Legal
FOSYNC LTD.
Last updated: 16 September 2026
This policy explains how FOSYNC LTD. ("Fosync", "we", "us", "our") collects, uses, shares, and protects personal information. It covers this website, our free website audit tool, our marketing communications, and the services we provide to our clients.
FOSYNC LTD. is an Ontario business corporation operating as a digital agency in Toronto, Canada.
Privacy matters are handled directly by our directors, Onur Bilgin (CEO) and Fatih Erkaner (CTO). Either can be reached at hello@fosync.com, and one of them is accountable for the decisions described in this policy.
Two different roles. For information we collect about visitors, prospects, and our own clients, we are the organisation responsible for it. For personal information we handle on behalf of a client while delivering services — enquiries submitted through a website we built for them, or an audience list in an advertising account we manage — we act on that client's instructions, that client's own privacy policy governs, and requests about that data should go to them. We assist our clients in responding.
Fosync provides services to businesses. Our website and services are intended for business owners and professionals who are at least the age of majority in their jurisdiction. We do not direct anything here at children and do not knowingly collect information from anyone under 18. If you believe a minor has given us information, email hello@fosync.com and we will delete it.
When you browse this website. Pages viewed, time on page, referring URL, approximate location derived from your IP address, device and browser type, and similar analytics data. This is collected only where you have accepted the relevant cookie categories.
When you request a free website audit. The website address you submit, your name, your email address, and optionally your phone number. The tool also retrieves publicly available technical information about the website address you give us — page speed, mobile rendering, structured data, and public search and business-listing signals.
When you contact us or book a call. Your name, email, phone, company, and whatever you choose to tell us about your business and your goals, together with scheduling information if you book through our calendar.
When you become a client. Business and billing details, tax identifiers, the contents of offers and agreements, project communications, brand assets and content you supply, and any credentials or delegated access you grant us to accounts you ask us to work on — domain registrars, hosting, Google Business Profile, advertising accounts, social accounts, and analytics.
We do not store payment card details. Payments are processed by Stripe through a payment link issued for your purchase; Stripe handles your card data under its own terms and we receive only the transaction record.
When we contact businesses about our services. We maintain a prospect database built from publicly available business listings and directories: business names, business addresses, business phone numbers, published business email addresses, website URLs, and industry categories. Under Canadian federal privacy law, business contact information collected and used solely to communicate with an individual in relation to their business or profession sits outside the general consent requirements. Under Canada's Anti-Spam Legislation, we rely on express consent where we have it, and otherwise on implied consent where a business address has been conspicuously published without any statement refusing commercial messages and our message is relevant to that person's business role. You can opt out at any time using the link in any message or by emailing hello@fosync.com, and we will stop.
When you apply for a role. Your application, CV, and anything you include with it. Retained for 12 months unless you ask us to delete it sooner.
We do not intentionally collect sensitive categories of personal information through this website — health data, racial or ethnic origin, religious beliefs, biometric identifiers, precise geolocation, or financial account numbers. Please do not send them to us through our forms.
| Purpose | Information used |
|---|---|
| Producing and sending your audit report | Website URL, name, email, technical scan results |
| Responding to enquiries and preparing offers | Contact and business details |
| Delivering, supporting, and invoicing for services | Client and project data |
| Working on accounts you have asked us to manage | Delegated access credentials |
| Improving the website and understanding what content works | Analytics data |
| Sending marketing emails you have consented to | Contact details, engagement data |
| Meeting tax, accounting, and legal obligations | Billing and transaction records |
| Protecting the site and our clients from abuse and fraud | Log data, IP addresses |
We do not sell personal information for money. We do use analytics and advertising tools that may share identifiers with third parties for measurement and targeted advertising. Under some United States state privacy laws this is treated as a "sale" or "sharing". Section 9 explains how to opt out.
A cookie is a small text file a website stores on your device. We also use related technologies that do similar jobs — pixels, local storage, and tags inside embedded tools. We refer to all of them as cookies here.
Strictly necessary cookies keep the site working: your session, your cookie preferences, form security, and load balancing. These cannot be switched off.
Analytics cookies tell us, in aggregate, how visitors find and use the site.
Functional cookies remember preferences and enable embedded features such as the booking calendar.
Advertising cookies measure campaign performance, attribute conversions, and support audience building on platforms such as Google and Meta.
Your choices. Everything except strictly necessary cookies stays off until you turn it on. A consent banner appears on your first visit, and you can change your choices at any time using the Cookie settings link in our footer. Withdrawing consent is as easy as giving it. We also honour the Global Privacy Control signal: if your browser or extension sends GPC, we treat it as an opt-out of targeted advertising and of any sale or sharing of personal information, with no further action needed from you. Your browser's own privacy settings can block or delete cookies as well, though blocking strictly necessary cookies will break parts of the site.
A current list of the specific cookies in use is available on request at hello@fosync.com.
Cookies on client websites. Where we build or manage a website for a client, cookies on that site are governed by that client's own policy, not this one.
We share personal information with service providers who process it on our instructions, under contract, and only for the purposes we specify:
| Provider | Purpose |
|---|---|
| DigitalOcean | Server hosting and application infrastructure |
| Cloudflare | DNS, content delivery, and security |
| Supabase | Database and application backend |
| Brevo | Transactional and marketing email delivery |
| Stripe | Payment processing and refunds |
| Google (Workspace, Analytics, Ads) | Business email and file storage, website analytics, advertising measurement |
| Meta (Facebook, Instagram) | Advertising measurement and delivery |
We also disclose information where the law requires it, to enforce our agreements, to protect people's safety or our rights, and — if the business is ever sold or reorganised — to the acquiring party, subject to equivalent protection.
