1. Who We Are
GoalfyData is a data asset layer for AI Agents that helps users turn business data, field definitions, table relationships, governance rules, and usage instructions into reusable datasets and applications. In this Policy, “GoalfyData,” “we,” “us,” and “our” refer to the registered legal entity that operates and provides the GoalfyData website and related services. The entity’s specific legal name, registered address, and contact information will be the information stated on the GoalfyData website, checkout page, invoice, service page, or other official notices we provide to you. Privacy-related questions may be sent to: goalfydata@goalfyai.com
GoalfyData acts as the data controller or business for account, website, payment, support, security, and product analytics data. For content uploaded or managed by customers, GoalfyData generally acts as a processor or service provider and processes that content on the customer's instructions, unless applicable law requires otherwise.
2. Scope of This Policy
This Policy applies to information processing activities involved when you access or use the GoalfyData website and services, including visiting website pages, registering for or signing in to an account, creating or managing datasets, creating or viewing applications, using Agents, MCP, CLI, or other tools to connect to GoalfyData, contacting us, submitting feedback, or participating in early trials.
This Policy does not apply to third-party websites, third-party Agents, third-party model services, or external tools. When you use GoalfyData through a third-party service, you should also review that third party’s privacy policy and terms of service.
3. Information We Collect
We may collect account and contact information, such as your name or nickname, email address, company or team name, account sign-in information, and contact content, feedback, or requirements that you voluntarily submit.
When you visit the website or use the services, we may automatically collect usage and device information, such as access time, pages, clicks, and basic usage records; device type, browser type, operating system, IP address, language settings, approximate region, sign-in status, error logs, performance logs, security logs, Cookies, or similar technology identifiers. This information is used to maintain service stability, security, and basic product analytics.
When you use GoalfyData to create datasets or applications, you may upload or generate raw business data, data tables and field structures, field definitions, primary keys and table relationships, metric definitions, governance rules and processing logic, update scripts, runtime configurations and invocation context, Agent Skills, usage instructions and query examples, applications, analysis results and report content, sharing settings, permission configurations, and access records. These materials are collectively referred to in this Policy as “User Content.”
If you connect to GoalfyData through Agents, MCP, CLI, or other third-party tools, we may process the integration method and authorization status, accessible datasets, applications and context scope, invocation requests, invocation time and basic logs, and execution status, error information, or result summaries returned by those tools.
If you purchase paid services, payment may be processed by Stripe or another payment processor. We may process orders, plans, billing status, invoices, payment status, transaction identifiers, tax information, and anti-fraud related information, but we generally do not receive or store full card numbers.
Unless we separately permit it in writing, please do not upload payment card data, health data, biometric data, children’s data, government classified data, or other sensitive or regulated data that requires special protection.
4. How We Use Information
We use the information we collect mainly to provide, maintain, and improve the GoalfyData services; create, store, update, and manage datasets; generate, display, and run applications; support Agents, MCP, CLI, or other tool integrations; manage accounts, permissions, sharing, and access scope; process payments, subscriptions, invoices, refunds, and payment disputes; handle user feedback, support requests, and product communications; monitor service operation, troubleshoot errors, and protect security; prevent abuse, fraud, unauthorized access, or other violations; comply with legal obligations and protect legitimate rights and interests.
Where the GDPR or UK GDPR applies, our legal bases for processing personal information may include performance of a contract with you, compliance with legal obligations, legitimate interests such as security, anti-fraud, service improvement, and customer support, your consent where required, and processing necessary to establish, exercise, or defend legal claims.
We do not use private User Content to train general-purpose AI models unless you give explicit permission. We may process User Content to provide the services, conduct security reviews, troubleshoot issues, prevent abuse, comply with legal obligations, or enable third-party tools according to your settings.
We do not sell your personal information. If in the future we use advertising or tracking technologies that would constitute a “sale” or “sharing” under applicable law, we will provide the relevant notices and choices as required by applicable law.
5. User Content and Datasets
You retain your rights in the User Content you upload or create. GoalfyData processes such content to provide dataset creation, updating, running, sharing, reuse, and Agent integration services to you.
You must ensure that you have the right to upload, process, share, and use the relevant data, including any personal information, business data, or third-party data contained in it, and that you have provided necessary notices, obtained necessary consents, or have another lawful basis for the relevant individuals.
Unless authorized by you or required by law, we will not display your private workspace data on public pages. Public links, active sharing, team administrator settings, authorized Agent access, or third-party tool integrations may make relevant content available to others according to your settings. Public example pages should use only sample data, de-identified data, or content authorized for display.
6. Agents and Third-Party Tool Integrations
GoalfyData may allow you to access datasets and applications through Agents, MCP, CLI, development environments, third-party models, or other third-party tools.
