Privacy Policy

Last updated: 8 August 2026.

This Privacy Policy explains how Lotics ("we", "us") collects, uses, shares, and protects personal data when you use our service.

Our role: controller and processor

Lotics is a multi-tenant workspace, CRM, and automation platform. Most data in the product belongs to the customer organization that created it — for that data the customer is the controller and Lotics is the processor, acting on the customer's instructions. For a narrow set of account data (your sign-up identity, sessions, and billing), Lotics is the controller. This policy describes how we handle data for which Lotics is the controller; for data inside a workspace your organization controls, that organization's own privacy notice and our agreement with them govern.

Data we collect

  • Account data (we are the controller): your name, email address, hashed password, authentication and multi-factor settings, and sessions; billing details where applicable.
  • Content you create (we are the processor, on your organization's behalf): records, fields, files, chat messages, knowledge documents, and voice recordings you add to a workspace.
  • Connected-account credentials: if you connect a third-party account, we store those credentials encrypted and scoped to the workspace you connected them in.
  • Usage and diagnostic data: product analytics, error reports, and application logs, used to operate and improve the service.

We do not collect or accept Protected Health Information (PHI); it is prohibited by our agreement.

How we use data

  • To provide, secure, and operate the service and authenticate you.
  • To provide support and send service communications (sign-in, notifications).
  • To monitor, debug, and improve the product.
  • To meet legal obligations.

When you use AI features (the chat assistant, document extraction), the content you submit is sent to our AI subprocessor to generate a response and is processed in transit.

Governing law and legal basis

Lotics is a Vietnamese company, and the law that governs how we handle personal data is the Law on Personal Data Protection No. 91/2025/QH15, together with Decree No. 356/2025/NĐ-CP, both in force since 1 January 2026.

We process personal data on your consent (Article 9), on the performance of our contract with you or your organization, to meet a legal obligation, and in the cases Article 19 allows processing without consent. For users in the EU/EEA, GDPR applies in addition and we rely on the corresponding bases there.

Where your data is stored

Our application and database run on Render in Singapore. Files are stored in Cloudflare object storage in the Asia-Pacific region. A small number of supporting services — email delivery, product analytics, voice transcription, and the AI model — operate from the United States; each is named on our Subprocessors page, which is the authoritative list of who processes what and where.

How we share data

We share data only with the subprocessors that help us run the service — see our Subprocessors page for the full list, what each processes, and where it is located. We do not sell your personal data. We may disclose data where required by law.

When you connect your own third-party account (such as Gmail, Outlook, MISA, FedEx, or Lark), data flows to that service at your direction; those providers are not our subprocessors, and their handling of that data is governed by your agreement with them.

Analytics and cookies

We use cookies and similar technologies for authentication and for product analytics (via PostHog). We do not record session replays. You can manage non-essential cookies through your browser settings.

How we protect data

We encrypt data in transit and at rest, additionally encrypt connected-account credentials at the application layer, enforce role-based access control and tenant isolation, and keep a tamper-evident audit log. See our Security page for details.

How long we keep data

We keep data only as long as needed to provide the service and meet legal obligations. In general: account data for the life of your account; sessions for up to 30 days; uploaded files for the life of the record that owns them; audit logs for up to 2 years. After deletion, data may remain in encrypted backups until those backups age out on their normal cycle.

Your rights

Article 4 of the Law on Personal Data Protection gives you the right to:

  • Know that your personal data is being processed, and how.
  • Consent, and withdraw consent, or ask us to restrict processing (Articles 9 and 10).
  • Access your data — use the in-product export to receive it in a machine-readable form. Secrets such as session tokens, connected-account credentials, and API key hashes are never included.
  • Correct inaccurate data by updating it in the product.
  • Delete your account, through a confirmed, 30-day deletion process you can cancel.
  • Complain, denounce, sue, and claim damages if your rights are infringed.

We act on a request promptly, within the period the law prescribes. For users in the EU/EEA, the equivalent GDPR rights apply and the outer bound is one month.

If your data is inside an organization's workspace, that organization is the controller and we act only on its instructions — please send your request to them, and we will support them in fulfilling it. Requests about your own Lotics account come to us.

To exercise a right or ask a privacy question, contact our data protection contact at [email protected], or [email protected] for general enquiries.

You may also complain to the Department of Cybersecurity and Hi-tech Crime Prevention (A05), Ministry of Public Security, which is the state authority for personal data protection in Vietnam.

Children

Lotics is not directed to children. You must be at least the age of majority in your jurisdiction to use the service.

Changes to this policy

We may update this policy from time to time. We will post changes on this page and update the date above; we will communicate material changes as appropriate.

Contact

For privacy questions or requests, contact our data protection contact at [email protected], or [email protected] for general enquiries.