On this page
This California Consumer Privacy Act Privacy Notice ("Notice") supplements the Privacy Policy and General Terms of Subscription applicable to FigureIQ and describes how Xelpmoc Design and Tech Limited, a company incorporated under the laws of India and having its registered office at No. 57, 13th Cross, Novel Business Park, Hosur Road, Anepalya, Adugodi, Bangalore - 560030, Karnataka, India ("Company," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes Personal Information relating to California residents in connection with the FigureIQ intelligent document processing platform and related software-as-a-service offerings ("Services").
This Notice is intended to address the disclosure requirements of the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations (collectively, the "CCPA"). Capitalized terms used but not defined in this Notice have the meanings given to them in the applicable General Terms of Subscription or, if not defined there, the CCPA.
Applicability of the CCPA
The CCPA generally applies to a for-profit entity that does business in California and satisfies one or more statutory thresholds, including: (i) having annual gross revenue in excess of a specified amount (approximately US$26.6 million for 2026, as periodically adjusted for inflation); (ii) annually buying, selling, or sharing the Personal Information of 100,000 or more California consumers or households; or (iii) deriving 50% or more of annual revenue from selling or sharing California residents' Personal Information. These thresholds are assessed at the level of the Company as a whole - Xelpmoc Design and Tech Limited, a company listed on the National Stock Exchange of India and BSE Limited - and not solely by reference to the revenue or California user base of the FigureIQ Services.
Based on the Company's current annual revenue and scale of operations, the Company has determined that it does not currently meet the CCPA's revenue threshold, and has no indication that it meets either of the CCPA's other two thresholds. On this basis, the CCPA does not currently apply to the Company's processing of Personal Information in connection with the Services. The Company nonetheless provides this Notice, and extends the CCPA-aligned rights and practices described in it to California residents, as a matter of good practice and transparency, and to support its Subscribers' own compliance obligations, and will reassess this determination as the Company's business grows.
Scope and Role of the Company
The Services enable subscribers to upload, submit, transmit, process, and manage documents and related data through the FigureIQ platform. In connection with the Services, we may process Personal Information relating to: (i) our subscribers and their authorized users; and (ii) individuals whose information is contained in documents, data, images, files, or other materials uploaded, submitted, or otherwise transmitted to or through the Services by subscribers or their authorized users ("End Clients").
Where we process Personal Information on behalf of a subscriber pursuant to the subscriber's instructions and the applicable subscription terms, we act as a service provider (and not a contractor) under the CCPA. This includes, in particular: uploading, extracting, analyzing, classifying, and otherwise processing documents and data submitted by a subscriber through the Services, including through our use of Google LLC's artificial intelligence and machine learning API services described below; storing documents that a subscriber elects to retain using DocuVault; and retrieving or synchronizing data through a subscriber's connected Google Drive or QuickBooks account, in each case only as authorized and instructed by the subscriber. In such circumstances, the subscriber is solely responsible for the content, legality, accuracy, completeness, quality, and integrity of all documents, files, data, and other information uploaded, submitted, transmitted, stored, or otherwise made available through the Services, including any Personal Information or Sensitive Personal Information contained therein. The subscriber is also responsible for providing any required notices to, and obtaining any required consents, authorizations, rights, permissions, and releases from, the relevant individuals, including End Clients. We process such Personal Information only as necessary to provide, secure, maintain, and support the Services, or as otherwise permitted by the applicable subscription terms and applicable law. When acting as a service provider, we will not combine or use Personal Information received from or on behalf of one subscriber to develop, improve, or train artificial intelligence or machine-learning models for the benefit of other subscribers or the Company generally, except (i) where the underlying information has first been aggregated or de-identified in accordance with the CCPA, or (ii) where the subscriber has separately and specifically authorized such use. Where we use a third-party artificial intelligence or machine learning service, such as Google LLC's API services, to analyze, extract, or verify data from documents on our behalf, we require that such service provider be contractually restricted from using that data to train or improve its own models, consistent with the limitations described in this paragraph. Consistent with this requirement, our agreement with Google LLC for these services is governed by Google's enterprise (paid) API terms, which contractually prohibit Google from using such data to train or improve its own models.
