Last updated 27 September 2026
Who we are
FinOps Robotics is a venture of US Global Consultancy FZE, a company registered in the United Arab Emirates. For anything in this policy — a copy of what we hold, a correction, or a deletion — write to [email protected] and a person reads it, not a queue.
What we collect, and only this
- What you type into the booking form, whether you use the one on the page or the one in the chat. Your name, work email and company, which robot you are after or which ledger you run, when it suits you to talk, and whatever you tell us about where the hours go.
- What you send us. Emails, WhatsApp messages and anything you attach to them.
- How the site is used. Which pages are opened, which buttons are clicked, the country and town your network places you in and whether you are on a phone or a computer. No cookies are set and your IP address is never stored. So that you are counted once a day rather than once a click, it is put through a one-way hash together with that day’s date and then thrown away — which means the same hash cannot follow you to tomorrow. Nothing is shared with an advertising network.
We do not run advertising pixels, we do not buy or enrich contact data, and we do not build a profile of you from other sources.
Why we hold it
To prepare the roadmap you asked for and to reply to you. In GDPR terms that is steps taken at your request before entering a contract, and our legitimate interest in responding to a business enquiry. You are not on a marketing list because you filled in the form; if we ever start a mailing list, you will be asked first.
How long
Enquiry details for 24 months, so we recognise you if you come back, then deleted. Ask us to delete them sooner and we will, within 30 days, and confirm when it is done. Engagement records are kept for the period set out in the engagement letter and any statutory retention that applies to it.
Your client data, during an engagement
This is the part that matters most, and it is deliberately narrow. We build inside your tenant. Your ledger, your documents and your master data stay in your systems, under credentials you issue and can revoke without asking us. We are a processor acting on your written instructions, set out in the engagement letter and the Data Processing Agreement that goes with it. Where a step genuinely cannot run in your environment, that is named in the blueprint before you sign it, along with what moves, why, and for how long.
Who else sees anything
Nobody, except the sub-processors described in the next tab, and only to the extent they must. We do not sell data. We do not share it with anyone for their own purposes. We will not hand it over in response to an informal request — only a valid legal order, and we will tell you unless we are legally barred from doing so.
Outside your country
We are based in the UAE and work with clients elsewhere, so correspondence may be processed outside your jurisdiction. Where that involves personal data from the UK or EEA, we rely on the appropriate safeguards under UK GDPR and GDPR Article 46, and name them in your DPA.
What you can ask for
A copy of what we hold, a correction, deletion, restriction, portability, or an objection to us holding it at all. Write to us and you will get an answer within 30 days, free. If you are unhappy with the answer you can complain to your data protection authority — the ICO in the UK, or your national regulator in the EEA.
Keeping it safe
MFA on every account, credentials in a managed vault rather than email, encrypted devices, no client data on personal machines, and access scoped to what the work needs. If we ever suffer a breach affecting your data we will tell you within 72 hours of becoming aware, with what was accessed and what we have done — not a drip-feed.
Changes
If this policy changes materially we will date-stamp it and, for anyone we hold an enquiry for, say so by email.