On this page
This Privacy Policy ("Policy") is issued by Xelpmoc Design and Tech Limited, a company incorporated under the laws of India and having its registered office at No. 57, 13th Cross, Novel Business Park, Hosur Road, Anepalya, Adugodi, Bangalore - 560030, Karnataka, India ("Company", "Xelpmoc", "we", "us" or "our"). This Policy governs the collection, receipt, storage, access, use, processing, disclosure, transfer, retention and protection of Personal Data in connection with the Company's FigureIQ platform, website, applications, products, tools, software, interfaces and related services made available by or on behalf of the Company (collectively, the "Services"/ "Platform").
This Policy is supplemental to, and shall be read together with, the applicable subscription agreement, order form, terms of use, service terms, data processing terms, statements of work and any other written agreement entered into between the Company and a Subscriber (collectively, the "Agreement"). In the event of any inconsistency between this Policy and the Agreement, the Agreement shall prevail to the extent of such inconsistency, unless expressly stated otherwise.
By accessing or using the Services, or by transmitting, uploading, submitting, enabling access to, or otherwise making available any Personal Data to the Company, each Subscriber, authorised user and other relevant person confirms that they have read, understood and agreed to this Policy. Where a Subscriber provides or makes available Personal Data relating to any End Client, employee, contractor, officer, representative, customer, user or other third party, the Subscriber represents and warrants that it has provided all legally required notices and obtained all legally required consents, authorisations and permissions for the Company to process such Personal Data in accordance with this Policy and the Agreement.
Definitions
For purposes of this Policy, unless the context otherwise requires:
- Authorised User. means any employee, consultant, contractor, agent, representative or other individual authorised by a Subscriber to access or use the Services.
- End Client. means any customer, client, counterparty, employee, consultant, contractor or other person whose information is submitted, uploaded, transmitted or otherwise made available to the Company by or on behalf of a Subscriber through or in connection with the Services.
- Personal Data. means any information relating to an identified or identifiable natural person and includes, where applicable, personal information, personal data, Sensitive Personal Data or Information, and any other analogous category of information protected under applicable Indian law or U.S. State Privacy Laws.
- Sensitive Personal Data or Information or "SPDI" has the meaning ascribed to it under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, as amended from time to time. Where applicable U.S. State Privacy Laws use a different or additional term, such as "Sensitive Personal Information" under the CCPA, that term has the meaning given to it under the applicable law, which may differ in scope from SPDI, and this Policy addresses both categories as applicable depending on which law governs the relevant processing.
- Subscriber. means any person or entity that subscribes to, purchases, accesses or uses the Services, whether directly or through its Authorised Users.
- Usage Data. means technical, diagnostic, operational, statistical, analytical and usage-related information generated from or relating to use of the Services, including logs, device information, IP address, browser type, operating system, referring URLs, access times, feature usage, performance data and similar information.
- CCPA. means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations, in each case as amended from time to time.
- U.S. State Privacy Laws. means the CCPA and other comprehensive consumer privacy laws of U.S. states applicable to the Company's processing of Personal Data in connection with the Services, including, as applicable and in effect from time to time, the laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota, Rhode Island, Kentucky, Indiana, Tennessee, Alabama, Florida and Arkansas, together with the CCPA, in each case as such laws may be amended, replaced or supplemented from time to time.
- Consumer. means a natural person who is a resident of a U.S. state for purposes of the applicable U.S. State Privacy Laws, and includes, as applicable, a Subscriber who is a natural person, an Authorised User, and an End Client.
- Sale or Sell. means the exchange of Personal Data for monetary or other valuable consideration by the Company to a third party, as defined under the applicable U.S. State Privacy Law.
- Share or Sharing. means the disclosure of Personal Data by the Company to a third party for cross-context behavioural advertising, whether or not for monetary consideration, as defined under the CCPA.
- Targeted Advertising. means displaying advertisements to a Consumer that are selected based on Personal Data obtained from the Consumer's activities over time and across unaffiliated websites or online applications, in order to predict the Consumer's preferences or interests, as defined under the applicable U.S. State Privacy Law, and excludes advertising based on a Consumer's current visit to, or search on, the Company's own website or application.
Scope and Applicability
This Policy applies to Personal Data collected, received, accessed, stored, used or otherwise processed by the Company in connection with the Services. This Policy is intended to comply with the laws of India, including the Information Technology Act, 2000 and the rules framed thereunder, as well as applicable data protection and privacy laws of the United States, including the CCPA and other applicable U.S. State Privacy Laws, in each case to the extent such laws apply to the Company's processing of Personal Data in connection with the Services.
