Privacy Policy

Last updated: September 21, 2026
FinOps AI™ (getfinops.cloud) is operated by HostingX Solutions LLC. This policy covers both the public website and the FinOps AI platform at app.getfinops.cloud.

1.Overview

This Privacy Policy explains how HostingX Solutions LLC ("Company", "we", "our") collects, uses, and protects data across two distinct surfaces: the public marketing website, and the FinOps AI platform that analyses a customer's cloud cost and usage data.

The distinction matters throughout this document, because our role differs between them — see §5.

HostingX Solutions LLC · LLC No. 0008072296 · Founded 2026 · Registered in New Mexico, USA · 8206 Louisiana Blvd NE, Suite A #8186, Albuquerque, NM 87113, United States

2.Data Categories

Website visitors

  • Contact Data: name, email, company, role, and the message you send through the contact form.
  • Consent & Preference Data: your cookie choice (including a United States opt-out, §12) and any unsubscribe request.
  • Booking Data: where you book a call — your name, email, company where provided, the meeting time you select, the booking status and the associated meeting details. A booking link sent to you by email carries a token identifying your enquiry.
  • Analytics, Attribution & Security Data: cookie and advertising identifiers, including the Google click identifier (gclid) where present; page and conversion events; and IP address and request metadata recorded in server access logs for security, abuse prevention and service operation.

Platform users (account holders)

  • Account Data: name, email address, company name, hashed password, and — where multi-factor authentication is enabled — the second factor itself: for an authenticator app, an encrypted secret and single-use recovery codes. We do not collect a telephone number. Where a workspace uses a third-party MFA provider instead, the factor the user enrols is held by that provider (§6) and never reaches us.
  • Authentication & Security Data: IP address, user-agent string, and timestamps recorded on sign-in, failed sign-in, and account changes. Held to detect and investigate unauthorised access.
  • Billing Data: subscription state and plan. Card details are handled by Stripe and are never transmitted to or stored by us.
  • Audit Records: a tamper-evident audit trail of actions taken in the platform — who approved a remediation, what was executed, and what the outcome was. When a workspace is erased, retained audit records are redacted as described in §9, and that redaction itself remains verifiable.
  • Support Reports: when you use “Report a problem” in the platform, what you write; your name, email address and role; the workspace and cloud account you were viewing; the page you were on (its path only, never the rest of the web address); and your browser's user-agent string, screen size, display theme, time zone and language. The report is emailed to our support mailbox (§6). We do not attach customer cloud data to it.
  • Advertising Click Identifier: if you click a sign-up link on our website while analytics and advertising cookies are on there (§12), the Google click identifier (gclid) from the web address you arrived on, or from Google's advertising cookie, is added to that link as you click it, with the time of the click. The platform ignores it if the click is more than 30 minutes old. We do not store it with your account. It is passed on once, when you finish signing up, so that the sign-up can be reported to Google Ads as a conversion (§6).

Notification recipients

  • Notification Settings: the email addresses a workspace admin saves to receive scan report summaries and alerts, which need not belong to platform users, and the address of a Slack incoming webhook where one is saved (§6, §13).

Customer cloud data (processed on your behalf)

  • Cost & Usage Data: spend by service, region, account, and tag, drawn from AWS Cost Explorer and the Google Cloud billing export.
  • Resource Metadata: inventory of compute, storage, database, and Kubernetes resources — identifiers, names, types, regions, sizes, tags and labels, and utilisation metrics.
  • Findings & Remediation Records: the optimisation findings we generate, the actions planned or executed against your cloud accounts, and their results.

Cloud resource metadata is not usually personal data, but it can contain it — a tag such as Owner=jane@example.com or an instance named after a person. We treat it accordingly.

3.Legal Bases (EEA / UK)

Where we act as an independent controller (§5), we rely on: contract performance for providing and administering your account; legitimate interests for security, fraud prevention, service operation and integrity, and for product-promotion email to customers and trial users about the service they signed up for, subject to the opt-out in §13; consent for analytics and advertising cookies; and legal obligation for accounting records and statutory retention.

