Data handling

Read-only credentials, defined retention, no resale.

Tallywyrm is a 24/7 FinOps agent for multi-cloud spend. This page codifies what we already promise on the landing page: how we get into your cloud, what we keep, and what we will not do with it.

The short version
Read-only cloud credentials via your existing OIDC trust.
No write surface, no resale, retention windows documented below, and the audit trail aligns with the compliance frameworks in the badge row at the foot of this page.
1 · Credentials

Bring-your-own credential scope.

Authentication uses an OIDC trust you already operate; the agent never holds long-lived cloud keys. The credential we ask for is read-only and tightly scoped.

What we ask for
The single line on the landing page, repeated here so the contract is identical:
Read-only cloud credentials via your existing OIDC trust.
What we do NOT request
  • No write surface — inventory and billing reads only.
  • No organisation-admin or account-break-glass role.
  • No role escalation, no IAM user creation, no console access.
  • No cross-account assume-role into resources you have not already federated.
2 · Collection

What data we collect.

Only what the agent needs to compute a recommendation, ship a PR, and prove the audit window. No browsing history, no employee telemetry, no marketing pixels.

Stored encrypted at rest with KMS-managed per-tenant keys. Read the framework-by-framework audit trail →

Prospect form submissions

Contact-form fields (name, work email, company, monthly spend band, free-form message) and waitlist signups (email). Captured only from a visitor who actively submitted the form; never from a third-party enrichment source.

Inventory snapshots

Hourly multi-cloud resource records across AWS, GCP and Azure — instance types, attached storage, network attachments, tag taxonomy, region, and account/tenant lineage.

Rightsizing recommendations and PR content

Computed candidates, the PR diff opened against your Terraform, Pulumi or Crossplane repo, the trace linking the recommendation back to the inventory snapshot it was derived from, and the approval state at each review.

Audit trail

Every action the agent takes — credential access, inventory reads, recommendation writes, PR opens, schedule changes — recorded with timestamp, actor, request payload and outcome for the compliance frameworks in the badge row below.

Weekly report metadata

The savings number, the PRs applied within the audit window, the credit applied to the invoice, and the recipient list. Kept so each invoice can be reconstructed from the report that produced it.

3 · Retention

How long we keep it.

The agent runs on a weekly audit-pass cadence — retention windows below are sized to that, and to the SOC 2 Type II / ISO 27001 control norms the audit trail must satisfy.

Prospect form submissions
Contact-form and waitlist entries kept online for 90 days, then deleted — the path-to-deletion window we honour for every data subject request.
90 days
Inventory snapshots
90 days kept online, archived for 13 months to support the rolling audit pass.
13 months
Weekly savings reports
Archived indefinitely so each invoice can be reconciled against the report that produced it.
Indefinite
Audit trail
Minimum 13 months; exportable on request during that window.
13 months min
4 · Cookies

What cookies we set.

A short list — and a firm line on what is not on it. We do not set third-party marketing, advertising, or retargeting cookies on any surface.

better-auth session
Purpose
Holds the signed session for authed dashboard surfaces.
Retention
Rolling 30-day session lifetime; cleared on sign-out.
Basis
Essential (Art. 6(1)(b) — performance of the contract with the authed user).
next-themes theme
Purpose
Remembers light/dark preference across pages.
Retention
1 year; cleared when the visitor clears site data.
Basis
Essential preference cookie (no analytical content).
PolsiaAnalytics
Purpose
First-party page-view counter — only set when the POLSIA_ANALYTICS_SLUG env is present at deploy time. Counts a single page-view event per request; no cross-session identity, no fingerprinting.
Retention
Anonymous page-view counter, 24-hour window.
Basis
Art. 6(1)(f) legitimate interest in operating the platform (only present when enabled).
No third-party cookies
Purpose
We do not set any Google Ads, Meta Pixel, LinkedIn Insight, Hotjar, or other third-party marketing/retargeting cookies on any surface — marketing, authed, or otherwise.
Retention
N/A — none are set.
Basis
No processing — there is nothing to consent or withdraw.
5 · GDPR lawful basis

Article 6(1), one row per data category.