The Company's engineering, support, and administrative operations that process Personal Data in connection with the Services are based in India; accordingly, Indian law governs the Company's processing of Personal Data regardless of the location of the Company's Subscribers, Authorised Users, or End Clients. Because the Subscribers, Authorised Users, and End Clients whose Personal Data the Company processes in connection with the Services are generally located in the United States, applicable U.S. federal and state privacy laws, including the CCPA and other U.S. State Privacy Laws, also govern such processing to the extent they apply. This Policy is accordingly intended to reflect both bases of applicability, rather than the laws of either jurisdiction alone.
Where the Company processes Personal Data of a California resident in a manner subject to the CCPA, the Company's CCPA Privacy Notice supplements this Policy and provides the disclosures required under the CCPA. Where the Company processes Personal Data of a Consumer resident in another U.S. state with an applicable comprehensive privacy law, the rights described in the "U.S. State Privacy Rights" section below apply, in addition to this Policy.
The Services are intended for business and professional use. The Company primarily processes Personal Data on behalf of Subscribers and in accordance with the Subscriber's instructions, the Agreement and this Policy. The Subscriber remains responsible for determining the lawfulness, accuracy, completeness and appropriateness of Personal Data submitted to the Company.
Nature of Services
The Company provides Subscribers with access to its FigureIQ platform and related document processing services, including services measured by processed document pages. The Services may include upload, extraction, analysis, classification, indexing, storage, transmission, retrieval, reporting and other processing of documents and information submitted by Subscribers or their Authorised Users.
Documents and data may be submitted to the Services by direct upload or, where a Subscriber connects a supported third-party platform such as Google Drive or QuickBooks, retrieved from or synchronised with that platform as authorised by the Subscriber. Where a Subscriber connects a QuickBooks account, this synchronisation is two-way: the Company retrieves vendor, customer, currency, item, tax code, payment term, account, and other configuration records from the Subscriber's QuickBooks account, and pushes sales and cost transaction records to that account; the Platform also allows a Subscriber to upload source document attachments directly to QuickBooks through an upload-to-QuickBooks feature. The Services also include a document storage and organisation feature ("DocuVault") that a Subscriber may use, at its option, to store and organise documents within the Platform, and identity and access management tools that allow a Subscriber to manage which of its Authorised Users may access particular data, features, or client accounts within the Services.
The Company may, for the purpose of providing, securing, monitoring, improving and administering the Services, process Personal Data contained in account information, usage records, documents, metadata, communications and other information made available to the Company.
Categories of Personal Data Processed
The Company may collect, receive, access, store, use or otherwise process the following categories of Personal Data, to the extent made available to the Company or generated through use of the Services:
- Account and registration information: name, email address, telephone number, organisation name, designation, department, mailing address, billing details, account identifiers and similar information required to create, administer and maintain accounts.
- Credential and access information: usernames, passwords, authentication details, access permissions, security logs and other information necessary to authenticate users and secure the Services.
- Document and project data: information contained in documents, files, records, datasets, images, text, extracts, annotations, outputs or other materials uploaded to or processed through the Services, which may include Personal Data relating to Subscribers, Authorised Users, End Clients or other third parties.
- Usage Data and technical information: IP address, browser type, operating system, device information, access times, referring URLs, log data, session information, location derived from technical identifiers, error reports, performance metrics and service interaction data.
- Communications information: information provided when a Subscriber or Authorised User contacts the Company by email, chat, telephone, support ticket or other communication channel.
- Marketing and preference information: preferences, subscriptions, feedback, survey responses, event participation information, testimonials and communication choices.
- Payment and transaction-related information: billing address, invoice details, payment status, transaction references and other commercial information required to administer subscriptions and payments. The Company may use third-party payment processors and may not itself store full payment instrument details.
- Sensitive Personal Data or Information: to the extent included in documents or information submitted by Subscribers or otherwise required for use of the Services, the Company may incidentally or necessarily process SPDI. Subscribers shall not submit SPDI unless they have authority and lawful basis to do so and unless such submission is necessary for use of the Services. Where applicable U.S. State Privacy Laws govern the relevant processing, this category also includes Sensitive Personal Information as defined under such laws, which may include additional or differently-scoped categories such as precise geolocation, racial or ethnic origin, religious beliefs, health information, sexual orientation, citizenship or immigration status, or genetic or biometric data processed for identification purposes, in each case as and to the extent included in documents or information submitted by Subscribers or otherwise required for use of the Services.
