Privacy Policy
Last updated: August 20, 2026
1. Who We Are
This Privacy Policy explains how CloudKnots Ltd ("CloudKnots", "we", "us") collects, uses, and protects personal data when you use Theama, our operational intelligence dashboard at dashboard.cloudknots.com and our mobile applications (the "Service").
2. Information We Collect
- Account information — name, email address, password (stored as a salted hash), company name, role, company size, and industry vertical you provide at registration.
- Connected integration data — when you authorize an integration (e.g. HubSpot, Mailchimp, FreshBooks, Google Analytics, QuickBooks, Stripe, AWS, security tools), we retrieve the business metrics needed to render your dashboard, such as revenue figures, pipeline stats, campaign performance, website analytics, invoice summaries, and security alert counts. OAuth access and refresh tokens are stored encrypted-at-rest in our database and are used only to fetch this data on your behalf.
- Billing information — payments are processed by Stripe; we never store your full card details.
- Usage data — log data such as IP address, device/browser type, and feature usage, used for security and product improvement.
3. How We Use Information
- Provide, personalize, and maintain your dashboard and AI insights.
- Send service emails (trial reminders, alerts, digests) — you can unsubscribe from marketing messages at any time.
- Process subscriptions and prevent fraud or abuse.
- Improve the Service using aggregated, de-identified analytics.
We do not sell your personal data or your business data to anyone.
4. Google API Services — Limited Use Disclosure
Theama's use and transfer of information received from Google APIs (including Google Analytics data) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Analytics data is used only to display your website metrics inside your own dashboard. It is never transferred to third parties, never used for advertising, and never read by humans except with your explicit consent, for security purposes, or to comply with law.
5. How We Share Information
- Service providers — infrastructure hosting, Stripe (payments), Resend (transactional email), and AI model providers that process dashboard metrics to generate insights, each bound by contractual confidentiality.
- Your team — dashboard configuration and metrics are shared with team members you invite.
- Legal — where required by law, or to protect the rights, safety, and security of CloudKnots and our users.
6. Data Retention and Deletion
We keep your data while your account is active. When you disconnect an integration, its stored tokens are removed. When you delete your account (or on request to admin@cloudknots.com), we delete or de-identify your personal data and connected-integration data within 30 days, except where retention is required by law (e.g. billing records).
7. Security
We protect data with encryption in transit (TLS), hashed passwords, httpOnly session cookies, role-based access controls, per-team data scoping, and signed payment webhooks. No method of transmission or storage is 100% secure, but we work continuously to safeguard your information.
8. AI Advisor — How Your Data Is Protected
When you use Theama's AI advisor, your data is isolated and minimised by design. We never rely on the AI to police its own boundaries — isolation is enforced by the systems around it:
- Your identity is verified on every request. A cryptographically signed token issued when you log in determines your data boundary; it cannot be spoofed or overridden by anything sent from your browser or app.
- The AI only ever sees a minimal, aggregated snapshot of your own account. When you ask a question, the advisor receives only high-level summary figures (for example, "YTD revenue" or "security score") assembled on our servers from your account only — never raw customer lists, individual invoices, contact details, or account numbers, and never another customer's data.
- The AI has no database access. It cannot run queries or tools; it can only reason over the small summary handed to it, so it is architecturally incapable of reaching another tenant's data.
- Every question is screened. Attempts to extract system instructions, raw records, or another customer's data are blocked before they ever reach the model.
- Every response is redacted. An automatic filter strips emails, card and account numbers, and similar identifiers from AI replies, while leaving ordinary business figures intact.
- Every AI request is logged. Account owners can review a full, timestamped audit log of AI activity for their team from inside the app.
- Your data is not used to train models. Summary metrics are sent to our AI model provider solely to generate your insight, under contractual confidentiality and no-training / no-retention terms. Our staff do not read your AI conversations except with your consent, for security, or to comply with law.
For a fuller, plain-language explanation, see our Security & Data Protection page.
9. Cookies
We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies.
10. Your Rights
Depending on your location, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. To exercise any of these rights, contact admin@cloudknots.com and we will respond within 30 days.
11. International Transfers
Data may be processed in countries other than your own. Where required, we use appropriate safeguards such as standard contractual clauses.
12. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect data from children.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be announced by email or in-app notice, and the "Last updated" date above will change.
14. Contact
Privacy questions or requests: admin@cloudknots.com — CloudKnots Ltd.