Where we act as a processor, the lawful basis for the underlying processing is determined by the customer as controller, and we process only on their documented instructions.

4.Use of Data

  • provide the FinOps AI platform — collect cloud cost and usage data, generate findings, and execute approved remediations,
  • generate AI-written narratives and answer questions you ask the in-product assistant (§7),
  • administer accounts, authenticate users, and operate multi-factor authentication,
  • bill for the service and reconcile usage,
  • detect, investigate and prevent unauthorised access, abuse and fraud,
  • maintain an audit trail of actions taken in the platform,
  • respond to inquiries and send service and security notifications, and
  • send product-promotion email about the service you signed up for, until you opt out (§13).

We do not sell personal data for money. How United States privacy laws may classify our website's advertising cookies is set out in §11. We do not use customer cloud data to train our own models, and under Anthropic's applicable commercial terms, Customer Content submitted through the commercial API is not used to train Anthropic's models (see §7).

5.Our Role — Controller and Processor

Status of our processor commitments. Our Terms of Service already limit what we may do with Customer Data: the licence to process it is confined to providing, securing, supporting and maintaining the service on your documented instructions. A Data Processing Addendum setting out the full Article 28 obligations — security measures, subprocessor notice, assistance with data-subject requests, deletion and return, and international transfer terms — is prepared but not yet executed. We say so plainly rather than implying a contract that is not in place: this section describes how we handle your data, and the DPA is what will make those handling commitments contractually binding. Customers who need it in force before then can request it at privacy@hostingx.co.il.

Our role is not the same for every category of data, and this policy does not claim that we are always one or the other.

  • Customer cloud data — you are the controller, we are the processor. For the cost, usage, resource metadata and findings we process in order to provide the service, the customer determines the purposes and essential means, and we act as processor and — where applicable and subject to the required contractual terms — as a "service provider" under the CCPA/CPRA, processing on the customer's documented instructions. Vendors who process that data on our behalf — including Anthropic — act as our subprocessors (§6).
  • Account, billing and security data — we are an independent controller. For data we process for our own purposes — account administration, authentication, billing, security and fraud prevention, legal and regulatory compliance, our own business communications, and operating and improving the service using account data, security information and service/operational telemetry (but not by repurposing customer cloud data) — we determine the purposes and means ourselves and act as controller.
  • Website visitors — we are the controller. Contact-form submissions, cookie choices and marketing preferences are processed under our own responsibility.

What we do not do with customer cloud data

Customer cloud data is processed only to provide, secure, support and maintain the contracted service, on the customer's documented instructions, except where applicable law requires otherwise. It is not repurposed for generalised model training, advertising, unrelated analytics, or cross-customer profiling.

Where we carry out analytics to improve the service, that work is kept separate from customer cloud data: it is based either on operational and service telemetry for which we independently determine the purpose and hold an appropriate legal basis, or on data that has genuinely been rendered non-personal and not attributable to any customer.

We use the word "anonymous" only where it is accurate. Where information could still reasonably be linked to a customer, workspace, cloud account, project, resource, user, company or identifiable individual, we do not describe it as anonymous — such data remains personal data and is treated accordingly.

6.Third-Party Service Providers and Subprocessors

These parties do not all occupy the same role. This list is a disclosure of who receives data, not a statement that each is our subprocessor — and the difference matters, because different obligations follow. Depending on the activity and the contract, a party may act as our processor or subprocessor, as an independent controller, as your own provider under your own relationship with them, or as an optional integration you choose to enable. Three examples: accessing your Google Cloud environment at your direction does not by itself make Google our subprocessor; where you connect your own Slack workspace, that is your Slack agreement rather than ours; and Stripe acts as a processor for payment activities carried out on our instructions while determining its own purposes for fraud, compliance and payment-network processing. The role recorded for each party is stated below.

