This Privacy Policy explains how Innovations24 LLC, doing business as Point of Contact AI ("Point of Contact AI", "we", "our", or "us"), handles personal information in connection with our websites, and how personal data is handled in the product our customers deploy.
We have written this policy to be read, not just filed. Where the law uses specific terms — "controller", "processor", legal bases under the EU and UK General Data Protection Regulation ("GDPR") — we use them, but we keep the explanations plain.
Who we are
Innovations24 LLC is a United States limited liability company that offers Point of Contact AI. For personal data collected through our websites, Innovations24 LLC is the data controller.
Innovations24 LLC (d/b/a Point of Contact AI)
5900 Balcones Drive, Ste 100
Austin, TX 78731
United States
Privacy contact: [email protected]
General contact: [email protected]
We have not appointed a Data Protection Officer, and we are not required to. If you are in the European Economic Area (EEA) or the United Kingdom and wish to raise a data protection matter, please write to [email protected] and we will handle your request directly.
Scope
This policy covers the two websites we operate:
- pointofcontact.ai — our marketing website.
- docs.pointofcontact.ai — our product documentation.
It also explains, in The product section below, how personal data is handled in the Point of Contact AI application that our customers deploy into their own Microsoft Azure subscriptions — because our role there is different, and narrower, than most SaaS vendors.
This policy does not cover third-party websites we link to. When you follow a link away from our sites, the destination's own privacy practices apply.
What we collect on the websites
We collect very little. There is no account to create, no analytics running, and no tracking.
Contact form (pointofcontact.ai)
When you submit the contact form, we collect the information you provide:
- Name (required)
- Email address (required)
- Company (required)
- Phone number (optional)
- Role (optional)
- Interest (a selection you choose)
- Message (required)
The form is submitted through Web3Forms, a third-party form-relay service, which delivers your submission to our sales inbox by email. A short notice and a link to this policy appear next to the submit button so you know where your information is going before you send it.
Server and security logs
Like any website, ours are served through infrastructure that keeps operational logs — typically your IP address, browser user-agent string, and a timestamp — for delivery, reliability, and security (for example, blocking malicious traffic). These logs are held by our hosting and CDN providers (see Processors below). We do not run our own analytics over them, and we do not build profiles from them.
Functional browser storage
Our sites store a small number of items in your browser to remember your own choices. These are not cookies, they are not used for tracking, and nothing in them is sent to us for analytics. They live on your device and you can clear them at any time.
| Item | Storage type | Site | Purpose | Duration |
|---|---|---|---|---|
poc_cookie_consent | localStorage | pointofcontact.ai | Records that you acknowledged the privacy banner, so it does not reappear | Until you clear it |
sticky_cta_dismissed | sessionStorage | pointofcontact.ai | Keeps a floating call-to-action hidden after you dismiss it | Current browser session |
starlight-theme | localStorage | docs.pointofcontact.ai | Remembers your light/dark reading preference | Until you clear it |
Our fonts are served from our own domain, so displaying a page does not send your data to a font provider.
For more on browser storage and the security cookies our CDN may set, see our Cookie Policy.
Purposes and legal bases
Under the GDPR we must have a lawful basis for each purpose. Here is the full picture for website data:
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Respond to your inquiry and take pre-contractual steps you ask for | Contact form fields | Art. 6(1)(b) — steps at your request before entering a contract; and/or Art. 6(1)(f) — our legitimate interest in responding to inquiries |
| Operate, deliver, and secure the websites | Server/security logs (IP, user-agent, timestamp) | Art. 6(1)(f) — our legitimate interest in a reliable, secure service |
| Remember your functional choices on the site | The three storage items above | Art. 6(1)(f) — our legitimate interest in a working interface; these are strictly necessary and set on your device |
| Meet legal, tax, and record-keeping obligations | Relevant correspondence | Art. 6(1)(c) — compliance with a legal obligation |
Where we rely on legitimate interests, we have considered your rights and expectations; you can object at any time (see Your rights).
What we don't do
To be unambiguous:
- We do not use analytics, tag managers, advertising pixels, or any tracking technology on our websites.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- We do not profile you or make automated decisions that produce legal or similarly significant effects.
- We do not collect special-category or "sensitive" personal data through our websites.
The product ("the Service")
This section matters for a specific reason: the Point of Contact AI application does not run on our servers. It is an Azure Marketplace managed application that each customer deploys into their own Microsoft Azure subscription.
The customer is the controller. Chat transcripts, visitor messages, uploaded files, and AI prompts and completions are processed by the customer's own Azure resources — Azure Functions, Azure SignalR, Cosmos DB, Key Vault, Azure AI Foundry, and Application Insights — inside the customer's tenant. For that end-user data, the customer is the data controller and Microsoft Azure is the customer's processor.
We have no data-plane access. By design, Innovations24 has no standing access to customer data. Role-based access control (RBAC) deny assignments block our publisher principal from the customer's data plane. The only information that leaves a customer's deployment to us is content-free operational telemetry — a seat count and deployment status. We do not receive, store, or read chat content, visitor identities, or any customer end-user data.
AI does not train on customer data. Prompts and completions stay within the customer's Azure tenant. The Azure AI Foundry platform does not use customer inputs or outputs to train its models. We do not train, fine-tune, or evaluate any model using customer data.
