FAC Cloud - Privacy Policy
Effective Date: September 15, 2026, Version: 1.0
1. Who we are and what this policy covers
This Privacy Policy explains how Promantia Business Solutions Pvt. Ltd (CIN: U72900KA2017PTC108567), with its registered office at No 103, Maria Regency Manor, Madras Sappers Officers Colony, Banaswadi Mn Rd , Bangalore, Karnataka, India - 560033 ("FAC Cloud", "we", "us", "our") collects, uses, shares and protects personal data when you interact with the FAC Cloud cloud service, our supported web client (including our open-source FAC Chat client), our mobile client, our administrator console, our developer interfaces and SDKs, and our websites and documentation (together, the "Service").
FAC Cloud is a business-to-business platform. In most cases we act as a processor (or, under DPDPA, a Data Processor) of personal data that our Customers route through the Service. Our Customers — the organisations that subscribe to FAC Cloud — are the controller (or Data Fiduciary) of personal data about their employees, contractors, customers and other individuals processed through their tenant. The relationship between us and our Customers in respect of that data is governed by our Data Processing Agreement ("DPA").
We also act as a controller in our own right for limited categories of data — for example, billing contacts, registration details, our own service telemetry, website visitors and people who contact us. This policy applies to that controller-level processing.
FAC Cloud is intended for business and professional use only. It is not directed at, and not designed for, individuals under the age of 18.
2. Personal data we collect
1. Registration and account data (controller)
- Tenant identity: Tenant ID, site URL of your Frappe / ERPNext deployment, application endpoint, the host name the tenant is bound to.
- Authentication credentials: Tenant Secret (HMAC), OAuth access tokens, refresh tokens and OAuth client secrets used to authorise our calls back into your Frappe instance. These are stored encrypted at rest.
- Owner / billing contact: name, email, country, locale, time zone, optional phone (required by Razorpay for eMandate enrolment), preferred billing currency.
- Acceptance metadata: the version of the Terms, Privacy Policy and DPA you accepted, the date and time, the IP address, user-agent and Accept-Language header of the accepting browser, and an email-verification timestamp.
2. End-User profile data (processor on behalf of Customer)
- Per-user identifier, display name, email, role, locale, time zone.
- Per-user custom instructions, memory-consent flag, processing-restricted flag, monthly credit limit, credits consumed.
3. Conversation and message content (processor)
- Conversation metadata: conversation ID, title, creation and last-message timestamps, soft-delete flag, serialised AI agent session.
- Message content: role (user / assistant / tool), text body, attachments (file references), in-product page-context snapshots passed by the client, tool-call payloads (sanitised), and per-message token counts, model identifier and credit cost.
4. AI memory and knowledge content (processor; where the optional memory and knowledge features are enabled)
- Personal memories: short facts, preferences and summaries extracted from conversations (with End-User consent), together with a confidence score,
source-conversation reference and the End-User who owns them. Vector embeddings of these memories are stored in our vector index, logically scoped to your tenant.
- Team instructions: a per-tenant shared instruction block created by your administrators (no vector indexing; injected in full into the context up to a configured token cap).
- Uploaded documents and chunks: the file you upload, the extracted text broken into chunks, vector embeddings of each chunk, file metadata (name, size, MIME type, document type), the uploading End-User, and a visibility setting (private / shared / public-within-tenant).
5. Workflow content (processor; where the optional automation features are enabled)
- Workflow definitions (node and edge graphs), schedule (cron expression, time zone), default model.
- Workflow run records: trigger type, who triggered it, inputs, outputs, total tokens and credits consumed, per-node logs (input, output, tool-call JSON, model used, error traceback).
6. Marketplace content (processor)
- The prompt packs, workflow templates and skills you install or publish; visibility and install-state flags; aggregate ratings and import counts.
7. Billing data (controller for invoices and tax records; processor for payment metadata)
- Subscription state: plan, status, billing email, billing phone, billing country, currency, monthly credit quota and consumption.
- Payment method *references* — opaque tokens returned by Stripe or Razorpay. We do not store full card numbers, CVV, bank account numbers or UPI IDs.
- Invoices: amounts, tax breakdown, period covered, external invoice IDs, links to an ERPNext Sales Invoice where used for Indian GST reporting.