Platform (app.getfinops.cloud)

  • Amazon Web Services, Inc. (United States): hosting and infrastructure for the platform — compute (ECS), database (RDS PostgreSQL), cache (ElastiCache), object storage (S3), content delivery (CloudFront), transactional email (SES), and logging (CloudWatch). AWS is our primary hosting and infrastructure provider for the hosted platform.
  • Anthropic, PBC (United States): the AI models behind narratives, the in-product assistant, and the daily brief. What is and is not sent is described in detail in §7.
  • Stripe, Inc. (United States): subscription billing and payment processing. Stripe receives billing contact details and handles card data directly; we never receive or store card numbers.
  • Google LLC (United States) — Google Workspace: our support mailbox, acting as our processor. When you use “Report a problem”, the report described in §2 (Support Reports) is sent to it by email through Amazon SES. We do not attach customer cloud data to it.
  • Auth0 (Okta) — United States: multi-factor authentication, where a workspace's second factor is set to Auth0. Receives the user's email address, our internal user id, and a marker recording that we created the account; the factor the user enrols there — an authenticator app or a telephone number — is held by Auth0 and never reaches us. We create and delete these accounts through Auth0's management API, so deleting a platform user also deletes the Auth0 account behind it. Our tenant is getfinops-cloud.us.auth0.com, hosted in the United States. Engaged for production use on 28 August 2026. Two things are open, and we would rather record that than imply otherwise: which Okta group entity contracts for it, and its Data Privacy Framework status. Neither has been confirmed, so we claim neither. Used only when MFA is enabled and Auth0 is the selected provider.
  • OneLogin, Inc. (One Identity LLC, United States): SMS multi-factor authentication — no longer used. It has received no data since 21 August 2026. The platform's default second factor is now an authenticator app, whose codes are computed on the user's own device and verified by us, so no third party receives anything for it and no telephone number is collected. This entry stays rather than disappearing because a customer who evaluated us while SMS was the second factor was told this vendor held their phone number; the change is theirs to see.
  • Slack (Salesforce): optional integration. Where a customer connects Slack, approval requests, outcome notifications, and budget, tag-compliance and AI-spend coverage alerts are delivered to the channel the customer designates, as are automation safety-block notices where a workspace switches them on. Approval requests and outcome notifications include finding details and the cloud account concerned. Where a customer saves a Slack incoming webhook, scan report summaries and budget, tag-compliance and AI-spend coverage alerts are posted to it. A report summary carries the workspace ID, the scan's run ID and date, finding, severity and action counts, estimated monthly savings, a link to the Reports page, and the names of cloud accounts not fully collected (a Slack message lists up to 20; an account with no name is shown by its account number or project ID). Both use the customer's own Slack workspace under the customer's own agreement with Slack, so the Slack entity involved, and the country in which it processes, follow that workspace rather than ours.
  • Notification email (optional): scan report summaries, budget, tag-compliance and AI-spend coverage alerts and, where a workspace switches them on, automation safety-block notices are emailed through Amazon SES (above) to the notification addresses a workspace admin saves. The customer chooses those addresses, and they need not belong to platform users. A report summary carries the same content as the Slack message above, and names every cloud account not fully collected.
  • Google LLC (United States): where a customer connects a Google Cloud account, we read their billing export and resource inventory through Google Cloud APIs. This is access to the customer's own Google Cloud environment at their direction. Authentication currently uses a customer-provided service-account credential, stored encrypted; see §8 for the planned move to keyless authentication.

Public website (getfinops.cloud)