Personal Data of End Clients and Third Parties
Subscribers may submit or make available Personal Data relating to End Clients and other third parties. The Company processes such Personal Data in reliance on the Subscriber's representations, warranties, authorisations and instructions. The Company is not responsible for verifying whether a Subscriber has obtained legally valid consent or provided legally adequate notice to any End Client or third party.
The Subscriber shall ensure that all Personal Data submitted to the Company has been collected and disclosed lawfully, fairly and transparently, and that the intended processing by the Company in connection with the Services has been adequately disclosed to the relevant individuals. The Subscriber shall be solely responsible for responding to End Client requests, complaints or claims, except to the extent the Company expressly agrees in writing to provide reasonable assistance.
Purposes of Collection and Processing
The Company may process Personal Data for the following purposes:
- to provide, operate, maintain, support, secure, monitor and administer the Services;
- to create, verify, authenticate, manage and maintain Subscriber and Authorised User accounts;
- to process documents and data submitted through the Services, including extraction, analysis, classification, storage, transmission and generation of outputs;
- to measure usage, calculate charges, manage subscriptions, issue invoices, process payments and administer commercial arrangements;
- to verify compliance with the Agreement, acceptable use restrictions, security requirements and applicable law;
- to provide technical support, respond to queries, investigate errors, resolve disputes and communicate service-related information;
- to maintain service integrity, prevent fraud, misuse, unauthorised access, security incidents and unlawful activity;
- to improve, test, develop, evaluate and enhance the Services, including performance, reliability, security, usability and functionality, subject to the restrictions on the use of Personal Data to train artificial intelligence or machine-learning models described in the "Third-Party Service Providers" section below;
- to generate aggregated, anonymised or de-identified information, analytics, benchmarks and statistics, provided such information does not identify a natural person;
- to send administrative, transactional, service-related, promotional and marketing communications concerning the Company's products and services, subject to applicable law and available opt-out mechanisms;
- to conduct surveys, research, events, market analysis and customer engagement initiatives;
- to comply with legal obligations, regulatory requirements, court orders, governmental requests and law enforcement processes;
- to enforce the Agreement, protect the Company's rights, defend claims, preserve evidence and pursue remedies available under law or contract; and
- for any other purpose expressly authorised by the Subscriber or permitted under applicable law.
Cookies, Web Beacons and Similar Technologies
The Company may use cookies, web beacons, pixels, local storage, logs and similar technologies to operate the Platform and Services, authenticate users, remember preferences, understand usage, diagnose technical issues, improve performance and support security. Cookies may be session cookies, which expire when the browser is closed, or persistent cookies, which remain for a longer period.
Subscribers and Authorised Users may configure their browsers to decline or restrict cookies where permitted by the browser. However, disabling cookies or similar technologies may impair or prevent access to certain features of the Website or Services. The Company uses Google Analytics to measure interactions with the website and within the Services, and uses Google Ads, Google's Display Network (which places advertising on websites and apps monetised through Google AdSense), Taboola, Inc., and Outbrain Inc. to deliver and measure advertising promoting the Services. These and other selected service providers may use cookies or similar technologies in connection with hosting, analytics, security, support, advertising, communications or other services performed for or in connection with the Company.
These advertising and analytics technologies may allow Google LLC, Taboola, Inc., and Outbrain Inc. to collect Personal Data about a Consumer's interactions with the Company's website and the Services for their own or joint advertising and analytics purposes. Depending on the applicable U.S. State Privacy Law, this may constitute a sale or sharing of Personal Data, or targeted advertising, as further described in the "Sale, Sharing, and Targeted Advertising" section below.
The Company also uses PostHog Inc. for product analytics, web analytics, session replay, heatmaps, and related behavioural analytics on the Company's website and within the Services, as described further in the "Session Replay and Behavioural Analytics" section below. Unlike Google Analytics, Google Ads, Taboola, Inc., and Outbrain Inc., PostHog acts solely as the Company's own analytics service provider under a signed data processing agreement that restricts PostHog from using Personal Data for its own independent purposes; the Company does not treat PostHog's processing of Personal Data as a sale or sharing of Personal Data under the CCPA or other U.S. State Privacy Laws. PostHog hosts and processes this analytics and session replay data on cloud infrastructure located in the United States, currently the us.i.posthog.com endpoint (or any successor endpoint PostHog may use).