- Webhook payloads received from Stripe and Razorpay, stored in raw form for reconciliation, dispute defence and audit.
- Credit ledger entries (purchases, consumption, expiry, refunds) and dunning state.
- Partner / reseller records, where applicable: name, bank details, PAN (India), TDS configuration, commission accruals and payout orders.
8. Telemetry, security and audit logs (controller)
- API request logs: timestamp, endpoint, status code, latency, HMAC signature and timestamp, the originating IP address, user agent.
- Streaming-event records (short-lived) and rate-limiting counters.
- HITL approval log: which tool was proposed, the decision (approved / denied / timeout), the trust level granted, the End-User who decided, the sanitised arguments.
- Audit log: append-only record of GDPR / DPDPA rights actions (export, erasure, rectification, restriction, consent change, conversation deletion) with actor, target, IP and details.
- Consent log and registration log (append-only; the registration log is anonymised, not deleted, on erasure).
9. Website and support data (controller)
- Basic server logs for our website and documentation: IP address, browser, pages visited.
- Information you provide when contacting support, sales or security: your name, email, organisation and the content of your message.
10. Notice to Data Principals
Before or at the time of collecting personal data of Indian Data Principals, FAC Cloud (as Data Fiduciary for its own controller-level processing) will provide a notice in clear, plain language that: (a) identifies the personal data being collected and the purpose of processing; (b) identifies the Consent Manager (if applicable) through whom consent may be given, managed or withdrawn; (c) states that Data Principals may withdraw consent at any time and the consequences of withdrawal; (d) describes the rights available under Chapter IV of the DPDPA (access, correction, erasure, grievance, nomination); and (e) identifies the Grievance Officer. This notice will be available in English and such other Indian languages as may be required.
3. Special categories
We do not solicit special-category data (such as health, racial or ethnic origin, political opinions, biometric or genetic data, religious beliefs, sexual orientation or trade-union membership) and we do not knowingly process it. If your prompts or uploaded documents contain such data because it sits in your business records, you remain the controller of that data and are responsible for ensuring a lawful basis. Configure access controls, redaction or visibility settings appropriately. Biometric data used by our mobile client (for device unlock) is evaluated by your device's operating system and never leaves the device
4. How we use personal data
We use personal data only for the following purposes:
- Provide the Service: authenticate API calls, route requests to LLM sub-processors, execute tools via MCP, persist conversations, generate memories and embeddings, run workflows, deliver streaming responses.
- Bill and collect: calculate usage, generate invoices, process payments and refunds, manage credits, comply with tax-reporting obligations.
- Operate and secure the Service: monitor uptime, rate-limit abuse, detect fraud and intrusion, investigate incidents, maintain audit trails.
- Communicate: send service announcements, billing notices, security alerts, terms-update notices and responses to your requests.
- Improve the Service: analyse aggregated and de-identified telemetry to fix bugs, reduce latency, tune routing and add capacity. We do not use Customer Data to train our own models, and we use only enterprise / API tiers of our LLM sub-processors that contractually do not train on your prompts or outputs.
- Comply with law: meet legal, regulatory, tax and audit obligations and respond to lawful requests.
5. Lawful bases (EEA / UK / GDPR)
Where the GDPR or UK GDPR applies and we act as controller, our lawful bases are:
- Performance of a contract with you or steps to enter into one — for account registration, authentication, billing and providing the Service.
- Legitimate interests — to secure the Service, prevent abuse, manage our business, improve our products through aggregated telemetry, defend legal claims. We have carried out a legitimate interests assessment (LIA) for each of the purposes above. A summary of these assessments is available on request at [email protected]. You have the right to object to processing based on legitimate interests at any time (see Clause 9); we will cease processing unless we demonstrate compelling legitimate grounds that override your interests..
Legal obligation — for tax, accounting and statutory record-keeping.
Consent — for any optional processing where we ask for it (such as marketing emails).
You may withdraw consent at any time.
Where we act as processor for Customer Data, the lawful basis is established by the Customer (Controller). Data-subject requests in respect of that data should be made to the Customer in the first instance; we will assist as required by the DPA.
6. Automated decision-making and AI processing
The Service uses AI models to generate responses, extract memories, classify task complexity and (where automation features are enabled) execute multi-step automations. These features may produce outputs that influence decisions you or your End-Users make about individuals.
