Legal

The boring pages,
written to be read.

Most privacy policies are written so nobody finishes them. Since we sell a control environment, ours says plainly what we take, why, and what we will never do with it.

Who we are

FinOps Robotics is a venture of US Global Consultancy FZE, a company registered in the United Arab Emirates. For anything in this policy — a copy of what we hold, a correction, or a deletion — write to [email protected] and a person reads it, not a queue.

What we collect, and only this

We do not run advertising pixels, we do not buy or enrich contact data, and we do not build a profile of you from other sources.

Why we hold it

To prepare the roadmap you asked for and to reply to you. In GDPR terms that is steps taken at your request before entering a contract, and our legitimate interest in responding to a business enquiry. You are not on a marketing list because you filled in the form; if we ever start a mailing list, you will be asked first.

How long

Enquiry details for 24 months, so we recognise you if you come back, then deleted. Ask us to delete them sooner and we will, within 30 days, and confirm when it is done. Engagement records are kept for the period set out in the engagement letter and any statutory retention that applies to it.

Your client data, during an engagement

This is the part that matters most, and it is deliberately narrow. We build inside your tenant. Your ledger, your documents and your master data stay in your systems, under credentials you issue and can revoke without asking us. We are a processor acting on your written instructions, set out in the engagement letter and the Data Processing Agreement that goes with it. Where a step genuinely cannot run in your environment, that is named in the blueprint before you sign it, along with what moves, why, and for how long.

Who else sees anything

Nobody, except the sub-processors described in the next tab, and only to the extent they must. We do not sell data. We do not share it with anyone for their own purposes. We will not hand it over in response to an informal request — only a valid legal order, and we will tell you unless we are legally barred from doing so.

Outside your country

We are based in the UAE and work with clients elsewhere, so correspondence may be processed outside your jurisdiction. Where that involves personal data from the UK or EEA, we rely on the appropriate safeguards under UK GDPR and GDPR Article 46, and name them in your DPA.

What you can ask for

A copy of what we hold, a correction, deletion, restriction, portability, or an objection to us holding it at all. Write to us and you will get an answer within 30 days, free. If you are unhappy with the answer you can complain to your data protection authority — the ICO in the UK, or your national regulator in the EEA.

Keeping it safe

MFA on every account, credentials in a managed vault rather than email, encrypted devices, no client data on personal machines, and access scoped to what the work needs. If we ever suffer a breach affecting your data we will tell you within 72 hours of becoming aware, with what was accessed and what we have done — not a drip-feed.

Changes

If this policy changes materially we will date-stamp it and, for anyone we hold an enquiry for, say so by email.