Who we are
Foreground Digital and Trading FZE LLC (trading as “Foreground” / “Foreground Digital Marketing Agency”; “we”, “us”) is the data controller for personal data collected through foreground.agency. We are a Free Zone Limited Liability Company licensed by Ajman Nuventures Centre (ANC) Free Zone, Government of Ajman, United Arab Emirates, owned and managed by Khmer Lee Ponce Lugod and operating from Dubai.
- Legal name: Foreground Digital and Trading FZE LLC
- Trade name / brand: Foreground · Foreground Digital · Foreground Digital Marketing Agency
- Entity type: Free Zone Limited Liability Company (FZE LLC), Ajman Free Zone, UAE
- Owner / manager: Khmer Lee Ponce Lugod
- Registered address: 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates
- Operating from: Dubai, United Arab Emirates
- Primary contact: privacy@foreground.agency
- Wikidata identifier: Q139718510
What data we collect
We collect different categories of personal data depending on how you interact with our site:
When you browse foreground.agency
- Your IP address, user agent, browser language, referring URL, and timestamp (Apache/server logs).
- Cookies and similar technologies — only if you accept them via our cookie banner. See section 04.
When you submit the contact form
- Name, email, company name, message body, project scope you selected.
- IP and timestamp for anti-spam.
When you run any free tool
- Your IP address (for rate-limiting), user agent, and the inputs you submit (URL, keyword, etc.).
- For audits and tools that email a report: your email address.
- For the audit-share-to-unlock feature: an anonymous referral token stored in your browser's localStorage to measure organic share-driven traffic.
When you use the AI chat widget
- The conversation content (your messages and the bot's responses).
- An anonymous session identifier (
fg-chat-uid) so the conversation persists across page reloads within a session. - If you choose to share your email or phone during the chat, we capture those as a lead.
When you click a Foreground ad on Meta (Facebook/Instagram)
- The
fbclidclick identifier from the URL, stored in a first-party cookie for attribution purposes — only if you accept marketing cookies. - Pageview and conversion events (Meta Pixel + Conversions API), again only with marketing-cookie consent.
Legal basis for processing
Under GDPR Article 6, we rely on the following legal bases:
- Consent (Art. 6(1)(a)) — for analytics cookies, marketing cookies, Meta Pixel/CAPI events, and any optional newsletter/follow-up communications. You give consent via our cookie banner or by explicitly submitting an email to receive a tool report.
- Contract / pre-contract (Art. 6(1)(b)) — when you submit the contact form to discuss working with us, processing your inquiry data is necessary to respond.
- Legitimate interests (Art. 6(1)(f)) — for security logging (preventing abuse of free tools, fraud detection), basic server logs, and aggregate non-identifying usage statistics. Our legitimate interest is balanced against your privacy — you can object via the contact email.
- Legal obligation (Art. 6(1)(c)) — where applicable UAE tax law or anti-fraud requirements require retention.
For UAE residents, equivalent provisions under the PDPL apply (Articles 5-6).
Cookies & tracking technologies
We use cookies and similar technologies (localStorage, sessionStorage, pixels) to deliver the site, measure usage, and — only with your consent — run targeted advertising. Categories:
- Necessary — required for the site to function (cookie-consent storage, chat session ID, anti-CSRF tokens). Set without consent because the site cannot operate without them.
- Preferences — remember your settings (e.g., booking widget time format). Optional.
- Statistics — Google Analytics 4 (anonymised page views, source attribution). Only set after you accept the “Statistics” consent category.
- Marketing — Meta Pixel and related cookies (
_fbc,_fbp). Only set after you accept the “Marketing” consent category.
Our cookie banner is powered by Cookiebot (operated by Usercentrics A/S, Denmark) and implements Google’s Consent Mode v2. When you reject cookies, only necessary ones are set; marketing and statistics scripts are held inactive until you give consent.
You can withdraw consent at any time by clicking the cookie icon in the bottom-left of the page, or by clearing your cookies.
