Read-only credentials, defined retention, no resale.
Tallywyrm is a 24/7 FinOps agent for multi-cloud spend. This page codifies what we already promise on the landing page: how we get into your cloud, what we keep, and what we will not do with it.
Bring-your-own credential scope.
Authentication uses an OIDC trust you already operate; the agent never holds long-lived cloud keys. The credential we ask for is read-only and tightly scoped.
Read-only cloud credentials via your existing OIDC trust.
- No write surface — inventory and billing reads only.
- No organisation-admin or account-break-glass role.
- No role escalation, no IAM user creation, no console access.
- No cross-account assume-role into resources you have not already federated.
What data we collect.
Only what the agent needs to compute a recommendation, ship a PR, and prove the audit window. No browsing history, no employee telemetry, no marketing pixels.
Stored encrypted at rest with KMS-managed per-tenant keys. Read the framework-by-framework audit trail →
Contact-form fields (name, work email, company, monthly spend band, free-form message) and waitlist signups (email). Captured only from a visitor who actively submitted the form; never from a third-party enrichment source.
Hourly multi-cloud resource records across AWS, GCP and Azure — instance types, attached storage, network attachments, tag taxonomy, region, and account/tenant lineage.
Computed candidates, the PR diff opened against your Terraform, Pulumi or Crossplane repo, the trace linking the recommendation back to the inventory snapshot it was derived from, and the approval state at each review.
Every action the agent takes — credential access, inventory reads, recommendation writes, PR opens, schedule changes — recorded with timestamp, actor, request payload and outcome for the compliance frameworks in the badge row below.
The savings number, the PRs applied within the audit window, the credit applied to the invoice, and the recipient list. Kept so each invoice can be reconstructed from the report that produced it.
How long we keep it.
The agent runs on a weekly audit-pass cadence — retention windows below are sized to that, and to the SOC 2 Type II / ISO 27001 control norms the audit trail must satisfy.
What cookies we set.
A short list — and a firm line on what is not on it. We do not set third-party marketing, advertising, or retargeting cookies on any surface.
- Purpose
- Holds the signed session for authed dashboard surfaces.
- Retention
- Rolling 30-day session lifetime; cleared on sign-out.
- Basis
- Essential (Art. 6(1)(b) — performance of the contract with the authed user).
- Purpose
- Remembers light/dark preference across pages.
- Retention
- 1 year; cleared when the visitor clears site data.
- Basis
- Essential preference cookie (no analytical content).
- Purpose
- First-party page-view counter — only set when the POLSIA_ANALYTICS_SLUG env is present at deploy time. Counts a single page-view event per request; no cross-session identity, no fingerprinting.
- Retention
- Anonymous page-view counter, 24-hour window.
- Basis
- Art. 6(1)(f) legitimate interest in operating the platform (only present when enabled).
- Purpose
- We do not set any Google Ads, Meta Pixel, LinkedIn Insight, Hotjar, or other third-party marketing/retargeting cookies on any surface — marketing, authed, or otherwise.
- Retention
- N/A — none are set.
- Basis
- No processing — there is nothing to consent or withdraw.
Article 6(1), one row per data category.
Every category above maps to one Article 6(1) legal basis. We do not process special categories of personal data under Article 9, and we do not base decisions solely on automated processing with legal or similarly significant effects on a data subject under Article 22.
Art. 6(1)(b) performance of contract with the prospect
The contact form + waitlist are pre-contract negotiation; processing is what the prospect asked us to do when they submitted.
Falls back to Art. 6(1)(a) consent at submit if the inquirer is not a contracting party.
Art. 6(1)(b) performance of contract with the customer workspace
The customer has purchased rightsizing output; reading the resource records the agent needs to compute it is the performance of that contract.
Art. 6(1)(b) performance of contract with the customer workspace
Recommendations and PR diffs are the deliverable the customer contracted for.
Art. 6(1)(b) performance of contract with the customer workspace
Plus Art. 6(1)(c) legal obligation under the SOC 2 / ISO 27001 control norms the platform is audited against.
Art. 6(1)(b) performance of contract with the customer workspace
Plus Art. 6(1)(c) legal obligation to reconcile each invoice against the report that produced it.
Art. 6(1)(f) legitimate interest in operating the platform
Queue latency, scheduler success rate, and similar metrics stripped of any tenant identifier before leaving the customer tenancy boundary.
Default US, EU on request at workspace signup.
Region is set per workspace at signup and is the boundary every control below operates within. Cross-region replication is opt-in — never the default.
us-east-1 and us-west-2 (AWS); us-central1 / us-east1 (GCP); eastus / westus2 (Azure). The region the SOC 2 / FedRAMP assessor sees, matching what an agency buyer audits against.
eu-west-1 / eu-central-1. Picked at workspace signup for buyers whose CSRD / GDPR evidence trail needs in-region processing. All inventory reads, billing reads, audit events and PR content stay within the EU region.
Tenancy boundary is enforced per workspace via the platform-managed per-tenant KMS encryption context — the same posture the security page describes in the How we host section. Cross-region replication is opt-in per workspace; off by default for every region, including the EU one.
