Privacy Policy
What we collect, why we collect it, who else sees it, and how we handle the account access our clients give us.
1. Who we are
My Cloud Company (“we”, “us”) builds and operates managed teams of AI agents for businesses. We are the data controller for the information described in this policy.
Registered entity: XISLABS PRIVATE LIMITED. Company number: 0181410. Registered address: 30-E1, Gulberg III, Lahore, Pakistan. Questions about this policy go to our contact page.
2. What we collect from visitors
Only what you type into a form. Specifically:
- Business name, work email, and optionally website and phone number
- What work you want taken off your plate, and any brief you write for an Enterprise quote
- Which industry, plan and departments you selected
Our hosting provider also records standard server logs, which include IP addresses and request timestamps. We do not use those to build a profile of you.
3. What we do not collect
Worth stating plainly, because most sites cannot:
- No cookies. This site sets none, so there is no cookie banner and nothing to consent to.
- No analytics or tracking. No Google Analytics, no advertising pixels, no session recording, no heatmaps.
- No third-party fonts or scripts at runtime. Fonts are served from our own domain, so your browser makes no request to Google or any other third party when you load a page.
- No browser storage. We do not write to local storage or session storage.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Replying to your enquiry or quote request | Steps taken at your request before entering a contract |
| Delivering the service to clients | Performance of a contract |
| Keeping the site secure and available | Legitimate interests |
| Meeting accounting and tax obligations | Legal obligation |
5. Client account access — the part that matters most
Clients connect business accounts so their AI company can do the work: social profiles, a CMS, email, a CRM. How that is handled:
- We never ask for your password. Access is granted through each platform's own permission screen.
- Credentials are stored encrypted in a secrets manager and scoped per agent — an agent only receives the credentials its own task requires.
- Secrets are kept out of prompts unless a specific run explicitly needs them.
- You can revoke access at any time from the platform that granted it, without asking us first.
- Each client's data is isolated. Nothing is pooled across clients.
We never require model provider API keys. By default the AI running costs are ours, so there is no reason for us to hold them. Clients who choose the bring-your-own-key option give us a scoped key deliberately; it is stored the same encrypted, per-agent way as any other credential and is revocable at any time.
6. AI processing
Delivering the service means sending the content your agents work on to third-party AI model providers. We do not use client data to train models, and we select providers that contractually commit not to train on data submitted through their business APIs.
AI output is drafted, not published blind. Anything that leaves your business waits in your approval queue first, and every action is logged.
7. Who we share data with
Processors we rely on to run the service:
| Provider | What it handles |
|---|---|
| Vercel | Website hosting and server logs |
| Resend | Delivering enquiry and quote emails to us |
| Lemon Squeezy | Payments. They act as merchant of record and handle card data — we never see your card details |
| AI model providers | Processing the work your agents produce |
We do not sell personal data, and we do not share it for advertising.
8. International transfers
Some providers process data outside your country. Where that happens we rely on the transfer mechanisms those providers put in place, such as standard contractual clauses. Governing jurisdiction for this policy: Pakistan.
9. How long we keep things
- Enquiries that do not become clients: up to 24 months, then deleted.
- Client data: for the life of the contract. On cancellation we export what your company produced and delete the working data within 30 days, unless you ask us to do it sooner.
- Invoices and accounting records: as long as tax law requires.
10. Your rights
You can ask for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, or ask for it in a portable format. Where we rely on consent you can withdraw it at any time. Use the contact page and we will respond within one month. If you are not satisfied, you can complain to your local data protection authority.
11. Security
Encryption in transit and at rest, per-agent credential scoping, approval gates before anything is published, hard spending caps per agent, and an immutable activity log. More detail is on the security page. No system is perfectly secure, and we will tell you promptly if a breach affects your data.
12. Children
This is a business service. It is not directed at anyone under 18 and we do not knowingly collect their data.
13. Changes
If we change this policy we will update the date at the top. For changes that materially affect clients, we will email you before they take effect.