Legal

Privacy Policy

Effective date: June 19, 2026

Fathomkey ("Fathomkey", "we", "us", or "our") operates Product Investment Intelligence (the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and the choices you have. We designed this policy to align with our internal governance program and with global frameworks including the EU GDPR, UK GDPR, California CCPA/CPRA, India DPDP Act 2023, SOC 2, ISO/IEC 27001, and the NIST AI Risk Management Framework (AI RMF 1.0).

1. Scope and roles

For customer account data and the customer content you upload to the Service (evidence, transcripts, PRDs, feedback), Fathomkey acts as a data processor on behalf of your organization, which is the data controller. For our marketing site, support communications, and billing records, Fathomkey acts as a data controller.

2. Data we collect

  • Account data: name, work email, organization, role, password hash, authentication identifiers.
  • Customer content: evidence, interviews, transcripts, tickets, documents, and PRDs you submit to the Service.
  • Usage data: product telemetry, feature usage, audit logs, device and browser metadata, IP address.
  • Billing data: company name, billing contact, tax identifiers, invoice history. Card details are processed by our PCI-DSS compliant payment processor; we never store full card numbers.
  • Support data: messages, attachments, and context you share with our support team.

3. How we use data

We process personal data to:

  • Provide, operate, secure, and improve the Service.
  • Authenticate users and prevent fraud or abuse.
  • Provide customer support and respond to requests.
  • Send service notices, security alerts, and (with consent) marketing communications.
  • Meet legal, tax, and regulatory obligations.

4. Legal bases (GDPR / UK GDPR)

We rely on: performance of a contract, legitimate interests (such as securing and improving the Service), legal obligations, and consent (where required, e.g., non-essential cookies and marketing emails). You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. AI and machine learning

Product Investment Intelligence uses AI to analyze evidence, score confidence, and gate PRDs. Our use of AI follows the NIST AI RMF, the EU AI Act transparency principles, and our internal Responsible AI Standard:

  • No training on customer content by default. We do not use customer content to train foundation models, and we contractually prohibit our sub-processors from doing so.
  • Human-in-the-loop. AI outputs are decision support, not autonomous decisions. A human reviewer remains accountable for PRDs and gating decisions.
  • Transparency. AI-generated content is labeled in the product and citations are preserved so reviewers can verify sources.
  • Bias and quality controls. Models are evaluated against accuracy, hallucination, fairness, and safety metrics before release, and continuously monitored in production.
  • Data minimization. Only the evidence required for the requested task is sent to a model; outputs are scoped to the originating workspace.

6. Sub-processors and sharing

We share data only with vetted sub-processors (cloud hosting, model providers, observability, payments, email delivery, customer support) under written agreements that impose confidentiality, security, and data-protection obligations at least as protective as this policy. A current list of sub-processors is available on request to choudhary[@]fathomkey.pro. We do not sell personal data and we do not share personal data for cross-context behavioral advertising.

7. International transfers

Where personal data is transferred outside its country of origin, we rely on appropriate safeguards, including the EU Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, and equivalent mechanisms under applicable law, together with supplementary technical and organizational measures.

8. Security

We operate an information security program aligned with ISO/IEC 27001 and SOC 2, including: encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access, MFA for all production access, segregated environments, continuous logging and monitoring, vulnerability management, secure SDLC, vendor risk reviews, and an incident response plan with defined notification timelines.

9. Retention

We retain personal data for as long as needed to deliver the Service and to meet legal, accounting, or reporting requirements. Customer content is retained per the customer's contracted retention configuration and deleted on termination within the period specified in our Data Processing Addendum.

10. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data, and to lodge a complaint with a supervisory authority. To exercise these rights, contact choudhary@fathomkey.pro. If your organization controls your account, please contact them first; we will support their response.

11. Children

The Service is intended for business users and is not directed to children under 16.

12. Changes

We will post material changes to this policy on this page and, where required, notify you in-product or by email before the changes take effect.

13. Contact

Fathomkey
Hyderabad, Telangana
Privacy and Data Protection: choudhary[@]fathomkey.pro