Legal
Privacy policy.
How CloudMonitor handles personal data.
Privacy Policy
Effective August 24, 2026.
1. Who we are and what this policy covers
Data-Driven AI Pty Ltd (ABN 58 635 718 455) operates CloudMonitor. In this policy, CloudMonitor, we, us, and our mean Data-Driven AI Pty Ltd.
This policy explains how we handle personal information in connection with:
- the public cloudmonitor.ai website, documentation, calculators, and support chat;
- inquiries, marketing, support, and our commercial relationship with customers and prospects;
- CloudMonitor accounts, Microsoft Marketplace transactions, and Microsoft Entra ID sign-in; and
- the CloudMonitor service, including its Microsoft Fabric data processing and AI-assisted features.
We apply the Australian Privacy Principles under the Privacy Act 1988 (Cth) where they apply. Other privacy and data-protection laws may also apply according to the individual, customer, and processing involved.
This policy is a public notice. A customer’s product agreement, order, and any privacy or data-processing terms incorporated into that agreement govern customer-directed processing within the CloudMonitor service. Those documents control if they set a more specific obligation.
2. Our privacy roles
Our legal role depends on why we process the information.
2.1 When we decide the purpose
We generally act as a controller, business, or equivalent responsible entity for personal information used to:
- operate and secure our website;
- respond to inquiries and provide requested calculator results;
- manage prospects, customer contacts, accounts, subscriptions, and support;
- administer our Microsoft Marketplace publisher relationship;
- send marketing where permitted; and
- meet our own legal, security, audit, and business-record obligations.
This includes the limited profile and tenant information needed to identify an authorized CloudMonitor user and administer the account.
2.2 When a customer directs the purpose
For personal information contained in data that a customer provides, connects, configures, or asks CloudMonitor to analyze, the customer generally acts as controller and we act as its processor or service provider. If the customer is itself a processor, we may act as its subprocessor. We process that information to provide the service and follow the applicable customer agreement and documented instructions.
Customer-directed data can include a person’s name or identifier in a resource name, tag, cost-group mapping, audit event, AI-usage record, or other business metadata. The same information may be processed in more than one role. For example, we may use an administrator’s work email to manage the account for our own business purposes while processing that administrator’s activity record on the customer’s instructions.
Requests about customer-directed data may need to be made through the relevant customer. Section 11 explains how we handle those requests.
3. Information we collect and where it comes from
| Category | Examples | Main sources |
|---|---|---|
| Website and device data | IP address, browser and device type, operating system, request time, requested URL, referrer, approximate region, page views, interactions, analytics or advertising identifiers, and cookie choices | Your browser or device; Cloudflare; Google; LinkedIn |
| Inquiry, calculator, and support data | Name and work contact details if provided, organization, support or chat content, the page from which you contacted us, calculator inputs and results, and a record of the choice shown with the form | You; our website forms; AnyChat |
| Account and identity data | User principal name, Microsoft Entra object ID, display name, work email, tenant ID, sign-in and authorization events, account role, and service preferences | You; your organization; Microsoft Entra ID |
| Marketplace and commercial data | Customer and purchaser contact details, organization, tenant and account identifiers, offer, plan, entitlement, order, and transaction status that Microsoft makes available to a publisher | You; your organization; Microsoft Marketplace |
| Azure cost and resource metadata | FOCUS billing and usage fields, subscription, resource group, resource and meter names, tags, quantities, costs, and related identifiers | Customer-owned Azure Storage and connected Microsoft services |
| Connected service metrics | Microsoft Fabric capacity metrics and connected AI-service usage or token metrics, which can include user, actor, project, model, or account identifiers | Microsoft and customer-authorized connected services |
| CloudMonitor configuration and output | Cost groups, tag mappings, budgets, alert rules, feature settings, audit history, analysis results, and derived reports | Customer users; CloudMonitor processing |
| Finn data | A submitted question, relevant cost data retrieved to answer it, visible conversation context, generated answer, and audit information such as outcome, timing, or error state | The user; CloudMonitor; Microsoft Fabric and Azure OpenAI |
CloudMonitor does not use its Azure cost access to read application data, secrets, or content held inside a customer’s workloads. Resource names, tags, account fields, and other metadata can still contain personal or confidential information if a customer puts it there.
