Skip to content
FactorFox

Legal

Privacy policy

How FactorFox Software LLC handles personal information collected through this website. Written to describe what the site actually does rather than to cover every possibility, because a policy that describes something other than the software it sits on is not worth reading.

Last updated 27 August 2026

Scope of this policy

This policy covers the factorfox.com website only. It describes information collected when you browse these pages, request a demonstration or write to us.

It does not govern the FactorFox platform. Information that a customer institution loads into or generates within the platform, including data about that customer’s own clients and debtors, is processed under the customer agreement and the data processing terms that form part of it. In that relationship the customer is the controller and FactorFox acts as a processor on its documented instructions. If you are an employee of a FactorFox customer asking how your institution’s data is handled, the answer is in your institution’s agreement with us, not on this page.

1

Who we are

FactorFox Software LLC operates this website and decides why and how the personal information described here is processed, which makes us the controller of it. Our registered details and any representative appointed for the United Kingdom or the European Union are set out in the contact section below.

We sell software to institutions, not to individuals. Almost all of the personal information we collect through this site is business contact information about people acting in a professional capacity.

2

What we collect, and how

Information you give us in the demonstration request form. Your name, business email address, company, your role, an optional indication of the size and shape of the book you fund, the system you run today if you tell us, which capabilities you would like to see, and any message you write. The form also carries the page you submitted it from and a timing value used to identify automated submissions. A hidden field is present for the same purpose and must be left empty.

Information in correspondence. If you email us, book time with us, or reply to something we send, we hold that correspondence and whatever you choose to put in it. Meetings booked through our scheduling page are handled in the Microsoft environment we operate.

Technical information created by visiting. Our hosting infrastructure records ordinary web server information for each request, which can include an internet protocol address, the requested address, a timestamp, a referring address and a browser user agent string. This is created by the act of serving a page and is used for delivery, security and diagnosing faults.

Attribution information stored in your own browser. If you arrive with campaign parameters in the web address, the site records the first and most recent of those in your browser under the keys ffx_first_touch and ffx_last_touch, together with the referring address, the landing page and the time. It stays in your browser and is transmitted to us only if you choose to submit the demonstration form, at which point it is attached to that submission so we know which piece of writing brought you here. It contains no identifier we assign to you. Clearing your browser storage for this site removes it.

We do not ask for and do not want special category information, financial account details or anything about consumers. Please do not put confidential information about your own clients or debtors into the message field.

3

Cookies, storage and consent

This website sets no advertising cookies, no cross site tracking cookies and no third party analytics cookies. It loads no third party scripts. Typefaces are served from our own origin rather than from a font network, so viewing a page here does not cause a request to another company.

The only client side storage the site uses is the attribution information described above, held in local and session storage rather than in cookies. We treat it as non essential and it is never used to build a profile, to target advertising or to identify you across other websites.

If we introduce measurement or advertising technology that requires consent, we will publish a consent mechanism before it is enabled, and this section will be updated and dated on the same day. We would rather tell you there is nothing to consent to than show you a banner that implies otherwise.

4

Why we process it, and our lawful basis

To answer a demonstration request and pursue the discussion that follows. Where you are asking us to take steps before entering into an agreement, that processing is necessary for those steps. Otherwise we rely on our legitimate interest in responding to a business enquiry made to us by a professional acting for their employer, which is an interest we consider you share, since you asked us to get in touch.

To send you material you asked for. Where consent is the appropriate basis for a particular communication, we obtain it separately and you may withdraw it at any time without affecting anything else.

To keep the site available, secure and working. Our legitimate interest in operating our own infrastructure, preventing abuse and diagnosing faults.

To understand which writing brings operators to us. Our legitimate interest in knowing which pages are useful, using the attribution information described above.

To meet legal, accounting and regulatory obligations. Where we are required to retain records, compliance with a legal obligation.

We do not sell personal information, we do not share it for cross context behavioural advertising, and we do not make decisions producing legal effects about you by automated means through this website.

5

How long we keep it

Demonstration requests and the correspondence attached to them are retained while the commercial discussion is live and for a defined period afterwards, so that a conversation picked up again later starts from what was actually said rather than from nothing. Where a relationship becomes a customer relationship, the record moves under the agreement between our institutions.