Session Replay and Behavioural Analytics
In addition to the cookies and analytics technologies described above, the Company uses PostHog's session replay feature to record and play back masked reconstructions of a Consumer's visits to the Company's website and use of the Platform, for the purpose of understanding and improving the usability of the Website and Services. Session replay begins only after the Consumer or Subscriber has granted analytics consent, using the same consent mechanism described in the "Cookies, Web Beacons and Similar Technologies" section above, and is currently configured to record all such consented sessions.
All on-screen text and the contents of form fields are masked and are not captured in a recording, regardless of the page being viewed. Network request and response payloads, and browser console logs, are not captured. Session replay is never recorded on pages that display the content of an uploaded document, Extracted Data, or a report (including document-detail pages and the Reports dashboard), and recording is stopped for the duration of the in-app document extraction workflow. As currently configured in the Company's PostHog project, session replay recordings are retained for thirty (30) days; this period may be adjusted from time to time as part of the Company's ordinary account configuration.
The Company also uses PostHog's autocapture, heatmap, and interaction-detection features, which automatically record clicks, scrolling, and similar interactions with the Website and Services - including instances where a click did not appear to register (a "dead click") or a Consumer clicked repeatedly in apparent frustration (a "rage click") - as well as page-load and responsiveness metrics (Core Web Vitals), for the same website- and product-analytics purposes described above. These features are also gated on analytics consent and are not used for advertising.
Where a Consumer's browser encounters a technical error while using the Website or Services, information about that error may be sent to PostHog, and a session replay recording may be started or retained around the error for the purpose of diagnosing and fixing the underlying issue. This error-diagnostic use is subject to the same analytics-consent gate described above and is not used for advertising.
Unlike Google Analytics, which derives an approximate location from a Consumer's IP address and then discards the IP address itself, PostHog retains the IP address associated with each event and uses it to derive general location information, such as country, region, city, approximate postal code, time zone, and approximate geographic coordinates (latitude/longitude). The Company has configured PostHog not to anonymise or truncate this IP address. This location information is approximate, is derived from network information rather than device GPS or other location services, and is separate from the CTA-slot property described elsewhere in this Policy as "location" (which refers to where a button appears on a page, not a geographic location).
Sharing and Disclosure of Personal Data
The Company does not sell Personal Data for monetary consideration. However, as described in the "Sale, Sharing, and Targeted Advertising" section below, certain advertising and analytics technologies used by the Company may constitute a sale or sharing of Personal Data, or targeted advertising, under applicable U.S. State Privacy Laws, regardless of whether the Company receives a monetary payment. The Company may disclose or make available Personal Data only as described in this Policy, in the Agreement, as authorised by the Subscriber, or as permitted or required by applicable law.
Without prejudice to the foregoing, the Company may disclose Personal Data to:
- service providers and partners who provide hosting, cloud infrastructure, storage, data processing, analytics, payment processing, customer support, communications, security, professional advisory or other services to the Company;
- affiliates, group companies and successors for business administration, service delivery, restructuring, corporate transactions and internal governance;
- regulators, courts, law enforcement agencies and governmental authorities where disclosure is required or reasonably considered necessary under applicable law, legal process or governmental request;
- professional advisers including legal counsel, auditors, accountants, insurers, bankers and consultants, where reasonably necessary for business, compliance, risk management or dispute resolution purposes;
- transaction counterparties in connection with any merger, acquisition, investment, financing, restructuring, insolvency, business transfer, sale of assets or similar corporate transaction involving the Company; and
- other persons where the Subscriber has authorised such disclosure or where disclosure is necessary to protect the rights, property, safety or legitimate interests of the Company, its users, customers or the public.
Where the Company engages third-party service providers to process Personal Data, the Company shall take reasonable steps to ensure that such service providers are subject to confidentiality or contractual obligations that are, in the Company's reasonable assessment, appropriate having regard to the nature of the services provided and applicable law.