Microsoft handles payment methods and the Marketplace storefront under its own terms. CloudMonitor does not ask for or receive payment-card or bank-account details through the website or CloudMonitor service.
We may receive information from an authorized customer administrator, employer, reseller, Microsoft, or another connected service rather than directly from the individual. Customers must have authority to provide personal information and configure connected sources.
4. Why we use personal information
Where a law requires a legal basis, the basis depends on the activity and the relationship involved.
| Purpose | Typical basis where applicable |
|---|---|
| Provide the website feature, calculator result, account, subscription, support, and CloudMonitor service requested | Take steps at your request; perform a contract; pursue our legitimate interest in providing and administering the requested business service |
| Authenticate users, apply permissions, keep audit records, prevent abuse, investigate incidents, and protect the service | Perform a contract; comply with law; pursue our legitimate interests in security, fraud prevention, and legal claims |
| Process customer-connected cost, resource, capacity, AI-usage, configuration, and audit data | The customer’s documented instructions and product agreement; the customer’s legal basis governs its role as controller |
| Complete and administer a Microsoft Marketplace transaction | Perform a contract; comply with legal and accounting obligations; use Marketplace contact data for the permitted transactional purpose |
| Respond to an inquiry, chat, or support request | Take steps at your request; perform a contract; pursue our legitimate interest in responding to business contacts |
| Measure website performance and understand use | Consent where required for non-essential analytics; otherwise our legitimate interest where the law permits |
| Measure advertising and reach relevant business audiences | Consent where required; an opt-out right where applicable law uses that model |
| Send direct marketing | Consent or another basis expressly permitted for the relevant business contact and jurisdiction; every marketing email provides an unsubscribe method |
| Meet legal, tax, regulatory, insurance, and dispute-resolution requirements | Legal obligation; legitimate interests in establishing, exercising, or defending legal claims |
Contact details Microsoft provides through Marketplace are used for the transaction or to answer a Marketplace inquiry. We use those details for marketing only if we obtain separate permission or received the contact details independently on a lawful basis.
You may withdraw consent at any time. Withdrawal affects future processing and does not make earlier processing unlawful. Where we do not rely on consent, we use personal information only on another basis permitted by applicable law.
5. How we disclose information
We disclose personal information only for the purposes described in this policy, including:
- to personnel and contractors who need it for their work and are subject to confidentiality and access controls;
- to service providers that host, secure, authenticate, measure, or support the website and service;
- within the relevant customer organization, including to authorized administrators and users, according to the customer’s configuration;
- to Microsoft and customer-authorized connected services where needed for the Marketplace transaction, identity, hosting, Fabric, or AI feature involved;
- to professional advisers, auditors, insurers, and prospective transaction advisers under appropriate duties of confidentiality;
- to a regulator, court, law-enforcement body, or other recipient where law requires or permits it; and
- in a merger, financing, reorganization, or sale of all or part of the business, subject to applicable law and appropriate confidentiality controls.
Our Service Provider Register identifies the providers currently evidenced for the website and CloudMonitor service and explains which ones may receive customer application data.
Microsoft acts as an independent controller for personal information it processes for the Microsoft Marketplace storefront, billing, and its own commercial relationship. Microsoft and Data-Driven AI are not joint controllers merely because Microsoft makes Marketplace customer contact information available to us.
We do not sell personal information for money. Some laws define disclosures to analytics or advertising providers as a sale, sharing, or targeted advertising even when no money changes hands. Where those definitions apply, you can reject the relevant non-essential category through our cookie controls and exercise the rights in Section 11.
6. Cookies and similar technologies
Our website uses browser storage, tags, pixels, user-requested embedded media, and server-side network information. Strictly necessary technologies support website delivery, security, forms, and your privacy choices. Google Analytics and LinkedIn Insight do not load until you affirmatively allow the combined Analytics and marketing category. AnyChat loads only when you actively request support. A documentation video uses YouTube’s privacy-enhanced domain, and its player is not created until you choose to load the video.
