1, Stockholm; risk scoring and anomaly detection run on Microsoft Azure in Sweden Central. No action payload is copied outside the EU.

Model providers. The risk classifier sends the action request (the tool, the operation, the parameters and the calling agent) to Azure OpenAI in Sweden Central under zero data retention, so Microsoft stores no prompt or output and trains nothing on it. Anomaly detection reads log metadata, never payloads or responses, on Azure Machine Learning in the same region. Planning still happens on the customer's side.

Isolation. Credentials, logs and metering records are scoped to one customer tenant and are never pooled across customers for any purpose, including improving the service.

Deletion. Revoking a connection deletes the stored grant immediately. Logs follow the retention schedule below.

B.3 Models, inference and training

Where inference runs. Risk classification runs on Azure OpenAI in Sweden Central under zero data retention, and anomaly detection on Azure Machine Learning in the same region. Action execution, the credential store and the action log run on AWS in eu-north-1, Stockholm, in the same country as the entity. The classifier receives the action request, never a connected tool's credentials, and no action payload is sent to any model provider outside the European Union.

Training. No action payload, response or credential is used to train or improve any model, ours or anyone else's, and Azure OpenAI is contracted neither to retain nor to train on what the classifier sends it. The one thing fitted on customer data is each tenant's anomaly baseline, built from that tenant's log metadata (agent, tool, operation, price, time and outcome), never pooled across customers, and deleted with the tenant.

Human review. A human decides which agents may act, up to what spend ceiling and at what risk ceiling, and may require a human approval step on any action class. The classifier can refuse an action or hold it for a named person; it can never approve one above a ceiling. Anomaly flags go to the named owner of the agent and pause nothing on their own unless the customer has set them to.

B.4 Where the data sits

Amazon Web Services, eu-north-1 (Stockholm): the gateway on EC2, and the credential store, the metering records and the action log in S3.

Microsoft Azure, Sweden Central: the risk classifier on Azure OpenAI and anomaly detection on Azure Machine Learning, where a smaller classifier is also fine-tuned on examples we write ourselves, never on customer payloads.

Nothing is processed outside the European Union, and no replica, backup or analytics copy leaves the European Economic Area.

B.5 Retention, deletion, and the limits of deletion

Action logs are kept for 400 days, which covers a full annual audit cycle plus the month it takes to run one.

Metering records are kept for seven years because they are the basis of an invoice under Swedish bookkeeping law.

Action payloads and responses are kept for 30 days by default, and a customer may set that to as low as 24 hours.

B.6 Requests from individuals whose data we process

If your personal data appears in a Ferrule action log and you wish to exercise your rights, contact the company that engaged us, which is the Ferrule customer whose tools the action touched. They are the controller. If you contact us directly we will pass the request to that customer without undue delay and support them in answering it.

Common provisions

5. International transfers

Ferrule is incorporated in the United States and serves customers established in the EEA. Personal data transferred outside the EEA is protected by the European Commission’s Standard Contractual Clauses, together with a transfer impact assessment and the supplementary technical measures described in our security documentation. A copy of the clauses is available on request.

EU representative (Article 27 GDPR)

6. Security

We maintain measures appropriate to the risk, including encryption in transit and at rest, credentials scoped to the minimum necessary, access control on the principle of least privilege, isolation of each customer’s data, and audit logging of access to production systems.

We notify affected customers of a personal data breach without undue delay and, in any event, within 36 hours of becoming aware of it, with the information they need to meet their own notification duties.

7. Children

The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.

8. Changes to this policy

We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect, and the version number and date at the top of this page are updated in every case.

9. Contact

Privacy enquiries and general: [email protected]
Postal: Ferrule, Sveavägen 44, 6 tr, 111 34 Stockholm, Sweden

← Back

Your request has been received.

Expect a message from Ferrule. It goes to the address you gave.