Privacy Policy
Version 2026-09-13. This policy explains what FOCOTAI (the company operating this service) (“FOCOTAI”) collects when you use the FOCOTAI service, why, and the choices you have.
1. What we collect
- Account data: name, work email, role, second-factor enrolment status, sign-in times and IP addresses, and the version of the terms you accepted.
- Workspace data: your organisation’s name, timezone, business hours, thresholds, budgets, notification settings and the integrations you configure.
- Infrastructure data: cost, usage, inventory and tag data read from the cloud and on-premises accounts your organisation connects. Credentials for those accounts are stored encrypted and never shown back.
- Usage data: pages visited, actions taken in the app, and the audit log of changes made through the Service. We do not use third-party advertising or analytics trackers.
2. Why we process it
- To provide the Service: ingest data, produce recommendations, run approved automation and send the notifications you configure (performance of the contract).
- To secure the Service: sign-in protection, audit trails, anomaly detection on access (legitimate interest).
- To support you and improve the product using aggregated, non-identifying statistics (legitimate interest).
- To meet legal obligations, such as accounting and responding to lawful requests.
3. Where it lives and who sees it
Data is hosted on Amazon Web Services in the region stated in your order form (by default Asia Pacific, Mumbai). Sub-processors are listed in the Data Processing Addendum. Access inside FOCOTAI is limited to staff who need it to operate the Service and is logged. We do not sell personal data.
4. Emails
We send account emails (verification, password reset, invitations, approvals) that you cannot opt out of while you hold an account, and alert emails that you can turn off in Settings or with the link at the bottom of any alert.
5. Retention
Account and workspace data is kept while the workspace exists and for the grace period after a deletion request, then permanently deleted. Audit logs are retained for as long as the workspace exists. Backups are rotated within 35 days.
6. Your rights
Depending on where you are, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. Administrators can export the audit log and manage users from Settings; for anything else, contact us at the support address in the app footer. You may also complain to your local data-protection authority.
7. Cookies
The app uses one strictly necessary cookie to keep you signed in. No advertising or cross-site cookies are set.
8. Changes
We will announce material changes in the app before they take effect and update the version above.