Every category above maps to one Article 6(1) legal basis. We do not process special categories of personal data under Article 9, and we do not base decisions solely on automated processing with legal or similarly significant effects on a data subject under Article 22.

Prospect form submissions

Art. 6(1)(b) performance of contract with the prospect

The contact form + waitlist are pre-contract negotiation; processing is what the prospect asked us to do when they submitted.

Falls back to Art. 6(1)(a) consent at submit if the inquirer is not a contracting party.

Inventory snapshots

Art. 6(1)(b) performance of contract with the customer workspace

The customer has purchased rightsizing output; reading the resource records the agent needs to compute it is the performance of that contract.

Rightsizing recommendations and PR content

Art. 6(1)(b) performance of contract with the customer workspace

Recommendations and PR diffs are the deliverable the customer contracted for.

Audit trail

Art. 6(1)(b) performance of contract with the customer workspace

Plus Art. 6(1)(c) legal obligation under the SOC 2 / ISO 27001 control norms the platform is audited against.

Weekly report metadata

Art. 6(1)(b) performance of contract with the customer workspace

Plus Art. 6(1)(c) legal obligation to reconcile each invoice against the report that produced it.

Aggregated, fully de-identified service-health metrics

Art. 6(1)(f) legitimate interest in operating the platform

Queue latency, scheduler success rate, and similar metrics stripped of any tenant identifier before leaving the customer tenancy boundary.

6 · EU data residency

Default US, EU on request at workspace signup.

Region is set per workspace at signup and is the boundary every control below operates within. Cross-region replication is opt-in — never the default.

Region selection and tenancy boundary.
Default = United States. EU available on request at workspace signup with no minimum commitment. Same controls, same audit trail, same retention windows in either region.
Default — United States

us-east-1 and us-west-2 (AWS); us-central1 / us-east1 (GCP); eastus / westus2 (Azure). The region the SOC 2 / FedRAMP assessor sees, matching what an agency buyer audits against.

On request — European Union

eu-west-1 / eu-central-1. Picked at workspace signup for buyers whose CSRD / GDPR evidence trail needs in-region processing. All inventory reads, billing reads, audit events and PR content stay within the EU region.

Tenancy boundary is enforced per workspace via the platform-managed per-tenant KMS encryption context — the same posture the security page describes in the How we host section. Cross-region replication is opt-in per workspace; off by default for every region, including the EU one.

7 · Sub-processors

The parties in the data path, named.

The read-only cloud-provider data plane the agent pulls inventory from is listed first — these are the sub-processors that touch your cloud telemetry. The wider table below covers hosting and notification counterparties. Every addition or region change is notified before it takes effect.

Read-only cloud-provider data plane
Three named read-only API surfaces, per provider.
Every inventory read is a request-scoped role assumption under the workspace's OIDC trust — no write API is ever invoked against these surfaces, and no long-lived cloud key is ever held by the platform.
AWS

AWS Cost Explorer (cost & usage) · AWS Config (resource inventory & configuration history) · AWS Organizations (account & OU lineage)

Read-only via the workspace-federated role; no write API ever invoked.

GCP

GCP Cloud Asset Inventory (resource records) · GCP Cloud Billing (cost data, labels, committed-use discounts)

Read-only via the workspace-federated service account; no write API ever invoked.

Azure

Azure Resource Graph (resource inventory) · Azure Cost Management (cost & usage, reservation & savings-plan coverage)

Read-only via the workspace-federated app registration; no write API ever invoked.