The Service is designed for human-in-the-loop use: it surfaces a HITL approval prompt for write, create, update, delete and submit operations against your business applications, and you can configure tool-trust settings per End-User. Where AI processing could produce legal or similarly significant effects on a natural person, you must not configure the Service to act solely on automated output without meaningful human review and the disclosures required under Article 22 GDPR, Regulation (EU) 2024/1689 (EU AI Act) where it designates the relevant AI system as high-risk, or equivalent law. We provide audit logs to help you demonstrate human involvement.
FAC Cloud will assess annually whether it meets the criteria for designation as a Significant Data Fiduciary (SDF) under s.10 of the DPDPA. Upon SDF designation: (a) an annual Data Protection Impact Assessment will be conducted by an independent auditor; (b) a Data Protection Officer resident in India will be appointed; (c) an algorithmic transparency assessment will be conducted for AI features; and (d) this Policy and the DPA will be updated within 30 days of designation. Customers will be notified of any SDF designation and its implications for their data.
We do not use Customer Data for profiling that affects you or any End-User.
7. Sub-processors and recipients
To provide the Service we share personal data with the following categories of recipients. A current list of named sub-processors, what each receives and where they process is maintained in our DPA.
- LLM providers (Anthropic, OpenAI and other providers we may add) — receive your prompts, the conversation context we inject, system instructions, retrieved RAG snippets and memories; return AI outputs. We use enterprise / API tiers under terms that contractually exclude use of inputs and outputs for training of their models.
- Payment processors (Stripe, Razorpay) — receive billing email, country, phone (Razorpay eMandate) and tokenised payment-method data; we receive customer and payment-method references and webhook events. Both are PCI-DSS-certified.
Cloud infrastructure providers — host the Service, databases, caches and storage.
Email delivery providers — send transactional emails (verification, invoices, alerts).
Professional advisers — auditors, accountants and lawyers under confidentiality obligations.
- Authorities and other third parties where legally required — to comply with law, court orders, lawful government requests, or to protect our rights, your safety or that of others.
- Successors — in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality.
We do not sell personal data and we do not "share" personal data for cross-context behavioural advertising as defined by California law.
Tools, MCP servers and integrations you configure yourself operate under their own terms and privacy practices.
8. International transfers
Our infrastructure is operated from India and other regions. Several sub-processors, including our LLM providers, process data in the United States; payment processors operate globally. Annex B of the Data Processing Agreement lists each sub-processor and where it processes. Where personal data of individuals in the EEA, UK or Switzerland is transferred to a country that has not received an adequacy decision, we rely on the European Commission's 2021 Standard Contractual Clauses (and the UK Addendum or Swiss Addendum, as applicable) together with appropriate supplementary measures (encryption in transit and at rest, access controls, transparency reporting, the right to challenge access requests). Where personal data of individuals in India is transferred outside India, transfers are made in accordance with the DPDPA and any country-restriction notifications issued by the Government of India. For data subjects in other jurisdictions: transfers of personal data of Singapore residents are made in accordance with the Personal Data Protection Act 2012 (Singapore PDPA) and its transfer-limitation obligations; transfers of personal data of Brazilian data subjects are made in accordance with the Lei Geral de Proteção de Dados (LGPD); transfers of personal data of Japanese data subjects are made in accordance with the Act on the Protection of Personal Information (APPI); and transfers of personal data of Australian individuals are made in accordance with the Privacy Act 1988 (Cth). In each case, we rely on contractual protections and, where required, prior verification of adequate protection in the receiving country. Customers regulated by the Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI) or Insurance Regulatory and Development Authority of India (IRDAI) should note that sector-specific data-localisation requirements issued by those regulators may apply to data they route through the Service. Such Customers are responsible for ensuring compliance with their applicable sector-specific localisation obligations and for notifying us if specific localisation arrangements are required.
9. Your rights
Depending on where you live, you may have the following rights in relation to personal data we hold about you as controller:
Access a copy of your personal data;
Rectify inaccurate or incomplete data;
Erase data ("right to be forgotten"), subject to legal retention obligations (for example, invoices retained under tax law);
Restrict or object to processing based on legitimate interests;
Portability — receive a structured, machine-readable copy of data you provided to us;
Withdraw consent where processing is based on consent (without affecting the lawfulness of prior processing);
- Nominate another person to exercise your rights in the event of death or incapacity (DPDPA);
- Lodge a complaint with your supervisory authority (in the EU/EEA, your local DPA; in the UK, the ICO; in India, the Data Protection Board of India).