Where we determine the purposes and means of processing Personal Information, we act as a business under the CCPA, including in relation to: creating, administering, authenticating, and billing subscriber and authorized user accounts; sending service, administrative, and marketing communications; measuring website and in-app interactions through Google Analytics, Google Ads, Google's Display Network, Taboola, Inc., and Outbrain Inc., as described in the "Disclosure of Personal Information" section below; monitoring the security, integrity, and performance of the Services across all subscribers; and complying with our own legal, regulatory, and contractual obligations. We also act as a business when we use aggregated or de-identified information, or subscriber-specific information with the subscriber's separate authorization, to develop or improve the underlying document-processing and artificial intelligence capabilities of the Services generally, as described above.
Categories of Personal Information We Collect
Depending on how a subscriber or authorized user uses the Services, we may collect or process the following categories of Personal Information, including Personal Information contained in Subscriber Data or End Client Data uploaded to the Services:
- Identifiers. Examples include name, alias, postal address, email address, telephone number, account name, username, password or credential-related information, unique personal identifier, online identifier, internet protocol address, and other similar identifiers.
- Customer records information. Examples include signature, address, telephone number, financial information, billing-related information, or other information contained in documents submitted to the Services that may fall within California Civil Code Section 1798.80(e). Full payment card numbers and security codes are entered directly into, and stored by, our payment processor, Stripe, Inc., whether for recurring subscription billing or one-time top-up page purchases; the Company itself receives only billing-related information such as billing name, address, plan or top-up type, and transaction status, not the full card number.
- Protected classification characteristics. Examples may include age, gender, marital status, nationality, citizenship, or other protected characteristics, but only to the extent such information is included in documents or data uploaded by subscribers or their authorized users.
- Commercial information. Examples include subscription package, plan type, page usage, top-up purchases, transaction records, billing cycle information, cancellation history, and records relating to Services obtained or considered.
- Internet or other electronic network activity information. Examples include account login information, usage data, access logs, device information, browser information, IP address, interactions with the Platform, page processing activity, error logs, and security event information.
- Geolocation data. Approximate location may be inferred from IP address or similar technical information.
- Audio, electronic, visual, thermal, olfactory, or similar information. Electronic or visual information may be processed where subscribers upload documents, images, videos, or files containing such information.
- Professional or employment-related information. Examples may include job title, employer, business contact details, professional credentials, or employment-related information contained in subscriber account records or documents uploaded to the Services.
- Education information. Education-related information may be processed where included in documents or data uploaded by subscribers or authorized users.
- Inferences. We may derive limited inferences from account usage, subscription activity, and service interactions for purposes such as service administration, support, product improvement, security, and usage monitoring.
- Sensitive Personal Information. Depending on the content uploaded by subscribers or authorized users, the Services may process Sensitive Personal Information, including account credentials, government identifiers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic information, information concerning a consumer's sex life or sexual orientation, a financial account, debit card, or credit card number in combination with any required security code, access code, or password permitting access to the account (processed directly by our payment processor, Stripe, Inc., rather than by the Company), health information, biometric information, contents of communications where we are not the intended recipient, or other sensitive information as defined by the CCPA.
The categories listed above reflect the possible scope of information that may be processed through an intelligent document processing platform. The specific categories collected or processed in any instance depend on the information provided by the subscriber, authorized users, or End Clients, and on the documents and data uploaded to the Services. The Company does not determine, control, or assume responsibility for the substance of documents or other materials uploaded by subscribers or authorized users, including any Personal Information or Sensitive Personal Information contained in such materials.
Sources of Personal Information
We may collect Personal Information from the following categories of sources:
- Subscribers and authorized users. We collect information provided during account registration, subscription selection, billing, support interactions, communications, and use of the Services.
- Documents and data uploaded to the Services. We process Subscriber Data and End Client Data submitted, uploaded, or transmitted to or through the Services by subscribers or authorized users.