  • Amazon Web Services, Inc. (United States): static hosting (S3 + CloudFront), Route 53 DNS, contact-form and booking compute (API Gateway + Lambda), inbound mail (SES) and access/security logs (CloudWatch). The website's access logs record, for each request, the visitor IP address, the time, the method, the page and its query string (which can include an advertising click identifier), the referring page, the browser user-agent, the response status and which of the CDN's locations served it. They do not record cookies. They are kept for 30 days (§9).
  • n8n GmbH (Germany): workflow automation. The validated contact-form and booking payload — role, name, email, subject, message, company where provided, requested meeting time and the gclid advertising identifier where present — is forwarded to n8n Cloud, which orchestrates the steps below. When you sign up for the platform from a link that carries a click identifier (§2, §12), n8n Cloud also receives that gclid and a fixed conversion value, and nothing else about you or your workspace, to report the sign-up to Google Ads.
  • Zoho Corporation (United States data centre): customer-relationship management. Enquiries and bookings are created and updated as leads in Zoho CRM. No customer cloud data — no cost figures, findings or resource information — is sent to Zoho.
  • Google LLC (United States) — Google Workspace: Gmail is used to send replies and booking confirmations, and Google Calendar to create the meeting and its video-conference link.
  • Slack Technologies, LLC (Salesforce, United States): internal notification of completed bookings to our own team channel, and a notice for each platform sign-up reported to Google Ads, which says only whether the conversion was reported and its value.
  • Google LLC (United States) — Google Tag Manager, Google Analytics 4, Google Ads: analytics and advertising measurement. Outside the United States these load only after you accept analytics cookies; in the United States they load unless you opt out — see §12. GA4 is configured with anonymize_ip, allow_google_signals: false and allow_ad_personalization_signals: false. We do not add your name, email address or contact-form message to the conversion event. Google may process network and device information, including IP-derived information, in accordance with its own applicable terms and settings — that processing is Google's, not something we control or can disclaim on its behalf. No remarketing audiences are built. Where a booking is completed, the associated click identifier is also uploaded to Google Ads server-side as an offline conversion, so that a booking can be attributed to the originating ad. The same applies to a sign-up for the platform that started from a link carrying a click identifier (§2, §12): the identifier, the time of sign-up and a fixed conversion value are uploaded, and nothing else about you or your workspace.

Where a third party acts as our subprocessor for customer data, we give advance notice of additions or replacements in accordance with the applicable Data Processing Addendum, and customers have an opportunity to object where required. The notice period and objection process are set by that agreement rather than by this policy. This applies to subprocessors specifically, not to every party listed above — some are not subprocessors, as the note at the top of this section explains.

7.Artificial Intelligence — What We Send to Anthropic

The platform uses Anthropic's models to write cost narratives, answer questions in the in-product assistant, and produce the daily brief. This section describes what is actually transmitted. It is deliberately specific, and deliberately avoids claims we cannot stand behind.

Credentials and secrets

We do not intentionally transmit stored cloud credentials to Anthropic. AWS access uses temporary STS credentials obtained by assuming a role in your account and does not require customer access keys. For Google Cloud connections that currently use a customer-provided service-account key, the credential is stored encrypted and is not included in AI prompts.

We likewise do not intentionally include stored passwords, session tokens, API tokens, External IDs or other secrets in AI prompts. Messages submitted to AI features are transmitted as entered, so you should not paste credentials or secrets into the assistant.

Payment card data is never transmitted, because we never hold it — card details go directly to Stripe.

Sent

  • Cost and usage data: spend figures, savings estimates, service and region breakdowns, and trends.
  • Resource metadata: resource types, sizes, regions, utilisation metrics, and resource names, tags and labels. Where a tag value or a resource name contains personal data — an owner email address, a person's name — that data is transmitted.
  • Findings and recommendations: the optimisation findings we generate and the remediation actions proposed or taken.
  • Identifiers: your company name and account labels. Your workspace identifier, cloud account identifiers (AWS account IDs, Google Cloud project IDs) and individual resource identifiers are substituted before sending, as described below — but that substitution is partial, and resource names, tags and labels are not covered by it.
  • Onboarding context: when you use the onboarding assistant, your company name, workspace or account label, onboarding progress, cloud provider and connection method, and — where you supply them — cloud account or project identifiers and the role identifier for cross-account access.
  • What you type: messages you send to the in-product assistant are transmitted verbatim, including anything you paste into them.