Sale, Sharing, and Targeted Advertising
The Company uses Google Analytics, Google Ads, Google's Display Network, Taboola, Inc., and Outbrain Inc. to measure interactions with the Company's website and the Services and to deliver and measure advertising promoting the Services, as described in the "Cookies, Web Beacons and Similar Technologies" section above. Taboola and Outbrain deliver native "recommended content" style advertising units, typically shown alongside editorial content on publisher websites. These technologies place cookies or similar identifiers on a Consumer's browser or device, which may allow Google LLC, Taboola, Inc., and Outbrain Inc. to receive Personal Data - such as identifiers, IP address, and information about a Consumer's interactions with the Company's website and the Services - for their own or joint advertising and analytics purposes.
The Company's Google Analytics account has Google Signals enabled, meaning Google may associate the analytics data described above with information from a Consumer's own Google Account (where that Consumer is signed in to a Google service and has enabled ad personalization on their Google Account), allowing Google to report on that Consumer's activity across multiple devices and to build advertising audiences for remarketing. The Company has also enabled Ads Personalization/remarketing (Google Analytics' "Advanced settings to allow for ads personalization") and granular location and device data collection, meaning Google Analytics collects more precise geographic and device information than its default configuration and may use analytics data to build and serve interest-based or remarketing advertising audiences through Google Ads. The Company has not enabled data sharing between its Google Analytics account and other Google products and services.
Depending on the applicable U.S. State Privacy Law, this use of cookies and similar technologies may constitute a Sale or Sharing of Personal Data under the CCPA, or Targeted Advertising under other U.S. State Privacy Laws, in each case regardless of whether the Company receives monetary consideration. The Company treats this use of cookies and similar technologies as triggering the opt-out right described in the "U.S. State Privacy Rights" section above.
A Consumer may opt out of this processing by using the "Do Not Sell or Share My Personal Information" link in the website footer, by submitting a request as described in the "Exercising Your U.S. State Privacy Rights" section above, or by activating an opt-out preference signal, such as the Global Privacy Control, which the Company will honour where required by applicable U.S. State Privacy Laws.
In the preceding twelve months, the Company has sold, shared, or used for Targeted Advertising the following categories of Personal Data, with Google LLC, Taboola, Inc., and Outbrain Inc., for the purposes described above: Identifiers (such as cookie and device identifiers and IP address); Internet or other electronic network activity information (such as website and in-app browsing, interaction, and usage data); and Inferences (such as interests or advertising segments inferred from browsing or usage activity). The Company does not currently sell, share, or use for Targeted Advertising any other category of Personal Data described in this Policy.
The opt-out mechanism and Global Privacy Control support described above are live. The Company provides a "Do Not Sell or Share" control alongside a separate "Cookie preferences" control, and honors the Global Privacy Control signal by denying both analytics and advertising consent. Activating either control, or the presence of a Global Privacy Control signal, stops Google Analytics, Google Ads, Taboola, and Outbrain tags and cookies from loading.
Third-Party Service Providers
The Services may require the transfer, hosting, storage or processing of Subscriber data and End Client data by third-party service providers, including cloud infrastructure and technology service providers. These currently include Amazon Web Services (cloud hosting and storage), Google LLC (where a Subscriber connects a Google Drive account as a document source, and separately as a sub-processor providing artificial intelligence and machine learning API services used to analyse, extract, and verify data from documents processed through the Services), Intuit Inc. (where a Subscriber connects a QuickBooks account for two-way data synchronisation), Stripe, Inc. (payment processing for recurring subscription billing and one-time top-up page purchases), and Twilio SendGrid (delivery of transactional and service-related emails). The Company may use additional or alternative providers for hosting, storage, infrastructure, security, analytics, support, communications and related functions. The scope of the QuickBooks integration with Intuit Inc. includes retrieving vendor, customer, currency, item, tax code, payment term, account, and other configuration records from, and pushing sales and cost transaction records to, the Subscriber's connected QuickBooks account, as well as, where the Subscriber elects to use the Platform's upload-to-QuickBooks feature, transmitting source document attachments - which may contain Personal Data relating to End Clients or other third parties - to that account.
When acting as a service provider, processor, or contractor, the Company will not combine or use Personal Data received from or on behalf of one Subscriber to develop, improve, or train artificial intelligence or machine-learning models for the benefit of other Subscribers or the Company generally, except (i) where the underlying information has first been aggregated or de-identified, or (ii) where the Subscriber has separately and specifically authorised such use. Where the Company uses a third-party artificial intelligence or machine learning service, such as Google LLC's API services, to analyse, extract, or verify data from documents on the Company's behalf, the Company requires that such service provider be contractually restricted from using that data to train or improve its own models. Consistent with this requirement, the Company's agreement with Google LLC for these services is governed by Google's enterprise (paid) API terms, which contractually prohibit Google from using such data to train or improve its own models.