A current list of our service providers is available on request.
We are based in Canada. Several of our providers store or process information in the United States and in other countries. Information held outside Canada may be accessible to the courts and law enforcement of the country where it is held. We use contractual protections, including standard contractual clauses where appropriate, and we choose providers with recognised security practices. If you would prefer your information stayed in Canada, contact us before sending it and we will tell you honestly whether that is possible for the service you want.
| Data | Retention |
|---|---|
| Audit requests that do not become enquiries | 12 months |
| Enquiries that do not become clients | 24 months |
| Client project records and communications | Duration of the engagement plus 7 years |
| Invoices, transaction records, and financial records | 6 years, as Canadian tax law requires |
| Marketing list membership | Until you unsubscribe, plus a suppression record kept indefinitely so that we do not email you again |
| Website analytics | 26 months |
| Job applications | 12 months |
| Server and security logs | 12 months |
Credentials and delegated access are revoked when an engagement ends. Ask us and we will confirm in writing when that has been done.
Everyone. You can ask what we hold about you, ask for a copy, ask us to correct it, ask us to delete it, withdraw consent, and unsubscribe from marketing at any time. Withdrawing consent is subject to legal and contractual limits, and we will tell you what withdrawing would mean before we act on it.
Residents of Quebec. Quebec's Law 25 additionally gives you the right to receive computerised personal information you provided in a structured, commonly used technical format, to request de-indexing in defined circumstances, and to be informed about automated decision-making.
Residents of United States states with comprehensive privacy laws. Twenty states now have them, including California, Colorado, Connecticut, Virginia, Texas, and Oregon. Where those laws apply to us, you may request access, correction, deletion, and portability; opt out of targeted advertising, profiling with significant effects, and the sale or sharing of personal information; and you will not be treated worse for exercising those rights. Several states give you a right to appeal a refusal — if we decline a request our response will tell you how to appeal, and if the appeal fails you may complain to your state Attorney General.
Residents of the UK and EU. Where the UK or EU GDPR applies to a particular engagement, you have the rights set out in those regulations, including access, rectification, erasure, restriction, portability, and objection.
Opting out of targeted advertising. Use the Cookie settings link in our footer, or send a Global Privacy Control signal from your browser. We honour GPC as a valid opt-out request.
How to make a request. Email hello@fosync.com telling us what you want. We will acknowledge promptly and respond within 30 days, extending only where the law permits and telling you if we do. We may need to verify your identity first and will ask for the minimum necessary to do so. An authorised agent may act for you with written proof.
In Canada we rely on your consent — express or implied depending on the sensitivity of the information and the reasonable expectations of the situation — and on the business contact information provisions where they apply. Where the UK or EU GDPR applies, we rely on performance of a contract, our legitimate interests in operating and promoting the business, your consent for marketing and non-essential cookies, and legal obligation for records we are required to keep.
We send marketing email only to people who have given express consent, or where Canadian law permits us to rely on implied consent as described in Section 3. Every message identifies us, carries our full mailing address, and includes a working unsubscribe link. Unsubscribe requests are honoured within 10 business days and in practice much faster. We keep records of when and how consent was given.
Service and transactional messages — project updates, invoices, security notices — continue regardless of marketing preferences, because you need them.
We send text messages or make marketing calls only where you have given consent specifically for that, separate from any email consent.
We use AI tools in producing content, drafting copy, and generating website audit reports. A person at Fosync reviews output before it reaches a client or a published page.
We do not make decisions producing legal or similarly significant effects about individuals based solely on automated processing. Audit scores and recommendations are automated estimates about a website, not assessments of a person, and they are not guarantees of any result.
We do not use your personal information to train third-party AI models, and we configure our tooling to opt out of provider training where that option is offered.
We use HTTPS across our sites, access controls on a least-privilege basis, two-factor authentication on administrative accounts, a password manager for credentials held on behalf of clients, encrypted backups, and regular patching. No system is perfectly secure and we do not claim otherwise.
If a breach creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as the law requires, and we will notify affected clients and any applicable state regulators. We maintain a record of breaches whether or not they meet the reporting threshold.
This website links to third-party platforms and to client websites. Their privacy practices are their own and this policy does not cover them. Reading their policies is worth the two minutes.
We update this policy as our practices change, and the "Last updated" date at the top tells you when. Where a change materially affects how we use information you have already given us, we will give you notice by email or through a prominent notice on this site before it takes effect. Superseded versions are available on request.
Contact us first at hello@fosync.com — most questions are resolved faster that way. If you are not satisfied with our response:
Share a few details, we’ll send a fixed quote in 24 hours.
🔒 100% free proposal. Zero sales pressure.
By submitting, you agree to our Terms of Service and Privacy Policy, and consent to receive project updates and proposal communications via email or text/WhatsApp.
We are reviewing your details now. Want to skip the 24-hour wait and discuss your project live with our team?
We’re reviewing your website, mobile speed, and AI visibility now. Your free PDF audit lands in your inbox shortly.
Auditing: —
By providing us with your information you are consenting to the collection and use of your information in accordance with our Terms of Service and Privacy Policy.