Partial identifier substitution

Before sending, we substitute certain identifiers with stable hashed placeholders. On AWS: ARNs, and EC2 instance, volume, snapshot and security-group IDs; account numbers are masked. On Google Cloud: projects/… resource paths, service-account addresses, and project numbers. In addition, your workspace identifier and the identifiers of every cloud account connected to your workspace are substituted wherever they appear in the data our AI features send, including inside budget names, account labels, descriptions, and report narratives that are sent again as context for a brief or a chat.

There are two exceptions. The onboarding assistant sends your company name and account label as stored, and the account or project identifiers you give it, so an identifier inside them is not substituted. In the cross-account analysis, an account's label is checked only against that account's own identifiers. We describe the substitution's limits accurately rather than presenting it as a guarantee:

  • It is pattern-based and therefore incomplete. It recognises identifier formats we have enumerated; an identifier in a form we have not anticipated passes through.
  • It does not cover resource names, tags or labels. An instance named after a person, or a tag such as owner=jane@example.com, is transmitted as you created it.
  • On Google Cloud it covers project identifiers, resource paths and service-account addresses. It does not cover instance names, label values or dataset names, except where those contain your project identifier.
  • It does not cover anything you type into the assistant, which is transmitted verbatim by design.
  • Consequently, some identifying information is still transmitted to Anthropic unaltered.
  • It is not anonymisation and does not make the data non-personal. You should not rely on it as a safeguard.

Anthropic's terms

We use Anthropic through its commercial API service. Under Anthropic's applicable commercial terms, customer content submitted through the API is not used to train Anthropic's models. Anthropic acts as our subprocessor for this data.

These are separate things and should not be read as one:

  • Model training — under Anthropic's applicable commercial terms, content submitted through the API is not used to train its models.
  • API processing — the content is nonetheless transmitted to and processed by Anthropic in order to return a response.
  • Provider retention — Anthropic may retain API inputs and outputs for a period in accordance with its applicable commercial data-retention terms, for example to operate the service and monitor for abuse.
  • Legal and security exceptions — retention may be extended where Anthropic is required to do so by law or to investigate a security or abuse matter.

Those terms are set by Anthropic under our commercial agreement with them and may change; we describe them here rather than guarantee them.

8.Security Measures

Encryption in transit (TLS). Passwords hashed with Argon2. Optional multi-factor authentication — by default an authenticator app, whose codes are computed on the user's device and verified by us with no third party involved; a workspace can select an external provider instead (§6). Tenant data is isolated at both the application and database layers. Access to production is least-privilege and audited, and privileged support access to a customer workspace requires an explicit, time-limited, audited grant. Remediation actions against a customer's cloud environment run behind configurable approval and safety controls. Where an action is reversible and rollback is supported, the platform can roll it back automatically following an execution or post-execution verification failure. Some destructive actions are irreversible and cannot be undone by any automated mechanism; those are subject to stricter pre-execution controls, and where a verification failure follows one, the platform records that manual intervention is required rather than implying a rollback occurred.

How cloud connections are authenticated

  • AWS: we assume a role that you create in your own account, guarded by an External ID. Access uses temporary STS credentials; no customer access key is required or stored.
  • Google Cloud (current): connections may use a service-account key that you provide. That credential is encrypted (AES-256-GCM) within our tenant configuration storage and decrypted only when a call to your Google Cloud environment requires it.
  • Google Cloud (planned): we are transitioning Google Cloud integrations toward keyless authentication using Google Cloud Workload Identity Federation and service-account impersonation where supported, so that short-lived credentials replace any stored key. Until that migration is complete, some Google Cloud connections may continue to use an encrypted customer-provided service-account credential.

Platform and integration secrets are held as encrypted values in AWS Systems Manager Parameter Store, with the exception noted above: customer-provided Google Cloud credentials are encrypted within tenant configuration storage rather than in Parameter Store.