The Subscriber acknowledges that third-party service providers may process Personal Data in accordance with their own applicable terms, policies, security standards and service descriptions, as updated from time to time. The Company may change, add or replace service providers in its discretion, provided that it does so in a manner consistent with the Agreement and applicable law.
The Company's processing of Personal Data as a service provider or processor on a Subscriber's behalf is further governed by the Company's Data Processing Agreement, a standalone document incorporated by reference into the Agreement and this Policy, which sets out additional contractual commitments including the Company's sub-processor list, security and breach-notification obligations, deletion and audit rights, and the artificial-intelligence and machine-learning training restriction described above. A Subscriber may request a copy of the Data Processing Agreement at any time.
Cross-Border Transfers
Personal Data may be stored, hosted, accessed, supported or otherwise processed in India or in other jurisdictions where the Company, its affiliates or service providers maintain facilities, systems, personnel or operations. By using the Services and submitting Personal Data to the Company, the Subscriber authorises such transfers and processing, subject to applicable Indian law and the Agreement.
As described in the "Session Replay and Behavioural Analytics" section above, PostHog Inc. hosts and processes analytics and session replay data on cloud infrastructure located in the United States, currently the us.i.posthog.com endpoint (or any successor endpoint PostHog may use).
The Company shall not be responsible for any restriction or requirement under non-Indian law unless expressly agreed in writing. The Subscriber shall be responsible for ensuring that any transfer of Personal Data to the Company, including any cross-border transfer initiated by the Subscriber, is lawful.
U.S. State Privacy Rights
Subject to applicable exceptions, verification requirements, and the scope of the Company's role as described in this Policy, Consumers may have the following rights under applicable U.S. State Privacy Laws with respect to their Personal Data:
- Right to confirm and access. the right to confirm whether the Company processes a Consumer's Personal Data, and to access that Personal Data.
- Right to correct. the right to correct inaccuracies in Personal Data, taking into account the nature of the Personal Data and the purposes of processing.
- Right to delete. the right to request deletion of Personal Data.
- Right to data portability. the right to obtain a copy of Personal Data in a portable and, to the extent technically feasible, readily usable format.
- Right to opt out. the right to opt out of the processing of Personal Data for purposes of targeted advertising, the sale of Personal Data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
- Right of non-discrimination. the right not to receive discriminatory treatment for exercising any of the rights described above.
Where the Company processes Personal Data as a service provider, processor, or contractor on behalf of a Subscriber, the Company may direct a Consumer's request to the relevant Subscriber, or support the Subscriber in responding to the request, consistent with the "Personal Data of End Clients and Third Parties" section above.
Exercising Your U.S. State Privacy Rights
To exercise any of the rights described in the "U.S. State Privacy Rights" section above, a Consumer may submit a request to the Company using the details in the "Contact Us" section below, including by email or by using the dedicated webform made available for this purpose.
The Company will take reasonable steps to verify the identity of a Consumer before acting on a request. The information required for verification may vary depending on the nature of the request and the sensitivity of the Personal Data at issue. The Company may request information sufficient to confirm the requester's identity, such as account or subscription details, or other information reasonably necessary to verify the request, and will use such information only for purposes of verifying and responding to the request, except as otherwise required or permitted by law.
The Company will respond to a verified request within forty-five (45) days of receipt. Where reasonably necessary, taking into account the complexity and number of requests received, the Company may extend this period by an additional forty-five (45) days, provided that the Company informs the Consumer of any such extension, and the reason for it, within the initial 45-day period. If the Company is unable to verify a request, or determines that an exception under applicable U.S. State Privacy Laws applies, the Company may decline to act on the request in whole or in part, and will inform the Consumer of the basis for its decision and of the Consumer's right to appeal as described in the "Appeals" section below.
Appeals
If the Company declines to act on a Consumer's request, in whole or in part, the Consumer may appeal that decision by contacting the Company using the details in the "Contact Us" section below and requesting that the decision be reviewed. Appeals are directed to the same contact as initial requests: the Privacy Officer, at the email address in the "Contact Us" section below.