Cookies set by this site
Current cookies, classified by category. Updated as our stack changes:
| Name | Provider | Type | Expiry | Purpose |
|---|---|---|---|---|
| CookieConsent | foreground.agency | HTTP | 1 year | Stores your cookie consent state so we don't show the banner again. Set only when you've interacted with the banner. |
| __cf_bm | cal.com | HTTP | 1 day | Cloudflare bot management on the Cal.com booking embed. Distinguishes humans from bots; required for the booking widget to load. |
| __Secure-next-auth.callback-url | cal.com | HTTP | Session | NextAuth callback URL for the Cal.com booking embed authentication flow. Cleared when the browser closes. |
| __Secure-next-auth.csrf-token | cal.com | HTTP | Session | CSRF protection token for the Cal.com booking form. Prevents cross-site request forgery. No tracking. |
| Name | Provider | Type | Expiry | Purpose |
|---|---|---|---|---|
| fg-chat-uid | foreground.agency | HTML (localStorage) | Persistent | Anonymous identifier for the in-page chat widget so your conversation persists across page reloads in this browser. No PII, no cross-site tracking. |
| embed-theme-30min:foreground-agency:light | app.cal.com | HTML (localStorage) | Persistent | Remembers the visual theme (light/dark) for the Cal.com booking embed across sessions. No PII. |
| timeOption.is24hClock | app.cal.com | HTML (localStorage) | Persistent | Remembers whether you prefer 12-hour or 24-hour time format in the booking widget. No PII. |
| nextauth.message | app.cal.com | HTML (localStorage) | Persistent | Preserves authentication state for the Cal.com booking flow across page reloads. |
| Name | Provider | Type | Expiry | Purpose |
|---|---|---|---|---|
| _ga | foreground.agency | HTTP | 2 years | Google Analytics 4 client identifier. Anonymous; tracks aggregate usage and source attribution. Sent to Google in the United States. |
| _ga_# | foreground.agency | HTTP | 2 years | Google Analytics 4 per-property session identifier. Anonymous. Sent to Google in the United States. |
| Name | Provider | Type | Expiry | Purpose |
|---|---|---|---|---|
| _fbp | foreground.agency | HTTP | 3 months | Meta Pixel browser identifier. Used to attribute conversions to Meta ads. Sent to Meta Platforms in the United States. |
| _fbc | foreground.agency | HTTP | 2 years | Stores the Facebook click identifier (fbclid) from the URL when you arrive from a Meta ad. Required for iOS 17/18 attribution recovery. |
We review this list whenever our stack changes. If you spot a cookie not described here, email us — we’ll update this page within 14 days.
Free tools — per-tool data flows
Our free tools at /tools each handle data differently. The table below covers every active tool:
- Meta Pixel & CAPI Auditor — we fetch your submitted URL with a server-side HTTP client + a headless browser (AWS Lambda, EU region). We analyze the HTML and runtime network requests for Meta tracking patterns. We save your email + URL + audit score in our database for follow-up. The audit report is emailed to you. Headless browser identifies itself as
Foreground-CAPI-Auditor/1.0. - 2026 SEO Audit — crawls up to 50 pages of your site with our identified crawler, extracts metadata + technical SEO signals, emails you the report. Stored 30 days, then auto-deleted.
- Keyword Volume Checker — sends your query to DataForSEO (third-party SERP/keyword API, Cyprus-based). Results cached 7 days for cost efficiency.
- SERP Rank Checker — same DataForSEO pipeline. Your query + checked URL are logged for rate limiting; no PII unless you provide it.
- AI Brand Mention Checker — submits 8 questions to Anthropic Claude, OpenAI GPT, Google Gemini, and DeepSeek APIs about a brand you specify. The questions, brand name, and responses are stored to compute scores. The brand name you provide may be a real company name; we treat it as public business data, not personal data.
- llms.txt Generator, robots.txt Generator, UTM Builder, WhatsApp Link Generator — all client-side or stateless. We log only IP + user-agent + tool name for rate-limiting. No data leaves your browser unless you explicitly submit it.
Permissions you confirm when running a site-audit tool: by submitting a URL to any of our crawlers (CAPI Auditor, SEO Audit), you confirm that you either own the site or have permission to audit it, or that it is publicly accessible. We honour robots.txt and identify ourselves in every request.
Email & marketing communications
We send three categories of email:
- Transactional — audit reports you requested, contact-form replies, scheduled-call confirmations. Sent based on your explicit request; not optional and not used for marketing.
- Follow-up — if you ran an audit and scored below 75, we may send one follow-up email within 14 days offering our paid Pixel Fix service. You can opt out via the unsubscribe link in the email, or by replying “unsubscribe”.
- Newsletter (optional) — if you opt in, occasional updates about new tools or industry shifts. Unsubscribe in every email.
Email is sent via Google Workspace SMTP (info@foreground.agency).
Third parties & international data transfers
To run the site and its tools, we share specific data with the following processors. Some are located outside the UAE; international transfers are made under the appropriate safeguards (standard contractual clauses, adequacy decisions, or your consent).
Infrastructure
- Siteground (EU/US) — web hosting, server logs.
- Supabase (US) — database for lead capture, audit results, share telemetry, blog content.
- Amazon Web Services (Frankfurt, eu-central-1) — AWS Lambda runs the Meta CAPI Auditor's headless browser.