The Cookie and Similar Technologies Policy lists the current tools, categories, purposes, and controls. You can reopen Cookie settings from the website to change a choice. Cloudflare may still process operational and security information needed to deliver the website.
7. Product data location and international processing
Different data classes follow different location boundaries:
- Raw FOCUS export. Azure Cost Management writes the raw export to the customer’s Azure Storage account. It remains in that customer-controlled account and region until the customer deletes it or applies its own lifecycle policy.
- Cost processing and derived data. CloudMonitor accesses the raw export through scoped permissions and a OneLake shortcut. During onboarding, the customer chooses any available Azure and Microsoft Fabric region worldwide. CloudMonitor deploys a dedicated customer shard in that region and processes cost data and derived outputs inside it.
- Management plane. CloudMonitor’s central management plane operates in Australia East. Management-plane, account, service-administration, and security records are separate from the raw export.
- Identity, Marketplace, support, and website data. Microsoft Entra ID, Microsoft Marketplace, Cloudflare, Google, LinkedIn, AnyChat, and business operations do not inherit the selected Fabric-region boundary. These providers may process information through global systems and provider-controlled locations.
Personal information may therefore be accessed or processed outside the individual’s country. Each customer’s cost-processing shard operates in the region they select. Customer-controlled raw Azure Storage can also be in the region the customer selects. Other provider locations can differ: for example, AnyChat states that it stores customer content in the European Union, including Germany, while business operations and transfers can involve the United States and other provider locations. A regional CloudMonitor deployment does not mean every website, identity, Marketplace, support, or provider record remains in that region.
We use the contractual, organizational, and technical protections required by applicable law and the relevant customer or provider agreement. We do not represent in this public policy that one transfer mechanism applies to every person, provider, or deployment. Contact us for the transfer information applicable to a particular customer arrangement.
8. Retention and deletion
We retain personal information only for the purpose for which it was collected and for applicable legal, security, accounting, and dispute-resolution needs. We delete or de-identify it when those purposes no longer require identifiable data.
The currently evidenced periods and criteria are:
| Data | Current period or criterion |
|---|---|
| Raw FOCUS export in customer-owned Azure Storage | CloudMonitor does not set its retention period. The customer controls deletion and Azure lifecycle settings. Revoking CloudMonitor’s Azure roles stops our access. |
| CloudMonitor user data after account termination | The current Microsoft Marketplace compliance commitment is less than 30 days after account termination. This statement covers user data within that submission. It does not set the customer’s raw-export retention or a new period for records that law requires us to keep. |
| Finn live conversation | Conversation context lasts for the current application session. Each submitted question and its outcome, timing, or error information can be retained in an administrator-only audit record; the answer text is not stored in that audit record. A separately enabled saved or shared investigation feature may have its own customer configuration and retention terms. |
| Website inquiry, calculator, chat, support, and Marketplace relationship records | Kept while needed to provide the requested response or manage the relationship, then for any period needed for security, legal obligations, or a dispute. No shorter fixed public period is represented for these records. |
| Cookie or browser-storage preference | Kept until it expires under the implemented setting, you change it, or you clear the relevant browser storage. We do not state a fixed lifetime because browser and implementation behavior can change. |
| Analytics and advertising data | Governed by the consent choice, our tool configuration, and the provider’s retention controls. Withdrawing consent stops future optional collection from this website but does not erase information a provider lawfully received earlier. |
| Security and access records | Kept for the period reasonably needed to detect, investigate, document, and respond to security events and legal requirements. |
We may preserve a limited record where deletion is suspended by law, a legal hold, fraud prevention, or the need to document a privacy request or opt-out. We restrict that record to the applicable purpose. Aggregated or de-identified information that no longer identifies an individual may be kept longer.
9. Sensitive information and children
CloudMonitor is an enterprise service and is not directed to anyone under 16. We do not knowingly collect personal information from anyone under 16 and do not seek parental or guardian consent for the service. If you believe a child has provided personal information, contact us so we can investigate and delete it where required.