The Company will respond to an appeal within sixty (60) days of receipt. If the Company denies the appeal, the Company will provide the Consumer with a written explanation of the reasons for the denial and, to the extent required by applicable U.S. State Privacy Laws, information on how the Consumer may submit a complaint to the attorney general of the Consumer's state of residence.
The CCPA does not require a formal appeal process of this kind. The Company will nonetheless apply the appeals process described in this section to all Consumers, regardless of state of residence, as a matter of consistent practice.
Authorised Agents
A Consumer may designate an authorised agent to submit a request on the Consumer's behalf under this Policy. The Company may require the authorised agent to provide proof of the Consumer's authorisation, and may require the Consumer to directly verify their own identity with the Company or confirm that the agent has been granted permission to submit the request, unless an exception applies under applicable U.S. State Privacy Laws.
Security Measures
The Company shall implement reasonable security practices and procedures appropriate to the nature of the information processed and the Services provided, including administrative, technical and organisational safeguards designed to protect Personal Data against unauthorised access, disclosure, alteration, destruction, loss or misuse. Such safeguards may include access controls, authentication measures, encryption technologies, logging, monitoring, infrastructure security, confidentiality obligations and internal policies. These safeguards include the identity and access management tools described in the "Nature of Services" section above, which allow a Subscriber to manage which of its Authorised Users may access particular data, features, or client accounts within the Services.
No method of transmission over the internet, electronic storage or digital processing is completely secure. Accordingly, the Company does not guarantee absolute security of Personal Data and shall not be liable for unauthorised access, loss, disclosure or alteration arising from factors beyond its reasonable control, Subscriber-side vulnerabilities, compromised credentials, insecure networks, third-party acts, force majeure events or breach of the Agreement by the Subscriber or its Authorised Users.
Subscriber Responsibilities
The Subscriber shall be solely responsible for:
- ensuring that Personal Data submitted to the Company is collected, used and disclosed lawfully;
- providing all required notices and obtaining all required consents from Authorised Users, End Clients and other relevant individuals;
- ensuring that Personal Data submitted to the Services is accurate, complete, relevant and not excessive having regard to the purposes of processing;
- maintaining the confidentiality and security of account credentials and access rights;
- controlling the acts and omissions of its Authorised Users;
- ensuring that it does not upload unlawful, unauthorised, infringing, malicious or excessive data to the Services;
- maintaining appropriate backups of its data unless otherwise expressly agreed in writing; and
- responding to requests, claims, inquiries or complaints from End Clients or other individuals whose Personal Data is submitted by or on behalf of the Subscriber.
Accuracy, Completeness and Integrity of Personal Data
The Company processes Personal Data on an "as is" basis as provided or made available by the Subscriber, Authorised Users or other relevant persons. The Company does not independently verify the accuracy, completeness, lawfulness, relevance, integrity or quality of Personal Data submitted through the Services and shall not be responsible for any error, omission, inaccuracy, incompleteness, illegality or defect in such Personal Data.
The Subscriber shall promptly correct, update or delete any inaccurate, incomplete or unlawful Personal Data submitted to the Services and shall notify the Company where assistance is reasonably required and expressly contemplated under the Agreement.
Data Retention and Deletion
The Company may retain Personal Data for as long as necessary to provide the Services, comply with the Agreement, satisfy legal, regulatory, tax, accounting, audit or evidentiary requirements, resolve disputes, enforce rights, maintain security, prevent fraud or misuse, and preserve business records. Retention periods may vary depending on the nature of the information, the purpose of processing, contractual requirements and applicable law. The specific retention periods and deletion mechanics that apply to documents and data processed through the Services, including documents stored using DocuVault, are described below.
Documents and data outside DocuVault. Uploaded source documents (such as scanned receipts, invoices, and other images or PDFs) and the data extracted from them using optical character recognition, visual document understanding, or other document-processing technology ("Extracted Data") are retained for a minimum period of seven (7) years, unless the Subscriber or Authorised User explicitly deletes the relevant document or Extracted Data using the "Delete" or "Delete file" controls in the Platform's user interface. Deletion initiated in this way takes effect immediately as a permanent, irreversible deletion; the Company does not perform a soft deletion or retain a recoverable copy of the deleted item.
Cancelling a Subscription Package (Bronze, Silver, or Gold) does not, by itself, result in deletion of any data. All data remains available to the Subscriber for a minimum period of seven (7) years, whether or not the Subscriber maintains a paid Subscription Package, for as long as the Subscriber's account remains open.