- Connected third-party platforms and integrations. Where a subscriber or authorized user connects the Services to a third-party platform, such as Google Drive as a document source or QuickBooks for two-way accounting data synchronization, we may receive Personal Information directly from that platform, including documents retrieved from a connected Google Drive account and vendor, customer, or chart-of-accounts records retrieved from a connected QuickBooks account, in each case only as authorized by the subscriber's use of the integration.
- Service usage and technical systems. We collect technical information generated through use of the Platform, including log data, usage data, security data, page processing information, and device or network information.
- Service providers and third-party infrastructure providers. We may receive or generate information through cloud hosting, storage, security, analytics, support, payment, or other service providers used to deliver the Services.
- Public, regulatory, or legal sources. We may collect information where necessary for legal compliance, enforcement of rights, dispute resolution, or cooperation with regulatory authorities.
Purposes for Collecting and Using Personal Information
We may collect, use, retain, disclose, or otherwise process Personal Information for the following business and commercial purposes:
- To provide, operate, maintain, host, and support the Services and the FigureIQ platform.
- To process documents and measure usage by processed document pages.
- To create, administer, authenticate, and secure subscriber and authorized user accounts.
- To manage subscription packages, billing cycles, payments, top-up pages, upgrades, downgrades, cancellations, and related account administration.
- To provide customer support, respond to inquiries, resolve errors, and communicate regarding service availability, changes, updates, and administrative matters.
- To monitor usage of the Services and verify compliance with subscription terms, usage limits, security requirements, and applicable law.
- To protect the integrity, availability, performance, and security of the Services, including detecting, preventing, investigating, and responding to unauthorized access, malware, abuse, fraud, security incidents, and other harmful activity.
- To store, back up, restore, and delete data in accordance with applicable subscription terms, account settings, retention practices, and legal requirements.
- To improve, modify, enhance, and develop the Services and related features and functionality for the benefit of the subscriber whose Personal Information is being processed, including through the use of aggregated or de-identified information, or subscriber-specific information with the subscriber's separate authorization, to improve the underlying document-processing and artificial intelligence capabilities of the Services generally, in each case consistent with the Scope and Role of the Company section above.
- To send product, service, and promotional communications, subject to applicable law and available opt-out rights.
- To enforce contractual rights, protect legal interests, resolve disputes, and comply with legal, regulatory, arbitral, court, governmental, or law enforcement obligations.
- To perform other purposes disclosed at or before the time of collection or otherwise permitted by the CCPA or applicable law.
Notice Regarding Sensitive Personal Information
We do not require subscribers or authorized users to upload Sensitive Personal Information unless such information is necessary for the subscriber's intended use of the Services. Because the Services process documents selected and uploaded by subscribers or authorized users, Sensitive Personal Information may be included in Subscriber Data or End Client Data. Subscribers are solely responsible for determining whether to upload such information and for ensuring that they have all rights, permissions, notices, consents, authorizations, and legal bases required to submit, store, transmit, and process such information through the Services. The Company is not responsible for the inclusion, accuracy, lawfulness, or appropriateness of any Personal Information or Sensitive Personal Information contained in uploaded documents, files, data, or other materials.
We use Sensitive Personal Information only for purposes permitted by the CCPA, including to provide the Services, maintain account security and integrity, process transactions, perform services requested by the subscriber, prevent fraud or security incidents, comply with law, and undertake activities reasonably expected in connection with the Services. We do not use Sensitive Personal Information for the purpose of inferring characteristics about a California resident unless expressly disclosed and permitted by applicable law.
Disclosure of Personal Information
We may disclose Personal Information to the following categories of recipients:
- Service providers and contractors. We may disclose Personal Information to hosting providers, cloud infrastructure providers, storage providers, payment processors, security vendors, analytics providers, support tools, communications providers, and other vendors that process information on our behalf. These currently include Amazon Web Services (cloud hosting and storage), Google LLC (where a subscriber connects a Google Drive account as a document source, and separately as a sub-processor providing artificial intelligence and machine learning API services used to analyze, extract, and verify data from documents processed through the Services), Intuit Inc. (where a subscriber connects a QuickBooks account for two-way data synchronization - including retrieving vendor, customer, currency, item, tax code, payment term, account, and other configuration records from the subscriber's QuickBooks account, and pushing sales and cost transaction records to that account - and, where the subscriber elects to use the Platform's upload-to-QuickBooks feature, transmitting source document attachments, which may contain Personal Information or Sensitive Personal Information about End Clients, to the subscriber's QuickBooks account), Stripe, Inc. (payment processing for recurring subscription billing and one-time top-up page purchases), and Twilio SendGrid (delivery of transactional and service-related emails). This list of third-party service providers is complete; there are no additional cloud, payment, analytics, communications, or security vendors.
