Privacy Policy

This Privacy Policy explains how [Platformr, Inc.] and its affiliates (“Platformr,” “we,” “us,” or “our”) collect, use, disclose, and protect personal information in connection with our cloud operations (“CloudOps”) automation and governance platform, our website at platformr.cloud, and related products and services (collectively, the “Service”).

Platformr provides a business-to-business Service that connects to customers’ Amazon Web Services (“AWS”) environments to deliver automation, governance, security posture, and cost-optimization capabilities. This Policy applies to website visitors, individuals who register for or use the Service, and personnel of our business customers and partners. It does not apply to the practices of third parties (including AWS) that we do not own or control.

Our role: controller and processor

Account and Service data (controller). Platformr acts as a “controller” (or “business” under U.S. state law) of the personal information described in this Policy that relates to account registration, billing, website use, product usage, and our communications with you.

Customer Cloud Data (processor). When we access configuration data, metadata, resource inventory, and telemetry within a customer’s connected AWS environment to provide the Service (“Customer Cloud Data”), we act as a “processor” (or “service provider”) on behalf of that customer, governed by our agreement with the customer, including any Data Processing Addendum (“DPA”). If you are an individual whose information appears in Customer Cloud Data, please direct privacy requests to the relevant customer (the controller), and we will support them in responding.

1 Information we collect

1.1 Information you provide to us

  • Account & identity information — name, business email, username, password, job title, company name, and phone number when you register or are invited to an account.
  • Billing & transaction information — product plan and subscription details, and payment records. Card and bank details are handled by our payment processor; we do not store full payment card numbers.
  • Support & communications — information you share when you contact us, request support, respond to surveys, or attend webinars and events.
  • Marketing information — details you submit through forms, content downloads, or event sign-ups.

1.2 Information we collect automatically

  • Usage & product data — features accessed, actions taken, pages viewed, configuration settings, and frequency and duration of use.
  • Device & connection data — IP address, browser type, operating system, device identifiers, and referring/exit pages.
  • Log data — system activity, diagnostic, and performance logs generated by the Service.
  • Cookies & similar technologies — see Cookies and tracking technologies.

1.3 Customer Cloud Data accessed to provide the Service

To deliver CloudOps automation and governance, the Service connects to a customer’s AWS account(s) — typically through a cross-account IAM role with scoped permissions and time-boxed — and accesses data such as resource configuration and metadata, account and organization structure, tagging, security and compliance posture findings, billing and cost-and-usage data, and operational metrics. We access this data to operate the Service for the customer and in accordance with the permissions the customer grants. We do not seek access to the content of a customer’s end-user applications or databases beyond what is necessary to provide the Service.

1.4 Information from third parties

  • Channel partners & marketplaces — we may receive contact and account information from partners or from AWS Marketplace when you transact through them.
  • Service providers — analytics, security, and enrichment providers that help us operate and improve the Service.

2 How we use information

We use personal information to:

  • Provide, operate, secure, maintain, and improve the Service;
  • Create and administer accounts and authenticate users;
  • Process transactions, manage subscriptions, and send billing-related communications;
  • Provide customer support and respond to inquiries and requests;
  • Monitor, detect, investigate, and prevent fraud, abuse, and security incidents;
  • Analyze usage to understand trends and develop new features and products;
  • Send administrative, transactional, and (where permitted) marketing communications;
  • Comply with legal obligations and enforce our agreements and policies; and
  • Carry out other purposes disclosed to you with your consent.

3 Legal bases for processing (EEA / UK)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process personal information under the following legal bases:

  • Contract — to provide the Service and perform our agreement with you or your organization.
  • Legitimate interests — to secure, support, analyze, and improve the Service, and to conduct direct marketing, balanced against your rights.
  • Consent — where required, for example for certain cookies and marketing communications. You may withdraw consent at any time.
  • Legal obligation — to comply with applicable laws and regulatory requirements.

4 How we disclose information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as described below:

  • Service providers & sub-processors — vendors that perform services on our behalf (hosting, payments, analytics, communications, support) under contractual confidentiality and data-protection obligations. See Sub-processors.
  • Within your organization — with administrators and authorized users of your organization’s account.
  • AWS — as necessary to host and operate the Service and to enable connections you authorize with your AWS environment.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to the protections of this Policy.
  • Legal & safety — to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and property of Platformr, our users, or others.
  • With your consent — for any other purpose disclosed to you.

5 Sub-processors

We engage trusted third parties to help us deliver the Service. The list below identifies our current sub-processors. We will update this list before engaging a new sub-processor where required by our agreements.

Sub-processorService providedProcessing location
Amazon Web Services, Inc.Cloud hosting & infrastructure for the ServiceUnited States
AmplitudeWeb AnalyticsUnited States
GoogleEmail communicationUnited States
HubspotCRMUnited States
AtlassianSupport systemUnited States

6 Data retention

We retain personal information for as long as needed to provide the Service, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer required, we delete or de-identify it. Customer Cloud Data is retained and deleted in accordance with the customer agreement and DPA. Typical retention periods include 90 days for infrastructure telemetry and 7 years for account and billing information.

7 How we protect information

We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls and least-privilege permissions, network segmentation, logging and monitoring, and regular security reviews. Connections to customer AWS environments use scoped, customer-authorized IAM roles. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

To report a security concern or vulnerability, contact us at customer-support@platformr.cloud.

8 International data transfers

Platformr is based in the United States, and we and our service providers may process personal information in the United States and other countries. Where we transfer personal information from the EEA, UK, or Switzerland to a country that has not been deemed to provide an adequate level of protection, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK Addendum. To request a copy of the relevant safeguards, contact us at customer-support@platformr.cloud.

9 Cookies and tracking technologies

We and our service providers use cookies and similar technologies to operate and secure the Service, remember your preferences, understand usage, and (where permitted) support marketing. You can manage cookies through your browser settings and, where available, our cookie preference tools.

10 Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal information:

RightWhat it means
AccessRequest a copy of the personal data we hold about you and how we process it.
CorrectionAsk us to correct personal data that is inaccurate or incomplete.
DeletionAsk us to delete your personal data, subject to certain legal exceptions.
PortabilityReceive certain personal data in a structured, commonly used, machine-readable format.
Restriction & objectionAsk us to restrict, or object to, certain processing of your personal data.
Withdraw consentWithdraw consent at any time where we rely on consent to process your data.
Non-discriminationNot receive discriminatory treatment for exercising your privacy rights.

10.1 California residents (CCPA/CPRA)

If you are a California resident, you have rights to know, access, correct, and delete your personal information, and to limit certain uses of sensitive personal information. We do not sell or share personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights. In the prior 12 months, we have collected the categories of personal information described above for the purposes described in “How we use information” and disclosed them to the categories of recipients described in “How we disclose information.”

10.2 EEA, UK, and Switzerland

You have the rights set out in the table above and may lodge a complaint with your local data protection authority. Where applicable, our EU/UK representative can be contacted at the address in Contact us.

10.3 How to exercise your rights

To make a request, contact us at customer-support@platformr.cloud. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where permitted. If your information is held within a customer’s account as Customer Cloud Data, we will refer your request to that customer.

11 Children’s privacy

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.

12 Third-party services and links

The Service may link to or integrate with third-party websites and services, including AWS. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.

13 Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the “Last updated” date above and, where appropriate, by additional notice such as email or an in-product message. Your continued use of the Service after an update becomes effective constitutes acceptance of the revised Policy.

14 Contact us

If you have questions or requests regarding this Privacy Policy or our privacy practices, contact us at: https://platformr.cloud/support/