The anonymous widget. The embeddable chat widget stores nothing persistent in a visitor's browser — only an in-memory session token that disappears when the tab closes. If a customer chooses to enable optional visitor sign-in (Microsoft Entra External ID), the visitor's browser will hold an MSAL token cache and a pocai:widget:authAt timestamp in localStorage. That processing is the customer's, configured and controlled by the customer — not by us.
Because we cannot access customer data, requests to access, correct, or delete data held inside a deployed Service should be directed to the customer operating that deployment. We will reasonably assist customers who ask for help responding.
Processors and sub-processors
We use a small number of providers to run our websites and relay contact-form messages. Each processes data only to provide its service to us.
| Provider | Role | Where |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, and DDoS protection for pointofcontact.ai; DNS/proxy in front of docs.pointofcontact.ai. Sees IP addresses in transit; may set strictly-necessary security cookies (e.g., __cf_bm) for bot mitigation. | United States, with global edge network |
| Web3Forms | Relays contact-form submissions from pointofcontact.ai to our sales inbox by email. | United States |
| Microsoft Azure (Microsoft Corporation) | Hosts docs.pointofcontact.ai (Azure Static Web Apps). Separately, the underlying platform on which customers run the deployed Service in their own subscriptions — where the customer, not us, is the controller. | United States / customer-selected region |
If we add or change a processor that handles website personal data, we will update this list.
International transfers
We are based in the United States, and the providers above process data in the United States. If you contact us from the EEA, the United Kingdom, or Switzerland, your information will be transferred to and processed in the US.
Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum), and — where a provider is certified — the EU-U.S. Data Privacy Framework. For example, Cloudflare, Inc. is certified under the Data Privacy Framework. This certification belongs to the provider; Innovations24 does not claim its own certification.
Data retention
We keep website personal data only as long as we need it, and no longer:
- Contact-form submissions and sales correspondence — kept while we handle your inquiry and any relationship that follows. If nothing comes of it, we delete or archive within about 24 months of our last contact.
- Server and security logs — held by our hosting and CDN providers under their operational defaults (short-lived). We do not keep our own separate copy for analysis.
- Functional browser storage — stored on your own device;
sticky_cta_dismissedclears at the end of the session, andpoc_cookie_consentandstarlight-themepersist until you clear them. - Records we must keep by law — retained for the period the relevant law requires (for example, tax and accounting rules).
Data inside a deployed Service is retained according to the customer's own configuration in the customer's Azure subscription; we cannot access or delete it.
Your rights
If you are in the EEA or the UK (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), where applicable.
- Restrict or object to processing based on our legitimate interests.
- Data portability for data you provided to us.
- Withdraw consent where we relied on it, without affecting prior processing.
- Lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
To exercise any of these, email [email protected]. We may need to verify your identity, and we will respond within the time the law allows (generally one month under the GDPR).
If you are a California resident (CCPA/CPRA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the purposes, and who we share it with.
- Delete personal information we collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of.
- Limit the use of sensitive personal information. We do not collect sensitive personal information through our websites, so this does not apply.
- Non-discrimination — we will not treat you differently for exercising your rights.
To submit a request, email [email protected] with the subject line "California Privacy Request." You may use an authorized agent, who must provide proof of authorization. We will verify your request and respond within the timeframe the CCPA requires (generally 45 days, extendable once where reasonably necessary).
Other U.S. states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable privacy laws have similar rights to access, correct, delete, and port their data, and to opt out of sale and targeted advertising (neither of which we do). Email [email protected] with your state of residence, and we will respond as that state's law requires.
We honor requests globally
Wherever you live, if you send us a privacy request we can reasonably act on, we will — we do not limit these rights to any one region.
Children
Our websites and product are intended for businesses, not for children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact [email protected] and we will delete it.
Security
We keep our security measures proportionate to the little data our websites handle:
- Encryption in transit — our websites are served over TLS (HTTPS).
- Least-privilege access — only the people who need to respond to inquiries can reach the sales inbox that receives contact-form messages.
- Minimal collection — the strongest protection is not holding data we do not need, and our sites collect almost none.
- Platform security — we rely on the security posture of Cloudflare and Microsoft Azure for the infrastructure they provide.
For the deployed Service, customer data is protected inside the customer's own Azure tenant by RBAC deny assignments on our publisher principal, Azure Managed Identity authentication, and secrets held in the customer's own Azure Key Vault. Any platform compliance certifications (for example, Azure's SOC and ISO attestations) belong to Microsoft, not to Innovations24, and apply to the extent the customer enables them.
No method of transmission or storage is perfectly secure. If we become aware of a breach affecting personal data we control, we will notify affected individuals and authorities as the law requires.
Changes to this policy
We may update this policy to reflect changes in our practices or the law. When we do, we will revise the "Last updated" date above and, for material changes, provide a more prominent notice. Your continued use of our websites after an update takes effect means you accept the revised policy.
Contact us
Innovations24 LLC (d/b/a Point of Contact AI)
5900 Balcones Drive, Ste 100
Austin, TX 78731
United States
Privacy: [email protected]
General: [email protected]