Privacy Policy

Last updated: July 3, 2026

Draft for review — this policy is grounded in AELIQ's current architecture and data-handling practices but has not yet received founder / legal sign-off. Do not treat it as final approved text until that review is complete.

1. Who we are

AELIQ ("AELIQ", "we", "us") is a technology financial management platform that unifies Cloud, AI, SaaS, and Security spend into a single console for mid-market enterprises, primarily in India and APAC. This policy describes how we collect, use, and protect data when you use our product (the "Service").

2. What data we collect

3. How we use data

Data is used solely to operate the Service: normalizing and displaying your spend, generating savings and anomaly recommendations, producing compliance exports, and securing your account. We do not sell customer data, and we do not use your billing or invoice data to train third-party AI models.

4. Data residency

All customer data is stored in Azure Central India (Pune), with disaster recovery in Azure South India (Chennai). A weekly automated residency-verification check confirms no customer resource is provisioned outside these regions.

5. AI processing

Classification, tagging, PII detection, root-cause analysis, and narrative generation run on a locally-hosted AI model (Ollama) within our infrastructure — this data never leaves our region for these purposes. In a narrow fallback case — when a small number of fields cannot be extracted from an invoice locally — the affected fields only (never the full document) may be sent to Anthropic's Claude API under a zero-data-retention agreement (anthropic-beta: no-training), with no use for model training.

6. Sub-processors

7. Data retention

Spend and invoice data is retained for the life of your account plus a reasonable transition period after cancellation. Audit log entries are append-only and retained for a minimum of 3 years to support compliance evidence (SOC 2 Type II, RBI CSF, SEBI CSCRF).

8. Your rights under DPDP

Under India's Digital Personal Data Protection Act, you may request erasure of your personal data. Erasure requests are tracked and actioned on a 30-day SLA (soft-delete, followed by hard-delete on confirmation). To submit a request, contact us using the details below.

9. Security

Credentials and secrets are encrypted at rest. All traffic is encrypted in transit (HTTPS). Access to customer data is tenant-isolated at the database level. We collect SOC 2 Type II evidence continuously from day one of operation.

10. Contact

Questions about this policy or data requests: privacy@costpilot.ai