Draft. This text has been prepared by the founders and is pending review by counsel. Until it is marked in force, the commercial terms agreed in writing with each design partner take precedence over anything here.

Data Processing Addendum

Version 2026-09-13. This addendum forms part of the Terms of Service between the Customer (controller) and FOCOTAI (the company operating this service) (processor) where the Service processes personal data on the Customer’s behalf.

1. Subject matter and duration

Processing of personal data contained in the account, workspace and infrastructure data described in the Privacy Policy, for the duration of the Terms and the deletion grace period.

2. Nature and purpose

Ingestion, storage, analysis and display of cloud cost and usage data; user administration; notifications; audit logging; automated actions approved by the Customer.

3. Categories of data subjects and data

Customer staff using the Service (identifiers, contact details, access logs) and, incidentally, personal data present in resource names or tags the Customer chooses to record in its cloud accounts.

4. Processor obligations

  • Process personal data only on the Customer’s documented instructions, which include the Terms and the configuration the Customer sets in the Service.
  • Ensure staff with access are bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the Customer with data-subject requests and security assessments, and notify the Customer without undue delay after becoming aware of a personal-data breach.
  • Delete or return personal data at the end of the Service, subject to legal retention duties.
  • Make available the information necessary to demonstrate compliance and allow audits on reasonable notice.

5. Sub-processors

The Customer authorises the following sub-processors; changes are announced in the app at least 30 days in advance and the Customer may object on reasonable grounds.

  • Amazon Web Services (hosting, email delivery) — region per order form, default Asia Pacific (Mumbai).
  • Timescale, Inc. (managed PostgreSQL database) — same region.
  • GitHub, Inc. (source code and deployment pipeline; no customer data).

6. Security measures

  • Tenant isolation enforced in the database (row-level security) and in every query.
  • Customer cloud credentials encrypted at rest with a platform key that is rotated; secrets never returned by the API.
  • TLS for every connection; second-factor authentication for administrators; sign-in lockout; session cookies that scripts cannot read.
  • Append-only audit log of every change; daily backups with point-in-time recovery; documented incident and restore runbooks.
  • Least-privilege access to the Customer’s accounts through roles the Customer creates and can revoke.

7. International transfers

Data stays in the hosting region unless the Customer instructs otherwise. Where a transfer outside that region is required, the parties rely on standard contractual clauses or an equivalent lawful mechanism.

8. Requesting a signed copy

A signed copy of this addendum, or the Customer’s own template, can be requested at meharabbas@focotai.com.

Questions about these documents: meharabbas@focotai.com.