1 Who this Policy covers
This Privacy Policy applies to personal data collected by FinOps Control ("we", "us", "our") through our website, our cloud cost management platform, our contact and sign-up forms, and in the course of supporting customers who use the platform.
FinOps Control is an independent cloud cost management platform. Because our customers and website visitors are based all over the world, this Policy is written to apply generally rather than to any single country's law — Section 9 below sets out how your rights work depending on where you're located.
We act as the data controller for the personal data described in this Policy, unless we are processing cloud account data on a customer's behalf as described in Section 10, in which case we act as a data processor for that customer.
2 Information we collect
We collect the following categories of information, depending on how you interact with us:
| Category | Examples | When it's collected |
|---|---|---|
| Contact & identity details | Full name, work email, company name, job title, phone number | When you fill in our contact form, request a demo, or start a free trial |
| Account information | Login credentials, role, subscription plan, billing contact | When you register for the platform |
| Communications | The content of messages you send us, and our replies | Emails, contact forms, support conversations, calls |
| Billing information | Company billing address, tax details, payment reference (processed by our payment provider — we do not store full card numbers) | When you subscribe to a paid plan or receive an invoice |
| Technical & usage data | IP address, browser and device type, pages viewed, approximate location, cookie identifiers | Automatically, when you visit our website or use the platform |
We do not knowingly collect sensitive categories of personal data (such as health or biometric data) through our website or platform, and we ask that you avoid including this kind of information in a contact form or support message.
3 How we use your information
We use the information above to: respond to your enquiries and provide the platform you ask for; create and manage your account; process payments and issue invoices; provide customer support; send service-related communications (for example, about a scheduled maintenance window); improve our website and platform; and meet our legal and tax obligations.
With your consent, we may also send you occasional product updates or marketing emails — you can opt out of these at any time using the unsubscribe link in the email or by contacting us directly.
Our reason for these uses is, depending on the situation: performing a contract with you, pursuing a legitimate business interest that does not override your rights, your consent, or a legal obligation we need to meet.
6 International transfers & where data is stored
FinOps Control serves customers in many countries, and the cloud infrastructure we and our providers use may store or process data in data centers located in a different country from where you are. Where this happens, we take reasonable steps to make sure the receiving party protects your information to an appropriate standard, including through contractual safeguards with our providers.
7 How long we keep information
We keep personal data for as long as needed for the purpose it was collected — for example, for the duration of an active account or customer relationship, plus a reasonable period afterward to meet our accounting, tax, and legal obligations, or to resolve disputes. When we no longer need it, we delete or anonymize it.
8 How we protect your information
We apply layered safeguards to our own systems: role-based access control and multi-factor authentication for internal systems, encryption of data in transit and, where appropriate, at rest, audit logging, and regular vulnerability testing of our own infrastructure. Cloud account connections used to read your cost and billing data (see Section 10) are read-only by default. No system is completely immune to risk, but we work to keep these safeguards current and to respond quickly if something goes wrong, including notifying affected parties and the relevant authority where required by law.
9 Your rights, wherever you're located
Regardless of where you're located, you generally have the right to: ask us to confirm what personal data we hold about you and obtain a copy of it; ask us to correct information that is inaccurate or incomplete; ask us to delete your personal data, subject to any legal or contractual reason we may need to keep it; object to, or ask us to restrict, certain uses of your personal data; withdraw consent at any time where we rely on consent (for example, for marketing emails); and request that we transfer certain data to you or another provider in a portable format, where technically feasible.
Depending on where you're located, you may also have specific statutory rights that go further — for example, rights under the EU or UK General Data Protection Regulation, the California Consumer Privacy Act, or an equivalent data protection law where you live. We honor the version of these rights that applies to you based on your location, and you can also lodge a complaint with your local data protection authority if you believe we have not handled your personal data properly.
To exercise any of these rights, contact us using the details in Section 14. We will respond within the timeframe required by the law that applies to you, and we may need to verify your identity before acting on a request.
10 Cloud account data we process on your behalf
To show you cost, usage, and optimization data, FinOps Control connects to your cloud provider accounts (such as AWS, Microsoft Azure, or Google Cloud) using credentials and permissions you configure — typically read-only access scoped to billing, usage, and resource metadata. We process this data only to provide the platform's features to you, according to your instructions and our agreement with you, and not for our own independent purposes. Where this data includes personal data belonging to your own organization's employees or customers (for example, resource tags containing names), you remain the data controller for that information and we act as your data processor.
If you are an individual whose data has been processed in this way and you have a query, please contact the organization that connected the account, as they are best placed to handle your request; we will support them in doing so.
11 Children's privacy
Our platform is intended for businesses and professionals, not children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us so we can remove it.
12 Links to other websites
Our website may contain links to third-party websites or services we do not control, including cloud provider consoles and partner sites. This Policy does not apply to those third parties, and we encourage you to review their own privacy notices before providing them with information.
13 Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or in the law. If we make a material change, we will update the effective date at the top of this page and, where appropriate, notify you directly. We encourage you to review this page periodically.
14 Contact us
If you have a question about this Policy or how we handle your personal data, or wish to exercise any of your rights, please contact us:
- Email: support@finopscontrol.com
- Website: www.finopscontrol.com