- Subscribers and authorized users. We may make Subscriber Data, End Client Data, extracted data, account information, usage information, and service outputs available to the subscriber and its authorized users as directed or enabled through the Services.
- Professional advisers. We may disclose information to auditors, accountants, legal counsel, consultants, insurers, and other professional advisers where reasonably necessary for business, legal, compliance, or risk management purposes.
- Authorities, courts, tribunals, and regulators. We may disclose information where required by law, legal process, court order, regulatory requirement, governmental request, or to cooperate with regulatory authorities and investigating agencies.
- Transaction counterparties. We may disclose information in connection with an actual or proposed merger, acquisition, financing, restructuring, sale of assets, corporate transaction, insolvency, or similar transaction involving all or part of our business.
- Other third parties at the subscriber's direction. We may disclose information to third parties where the subscriber or authorized user directs or enables such disclosure through use of the Services.
- Advertising and analytics partners. We use Google Analytics to measure interactions with our website and within the Services, and we use Google Ads (AdWords) and Google's Display Network - which places advertising on websites and apps monetized through Google AdSense - together with Taboola, Inc. and Outbrain Inc., to deliver and measure advertising promoting the Services. These tools use cookies or similar technologies that may allow Google LLC, Taboola, Inc., and Outbrain Inc. to collect Personal Information about your interactions with our website and the Services for their own or joint advertising and analytics purposes. This disclosure is addressed further in the "Sale or Sharing of Personal Information" and "Categories of Personal Information Sold or Shared" sections below. Our Google Analytics account has Google Signals enabled, meaning Google may associate the analytics data described above with information from a visitor's or user's own Google Account (where that person is signed in to a Google service and has enabled ad personalization on their Google Account), allowing Google to report on that person's activity across multiple devices and to build advertising audiences for remarketing. We have also enabled Ads Personalization/remarketing (Google Analytics' "Advanced settings to allow for ads personalization") and granular location and device data collection, meaning Google Analytics collects more precise geographic and device information than its default configuration and may use analytics data to build and serve interest-based or remarketing advertising audiences through Google Ads. We have not enabled data sharing between our Google Analytics account and other Google products and services.
- Product analytics and session replay providers. We use PostHog Inc. for product analytics, web analytics, session replay, heatmaps, and related behavioral analytics on our website and within the Services. Session replay records masked reconstructions of a visitor's or user's browsing sessions - all on-screen text and form field contents are masked, and recording never occurs on pages that display the content of an uploaded document, Extracted Data, or a report - for the purpose of understanding and improving the usability of our website and Services. We also use PostHog's autocapture, heatmap, dead-click, rage-click, and Core Web Vitals features to automatically record clicks, scrolling, and page-performance information. Unlike Google Analytics, which discards the IP address after deriving an approximate location, PostHog retains the IP address associated with each event and uses it to derive approximate location information (such as country, region, city, postal code, and time zone); we have configured PostHog not to anonymize or truncate this IP address. PostHog acts solely as our own analytics service provider under a signed data processing agreement that restricts PostHog from using Personal Information for its own independent purposes; we do not treat PostHog's processing of Personal Information as a sale or sharing of Personal Information under the CCPA.
Categories of Personal Information Disclosed for a Business Purpose
In the preceding twelve months, we may have disclosed the following categories of Personal Information for a business purpose, depending on subscriber use of the Services and the content uploaded to the Platform:
Not every category listed below is disclosed to every category of recipient identified in the "Disclosure of Personal Information" section above; the specific category disclosed, and the recipient to whom it is disclosed, depends on the particular processing activity involved.