Wider sub-processor list
Hosting, billing, notification, and authentication counterparties.
Sub-processorPurposeData categoryRegion
AWSHosting platform and inventory source for AWS-hosted customer workspacesInventory snapshots, audit events, weekly report metadataUS by default (eu-west-1, us-east-1, us-west-2 at signup); EU on request
GCPHosting platform and inventory source for GCP-hosted customer workspacesInventory snapshots, audit events, weekly report metadataUS by default (us-central1, us-east1); EU on request
AzureHosting platform and inventory source for Azure-hosted customer workspacesInventory snapshots, audit events, weekly report metadataUS by default (eastus, westus2); EU on request
StripeSubscription and percentage-of-savings billingBilling email, subscription state, invoice amountsUS-default with EU replication
Polsia emailTransactional and operational mail (contact-form submissions, weekly savings report delivery) via the Polsia platform email proxyNotification payloads, contact-form content, weekly report recipient listDelivered from the EU region by default via the Polsia email proxy
Cloudflare R2Object storage for report artifacts and audit-log archivesCSV exports, diff payloads, archived audit logsGlobal edge (per-bucket region pinning available on request)
Better-auth / session libraryAuthentication and session lifecycle for authed surfacesSession cookies, user identity claimsRuns in the workspace-selected AWS or GCP region
8 · Pledge

No resale of customer data or telemetry.

We do not sell, rent, or barter your inventory, audit events, or cost data. We do not share it with third parties beyond payment and billing counterparties required to raise an invoice.

The telemetry categories above — cost data, inventory snapshots, audit events, recommendation and PR traces — are processed only to deliver the service to you.

Aggregated, fully de-identified service-health metrics (queue latency, scheduler success rate) are the only data used outside a customer tenancy, and only to keep the platform operating.

9 · Rights

Your rights.

The rights below are anchored in GDPR (Articles 15, 16, 17, 20, 21) and the UK GDPR equivalents, with parallel CCPA rights under §1798.105, §1798.106, §1798.110, §1798.115, §1798.121 and §1798.130. They apply to every customer and to every end-user whose data we process in connection with a customer workspace, regardless of jurisdiction.

The concrete path for an access, deletion, portability or objection request is tallwyrm@polsia.app — we acknowledge within one business day and complete within 30 days.

  • Access — request a copy of every record we hold against your tenancy (GDPR Art. 15; CCPA §1798.110).
  • Correction — flag any inventory record or audit entry you believe is wrong; we re-pull from the cloud source of truth on the next hourly snapshot (GDPR Art. 16; CCPA §1798.106).
  • Deletion — close your workspace and we delete tenancy-scoped data within the same retention window we publish below (GDPR Art. 17; CCPA §1798.105).
  • Export — receive the audit trail and report metadata in a portable format on request (GDPR Art. 20; CCPA §1798.110(d)).
  • Objection — opt specific resource classes or regions out of inventory at any time; the agent downscopes on the next cycle (GDPR Art. 21; CCPA §1798.121).
10 · DPA availability

Data Processing Addendum, on request.

Tallywyrmpublishes a Data Processing Addendum (DPA) that codifies the Art. 28 controller-to-processor contract for every customer workspace. The DPA is available on request — no NDA, no procurement-gate — and ships the Standard Contractual Clauses already accepted on the customer side.

Art. 28 controller-to-processor contract.
Two routes to receive it, plus the cross-border transfer posture it ships with.
Privacy contact form

Open the contact form pre-routed to the privacy enquiry route. Reply within one business day.

Request the DPA →
Email the DPO

Direct line to the data protection contact. Same one-business-day ack SLA.

Email the DPO →
Cross-border transfer posture
  • EU GDPR + UK GDPR + Swiss FADP in scope under a single DPA executed at the customer workspace boundary.
  • 2021 European Commission Standard Contractual Clauses, Module 2 (Controller-to-Processor), incorporated by reference for transfers from the EEA to the default US region.
  • UK International Data Transfer Addendum (IDTA), incorporated for transfers from the UK to the default US region.
  • EU-resident workspaces (eu-west-1 / eu-central-1) process all inventory, billing, audit, and PR content in-region — no SCCs needed there.
11 · Compliance posture

Aligned with the frameworks finance and platform teams already audit against.

Same badges as the landing page. The audit trail we keep above is what these frameworks demand.

  • SOC 2 Type II
  • ISO 27001
  • FedRAMP Moderate
  • EU CSRD
  • SEC climate disclosure
  • GDPR
Privacy contact channel
Open the privacy contact formEmail the data protection contactRead the framework-level audit posture →Read the terms →Data subject requests — access, deletion, portability, objection — acknowledged within one business day, completed within 30 days.