Legal Document
Privacy Policy
This Privacy Policy describes how SAMSOFT AI TECHNOLOGIES PRIVATE LIMITED collects, uses, and protects your information when you use FinOpsAI — our multi-cloud cost intelligence platform (Google Cloud, AWS and Microsoft Azure).
DPDP Act 2023 notice
asia-south1
Key Summary: FinOpsAI is a B2B enterprise tool. We process your cloud billing exports (Google Cloud, AWS, Azure) solely to provide cost intelligence services. All billing data stays in asia-south1 (Mumbai) and is never used to train AI models. We never sell your data.
01Information We Collect
When you use FinOpsAI, we collect the following categories of information:
- Account Information: Email address, name, and authentication credentials via Google Firebase Authentication
- Cloud Access Grants: FinOpsAI stores no cloud account keys or secrets. You grant read-only access — an IAM grant to our reader service account on your Google Cloud billing-export dataset, a cross-account IAM role for your AWS export bucket, or a federated credential for your Azure export storage. We store the identifiers of those grants (project, dataset, role ARN, storage account), not credentials
- Billing Data: Google Cloud billing exports are queried in place in your BigQuery dataset. AWS and Azure cost exports are read from your export storage and loaded into FinOpsAI's own BigQuery tables in asia-south1 so they can be analysed; those rows are deleted with your workspace
- Usage Data: Agent analysis requests, action cards created, and Fix Now approvals — stored for audit trail
- Technical Data: IP address, browser type, and access logs for security monitoring
02How We Use Your Information
We use the information we collect exclusively to provide and improve the FinOpsAI service:
- Detecting cloud cost anomalies in your billing data using statistical analysis
- Running AI analysis via Google Vertex AI (Gemini 2.5 Flash, asia-south1) on anonymised cost summaries
- Generating remediation recommendations and action cards
- Keeping an audit log of the actions taken in your workspace (approvals, report issuance, downloads)
- Sending email notifications for anomaly alerts and Fix Now confirmations
- Improving our anomaly detection algorithms using aggregated, anonymised data
We never: sell your data, use your billing data to train AI models, share your data with third parties for marketing, or process your data outside India without explicit consent.
03Data Residency and Sovereignty
Sovereign-First Architecture: All customer data including cloud access grant identifiers, ingested billing rows, billing summaries, recommendations, issued reports and audit logs are stored exclusively in Google Cloud asia-south1 (Mumbai, India) in compliance with the Digital Personal Data Protection Act 2023.
- Firestore database: asia-south1 (Mumbai)
- Cloud Run API: asia-south1 (Mumbai)
- BigQuery queries: executed in your project's region
- AI inference: Google Vertex AI (Gemini 2.5 Flash) in asia-south1 (Mumbai) — prompts processed in-region, not stored
- Firebase Hosting: Global CDN for static assets only (no personal data)
04AI and Machine Learning
FinOpsAI uses the following AI services to provide cost intelligence:
- Gemini 2.5 Flash — Brain (Google Vertex AI): Analyses compressed, anonymised cost summaries in asia-south1 (Mumbai). Prompts are processed in-region and not stored. No training on your data.
- Gemini 2.5 Flash — Scout (Google Vertex AI): Filters anomaly noise before deeper analysis by the Brain. Stateless processing — no data retained.
- Human-in-the-Loop: No AI system executes remediation actions automatically. All Fix Now actions require explicit human approval.
05Data Security
We implement enterprise-grade security controls to protect your data:
- No customer cloud credentials are stored; access is by IAM grant and federated identity only
- All API secrets stored in GCP Secret Manager — never hardcoded
- Zero-Trust IAM — service accounts with minimal required permissions
- Firebase JWT authentication for all API endpoints
- HTTPS/TLS encryption for all data in transit
- GitHub Actions CI/CD with encrypted secrets
- Complete audit trail of all agent actions and human approvals
06Data Retention
- Billing history: 30 days (Starter), 90 days (Business) or 365 days (Enterprise), per your plan
- Action cards: Attested cards are kept 12 months; a card awaiting approval is kept until decided
- Audit log and issued reports: The audit log is kept for the life of your subscription. The stored PDF of an issued report is kept 12 months on Starter and Business and 7 years on Enterprise unless your contract sets a different period; the record that it was issued, with its SHA-256, is kept with the audit log
- After a subscription ends: All workspace data is kept for 30 days so you can reactivate or request an export, then permanently deleted
- Account data: Retained until account deletion request
- Cloud access grant identifiers: Deleted with your workspace at the end of the grace period; you remove the grants themselves from your cloud environment
07Your Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act 2023, you have the following rights:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Correction: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of your personal data
- Right to Grievance: File a complaint with our Data Protection Officer
- Right to Nominate: Nominate a person to exercise rights on your behalf
To exercise any of these rights, email us at privacy@samsofttechnologies.com
08Third-Party Services
FinOpsAI integrates with the following third-party services:
- Google Firebase: Authentication and Firestore database — Google Privacy Policy applies
- Google Cloud: Cloud Run, BigQuery, Secret Manager — Google Cloud DPA applies
- Google Cloud (Vertex AI): Gemini 2.5 Flash in asia-south1 — Google Cloud Data Processing Addendum applies
- Stripe: Payment processing — Stripe Privacy Policy applies
Google and Microsoft sign-in used to grant access ("Connect everything")
When you choose Connect everything with Google, you sign in with Google and FinOpsAI requests the https://www.googleapis.com/auth/cloud-platform scope. That access is used only in your browser, only after you review the changes, and only to add read-only IAM roles (Compute Viewer, Monitoring Viewer, Kubernetes Engine Cluster Viewer, Recommender Viewer, and BigQuery Data Viewer on your billing-export dataset) for the FinOpsAI service account dedicated to your workspace, and, if you tick it, to switch on an API you choose. It is never sent to or stored on FinOpsAI servers, never used to read your data, and it is revoked when the step ends. FinOpsAI receives only the result of each change, for your audit log.
When you choose Connect everything with Microsoft, you sign in with Microsoft and FinOpsAI requests the Azure Service Management user_impersonation permission. FinOpsAI uses that sign-in once, server-side, only to add read-only role assignments (Reader, Cost Management Reader and, if you tick it, Reservations Reader) for the FinOpsAI application in your directory, then discards it. It is never stored.
FinOpsAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. No data obtained through these sign-ins is used for advertising, sold, or used to train AI models.
09Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email at least 30 days before the changes take effect. Continued use of FinOpsAI after the effective date constitutes acceptance of the updated policy.