Compliance
Version 1.1 - Last updated July 31, 2026
This page summarizes how fylt aligns with major privacy, security, payments, and accessibility expectations for global service businesses. For the full legal text, see our Terms of Service, Privacy Policy, and Data Security pages.
GDPR & UK GDPR
fylt processes personal data under documented legal bases, supports data-subject requests, and uses Standard Contractual Clauses or an equivalent lawful mechanism for applicable international transfers. Data Processing Agreements are available on request.
CCPA / CPRA
California residents can exercise applicable rights to know, delete, and opt out of sale or sharing of personal information. fylt does not sell personal data as defined by the CCPA.
PCI DSS scope
Payment details for fylt subscriptions are collected and processed directly by Razorpay, a PCI DSS compliant payment processor. fylt does not store full payment card numbers, which supports a focused SAQ-A PCI scope. fylt does not process, hold, or route payments between a business and its own clients.
SOC 2 (in progress)
Our security program is progressing through a formal audit against SOC 2 Trust Services Criteria for Security, Availability, and Confidentiality. Status updates are shared here as milestones are reached.
Accessibility
We build toward WCAG 2.1 AA with keyboard navigability, visible focus states, labeled form fields, and accessible color contrast across core product surfaces.
Cookie & consent management
Visitors can manage functional, analytics, and marketing cookies through the Privacy choices badge on every page. Essential cookies support a secure, functional service experience.
Data Processing Agreement
Business customers may request a Data Processing Agreement (DPA) covering the processing of personal data on their behalf by emailing legal@fylt.app.