Privacy Policy

Effective Date: May 3, 2026

This Privacy Policy describes how Xosphere, Inc. ("Xosphere," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our websites, products, and services (collectively, the "Services").

Xosphere provides cloud infrastructure optimization, Spot orchestration, and FinOps tooling to business customers. This Privacy Policy reflects modern SaaS data practices and applicable privacy laws and is intended for enterprise customers, security reviewers, and legal teams.

1. Scope and Applicability

This Privacy Policy applies to:

  • Visitors to our websites
  • Customers and authorized users of the Services
  • Representatives, administrators, and contacts of our customers
  • Individuals who communicate with us for support, sales, marketing, or other business purposes

This Privacy Policy does not apply to data processed by Xosphere on behalf of customers where Xosphere acts as a processor or service provider under a separate written agreement (such as a Master Services Agreement or Data Processing Addendum). In those cases, customer instructions and contractual terms govern.

2. Categories of Data We Collect

We collect and process the following categories of information:

2.1 Account and Contact Information

  • Name
  • Business email address
  • Company name
  • Job title
  • Contact details provided by customer representatives or administrators

2.2 Customer-Provided Configuration Data

  • Cloud configuration data
  • Infrastructure definitions and metadata
  • Service settings and preferences
  • Integration parameters for AWS, Google Cloud Platform, or other supported platforms

2.3 Usage, Telemetry, and Operational Metadata

  • Service usage metrics
  • Performance and operational telemetry
  • Resource identifiers and infrastructure metadata
  • System logs and diagnostic data generated by the Services

2.4 Billing and Usage Metadata

  • Subscription details
  • Usage measurements relevant to billing
  • Invoices and payment-related records (processed via third-party payment providers)

2.5 Support and Communications

  • Support tickets and correspondence
  • Chat, email, or other communications with Xosphere
  • Information provided during onboarding, sales, or troubleshooting

2.6 Website Analytics, Advertising, and Cookies

  • IP address (typically truncated for analytics)
  • Device, browser, and operating system information
  • Pages visited, referrers, and interactions
  • Approximate geographic location derived from IP address
  • Cookie identifiers and similar tracking technologies

2.7 Sensitive Personal Information

Xosphere does not knowingly collect or process Sensitive Personal Information as defined under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), including government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, health information, or contents of personal communications.

3. Purposes of Data Use and Lawful Bases

We use the information we collect for the following purposes. Where the General Data Protection Regulation ("GDPR") or UK GDPR applies, the lawful basis for each purpose is identified.

  • Service Delivery and Operation — performance of a contract with the customer; legitimate interests in operating the Services.
  • Security, Availability, Confidentiality, and Processing Integrity — legitimate interests in protecting the Services and our users; compliance with legal obligations.
  • Customer Support and Communications — performance of a contract; legitimate interests in supporting users.
  • Product Improvement and Analytics — legitimate interests in improving the Services; consent where required for non-essential cookies.
  • Marketing and Communications — consent where required; legitimate interests in B2B outreach where permitted.
  • Legal and Compliance — compliance with legal obligations; establishment, exercise, or defense of legal claims.

4. Data Sharing and Disclosure

We may disclose information in the following circumstances:

4.1 Service Providers and Sub-Processors

We engage third-party service providers to support our operations. Categories include:

  • Cloud infrastructure providers
  • Hosting and DDoS protection
  • Web analytics and tag management
  • Customer relationship management and marketing automation
  • Transactional email delivery
  • Payment processing providers

These providers are authorized to process data only as necessary to provide services to Xosphere and are subject to contractual confidentiality and data protection obligations.

4.2 Advertising and Analytics Partners

Xosphere may share limited identifiers (such as cookie identifiers or hashed business contact information) with advertising and analytics partners for the purpose of measuring campaign effectiveness and delivering relevant advertisements to business audiences.

Xosphere does not permit advertising partners to use personal data for their own independent purposes and does not target individuals based on Sensitive Personal Information.

4.3 Legal and Regulatory Requirements

We may disclose information if required to do so by law or in response to valid legal process.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, information may be transferred as part of the transaction, subject to appropriate confidentiality protections.

5. Data Retention

We retain information for the periods set out below, unless a longer period is required by law or necessary to resolve disputes, enforce agreements, or meet accounting obligations:

  • Account and contact information: for the duration of the customer relationship plus 7 years thereafter.
  • Customer-provided configuration data: for the duration of the subscription; deleted or returned within 30 days of termination.
  • Usage, telemetry, and operational logs: up to 24 months in identifiable form, then aggregated or deleted.
  • Billing and payment records: 7 years to meet tax and accounting requirements.
  • Support tickets and communications: up to 3 years after resolution.
  • Website analytics data: up to 14 months.
  • Marketing prospect data: until consent is withdrawn or after 24 months of inactivity.
  • Cookie consent records: 12 months from the date of the consent decision.

6. Security Measures

Xosphere implements administrative, technical, and organizational safeguards designed to protect information and support secure data processing. These measures are aligned with industry standards and SOC 2 principles related to security, availability, confidentiality, and processing integrity.

7. Your Rights

7.1 GDPR Rights (EEA, UK, Switzerland, and Similar Jurisdictions)

Where applicable, individuals have the right to:

  • Access their personal data
  • Correct inaccurate or incomplete data
  • Request deletion of personal data
  • Restrict or object to processing
  • Request data portability

7.2 California Privacy Rights (CCPA / CPRA)

California residents have the right to:

  • Know what personal information is collected.
  • Access a copy of the specific pieces of personal information we hold.
  • Delete personal information, subject to legal exceptions.

7.3 Categories of Personal Information (CPRA Disclosure)

In the preceding 12 months, Xosphere has collected the following statutory categories of personal information:

Category Collected Sold Shared (Cross-Context Ads)
Identifiers (name, email, IP, cookie IDs) Yes No Yes
Customer records Yes No No
Commercial information Yes No No
Internet/network activity Yes No Yes
Geolocation Yes No No
Professional/employment information Yes No No

7.4 Exercising Your Rights

Requests may be submitted using the contact information in Section 13. We will verify your identity before fulfilling requests.

8. International Data Transfers

Xosphere is headquartered in the United States and may process information in the United States and other jurisdictions. Where required, we rely on appropriate safeguards for cross-border data transfers.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to operate, secure, improve, and market our websites.

9.1 Types of Cookies and Vendors

  • Essential: required for basic functionality and security.
  • Analytics: used to understand site usage and improve performance.
  • Marketing / Advertising: used for B2B retargeting and campaign measurement.

9.2 Cookie Controls and Consent

For visitors located in the EEA, UK, or Switzerland, non-essential cookies are deployed only after explicit opt-in consent.

10. Children's Privacy

The Services are not directed to children under the age of 16, and we do not knowingly collect personal data from children.

11. Third-Party Websites

Our websites may contain links to third-party sites. This Privacy Policy does not apply to those sites.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the website or other appropriate means. The "Effective Date" at the top of this policy indicates when it was last updated.

13. Contact Information

For questions or requests regarding this Privacy Policy or our data practices, please contact:

Privacy Contact
Xosphere, Inc.
6320 Canoga Avenue, 15th Floor
Woodland Hills, CA 91367
Email: privacy@xosphere.io

EU/UK Establishment: Xosphere does not currently maintain an establishment in the European Union or the United Kingdom.