Your privacy is important to us. This policy explains how CloudKnots collects, uses, and protects your information.
Last Updated: December 2024
We do not sell, trade, or rent your personal information to third parties.
We implement industry-standard security measures to protect your information:
Data encrypted in transit and at rest
SOC 2 compliant hosting environment
Limited employee access on need-to-know basis
Continuous security monitoring and auditing
Request access to your personal information
Update or correct inaccurate information
Request deletion of your personal data
Export your data in a portable format
Unsubscribe from marketing communications
Limit how we process your information
We use cookies and similar technologies to enhance your experience:
You can control cookies through your browser settings.
We retain your information for as long as necessary to:
Account Data: Retained while your account is
active and for 90 days after deletion
Usage Data: Typically retained for 2 years for
analytics purposes
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including:
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
We may update this Privacy Policy from time to time. When we do, we will:
Your continued use of our service after changes become effective constitutes acceptance of the updated policy.
Theama is a multi-tenant platform — many businesses use it at once. Keeping every customer's financial, sales, and customer data strictly inside their own environment is a first-class design goal. Our guiding principle: we never rely on the AI to police its own boundaries. Isolation is enforced by the architecture around it.
Access is controlled by a cryptographically signed security token issued at login and verified on our servers for every single request. Your data boundary is derived from that verified token — it can never be spoofed or overridden by anything sent from a browser or app. Sessions run over encrypted (TLS) connections and can be revoked across all your devices instantly.
Every dashboard metric, integration credential, and AI conversation is stored and retrieved scoped strictly to your account and team. One customer's request can never reach another customer's data, and we do not pool different customers' data into any shared store or search index.
When you ask the AI advisor a question, it receives only high-level summary figures (e.g. "YTD revenue", "security score") plus your question — assembled on our servers from your account only, never taken from anything the browser or app sends. It never receives raw customer lists, invoices, contact details, or account numbers, and it has no access to our database and no ability to run queries or tools. It can only reason over the small summary handed to it — so it is architecturally incapable of "dumping" data or reaching another customer's information.
Summary metrics are sent to our AI model provider solely to generate your insight, under contractual confidentiality and no-training / no-retention terms. Our staff do not read your AI conversations except with your consent, for security, or to comply with law.
We do not sell your data, pool tenants' data into a shared index or model, or let the AI read your raw records or reach another tenant's data.
If you have questions about this Privacy Policy or our data practices, please contact us:
For GDPR-related inquiries, you can contact our Data Protection Officer directly.
dpo@cloudknots.com