9.Retention

  • Account data: retained while the account is active. Deleting a workspace suspends it for a 14-day recovery window, after which the workspace and its customer data are deleted from active production systems. Residual copies may remain temporarily in encrypted backups until those backups expire under our backup-retention schedule. Backups are held solely for disaster recovery and are not used for ordinary processing.
  • Audit records (active workspace): we keep a tamper-evident record of actions taken in the platform. Sign-in and security records — including sign-in attempts, multi-factor events, administrative access and permission changes — are kept for 12 months. Records of what was done to your cloud accounts — approvals, remediations, budget and account changes — are kept for 24 months. Routine system activity, such as scheduled collection runs, is kept for 90 days. After 12 months we remove the identifying details — the acting person's email address, IP address and browser identifier — from any record kept beyond that point, retaining the fact that the action occurred.
  • Audit records (erased workspace): when a workspace is erased, its audit trail is retained in redacted form — the identity of the person who acted is erased, the record that the action occurred is kept — for 24 months, so that we can evidence how data was handled. The record that an erasure was carried out is retained for 7 years.
  • Cloud resource inventory: 90 days from last observation.
  • Billing records: retained by Stripe and by us as required by tax and accounting law, commonly 6–7 years.
  • Problem reports: kept in our support mailbox for 24 months from when we receive them, after which a retention rule on the mailbox deletes them. The report itself is not stored in the platform; its audit record notes only that a report was sent, from which page, and whether it was delivered.
  • Website access logs: the request records described in §6 are kept for 30 days, after which the log store deletes them.
  • Website enquiry, booking and consent records: retained while needed to respond to you, to hold the resulting business relationship, and to evidence your consent choices — across the systems named in §6. Our workflow-automation provider retains execution records for 30 days. A click identifier received with a platform sign-up is not stored with your account. That provider keeps it in its execution record for the same 30 days, and Google Ads keeps it under Google's terms (§6). Your cookie-consent choice is stored in your own browser. A choice to accept or decline expires after 12 months; outside the United States we then ask you again, and in the United States the default described in §12 applies again. A United States opt-out (§12) does not expire: it stays in force until you change it. For our CRM and mailbox we have set a period of 24 months from our last contact with you, and for the internal notification of your enquiry 90 days. If your enquiry becomes a customer relationship, the data is kept under that relationship instead. You may ask us to delete your enquiry at any time (§11), which takes precedence over every period above. Unsubscribe records are retained to enforce suppression.

10.International Transfers

Status of our transfer mechanisms. We maintain an internal transfer record covering every flow described below — the exporter, the importer, the categories of data, the destination, and the mechanism available for it. Where a recipient is certified under an applicable data-privacy framework, that certification has been checked against the official participant list, and where it is not available we rely on contractual safeguards supported by a documented transfer risk assessment.

Two qualifications we would rather state than leave implied. Describing a transfer mechanism does not create it: Standard Contractual Clauses, a UK Addendum or IDTA, and Swiss safeguards are relied upon only where they are actually executed in the relevant agreement — which is why the paragraph below is written conditionally. And several of these mechanisms sit in agreements we are still finalising, including our own Data Processing Addendum (see §5); the applicable SCC module also differs depending on whether a customer is itself a controller or a processor, so it is fixed per customer rather than assumed. Confirmation of the final instruments remains with qualified counsel.

HostingX Solutions LLC is a United States company (registered in New Mexico). Our service providers and other third parties may be established in, or process data in, the United States, the EEA, the United Kingdom and other jurisdictions, as described in §6 and in their own applicable service terms — our workflow-automation provider, for example, contracts from Germany. Personal data processed through the hosted platform and the website is therefore processed internationally, including in the United States, and may be processed in any region where a subprocessor operates.

Where an international transfer requires additional safeguards under applicable EEA, UK or Swiss data-protection law, we use a valid transfer mechanism for the relevant jurisdiction. Depending on the transfer, that may include an applicable adequacy determination or data-privacy framework, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, Swiss-recognised contractual safeguards, or another mechanism permitted by applicable law. Any contractual safeguard is relied upon only where it has been validly incorporated into the relevant agreement.