When you enable such integrations, you can control which datasets, applications, or context may be invoked; the relevant tools or models may receive data or context within the scope you authorize; third-party tools may process data under their own terms and policies; and you should configure access scope carefully and ensure that you have the right to provide the relevant data to third-party tools.
GoalfyData provides access capabilities according to your configuration, but is not responsible for the data processing practices, availability, policy restrictions, or outputs of third-party tools, models, or services.
7. How We Share Information
We may share necessary information with service providers that help us provide infrastructure, hosting, data storage, payment processing, email delivery, analytics, customer support, security, model, or Agent integration services. These service providers may process information only within the scope necessary to provide their services.
When you actively share datasets, applications, links, or authorize Agent access, the relevant content will be made available to the specified recipients according to your settings.
We may disclose necessary information when required by law, regulatory requirements, court orders, or where necessary to protect the rights and safety of GoalfyData, users, the public, or third parties.
If a merger, acquisition, financing, asset transfer, reorganization, or similar transaction occurs, relevant information may be transferred as part of the business assets, but the recipient should continue to process such information subject to reasonable privacy protection requirements.
8. Data Retention
We retain information for as long as necessary to fulfill the purposes described in this Policy, including the time needed to provide the services, maintain accounts, process payments and invoices, comply with legal obligations, resolve disputes, protect security, and enforce agreements.
In general, account and contact information is retained while the account is active and for a reasonable period after closure; billing, payment, and tax records are retained as required by law and accounting requirements; security logs, error logs, and access records are retained for the period needed for security, audit, and abuse prevention; and User Content will be deleted or retained for a limited period after you or your organization deletes it, closes the account, or the service terminates, depending on product functionality, backup cycles, legal obligations, and security requirements.
You may contact GoalfyData to request deletion or correction of your information. Certain information may continue to be retained for a limited period due to security, backup, audit, legal obligations, payment disputes, or abuse prevention.
9. Data Security
GoalfyData takes reasonable technical and organizational measures to protect data, including access controls, authorization, data isolation, logging, security monitoring, and necessary service provider management.
You can control the access scope for datasets, applications, and Agents. Private workspace data will not be publicly displayed unless based on your settings, authorized sharing, team administrator actions, legal requirements, or security processing needs.
However, no internet service can guarantee absolute security. You should also properly protect your account, access credentials, API Keys, and other authorization information to avoid unauthorized access. If a security incident requiring notice occurs, we will handle it in accordance with applicable law.
10. Your Rights and Choices
Depending on the laws applicable in your region, you may have rights to access, correct, delete, restrict processing of, object to processing of, export or transfer information, withdraw consent, close your account, disable access permissions, and lodge complaints regarding privacy processing.
You may contact us by email at: goalfydata@goalfyai.com. We will handle your request in accordance with applicable law, identity verification requirements, and the circumstances. Certain requests may be limited by legal obligations, security, backups, payment, anti-fraud, dispute handling, or the rights of others.
If the GDPR, UK GDPR, CCPA / CPRA, PIPEDA, Australian Privacy Act, or Singapore PDPA applies to your request, we will provide the relevant rights and responses in accordance with applicable law. You may also lodge a complaint with a privacy or data protection regulator that has jurisdiction in your location.
11. Children’s Privacy
GoalfyData is intended for business and professional use cases and is not directed to children. You must be at least 18 years old, or the age required by the laws of your location to use this service, to create an account or use services that require an account.
If you believe a minor has provided personal information to us, please contact us and we will handle it in accordance with applicable law. Customers may not upload children’s personal information unless they have the right to do so and have satisfied applicable legal requirements.
12. International Data Transfers
GoalfyData and its service providers may process and store information outside your region, including in countries or regions where we or our service providers operate, host, support, or process payments.
For information processed across regions, we will take reasonable safeguards in accordance with applicable law, such as entering into data processing and confidentiality obligations with service providers, using applicable cross-border transfer mechanisms, implementing access controls and security measures, and providing further information when required.
13. Cookies and Similar Technologies
We may use Cookies, logs, pixels, SDKs, or similar technologies to maintain sign-in status, protect security, remember preferences, analyze website and product usage, improve services, and prevent abuse.
Strictly necessary Cookies are used to provide the website and services. For non-essential analytics, advertising, or similar tracking technologies, we will provide notice, consent, or opt-out choices where required by applicable law. You may also restrict or delete Cookies through your browser settings, but some features may not function properly as a result.
14. Updates to This Policy
We may update this Privacy Policy from time to time. After an update, we will revise the “Effective Date” or “Last Updated” date on the page. If a change is material, we may notify you through website notices, email, or other reasonable means.
If a change involves a new material processing purpose and applicable law requires consent or an opt-out choice, we will handle it in accordance with applicable law.
15. Contact Us
If you have any questions about this Privacy Policy or our data processing practices, you may contact us at: goalfydata@goalfyai.com