Last updated: 8 August 2026.
This Privacy Policy explains how Lotics ("we", "us") collects, uses, shares, and protects personal data when you use our service.
Lotics is a multi-tenant workspace, CRM, and automation platform. Most data in the product belongs to the customer organization that created it — for that data the customer is the controller and Lotics is the processor, acting on the customer's instructions. For a narrow set of account data (your sign-up identity, sessions, and billing), Lotics is the controller. This policy describes how we handle data for which Lotics is the controller; for data inside a workspace your organization controls, that organization's own privacy notice and our agreement with them govern.
We do not collect or accept Protected Health Information (PHI); it is prohibited by our agreement.
When you use AI features (the chat assistant, document extraction), the content you submit is sent to our AI subprocessor to generate a response and is processed in transit.
Lotics is a Vietnamese company, and the law that governs how we handle personal data is the Law on Personal Data Protection No. 91/2025/QH15, together with Decree No. 356/2025/NĐ-CP, both in force since 1 January 2026.
We process personal data on your consent (Article 9), on the performance of our contract with you or your organization, to meet a legal obligation, and in the cases Article 19 allows processing without consent. For users in the EU/EEA, GDPR applies in addition and we rely on the corresponding bases there.
Our application and database run on Render in Singapore. Files are stored in Cloudflare object storage in the Asia-Pacific region. A small number of supporting services — email delivery, product analytics, voice transcription, and the AI model — operate from the United States; each is named on our Subprocessors page, which is the authoritative list of who processes what and where.
We share data only with the subprocessors that help us run the service — see our Subprocessors page for the full list, what each processes, and where it is located. We do not sell your personal data. We may disclose data where required by law.
When you connect your own third-party account (such as Gmail, Outlook, MISA, FedEx, or Lark), data flows to that service at your direction; those providers are not our subprocessors, and their handling of that data is governed by your agreement with them.
We use cookies and similar technologies for authentication and for product analytics (via PostHog). We do not record session replays. You can manage non-essential cookies through your browser settings.
We encrypt data in transit and at rest, additionally encrypt connected-account credentials at the application layer, enforce role-based access control and tenant isolation, and keep a tamper-evident audit log. See our Security page for details.
We keep data only as long as needed to provide the service and meet legal obligations. In general: account data for the life of your account; sessions for up to 30 days; uploaded files for the life of the record that owns them; audit logs for up to 2 years. After deletion, data may remain in encrypted backups until those backups age out on their normal cycle.
Article 4 of the Law on Personal Data Protection gives you the right to:
We act on a request promptly, within the period the law prescribes. For users in the EU/EEA, the equivalent GDPR rights apply and the outer bound is one month.
If your data is inside an organization's workspace, that organization is the controller and we act only on its instructions — please send your request to them, and we will support them in fulfilling it. Requests about your own Lotics account come to us.
To exercise a right or ask a privacy question, contact our data protection contact at [email protected], or [email protected] for general enquiries.
You may also complain to the Department of Cybersecurity and Hi-tech Crime Prevention (A05), Ministry of Public Security, which is the state authority for personal data protection in Vietnam.
Lotics is not directed to children. You must be at least the age of majority in your jurisdiction to use the service.
We may update this policy from time to time. We will post changes on this page and update the date above; we will communicate material changes as appropriate.
For privacy questions or requests, contact our data protection contact at [email protected], or [email protected] for general enquiries.