Where you are an End-User of a Customer (for example, an employee of a business that subscribes to FAC Cloud), the Customer is the controller of that data and your rights should be exercised with the Customer. We will assist the Customer to respond. The Customer can use our built-in APIs — export, erase, rectify, restrict and consent toggle (see Clause 11) — to action your request.
To exercise rights where we are the controller, contact [email protected]. We may need to verify your identity. We aim to respond within 30 days. For grievances under the DPDPA, our Grievance Officer acknowledges within 48 hours and resolves within 30 days of receipt. We do not charge for reasonable requests.
10. Data retention
We retain personal data only for as long as necessary for the purposes set out in Clause 4 and to comply with our legal obligations. Indicative retention periods are:
| Data | Retention | |
|---|---|---|
| Conversation and message content | Configurable; default 365 days; soft-deleted items purged after 30 days | |
| Token-usage records (per user, per model, per day) | Configurable; default 365 days | |
| API request and streaming-event logs | 30 to 90 days | |
| Workflow runs | 90 days | |
| Workflow per-node run logs | 30 days | |
| HITL approval log | Tied to conversation retention | |
| Personal memories and uploaded documents | Until the End-User or Customer deletes them, or account closure | |
| Audit log, consent log, data-request log | 5 years after customer disengages (retained for compliance evidence even after erasure of underlying data) | |
| Invoices, payment records, tax records | As required by Indian tax law (currently 8 years) and equivalent local law | |
| Webhook payloads from Stripe / Razorpay | Indefinitely for audit; redacted on erasure where redaction does not impair fraud / dispute defence | |
| Registration log | Indefinitely; anonymised (not deleted) on erasure | |
| Terms-acceptance records | Indefinitely (legal evidence) |
You may configure shorter retention periods for several of these categories in your tenant settings.
11. Built-in privacy controls
We expose tenant-level APIs that allow your administrators to act on End-User requests:
- Export — full export of an End-User's profile, conversations, messages, token usage, memories and uploaded documents in structured JSON.
- Erasure — permanent deletion of conversation history, token usage, memories, documents and the End-User profile, with cascade into the memory and payments modules. Append-only audit, consent and data-request logs are retained as compliance evidence (with personal identifiers anonymised where possible). Billing records are retained as required by law; PII in the billing scope is redacted.
- Rectification — update display name, email, time zone, locale, custom instructions.
Restriction — set a "processing restricted" flag on an End-User to block new processing while keeping data accessible.Consent management — toggle memory consent; all changes append to an immutable consent log.
12. Security
We apply administrative, technical and physical safeguards designed to protect personal data, including:
TLS 1.2+ for all data in transit;
AES-256 encryption at rest for sensitive fields (tenant secrets, OAuth tokens, LLM API keys, payment-gateway secrets), using the Frappe framework's encryption layer;
HMAC-SHA256 signing of API requests with timestamp checks to prevent replay;
per-tenant logical isolation of conversations, memories, documents, workflows and embeddings (Redis keys are scoped by tenant ID);
role-based access for our staff; production access logged and restricted;
vulnerability management, patching and dependency monitoring;
backup and recovery procedures;
documented incident response.
No system is perfectly secure. Report suspected vulnerabilities or incidents to [email protected].
13. Breach notification
If we become aware of a personal-data breach affecting your data, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware. For Customers subject to GDPR, the DPA sets out the assistance we provide for the Customer's own notification duties. For Customers and Data Principals in India under the DPDPA, we will also assist with the Data Fiduciary's reporting obligations to the Data Protection Board of India and direct notification of affected Data Principals as required by Rule 7 of the DPDP Rules, 2025. In addition, as a body corporate operating in India, FAC Cloud is subject to the CERT-In Directions on Information Security Practices, Procedures, Prevention, Response and Reporting of Cyber Incidents (April 2022), which require mandatory reporting of personal-data breaches and other cyber incidents to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of becoming aware of the incident. We maintain procedures to comply with this obligation and will inform affected Customers promptly.
14. Cookies and tracking
FAC Cloud is primarily an API service.
Our cloud API does not set cookies.