- Identifiers.
- Customer records information.
- Protected classification characteristics, if included in uploaded content.
- Commercial information.
- Internet or other electronic network activity information.
- Approximate geolocation data.
- Audio, electronic, visual, or similar information, if included in uploaded content.
- Professional or employment-related information.
- Education information, if included in uploaded content.
- Inferences.
- Sensitive Personal Information, if included in uploaded content or required for account security or service delivery.
Such disclosures may be made to service providers, contractors, subscribers and authorized users, professional advisers, regulators, authorities, transaction counterparties, or other recipients identified in this Notice.
Sale or Sharing of Personal Information
We do not sell Personal Information for monetary consideration. We also do not knowingly sell or share Personal Information of California residents under 16 years of age.
The CCPA defines "sale" and "sharing" broadly, and includes the disclosure of Personal Information to a third party for valuable consideration or for cross-context behavioral advertising purposes, even without a monetary payment.
We use Google Analytics to measure interactions with our website and within the Services, and we use Google Ads (AdWords) and Google's Display Network - which places advertising on websites and apps monetized through Google AdSense - together with Taboola, Inc. and Outbrain Inc., to deliver and measure search, display, and native advertising promoting the Services. Taboola and Outbrain deliver native "recommended content" style advertising units, typically shown alongside editorial content on publisher websites. These technologies place cookies or similar identifiers on your browser or device, which may allow Google LLC, Taboola, Inc., and Outbrain Inc. to receive Personal Information - such as identifiers, IP address, and information about your interactions with our website and the Services - for their own or joint advertising and analytics purposes. We treat this use of cookies and similar technologies as constituting a "sale" or "sharing" of Personal Information under the CCPA, regardless of how it is ultimately characterized.
We provide a "Do Not Sell or Share My Personal Information" link in the website footer and honour opt-out preference signals, including the Global Privacy Control, sent by a consumer's browser or device. California residents may also submit an opt-out request using the methods described in the "How to Submit a California Privacy Request" section below.
The "Do Not Sell or Share" link and Global Privacy Control support described above are live. Activating either the link or a Global Privacy Control signal denies both analytics and advertising consent and stops Google Analytics, Google Ads, Google's Display Network, Taboola, and Outbrain tags and cookies from loading.
Categories of Personal Information Sold or Shared
In the preceding twelve months, we have sold or shared the following categories of Personal Information, for the business or commercial purposes and with the categories of third parties described below, in connection with the advertising and analytics technologies described in the "Sale or Sharing of Personal Information" section above:
- Identifiers, such as cookie identifiers, device identifiers, and IP address - sold or shared with Google LLC (through Google Analytics, Google Ads, and Google's Display Network), Taboola, Inc., and Outbrain Inc., for the business purpose of delivering, measuring, and improving advertising, and for cross-context behavioral advertising.
- Internet or other electronic network activity information, such as website and in-app browsing, interaction, and usage data - sold or shared with the same categories of third parties identified above, for the same purposes.
- Inferences, such as interests or advertising segments inferred from browsing or usage activity - sold or shared with the same categories of third parties identified above, for advertising personalization and measurement purposes.
The Company does not currently sell or share any other category of Personal Information described in this Notice.
Retention of Personal Information
We retain Personal Information for as long as reasonably necessary and proportionate to fulfil the purposes for which it was collected or processed, including to provide the Services, administer accounts, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations. The specific retention periods and deletion mechanics that apply to documents and data processed through the Services, including documents stored using DocuVault, are described below.
Documents and data outside DocuVault. Uploaded source documents (such as scanned receipts, invoices, and other images or PDFs) and the data extracted from them using optical character recognition, visual document understanding, or other document-processing technology ("Extracted Data") are retained for a minimum period of seven (7) years, unless the subscriber or authorized user explicitly deletes the relevant document or Extracted Data using the "Delete" or "Delete file" controls in the Platform's user interface. Deletion initiated in this way takes effect immediately as a permanent, irreversible deletion; the Company does not perform a soft deletion or retain a recoverable copy of the deleted item.