- Cloudflare — CDN, edge cache.
Analytics & advertising
- Google Analytics 4 (Google LLC, US) — statistics. Only if you consent.
- Google Tag Manager (Google LLC, US) — tag orchestration.
- Meta Pixel + Conversions API (Meta Platforms Inc., US) — conversion attribution for Meta ads. Only if you consent.
- Cookiebot / Usercentrics A/S (Denmark, EU) — consent management.
AI processing
- Anthropic PBC (US) — Claude API. Powers the chat widget and AI Brand Check.
- OpenAI (US) — AI Brand Check.
- Google Cloud AI (US) — Gemini API for AI Brand Check.
- DeepSeek (Hong Kong / China) — AI Brand Check.
These AI providers may process the content of your queries to generate responses. We do not share PII with them unless you include it in your input. They do not train on inputs unless their own published terms say otherwise; we do not opt our inputs into their training corpora.
Marketing data
- DataForSEO (Cyprus, EU) — keyword volume, SERP rank, search-related APIs.
- LinkedIn API (Microsoft Corp., US) — auto-share of new blog posts to our company page.
- Facebook Graph API (Meta Platforms, US) — auto-share of blog posts to our Facebook page.
- Telegram Bot API (Telegram FZ-LLC, UAE) — auto-share to our Telegram channel and approved groups.
Communication
- Google Workspace (Google LLC, US) — email hosting (info@foreground.agency) and SMTP delivery.
- Cal.com (Cal.com Inc., US) — meeting scheduling embed. Their own privacy policy applies when you book.
We do not sell personal data to any party. We do not engage in any “sale” or “sharing” of personal information for cross-context behavioural advertising as defined by the California Consumer Privacy Act.
Data retention
We retain personal data only as long as necessary for the purposes it was collected for, and consistent with applicable law. Approximate windows:
- Contact-form inquiries: kept in our email system for the duration of the project conversation, then archived.
- Audit results & lead records (CAPI Auditor, SEO Audit, etc.): up to 24 months, then anonymised or deleted, unless you become a paying client (in which case business-records retention may extend).
- Tool usage logs (IP + user-agent): 90 days for security/abuse prevention.
- Chat widget transcripts: 12 months, anonymised.
- Email subscribers: kept until you unsubscribe.
- Server access logs: rotated every 30 days by Siteground.
- Anonymous share telemetry (referral tokens): 12 months.
Your rights
Depending on where you live, you have some or all of the following rights:
- Access — request a copy of the personal data we hold on you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your personal data (subject to legal retention requirements).
- Restriction — ask us to limit processing in certain circumstances.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests, including direct marketing.
- Withdraw consent — if processing is based on consent, withdraw it at any time. This does not affect the legality of prior processing.
- Automated decision-making — we do not subject you to decisions based solely on automated processing.
To exercise any right, email info@foreground.agency with a short description of your request. We will respond within 30 days (sooner where law requires).
Right to lodge a complaint
If you believe we have violated your data protection rights, you can lodge a complaint with:
- UAE Data Office — the UAE federal data protection authority and the regulator of our registered entity — for UAE residents.
- National Privacy Commission (NPC) — the Philippine data protection authority (privacy.gov.ph) — for Philippine residents.
- The data protection authority of your EU member state — for EU residents (a full list is published by the European Data Protection Board).
- Information Commissioner’s Office (ICO) — for UK residents.
We’d appreciate the chance to address your concern first, but it is your right to go directly to the regulator.
Security
We use technical and organisational measures to protect your data: HTTPS everywhere, infrastructure with industry-standard access controls (Supabase, AWS), service-account credentials with least-privilege scopes, encryption-at-rest on our database provider, and SSRF protection on tools that fetch external URLs. We do not transmit personal data over unencrypted channels.
If a breach occurs that’s likely to result in risk to your rights and freedoms, we will notify affected users within 72 hours of becoming aware, and notify the relevant regulator where required.
Children
Foreground’s services are intended for business users (marketers, agencies, founders). We do not knowingly collect personal data from anyone under 16 years of age (or the equivalent local minimum where higher). If you believe we have data on a minor, contact us and we will delete it.
Changes to this policy
We update this policy when our processing meaningfully changes (new tools, new processors, new legal bases). The “Last updated” date at the top reflects the most recent revision. Where the change is material and we have your email, we will notify you directly. Otherwise, please re-check this page periodically.
Contact
For privacy questions, data requests, or anything else covered by this policy:
- Email: privacy@foreground.agency
- Registered postal address: Foreground Digital and Trading FZE LLC, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates.
- For Dubai correspondence: please email first.