Privacy policy.
Floburn Inc operates floburn.com. This page describes what we collect, why, where it goes, and how long we keep it. Plain English, no dark patterns.
Last updated — September 2, 2026
Three things, and only when you give them to us.
Inquiries you submit. When you use the contact form, we collect the name, email address, optional company name, and message you provide. We use that information to reply to you and, where appropriate, to continue a sales or engagement conversation.
Standard server logs. Our web server records routine technical information about each request — IP address, user-agent string, requested URL, timestamp, and HTTP status. This is used for security, abuse prevention, and operational diagnostics. Logs are not joined to inquiry data or used for advertising.
Notes on private engagement pages. Clients and counsel we work with can leave signed notes on the access-controlled pages we share with them. We record the name entered, the date and time, and the text of the note; each note is delivered to our internal Slack so we can follow up. Those pages are not part of the public site, and nothing there is collected from ordinary visitors.
What we don’t collect. No analytics. No cookies. No tracking pixels. No third-party advertising scripts. No session recording. No fingerprinting. The public site sets no cookies of its own. We do not use Google Analytics, Meta Pixel, or any equivalent tool.
Two carve-outs, and neither is about you. When Floburn personnel sign in to the site’s private administrative area, that sign-in sets a single authentication cookie so they stay signed in. And when a client or counsel we work with opens a private page with the passkey we sent them, that unlock sets a single cookie scoped to that page so they are not asked for the passkey again for a week. Both do nothing on any public page, and neither tracks anyone.
A short, specific list.
Inquiry submissions are delivered to our internal Slack workspace so the team sees them in real time, and to our Google Workspace email account so they can be replied to. Once an inquiry becomes an active conversation, the relevant details are entered into Agent Floburn, our internal application for keeping track of inquiries and client relationships. Agent Floburn is operated by Floburn Inc; it is not a third-party service.
If you book a consultation through the scheduler on our contact page, the booking form is provided by Cal.com, Inc. The name, email address, and booking details you enter there are collected on Cal.com’s infrastructure under its own published privacy practices, and the resulting booking is delivered to us. The scheduler runs in an embedded frame and may set cookies of its own; the “no cookies” statement above describes floburn.com’s own pages, not the embedded scheduler.
We do not sell, rent, or share inquiry data with advertisers, data brokers, or marketing partners. We do not share it with other clients. We use it to talk to you, and to remember the conversation.
The vendors we rely on to receive and route this information — Slack Technologies (Salesforce), Google Workspace, and Cal.com for scheduling — each maintain their own published privacy practices and security commitments under their standard business terms.
What AI touches, and what it never touches.
On this website, nothing. Nothing you submit here — a contact-form inquiry, a note on a private engagement page, a booking — is read, sorted, or answered by an AI model. People read it.
In the MicroForensics service, the record is not AI. The software that collects, stores and seals a client’s payroll and timekeeping records is ordinary deterministic code. No AI model sits in that path: none decides what a record says, none decides whether a rule was broken, and none changes anything in the record.
Where we do use it. At the edges of the service: to draft plain-language text for a person to edit, to translate worker-facing text for a person to check, and to sort exceptions for a person to review. Every such call is logged with what went in and what came out, and only the content the task needs is sent. The providers are commercial AI services engaged under business terms; they process that content on our instructions, and we do not permit them to train on it. We use no client data to train anything ourselves.
A client’s choices. A client can ask for any AI-drafted text to be reviewed by a person, or ask that no AI model be used on its engagement at all. Both are written into our engagement paper, and where a client’s contract sets an option, that contract governs.
Two years, then deleted.
Inquiry records are retained for two years from the date of last contact, after which they are deleted from our internal systems. If a conversation becomes an active engagement, the retention clock resets to the date the engagement ends; we keep records of completed engagements for the period required by our contract, our tax and accounting obligations, and any applicable legal or regulatory hold.
Notes left on private engagement pages follow the engagement rather than the inquiry clock: they are kept while the engagement’s records are kept, and deleted with them. A commenter can ask us to delete a note at any time.
Server logs are retained for a short operational window (typically 30 to 90 days) and then rotated.
You can ask us to stop, see, or delete.
You can ask us, at any time, to tell you what we have on file about you, correct anything that is wrong, or delete it. Email hello@floburn.com and we will respond within thirty days. We will not retaliate for any privacy request and we do not require an account or payment to make one.
If you are a California resident, you have the rights described in the California Consumer Privacy Act, as amended by the California Privacy Rights Act — including the right to know, to delete, to correct, and to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, so there is no opt-out signal to honor; we honor Global Privacy Control headers as a confirmation of that posture.
If you are in the European Economic Area or the United Kingdom, you have the rights described in the General Data Protection Regulation and the UK GDPR, including access, rectification, erasure, restriction, portability, and objection. Our lawful basis for processing inquiry data is the legitimate interest of responding to a business inquiry you initiated, and your consent where consent applies.
What we do, what we don’t pretend to.
Floburn.com is served over HTTPS. Inquiry submissions are transmitted over TLS to Slack and Google Workspace, both of which encrypt data in transit and at rest under their standard terms. Access to internal systems is limited to Floburn personnel with a business need.
No system is perfectly secure. We will notify affected individuals and the appropriate authorities of a confirmed personal-data breach in accordance with applicable law.
This is a business site.
Floburn provides services to businesses. We do not knowingly collect personal information from anyone under sixteen. If you believe a minor has submitted information through floburn.com, email hello@floburn.com and we will delete it.
We’ll date them.
If we update this policy, we will change the “Last updated” date at the top and, for material changes, post a notice on the homepage for a reasonable period. Continued use of the site after a change indicates acceptance of the updated policy.
One inbox handles all of it.
Questions, requests, or complaints about this policy or our handling of your information:
Floburn Inc
hello@floburn.com
If you are not satisfied with our response, EEA and UK residents may lodge a complaint with their local data protection authority; California residents may contact the California Privacy Protection Agency.