We take privacy seriously, and we collect as little as we need. This policy explains what personal data Pregress (trading as Finimbus), registered at [registered address] under company number [company registration number] ("Finimbus", "we", "us") processes when you visit finimbus.dev or use the Finimbus application, why, and what rights you have. It follows the EU General Data Protection Regulation (GDPR).
Roles. For visitors, prospects and the people who register to use Finimbus, we are the controller. For the Azure data we read on behalf of a customer, the customer is the controller and we are its processor; that is covered by the Data Processing Agreement.
Who to contact
Privacy questions and requests to exercise your rights: privacy@finimbus.dev.
Pregress (trading as Finimbus), [registered address].
What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Account data: name, work email, employer, job title, hashed credentials, sign-in and security events | Create and secure your account, sign you in, send service emails | Contract |
| Azure metadata and cost data of subscriptions you connect: resource names, types, SKUs, configuration, tags, utilisation, spend. This can include personal data such as user names in tags or resource names. | Produce findings and savings estimates for you | Contract (as processor for the customer, see the DPA) |
| Azure app-registration identifiers and client secrets that you provide | Read your Azure data, read-only, on your behalf | Contract |
| Messages you send us (demo requests, support, email) | Reply and keep a record of our conversation | Legitimate interest / pre-contract steps |
| Technical data: IP address, browser, pages requested, timestamps, errors | Operate and secure the website and application, diagnose faults | Legitimate interest |
| Billing data: invoicing contact, VAT number | Invoice and meet tax obligations | Contract, legal obligation |
| Optional consent for research and development use | Improve our rules and benchmarks using de-identified, aggregated findings | Consent, withdrawable at any time |
We do not sell personal data, and we do not use it for advertising or profiling.
Read-only access to your Azure environment
Finimbus reads metadata and cost data only. We do not read the contents of your storage accounts, databases, key vaults, secrets, virtual machines or application data, and we cannot change anything in your subscriptions. Client secrets you supply are encrypted at rest with a key held separately from the database. You can revoke our access at any moment by removing the role assignment or the secret in Azure.
Cookies
The website uses no analytics or advertising cookies. The application uses a small number of strictly necessary cookies (session and display theme). See our Cookie Policy.
Who we share data with
We share personal data only with providers that help us run Finimbus, under data processing agreements, and where the law requires it:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure (including Azure Static Web Apps for the website) | Hosting, database, storage, logging, secrets management | West Europe (Netherlands) |
| Microsoft Azure Communication Services | Sending service emails | EU |
We keep a current list of subprocessors, and we notify customers of changes as set out in the DPA. We may disclose data if required by law or to protect rights, safety or the Service.
Transfers outside the EEA
Customer and account data is stored and processed in the EU. If any provider processes personal data outside the EEA, we ensure an adequate level of protection, through an adequacy decision or the EU Standard Contractual Clauses (GDPR Article 46) with supplementary measures where needed.
How long we keep data
- Account data: while your account is active, then deleted within 90 days of closure unless the law requires us to keep it.
- Azure scan data: while you are a customer; deleted within 30 days after you disconnect a subscription or close your account, and in backups within a further 35 days.
- Azure client secrets: deleted immediately when you remove the connection.
- Billing records: 7 years, as required by Belgian accounting law.
- Logs: up to 90 days.
- Prospect enquiries: up to 24 months after our last contact.
Security
We protect data with encryption in transit (TLS) and at rest, role-based access limited to people who need it, separation of environments, secrets kept in a managed key vault, audit logging, and least-privilege read-only access to your Azure environment. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.
Your rights
Under the GDPR you may ask us to access, correct, delete or restrict the use of your personal data, to receive it in a portable format, and to object to processing based on legitimate interest. Where processing is based on consent you may withdraw it at any time. Write to privacy@finimbus.dev; we reply within one month. If you are not satisfied you can complain to the Belgian Data Protection Authority (dataprotectionauthority.be) or to the authority in your own country.
If your data belongs to a customer's Azure environment, we may redirect your request to that customer, who decides how it is handled.
Children
Finimbus is a business service for adults. We do not knowingly collect data from anyone under 18.
Changes to this policy
We may update this policy. The date at the top shows the current version. For material changes we will tell registered users, and ask for your consent again where the law requires it.