CloudKnots Privacy Policy | How We Protect Your Data

Privacy Policy

Your privacy is important to us. This policy explains how CloudKnots collects, uses, and protects your information.

Last Updated: December 2024

1. Information We Collect

Personal Information

  • Name, email address, and contact information
  • Account credentials and authentication data
  • Billing and payment information
  • Company information and job title

Usage Information

  • How you use our service and interact with features
  • Log data including IP addresses, browser type, and device information
  • Performance metrics and analytics data
  • Cookies and similar tracking technologies

2. How We Use Your Information

Service Delivery

  • Provide and maintain our SaaS platform
  • Process transactions and billing
  • Provide customer support
  • Send service-related communications

Improvement & Analytics

  • Analyze usage patterns and performance
  • Improve our services and features
  • Conduct research and development
  • Ensure security and prevent fraud

3. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties.

We may share information in these limited circumstances:

  • Service Providers: Trusted third-party vendors who help us operate our service
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • With Your Consent: When you explicitly authorize us to share information

4. Data Security

We implement industry-standard security measures to protect your information:

Encryption

Data encrypted in transit and at rest

Secure Infrastructure

SOC 2 compliant hosting environment

Access Controls

Limited employee access on need-to-know basis

Monitoring

Continuous security monitoring and auditing

5. Your Rights and Choices

Access

Request access to your personal information

Correction

Update or correct inaccurate information

Deletion

Request deletion of your personal data

Portability

Export your data in a portable format

Opt-out

Unsubscribe from marketing communications

Restriction

Limit how we process your information

6. Cookies and Tracking

We use cookies and similar technologies to enhance your experience:

Essential Cookies: Required for basic site functionality
Analytics Cookies: Help us understand how you use our service
Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings.

7. Data Retention

We retain your information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Improve our services

Account Data: Retained while your account is active and for 90 days after deletion
Usage Data: Typically retained for 2 years for analytics purposes

8. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including:

Standard Contractual Clauses
Adequacy Decisions
Privacy Shield Frameworks
Data Processing Agreements

9. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Post the updated policy on this page
  • Update the "Last Updated" date
  • Notify you via email for material changes
  • Provide notice within our service

Your continued use of our service after changes become effective constitutes acceptance of the updated policy.

11. How Theama Protects Each Customer's Data When Using AI

Theama is a multi-tenant platform — many businesses use it at once. Keeping every customer's financial, sales, and customer data strictly inside their own environment is a first-class design goal. Our guiding principle: we never rely on the AI to police its own boundaries. Isolation is enforced by the architecture around it.

1. Your identity is proven on every request

Access is controlled by a cryptographically signed security token issued at login and verified on our servers for every single request. Your data boundary is derived from that verified token — it can never be spoofed or overridden by anything sent from a browser or app. Sessions run over encrypted (TLS) connections and can be revoked across all your devices instantly.

2. Your data is only ever queried within your own account

Every dashboard metric, integration credential, and AI conversation is stored and retrieved scoped strictly to your account and team. One customer's request can never reach another customer's data, and we do not pool different customers' data into any shared store or search index.

3. The AI only ever sees a minimal, aggregated snapshot

When you ask the AI advisor a question, it receives only high-level summary figures (e.g. "YTD revenue", "security score") plus your question — assembled on our servers from your account only, never taken from anything the browser or app sends. It never receives raw customer lists, invoices, contact details, or account numbers, and it has no access to our database and no ability to run queries or tools. It can only reason over the small summary handed to it — so it is architecturally incapable of "dumping" data or reaching another customer's information.

4. Deterministic guardrails around every AI request

  • Every question is screened — attempts to extract system instructions, raw records, or another customer's data are blocked before they reach the model.
  • Every response is redacted — an automatic filter strips emails, card/account numbers, and similar identifiers from replies, while leaving ordinary business figures intact.
  • Every AI request is logged — owners can review a full, timestamped audit log of their team's AI activity inside the app.

5. Your data is not used to train models

Summary metrics are sent to our AI model provider solely to generate your insight, under contractual confidentiality and no-training / no-retention terms. Our staff do not read your AI conversations except with your consent, for security, or to comply with law.

6. What we don't do

We do not sell your data, pool tenants' data into a shared index or model, or let the AI read your raw records or reach another tenant's data.

Contact Us About Privacy

If you have questions about this Privacy Policy or our data practices, please contact us:

privacy@cloudknots.com
+44 (020) 45690180
167-169, Great Portland Street, 5th Floor, London W1W 5PF

Data Protection Officer

For GDPR-related inquiries, you can contact our Data Protection Officer directly.

dpo@cloudknots.com