Privacy Policy

Last updated: 24 June 2026.

This Privacy Policy explains how Lotics ("we", "us") collects, uses, shares, and protects personal data when you use our service.

Our role: controller and processor

Lotics is a multi-tenant workspace, CRM, and automation platform. Most data in the product belongs to the customer organization that created it — for that data the customer is the controller and Lotics is the processor, acting on the customer's instructions. For a narrow set of account data (your sign-up identity, sessions, and billing), Lotics is the controller. This policy describes how we handle data for which Lotics is the controller; for data inside a workspace your organization controls, that organization's own privacy notice and our agreement with them govern.

Data we collect

  • Account data (we are the controller): your name, email address, hashed password, authentication and multi-factor settings, and sessions; billing details where applicable.
  • Content you create (we are the processor, on your organization's behalf): records, fields, files, chat messages, knowledge documents, and voice recordings you add to a workspace.
  • Connected-account credentials: if you connect a third-party account, we store those credentials encrypted and scoped to the workspace you connected them in.
  • Usage and diagnostic data: product analytics, error reports, and application logs, used to operate and improve the service.

We do not collect or accept Protected Health Information (PHI); it is prohibited by our agreement.

How we use data

  • To provide, secure, and operate the service and authenticate you.
  • To provide support and send service communications (sign-in, notifications).
  • To monitor, debug, and improve the product.
  • To meet legal obligations.

When you use AI features (the chat assistant, document extraction), the content you submit is sent to our AI subprocessor to generate a response and is processed in transit.

Legal bases (where GDPR applies)

We rely on performance of a contract (to provide the service you signed up for), legitimate interests (to secure, operate, and improve the service), legal obligation, and consent where we ask for it. We follow GDPR-aligned practices. We process and store data in the United States.

How we share data

We share data only with the subprocessors that help us run the service — see our Subprocessors page for the full list, what each processes, and where it is located. We do not sell your personal data. We may disclose data where required by law.

When you connect your own third-party account (such as Gmail, Outlook, MISA, FedEx, or Lark), data flows to that service at your direction; those providers are not our subprocessors, and their handling of that data is governed by your agreement with them.

Analytics and cookies

We use cookies and similar technologies for authentication and for product analytics (via PostHog). We do not record session replays. You can manage non-essential cookies through your browser settings.

How we protect data

We encrypt data in transit and at rest, additionally encrypt connected-account credentials at the application layer, enforce role-based access control and tenant isolation, and keep a tamper-evident audit log. See our Security page for details.

How long we keep data

We keep data only as long as needed to provide the service and meet legal obligations. In general: account data for the life of your account; sessions for up to 30 days; uploaded files for the life of the record that owns them; audit logs for up to 2 years. After deletion, data may remain in encrypted backups until those backups age out on their normal cycle.

Your rights

Subject to applicable law, you may:

  • Access and export your personal data through the in-product export.
  • Request erasure of your account, which runs through a confirmed, 30-day deletion process.
  • Correct inaccurate data by updating it in the product.
  • Restrict or object to certain processing.

For data inside a workspace your organization controls, please direct your request to that organization (the controller); we assist them as their processor. To exercise a right or ask a privacy question, contact us at support@lotics.ai.

Children

Lotics is not directed to children. You must be at least the age of majority in your jurisdiction to use the service.

Changes to this policy

We may update this policy from time to time. We will post changes on this page and update the date above; we will communicate material changes as appropriate.

Contact

For privacy questions or requests, contact us at support@lotics.ai.