Each régime is assessed separately rather than treated as one: EU/EEA transfers under the EU GDPR, UK transfers under the UK GDPR, and Swiss transfers under the Swiss Federal Act on Data Protection. Where a recipient is certified under an applicable data-privacy framework, that framework may cover the transfer without additional contractual clauses; where it is not, we identify the appropriate mechanism for that specific flow. Technical and organisational measures such as encryption in transit and access controls are supplementary to the legal mechanism and are not a substitute for it.

The Privacy Policy describes where processing may occur. The DPA, the Standard Contractual Clauses and the applicable vendor/customer agreements establish the legal transfer mechanisms.

No regional guarantee for the hosted service. We make no representation that data processed through the hosted service remains within any particular country or region.

Self-hosted deployment

Customers with strict regional or sovereign-data requirements can run the platform themselves, inside their own cloud environment. That changes where the application and its data plane run — the database, the collectors and the dashboard operate in the customer's own account and region.

It does not by itself confine every processing activity to that region. Where a self-hosted deployment uses features that call an external service — most notably the AI features, which call Anthropic's hosted API — the data sent to that service leaves the customer's environment and is processed wherever that provider processes it. Customers requiring absolute geographic confinement should review which integrations they enable, and should raise the requirement with us before onboarding.

A current list of the service providers and other third parties we use, and their locations, is maintained in §6. Copies of the relevant transfer mechanisms, where executed, are available on request from privacy@hostingx.co.il.

11.Your Rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time without affecting processing carried out before withdrawal.

Deleting a workspace in the product removes it and its customer data from active production systems after the 14-day recovery window, subject to the backup-retention treatment described in §9. For all other requests, email privacy@hostingx.co.il — we respond without undue delay and in any event within one month of receipt, subject to any extension permitted by applicable law. Where an extension applies we will tell you within that first month, and explain why.

Where we process data as a processor on a customer's behalf and you are that customer's employee or end user, we will refer your request to them as the controller.

Where the CCPA/CPRA applies, California residents may have additional and separate rights — to know what personal information is collected and how it is used and shared, to delete it, to correct inaccurate information, to opt out of its sale or sharing, to limit the use and disclosure of sensitive personal information, and not to be discriminated against for exercising any of them. These are not simply the equivalents of the rights described above.

We do not sell personal information for money. For visitors in the United States, our website loads Google Analytics and Google Ads conversion cookies unless you opt out (§12). Making cookie identifiers and browsing activity on our website available to Google in this way may be treated as “sharing” for cross-context behavioural advertising, or as a “sale”, as those terms are defined in California Civil Code § 1798.140 and in similar laws of other US states. You can opt out at any time with the “Do Not Sell or Share My Personal Information” link in the footer of our website, and we treat a Global Privacy Control signal sent by your browser as the same opt-out. We do not knowingly sell or share the personal information of anyone under 16. The same opt-out also stops our servers reporting a booking, a contact-form enquiry or a sign-up to Google Ads as a conversion (§6), which may be treated the same way. Apart from these, we do not sell or share personal information. An opt-out is recorded in the browser you make it in (§12), so make it in each browser you use.

You may also lodge a complaint with your local supervisory authority.

12.Cookies & Local Storage

getfinops.cloud sets a small number of first-party cookies and two localStorage entries. Which rule applies to the analytics and advertising cookies depends on where you are. When a page loads, it asks our content delivery network for your country, which the network derives from your IP address; the page does not store the answer.

  • Outside the United States: analytics and advertising cookies are not set unless you accept them. Declining is a single click and the site is fully functional without them. If your country cannot be determined, this rule applies.
  • In the United States (the 50 states and the District of Columbia): they are set unless you opt out. The “Do Not Sell or Share My Personal Information” link in the site footer opts you out. An opt-out stays in force until you change it, and if your browser blocks site storage we treat you as opted out.

Global Privacy Control is honoured everywhere: if your browser sends it, analytics and advertising cookies are not set, whichever rule would otherwise apply.

You can change your choice at any time from the link in the site footer.