Server request logs are retained for a short operational period sufficient for security and fault diagnosis, then discarded on a rolling basis. Attribution information in your browser persists until you clear your browser storage, because it is held by your browser rather than by us.

Where we are required to keep records for legal, tax or accounting purposes, we keep them for the period the relevant law requires and no longer. Ask us and we will tell you what we hold about you and how long it is scheduled to be kept.

6

Who we share it with

We do not sell or rent personal information and we do not disclose it to anyone for their own marketing. We share it only with service providers acting on our instructions, and only to the extent each one needs to perform its function. The categories are:

  • Hosting and content delivery infrastructure, which serves these pages and holds the request logs described above.
  • Email delivery and mailbox services, used to send and receive correspondence with you.
  • Scheduling services within the Microsoft environment we operate, where you book a meeting with us.
  • Customer relationship and workflow tools that receive a demonstration request so that a person is assigned to answer it.
  • Professional advisers, auditors and insurers, where they need the information to advise us.

Each provider is engaged under a written contract requiring it to act only on our instructions, to keep the information confidential and to apply appropriate security. We may also disclose information where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. If our business or part of it is transferred to another party, information may transfer with it, and we would tell you before that changed how it is used.

7

International transfer

We are established in the United States and our customers are in North America, Latin America, Europe, Australia and South Africa. Information collected through this site will therefore be processed in the United States and may be processed elsewhere by the service providers described above.

Where personal information is transferred out of the United Kingdom or the European Economic Area to a country that has not been found to provide an adequate level of protection, we rely on an appropriate safeguard for that transfer, which for our providers is normally the European Commission standard contractual clauses together with the United Kingdom addendum where relevant. Ask us and we will tell you which mechanism applies to a specific transfer and provide the relevant information about it.

8

Your rights

Depending on where you are, you have some or all of the following rights over personal information we hold about you. We do not charge for exercising them and we do not treat anyone differently for having done so.

  • Access. A copy of the personal information we hold about you and an explanation of what we do with it.
  • Correction. Rectification of anything inaccurate or incomplete.
  • Deletion. Erasure, where we no longer have a lawful reason to keep it.
  • Objection. An objection to processing carried out on the basis of legitimate interests, including any direct marketing, which we stop on request without needing a reason.
  • Restriction. A pause on processing while a dispute about accuracy or lawful basis is resolved.
  • Portability. A copy in a structured, commonly used and machine readable form, where the right applies.
  • Withdrawal of consent. Where we relied on consent, withdrawal at any time, without affecting processing already carried out.
  • Complaint. A complaint to your supervisory authority. We would rather you came to us first, but that is your choice and not a condition.

To exercise any of these, write to us using the contact details below. We will ask for enough information to be confident who you are, and we will answer within the period the applicable law allows.

9

Security

The site is served over an encrypted connection with strict transport security, and it sets content type, framing, referrer and permissions policy headers to reduce the ways a page can be misused. Demonstration requests are validated on receipt and recorded so that an enquiry is never lost silently, even when a downstream delivery fails.

Access to the information described here is limited to the people who need it to do their jobs. The controls that protect the FactorFox platform itself, which are a different and larger subject, are described on our security and controls page.

10

Children

This website is for people acting on behalf of financial institutions. It is not directed at children, and we do not knowingly collect personal information from anyone under the age at which consent for information services applies in their country. If you believe a child has sent us information, tell us and we will delete it.

11

Changes to this policy

When this policy changes, the date at the top changes with it, and we will describe what changed rather than only saying that something did. Where a change materially affects how we use information already collected from you, we will tell you directly before it takes effect.

12

Contact us

Write to sales@factorfox.com with anything about this policy, including a request to exercise one of the rights above. Put the word privacy in the subject line so it reaches the right person quickly.

Our registered entity is FactorFox Software LLC. Our postal address, and the details of any representative appointed in the United Kingdom or the European Union, are published here on publication of the reviewed version of this policy.

If you are in the United Kingdom or the European Economic Area and you are not satisfied with how we have handled a request, you may complain to your national supervisory authority.

FactorFox Software LLC · Privacy policy · Last updated 27 August 2026 · Terms of use