Cancelling a Subscription Package (Bronze, Silver, or Gold) does not, by itself, result in deletion of any data. All data remains available to the subscriber for a minimum period of seven (7) years, whether or not the subscriber maintains a paid Subscription Package, for as long as the subscriber's account remains open.
Account deletion. If a subscriber deletes its account altogether, all of the subscriber's data is permanently deleted immediately, including uploaded files, Extracted Data, account settings, client lists, business settings, integrations with QuickBooks and Google Drive, team member records, identity and access management settings, workspace configuration, and subscription-related information.
Exceptions. The following records are not deleted upon account deletion: historical purchase records, historical credit (page) usage data, email correspondence with the Company, and current or historical support tickets raised by the subscriber. These records are retained for audit purposes and to inform product improvement, including through the analysis of user feedback.
Documents stored in DocuVault. DocuVault, the Company's optional document storage and organization feature, is subject to the same retention and account-deletion rules described above, with one difference: a document deleted from DocuVault is not deleted immediately. It is instead moved to a "Trash" folder, where it is retained for thirty (30) days. During this 30-day period, the subscriber may restore the document from the Trash folder. A document is permanently and irreversibly deleted, and can no longer be restored, either (i) automatically at the end of the 30-day period, or (ii) earlier, if the subscriber permanently deletes it from the Trash folder, whether individually or by using a "Clear Trash" function that permanently deletes all documents then in the Trash folder. As with documents outside DocuVault, this is a hard deletion; the Company does not retain a further recoverable copy once a document is permanently deleted from the Trash folder or the 30-day period expires.
Top-up page balances, subscription page balances, billing records, system logs, and other operational records may be retained for different periods depending on their purpose, applicable law, and legitimate business requirements.
Analytics data. Data collected through Google Analytics is retained by Google for fourteen (14) months of event data and fourteen (14) months of user data, in each case measured from an individual's most recent activity (the retention period resets upon new activity), in accordance with our Google Analytics account configuration.
PostHog analytics and session replay data. Event data collected through PostHog is retained for twelve (12) months, and session replay recordings are retained for thirty (30) days, in each case in accordance with our PostHog project configuration.
California Privacy Rights
Subject to applicable exceptions and verification requirements, California residents may have the following rights under the CCPA:
- Right to know/access. The right to request that we disclose the categories and specific pieces of Personal Information we have collected about the consumer, the categories of sources from which the information was collected, the purposes for collecting, selling, or sharing the information, and the categories of third parties to whom the information was disclosed.
- Right to delete. The right to request deletion of Personal Information collected from the consumer, subject to applicable exceptions.
- Right to correct. The right to request correction of inaccurate Personal Information maintained about the consumer.
- Right to opt out of sale or sharing. The right to opt out of the sale or sharing of Personal Information, if applicable.
- Right to limit use and disclosure of Sensitive Personal Information. The right to limit the use and disclosure of Sensitive Personal Information where such information is used or disclosed for purposes beyond those permitted by the CCPA.
- Right of non-discrimination. The right not to receive discriminatory treatment for exercising CCPA rights.
- Right to portability. The right to receive Personal Information in a portable and, to the extent technically feasible, readily usable format where required by the CCPA.
Where we process Personal Information as a service provider on behalf of a subscriber, we may refer the request to the relevant subscriber or require the requester to submit the request directly to that subscriber. We will support subscribers in responding to verifiable consumer requests to the extent required by applicable law and the applicable subscription terms.
How to Submit a California Privacy Request
California residents may submit a privacy request using the following methods:
- Email: privacy@figureiq.ai
- Webform: A dedicated webform will also be provided, here
- Toll-free number: Not offered. The Company relies on the online-only business exemption described below and has no current plans to adopt a toll-free number.
- Postal address: Xelpmoc Design and Tech Limited, No. 57, 13th Cross, Novel Business Park, Hosur Road, Anepalya, Adugodi, Bangalore - 560030, Karnataka, India, Attn: Privacy Officer
As an exclusively online business, the Company may rely on the exemption from the toll-free number requirement available under the CCPA's implementing regulations where it maintains a direct relationship with the California residents who interact with the Services and provides at least one online method, such as the email address or web form above, for submitting requests. This exemption applies.