Account deletion. If a Subscriber deletes its account altogether, all of the Subscriber's data is permanently deleted immediately, including uploaded files, Extracted Data, account settings, client lists, business settings, integrations with QuickBooks and Google Drive, team member records, identity and access management settings, workspace configuration, and subscription-related information.
Exceptions. The following records are not deleted upon account deletion: historical purchase records, historical credit (page) usage data, email correspondence with the Company, and current or historical support tickets raised by the Subscriber. These records are retained for audit purposes and to inform product improvement, including through the analysis of user feedback.
Documents stored in DocuVault. DocuVault, the Company's optional document storage and organisation feature, is subject to the same retention and account-deletion rules described above, with one difference: a document deleted from DocuVault is not deleted immediately. It is instead moved to a "Trash" folder, where it is retained for thirty (30) days. During this 30-day period, the Subscriber may restore the document from the Trash folder. A document is permanently and irreversibly deleted, and can no longer be restored, either (i) automatically at the end of the 30-day period, or (ii) earlier, if the Subscriber permanently deletes it from the Trash folder, whether individually or by using a "Clear Trash" function that permanently deletes all documents then in the Trash folder. As with documents outside DocuVault, this is a hard deletion; the Company does not retain a further recoverable copy once a document is permanently deleted from the Trash folder or the 30-day period expires.
Analytics data. As currently configured in the Company's Google Analytics account, data collected through Google Analytics is retained by Google for fourteen (14) months of event data and fourteen (14) months of user data, in each case measured from an individual's most recent activity (the retention period resets upon new activity); these periods may be adjusted from time to time as part of the Company's ordinary account configuration.
PostHog analytics and session replay data. As currently configured in the Company's PostHog project, event data collected through PostHog is retained for twelve (12) months, and session replay recordings are retained for thirty (30) days; these periods may be adjusted from time to time as part of the Company's ordinary account configuration.
The Company shall not be liable for deletion of data following termination.
Children's Privacy
Our Services are not directed at anyone who we know to be under the age of 18, nor do we collect any personal information from anyone who we know to be under the age of 18. If you are under the age of 18, you should not use our Services and should not submit any personal information to us.
This age threshold reflects the Company's general eligibility requirement for using a business and professional product, and is in addition to, and independent of, the age threshold referenced in the Company's CCPA Privacy Notice concerning the sale or sharing of a California resident's Personal Data, which addresses a different, narrower question under the CCPA specifically.
Phishing
The Company will never ask a Subscriber or Authorised User to disclose account passwords, full payment card details, or other authentication credentials by email, telephone, or unsolicited message. If a Subscriber or Authorised User receives a communication purporting to be from the Company that requests such information, or that directs them to a suspicious link, they should not respond and should contact the Company using the details in the "Contact Us" section below to verify its authenticity.
Links
This Platform may contain links and advertisements which may lead you to other websites, applications or platforms. Please note that once you leave our Platform you will be subjected to the privacy policy of the other websites and this Policy will no longer apply.
Limit of Liability
Any limitation of the Company's liability in connection with its processing of Personal Data under this Policy is set out in, and governed by, the limitation of liability provisions of the Agreement, which cap the Company's maximum aggregate liability at the Subscription Fees paid by the Subscriber in the twelve (12) months immediately preceding the event giving rise to the claim.
Contact Us
If you believe that Company has not complied with this Policy with respect to your personal information or would like us to update information, we have about you or your preferences or if you have any questions about our Policy, please feel free to contact our Privacy Officer (who also serves as the Grievance Officer for purposes of applicable Indian law) at: privacy@figureiq.ai
A dedicated webform for submitting requests is also available here.
Requests may also be submitted by post to the Company's registered office address set out at the beginning of this Policy, for the attention of the Privacy Officer.
Applicability of Policy
While this Policy applies to all personal information collected, stored and used by Company, it is intended to comply with the laws described in the "Scope and Applicability" section above, including the Information Technology Act, 2000 and applicable U.S. State Privacy Laws. Subject to any non-waivable statutory rights a Consumer may have under applicable U.S. State Privacy Laws, all matters of dispute arising out of or relating to this Policy are subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka, India.
Amendments
Company may modify this Policy in its sole discretion at any time. While Company shall make best efforts to notify you of any such modification, it shall be your responsibility to read and understand the Policy as prevalent from time to time. Continued use of the Platform shall be deemed to constitute acceptance of the Policy as amended.