Privacy Policy
Fixpoint ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, how long we keep it, and your rights regarding that data. If you have questions, contact us at fixpoint-3@polsia.app.
1. Data We Collect
Account & Contact Data: Name, email address, company name, and job title provided when you sign up or submit a contact form.
Endpoint Metadata: Hostnames, Windows service names, and operational state information collected from the systems you register with Fixpoint. We do not collect file contents, screen captures, keystrokes, or personal data from endpoint users.
Usage Data: Drift events, script generation records, API request logs, and session timestamps used to operate and improve the service.
Payment Data: Processed by Stripe. Fixpoint does not store card numbers or billing PWIs — see Third-Party Services.
Browser Data: A randomly generated visitor ID stored in localStorage for analytics. No personally identifiable information is stored in this identifier.
2. How We Use It
- Deliver autonomous drift detection and remediation script generation;
- Authenticate your account and manage session state;
- Send transactional emails related to your subscription or drift alerts;
- Generate aggregate statistics to improve product reliability and performance;
- Detect and respond to security incidents and Terms violations;
- Comply with legal obligations.
We do not use your endpoint data to train AI models shared with third parties.
3. Data Sharing
We do not sell, trade, or rent your personal data to third parties. We share data only in these circumstances:
- Service providers: With vendors who process data on our behalf (hosting, email delivery, analytics) under strict data processing agreements;
- Legal compliance: When required by law, court order, or government request;
- Business transfers: In the event of a merger, acquisition, or sale of assets, data may transfer under the same privacy commitments.
4. Data Retention
- Account data: Retained while your subscription is active and deleted within 30 days of termination;
- Endpoint metadata: Retained for 90 days after the associated endpoint is removed from monitoring;
- Drift & script logs: Retained for 12 months for reliability analysis;
- Payment records: Retained for 7 years per financial compliance requirements;
- Lead form submissions: Retained for 24 months unless you request deletion.
You may request earlier deletion at any time — see Your Rights.
5. Security
We use industry-standard encryption (TLS 1.2+) for data in transit and AES-256 for data at rest. Access to production systems is restricted to authorized personnel and reviewed quarterly. We maintain an incident response process and will notify affected users within 72 hours of discovering a breach that compromises personal data.
No system is 100% secure. You are responsible for keeping your account credentials confidential and for controlling which users within your organization have access to Fixpoint.
6. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data;
- Correction: Request correction of inaccurate data;
- Deletion: Request deletion of your personal data ("right to be forgotten");
- Portability: Receive your data in a structured, machine-readable format;
- Objection: Object to processing for direct marketing purposes;
- Restriction: Request restriction of processing in certain circumstances.
To exercise any right, email fixpoint-3@polsia.app. We will respond within 30 days.
7. CCPA Notice (California Residents)
Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding personal information. We do not sell personal information and have not sold personal information in the past 12 months.
Categories of personal information collected: identifiers (name, email), professional information (company, job title), and internet activity data (API usage logs).
To exercise your CCPA rights, contact us at fixpoint-3@polsia.app. We verify requests through email confirmation and do not discriminate against users who exercise their rights.
8. GDPR Notice (EEA Residents)
If you are located in the European Economic Area, the legal basis for our processing is:
- Contract performance: Processing your data to deliver the contracted service;
- Legitimate interests: Security monitoring, fraud prevention, and service improvement;
- Consent: For direct marketing communications, where applicable.
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your rights. We commit to cooperating with EU supervisory authorities.
9. Third-Party Services
Fixpoint uses the following third-party services, each operating under their own privacy policies:
- Neon (PostgreSQL): Cloud database — stores account data, endpoint metadata, and logs. Privacy Policy
- OpenAI: Provides AI model access for PowerShell script generation. Privacy Policy
- Stripe: Handles payment processing. Privacy Policy
- Render: Cloud hosting provider for the Fixpoint application. Privacy Policy
- Polsia: Platform infrastructure for authentication and analytics. Privacy Policy
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the revised policy on this page with an updated "Effective" date. We encourage you to review this page periodically.
11. Contact
Fixpoint
Email: fixpoint-3@polsia.app