The parties in the data path, named.
The read-only cloud-provider data plane the agent pulls inventory from is listed first — these are the sub-processors that touch your cloud telemetry. The wider table below covers hosting and notification counterparties. Every addition or region change is notified before it takes effect.
AWS Cost Explorer (cost & usage) · AWS Config (resource inventory & configuration history) · AWS Organizations (account & OU lineage)
Read-only via the workspace-federated role; no write API ever invoked.
GCP Cloud Asset Inventory (resource records) · GCP Cloud Billing (cost data, labels, committed-use discounts)
Read-only via the workspace-federated service account; no write API ever invoked.
Azure Resource Graph (resource inventory) · Azure Cost Management (cost & usage, reservation & savings-plan coverage)
Read-only via the workspace-federated app registration; no write API ever invoked.
| Sub-processor | Purpose | Data category | Region |
|---|---|---|---|
| AWS | Hosting platform and inventory source for AWS-hosted customer workspaces | Inventory snapshots, audit events, weekly report metadata | US by default (eu-west-1, us-east-1, us-west-2 at signup); EU on request |
| GCP | Hosting platform and inventory source for GCP-hosted customer workspaces | Inventory snapshots, audit events, weekly report metadata | US by default (us-central1, us-east1); EU on request |
| Azure | Hosting platform and inventory source for Azure-hosted customer workspaces | Inventory snapshots, audit events, weekly report metadata | US by default (eastus, westus2); EU on request |
| Stripe | Subscription and percentage-of-savings billing | Billing email, subscription state, invoice amounts | US-default with EU replication |
| Polsia email | Transactional and operational mail (contact-form submissions, weekly savings report delivery) via the Polsia platform email proxy | Notification payloads, contact-form content, weekly report recipient list | Delivered from the EU region by default via the Polsia email proxy |
| Cloudflare R2 | Object storage for report artifacts and audit-log archives | CSV exports, diff payloads, archived audit logs | Global edge (per-bucket region pinning available on request) |
| Better-auth / session library | Authentication and session lifecycle for authed surfaces | Session cookies, user identity claims | Runs in the workspace-selected AWS or GCP region |
No resale of customer data or telemetry.
We do not sell, rent, or barter your inventory, audit events, or cost data. We do not share it with third parties beyond payment and billing counterparties required to raise an invoice.
The telemetry categories above — cost data, inventory snapshots, audit events, recommendation and PR traces — are processed only to deliver the service to you.
Aggregated, fully de-identified service-health metrics (queue latency, scheduler success rate) are the only data used outside a customer tenancy, and only to keep the platform operating.
Your rights.
The rights below are anchored in GDPR (Articles 15, 16, 17, 20, 21) and the UK GDPR equivalents, with parallel CCPA rights under §1798.105, §1798.106, §1798.110, §1798.115, §1798.121 and §1798.130. They apply to every customer and to every end-user whose data we process in connection with a customer workspace, regardless of jurisdiction.
The concrete path for an access, deletion, portability or objection request is tallwyrm@polsia.app — we acknowledge within one business day and complete within 30 days.
- Access — request a copy of every record we hold against your tenancy (GDPR Art. 15; CCPA §1798.110).
- Correction — flag any inventory record or audit entry you believe is wrong; we re-pull from the cloud source of truth on the next hourly snapshot (GDPR Art. 16; CCPA §1798.106).
- Deletion — close your workspace and we delete tenancy-scoped data within the same retention window we publish below (GDPR Art. 17; CCPA §1798.105).
- Export — receive the audit trail and report metadata in a portable format on request (GDPR Art. 20; CCPA §1798.110(d)).
- Objection — opt specific resource classes or regions out of inventory at any time; the agent downscopes on the next cycle (GDPR Art. 21; CCPA §1798.121).
Data Processing Addendum, on request.
Tallywyrmpublishes a Data Processing Addendum (DPA) that codifies the Art. 28 controller-to-processor contract for every customer workspace. The DPA is available on request — no NDA, no procurement-gate — and ships the Standard Contractual Clauses already accepted on the customer side.
Open the contact form pre-routed to the privacy enquiry route. Reply within one business day.
Request the DPA →Direct line to the data protection contact. Same one-business-day ack SLA.
Email the DPO →- EU GDPR + UK GDPR + Swiss FADP in scope under a single DPA executed at the customer workspace boundary.
- 2021 European Commission Standard Contractual Clauses, Module 2 (Controller-to-Processor), incorporated by reference for transfers from the EEA to the default US region.
- UK International Data Transfer Addendum (IDTA), incorporated for transfers from the UK to the default US region.
- EU-resident workspaces (eu-west-1 / eu-central-1) process all inventory, billing, audit, and PR content in-region — no SCCs needed there.
Aligned with the frameworks finance and platform teams already audit against.
Same badges as the landing page. The audit trail we keep above is what these frameworks demand.
- SOC 2 Type II
- ISO 27001
- FedRAMP Moderate
- EU CSRD
- SEC climate disclosure
- GDPR