We do not ask for special-category or sensitive information such as health, biometric, genetic, religious, political, or sexual-orientation data. Do not place that information in general website forms, support messages, resource names, tags, cost-group labels, or AI questions. If a customer includes sensitive information in customer-directed data, the customer is responsible for having an appropriate legal basis and giving us documented instructions. We will handle it according to the customer agreement and applicable law.
10. AI features and automated decisions
Finn is CloudMonitor’s read-only, AI-assisted cost-analysis feature. When a user asks Finn a question, Microsoft Fabric and Azure OpenAI process the question and relevant customer cost data to generate an answer. Visible conversation context lasts for the current application session. Administrators can see the audit information described in Section 8.
Microsoft states that prompts and completions used for Azure model inferencing are not used to train, retrain, or improve its base models. Microsoft may apply automated content filtering and abuse monitoring, and its service documentation describes circumstances in which human review may occur. See Microsoft’s Azure Direct Models privacy documentation for the provider-side rules and deployment exceptions.
CloudMonitor does not use solely automated processing to make a decision about an individual that produces a legal or similarly significant effect. Finn and CloudMonitor recommendations provide information for human review. CloudMonitor does not execute the recommended change, and the customer remains responsible for checking the evidence and deciding whether to act.
11. Your privacy choices and rights
Your rights depend on the law that applies. They may include the right to:
- request access to personal information we hold about you;
- ask us to correct inaccurate, incomplete, out-of-date, irrelevant, or misleading information;
- ask us to delete information;
- restrict or object to processing;
- receive certain information in a portable format;
- withdraw consent and unsubscribe from direct marketing;
- opt out of processing defined as a sale, sharing, or targeted advertising; and
- complain to a privacy regulator without being treated unfairly for exercising a right.
Send a request to support@cloudmonitor.ai. Describe the information or account involved and the right you want to exercise. We may ask for information reasonably needed to verify identity and authority. An authorized agent may make a request where applicable law permits it.
If the request concerns information we process only for a customer, we will notify or refer the request to that customer and assist as required. We will respond within the period required by applicable law. We do not normally charge for a request, but may refuse or charge a reasonable amount where the law expressly permits that response, such as for a manifestly unfounded or excessive request.
You can also:
- use the unsubscribe link in a marketing email;
- reopen Cookie settings to change non-essential website choices;
- ask your customer administrator to update account or customer-controlled data; and
- revoke CloudMonitor’s Azure roles through the Azure portal if you are authorized to manage them.
12. Security and data breaches
We use administrative, technical, and physical safeguards proportionate to the information and service involved. Current controls include scoped access, per-customer Fabric isolation, encryption in transit and at rest, access reviews, logging, vulnerability management, change review, incident response, and recovery procedures. The Information Trust Center explains these controls and their scope.
No transmission, system, or storage method is completely secure. We investigate suspected incidents and notify affected customers, individuals, and authorities when and within the time required by applicable law and contract. Where we act as a processor, we notify and assist the relevant customer as required by the product agreement and applicable law.
13. Complaints and regulators
Send privacy questions, rights requests, or complaints to:
Data-Driven AI Pty Ltd
ABN 58 635 718 455
111 Harrington Street, The Rocks, NSW 2000, Australia
support@cloudmonitor.ai
We will acknowledge the complaint, investigate it, and explain our response. We aim to respond within 30 days unless the matter is complex or applicable law requires a different period. If we need more time, we will explain why.
If you are not satisfied, you may contact the Office of the Australian Information Commissioner. If EEA, UK, or another local privacy law applies, you may also complain to the supervisory authority for your location. Contacting us first may allow us to resolve the issue, but it does not remove a right to contact a regulator.
14. Third-party sites and customer-controlled services
Links to third-party sites are provided for reference. The third party controls its own privacy practices. A customer may also connect services that it procures and controls. Those providers’ terms apply to the customer’s relationship with them, while this policy applies to CloudMonitor’s own handling.
15. Changes to this policy
We may update this policy when our processing, providers, product, or legal obligations change. The current version shows its effective date.
If a change materially affects how we use personal information, we will provide reasonable notice through the website, service, or available contact details before the change takes effect where practicable. An urgent legal or security change may take effect sooner. A policy update does not change the terms of an existing customer agreement unless that agreement permits it.