Compliance
Version 1.1 - Last updated July 31, 2026
This page summarizes how fylt aligns with major privacy, security, payments, and accessibility expectations for global service businesses. For the full legal text, see our Terms of Service, Privacy Policy, and Data Security pages.
This page summarizes how fylt aligns with major compliance requirements: GDPR and UK GDPR data-subject rights, CCPA/CPRA opt-out and deletion rights for California residents, PCI DSS scope handled through Razorpay, SOC 2 Trust Services Criteria alignment, WCAG 2.1 AA accessibility, and cookie-consent management, with the full legal text in the linked Terms and Privacy pages.
GDPR & UK GDPR
fylt processes personal data under documented legal bases, supports data-subject requests, and uses Standard Contractual Clauses or an equivalent lawful mechanism for applicable international transfers. Data Processing Agreements are available on request.
CCPA / CPRA
California residents can exercise applicable rights to know, delete, and opt out of sale or sharing of personal information. fylt does not sell personal data as defined by the CCPA.
PCI DSS scope
fylt subscription fees are collected by Razorpay. fylt Billing invoices and the Workspace client portal never collect payment on a business's behalf — they record payments the business receives directly and show clients how to pay. Optional paid booking on Calendar can be processed by Razorpay or PayPal. In every case where a card or PayPal checkout is used, the payment gateway's hosted checkout collects the details; fylt never stores full payment card numbers.
SOC 2 Trust Criteria Alignment
Our security program is aligned with the SOC 2 Trust Services Criteria for Security, Availability, and Confidentiality. A formal third-party audit is in progress, and fylt is not yet SOC 2 certified.
Accessibility
We build toward WCAG 2.1 AA with keyboard navigability, visible focus states, labeled form fields, and accessible color contrast across core product surfaces.
Cookie & consent management
Visitors can manage functional, analytics, and marketing cookies through the Privacy choices badge on every page. Essential cookies support a secure, functional service experience.
Data Processing Agreement
Business customers may request a Data Processing Agreement (DPA) covering the processing of personal data on their behalf by emailing legal@fylt.app.
Frequently Asked Questions
fylt's privacy practices are designed to support GDPR and applicable data-protection requirements: documented legal bases, data-subject requests, and Standard Contractual Clauses (or an equivalent lawful mechanism) for applicable international transfers.
Yes. California residents can exercise their rights to know, delete, and opt out of the sale or sharing of personal information, and fylt does not sell personal data as defined by the CCPA.
fylt subscription fees are collected by Razorpay. fylt Billing invoices and the Workspace client portal never collect payment on a business's behalf — they record payments the business receives directly and show clients how to pay. Optional paid booking on Calendar can be processed by Razorpay or PayPal. In every case where a card or PayPal checkout is used, the payment gateway's hosted checkout collects the details; fylt never stores full payment card numbers.
Yes. Business customers can request a DPA covering fylt's processing of personal data on their behalf by emailing legal@fylt.app.
fylt is built toward WCAG 2.1 AA, including keyboard navigability, visible focus states, labeled form fields, and accessible color contrast.