  • saas-theme (localStorage): records your light/dark-mode preference. Strictly necessary functional storage under Article 5(3) of the ePrivacy Directive; does not require consent.
  • getfinops-cookie-consent (localStorage): records the cookie choice you made — accept, decline or a United States opt-out — so we do not ask again. Strictly necessary; set only once you have made a choice. If your browser refuses to store an opt-out there, it is kept instead in a first-party cookie, getfinops-optout, for five years, for the same purpose.
  • _ga and _ga_* (first-party, 24-month TTL): set by Google Analytics 4 (§6) to distinguish visitors and maintain per-session state. Only set while analytics cookies are on for you, as described above. IP addresses are truncated before storage and Google Signals is disabled.
  • _gcl_* cookies, including _gcl_au and _gcl_aw (first-party), and any associated browser storage used by Google's conversion-linking implementation (such as _gcl_ls): set by Google Ads conversion tracking (§6) to attribute a subsequent successful contact-form submission — one whose declared role is "Prospective customer"; investor, press and "something else" submissions are excluded by design — or a sign-up for the platform started from our website, back to the originating ad. We read the click identifier from the _gcl_aw cookie (or the URL) so that it can be attached to your enquiry, your booking, or a sign-up link at the moment you click it. Only set while analytics cookies are on for you, as described above, and only on deploys configured with a conversion ID.
  • Platform session cookies: finops-session and a refresh cookie on app.getfinops.cloud keep you signed in. HttpOnly, Secure, SameSite=Lax. Strictly necessary — the product cannot function without them.

Withdrawing consent or opting out from the footer link clears the analytics cookies we can reach and stops the tags loading on subsequent visits. It also stops the advertising click identifier being used: if you book a call after withdrawing, no advertising conversion is reported for it, even where an identifier was captured earlier while consent was in force.

A sign-up for the platform differs in one respect. The platform at app.getfinops.cloud cannot read your choice on getfinops.cloud, so our website checks whether analytics and advertising cookies are on for you at the moment you click a sign-up link, in whichever tab you click it, and the result travels with that click. If you withdraw consent or opt out after clicking, before you finish signing up, that sign-up is still reported.

13.Communications

Service, security and transactional messages — email verification, account-security notices, safety notifications, billing notices — are sent when required and cannot be unsubscribed from while the account is active.

Scan report summaries and alerts are emailed only to the notification addresses a workspace admin saves in Settings → Notifications. They carry no unsubscribe link; an admin stops them by removing the address.

Product-promotion email is limited to messages about the service you signed up for — currently, notices to the workspace owner as a trial approaches its end. We send these because you signed up for that trial (the existing-customer “soft opt-in” under PECR / the ePrivacy Directive, on our legitimate interest in telling you about the service you are evaluating), not on the basis of a separate marketing consent — we do not currently collect one, and we do not run a general marketing mailing list. If you contact us through the website, you receive a reply and your details are recorded as a sales lead in our CRM (§6); that does not enrol you in any automated promotional email.

Every product-promotion message carries a one-click unsubscribe link and the standard list-unsubscribe headers, so your mail client can also offer the option directly. An opt-out is honoured permanently: it is recorded against your email address, applies to all promotional email from us, and survives deleting and re-creating a workspace. It never affects the service and security messages above.

14.Children

Not directed to children under 16. Contact us for prompt removal if such data is discovered.

15.Changes

Material updates announced via site notice or email with effective date. Changes to the subprocessor list in §6 are notified in advance in accordance with the applicable Data Processing Addendum (§6).

16.Contact

Privacy questions
privacy@hostingx.co.il
General inquiries
hello@getfinops.cloud

FinOps AI™ is a product of HostingX Solutions LLC. These policies apply to getfinops.cloud, hostingx.co.il, and all services operated by HostingX Solutions LLC.

© 2026 HostingX Solutions LLC. LLC No. 0008072296 · 8206 Louisiana Blvd NE, Suite A #8186, Albuquerque, NM 87113, USA. All rights reserved.