Verification of Requests
We will verify privacy requests in accordance with the CCPA. The information required for verification may vary depending on the nature of the request, the sensitivity of the Personal Information at issue, and the context in which the information was collected. We may request information sufficient to verify the requester's identity and authority, including account identifiers, contact information, transaction information, or other information reasonably necessary to confirm the request.
We will use information provided for verification only for the purpose of verifying and responding to the request, except as otherwise permitted by law. If we cannot verify a request, we may deny the request in whole or in part and will explain the basis for the denial to the extent required by law.
We will respond to a verified request within forty-five (45) days of receipt. Where reasonably necessary, taking into account the complexity and number of requests received, we may extend this period by an additional forty-five (45) days, provided that we inform the requester of any such extension, and the reason for it, within the initial 45-day period.
Appeals
Although the CCPA does not require a formal appeal process, if we decline to act on a California resident's request, in whole or in part, the resident may appeal that decision by contacting us using the details in the "Contact Information" section below and requesting that the decision be reviewed. We will respond to an appeal within sixty (60) days of receipt. If we deny the appeal, we will provide the resident with a written explanation of the reasons for the denial. We apply this appeals process to California residents as a matter of consistent practice with the appeal rights available to consumers under other applicable U.S. State Privacy Laws, as described in our Privacy Policy.
Authorized Agents
A California resident may designate an authorized agent to submit a CCPA request on the resident's behalf. We may require the authorized agent to provide proof of authorization and may require the consumer to verify their identity directly with us or confirm that the agent has permission to submit the request, unless an exception applies under the CCPA.
Requests Relating to End Client Data
Because End Client Data is typically collected, selected, and uploaded to the Services by subscribers or authorized users, we may not have a direct relationship with the relevant End Client. The subscriber, and not the Company, is responsible for the End Client Data and for any Personal Information or Sensitive Personal Information contained in documents, files, data, or other materials uploaded to the Services by or on behalf of the subscriber. Requests relating to End Client Data should be directed to the subscriber that collected or uploaded the relevant information unless we identify that we are acting as a business with respect to the particular Personal Information. If we receive a request from an End Client regarding Personal Information that we process on behalf of a subscriber, we may refer the End Client to the subscriber and may notify the subscriber of the request.
Children's Personal Information
The Services are intended for business and professional use and are not directed to children. We do not knowingly sell or share Personal Information of California residents under 16 years of age. Subscribers must not upload children's Personal Information to the Services unless they have all rights, consents, authorizations, and legal bases required by applicable law.
Security
We implement reasonable security procedures designed to help protect Subscriber Data and End Client Data from security attacks and unauthorized access, disclosure, alteration, and destruction. These procedures include identity and access management controls that allow a subscriber to manage which of its authorized users may access particular data, features, or client accounts within the Services. Use of the Services necessarily involves transmission of information over networks and to cloud providers that may not be owned, operated, or controlled by the Company. No security procedure is error-free, and we do not guarantee that transmissions or storage of Personal Information will always be secure or that unauthorized third parties will never defeat security measures.
International Processing
The Company is incorporated in India and provides the Services using systems, personnel, infrastructure, and service providers that may be located in India, the United States, or other jurisdictions. Personal Information may therefore be transferred to, stored in, or processed in jurisdictions outside California or the United States, where privacy laws may differ from California law. We process such information in accordance with this Notice, the applicable subscription terms, and applicable law.
Changes to this Notice
We may update this Notice from time to time. The updated Notice will be effective as of the date posted or otherwise communicated, unless a later effective date is stated. Where required by law, we will provide additional notice or obtain consent before using Personal Information for materially different purposes.
Contact Information
For questions regarding this Notice or our privacy practices, contact us at:
Xelpmoc Design and Tech Limited
No. 57, 13th Cross, Novel Business Park, Hosur Road, Anepalya, Adugodi, Bangalore - 560030, Karnataka, India
Email: privacy@figureiq.ai
Attention: Privacy Officer