Privacy Policy
Last updated: July 3, 2026
Draft for review — this policy is grounded in AELIQ's current architecture and data-handling practices but has not yet received founder / legal sign-off. Do not treat it as final approved text until that review is complete.
1. Who we are
AELIQ ("AELIQ", "we", "us") is a technology financial management platform that unifies Cloud, AI, SaaS, and Security spend into a single console for mid-market enterprises, primarily in India and APAC. This policy describes how we collect, use, and protect data when you use our product (the "Service").
2. What data we collect
- Account data: name, work email, company name, role, authentication credentials.
- Billing and cost data: cloud provider billing exports (AWS, Azure, GCP), SaaS and AI vendor invoices you upload or connect, normalized into the FOCUS spend schema.
- Connector credentials: read-only cloud role ARNs / service principals you provision for ingestion — never write-capable credentials.
- Usage data: product interaction logs and audit events needed for security and support.
3. How we use data
Data is used solely to operate the Service: normalizing and displaying your spend, generating savings and anomaly recommendations, producing compliance exports, and securing your account. We do not sell customer data, and we do not use your billing or invoice data to train third-party AI models.
4. Data residency
All customer data is stored in Azure Central India (Pune), with disaster recovery in Azure South India (Chennai). A weekly automated residency-verification check confirms no customer resource is provisioned outside these regions.
5. AI processing
Classification, tagging, PII detection, root-cause analysis, and narrative generation run on a locally-hosted AI model (Ollama) within our infrastructure — this data never leaves our region for these purposes. In a narrow fallback case — when a small number of fields cannot be extracted from an invoice locally — the affected fields only (never the full document) may be sent to Anthropic's Claude API under a zero-data-retention agreement (anthropic-beta: no-training), with no use for model training.
6. Sub-processors
- Microsoft Azure — cloud hosting and data storage (Central/South India).
- Anthropic — narrow, zero-retention invoice-field extraction fallback only.
- Stripe — subscription billing and payment processing.
- Resend / SendGrid / AWS SES — transactional email and invoice-email ingestion.
- Sentry — error monitoring.
7. Data retention
Spend and invoice data is retained for the life of your account plus a reasonable transition period after cancellation. Audit log entries are append-only and retained for a minimum of 3 years to support compliance evidence (SOC 2 Type II, RBI CSF, SEBI CSCRF).
8. Your rights under DPDP
Under India's Digital Personal Data Protection Act, you may request erasure of your personal data. Erasure requests are tracked and actioned on a 30-day SLA (soft-delete, followed by hard-delete on confirmation). To submit a request, contact us using the details below.
9. Security
Credentials and secrets are encrypted at rest. All traffic is encrypted in transit (HTTPS). Access to customer data is tenant-isolated at the database level. We collect SOC 2 Type II evidence continuously from day one of operation.
10. Contact
Questions about this policy or data requests: privacy@costpilot.ai