Our administrator console and our web client (including FAC Chat, our open-source AGPLv3 client) rely on standard first-party session cookies (HTTP-only, Secure, SameSite) for authentication; the web client stores small non-sensitive UI state in browser localStorage and sessionStorage (such as banner-dismiss flags and the active session ID).
Our mobile client stores OAuth tokens in the device secure enclave (iOS Keychain / Android Keystore) and uses a local cache for offline message history. Biometric check are evaluated by the device OS; biometric data is never transmitted to us. Push notifications use FCM (Android) and APNs (iOS) with generic payloads.
- Our website and documentation may use strictly necessary cookies and, where required, a cookie banner to obtain consent for any non-essential analytics. We do not run third-party advertising trackers.
15. Children
The Service is not intended for individuals under the age of 18 and we do not knowingly process their personal data. If we become aware that we have processed personal data of a child, we will delete it. Customers must not provision End-User accounts for individuals under 18 and indemnify us for any breach of this restriction. For the purposes of the DPDPA, in respect of any personal data of children (persons under 18 in India) that FAC Cloud processes as Data Fiduciary: (a) we do not process personal data of children in a manner that is detrimental to their wellbeing (Sec 9(1)); (b) we do not undertake tracking or behavioural monitoring of children (Sec 9(3)); and (c) we do not target advertising directed at children (Sec 9(3)). Where a Customer enables processing of Indian children’s data through its tenant, the Customer (as Data Fiduciary) must obtain verifiable parental consent before such processing commences and is responsible for compliance with Sec 9 DPDPA.
16. Indian-law specifics (DPDPA)
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDPA"):
- When you provide personal data of Data Principals to the Service, you are the Data Fiduciary and we are the Data Processor. We process such data only on your documented instructions, as set out in our DPA.
- For data we hold as controller (billing contacts, registration metadata, telemetry, support correspondence), we are the Data Fiduciary.
- Data Principals may exercise rights of access, correction, completion, erasure and grievance redressal, and may nominate a person to exercise their rights.
- Our Grievance Officer can be reached at [email protected]. We aim to acknowledge grievances within 48 hours and resolve them within 30 days of receipt.
- If we are notified by the Government of India of any country-transfer restrictions or are designated a Significant Data Fiduciary, we will update this policy and our DPA to reflect the applicable additional obligations (annual DPIA, independent audit, India-resident DPO).
17. California-law specifics
To the extent the CCPA / CPRA applies (whether to us or to data we process on your behalf), in the preceding 12 months we have collected the categories of personal information set out in Clause 2 for the purposes set out in Clause 4. We do not sell or share personal information for cross-context behavioural advertising. California residents have rights of access, deletion, correction, portability, opt-out of sale / sharing, limit-use of sensitive personal information and non-discrimination; to exercise these, contact [email protected]. Authorised agents may submit requests with verifiable authority.Regarding the right to limit use of Sensitive Personal Information under Cal. Civ. Code § 1798.121: we do not use or disclose sensitive personal information for purposes beyond those listed in Cal. Civ. Code § 1798.121(a), so no opt-out mechanism is required. If this position changes, we will add a “Limit the Use of My Sensitive Personal Information” link to this policy and our website.
18. Changes to this Policy
We may update this Policy from time to time. We will update the effective date and version above and, for material changes, notify you by email, in-product banner or API response header at least 30 days before the change takes effect (a shorter period may apply for changes required by law). For changes that do not materially affect your rights or the nature of our processing, continued use after the effective date constitutes acknowledgment of the updated Policy. For material changes, including changes to the categories of personal data collected, purposes of processing, sub-processors, or your rights, we will obtain fresh confirmation of acceptance (or, where processing is based on consent, fresh consent) before the change takes effect. You may object to material changes; if we cannot address your objection, you may terminate your subscription.
19. How to contact us
General privacy enquiries: [email protected]
Data Protection Officer: [email protected]
Grievance Officer (India, DPDPA): Sunitha Ravindran, Manager - HR & Administration, Promantia . Email [email protected]
Security incidents: [email protected]
Postal: Promantia Business Solutions Pvt. Ltd. (CIN: U72900KA2017PTC108567), No 103, Maria Regency Manor, Madras Sappers Officers Colony, Banaswadi Mn Rd, Bangalore, Karnataka, India – 560033