This Privacy Policy explains how Innovations24 LLC, doing business as Point of Contact AI ("Point of Contact AI", "we", "our", or "us"), handles personal information in connection with our websites, and how personal data is handled in both editions of our product — Point of Contact — Self-Hosted, which a customer deploys into an Azure subscription the customer controls, and Point of Contact — Hosted, which we operate.
We have written this policy to be read, not just filed. Where the law uses specific terms — "controller", "processor", legal bases under the EU and UK General Data Protection Regulation ("GDPR") — we use them, but we keep the explanations plain.
Who we are
Innovations24 LLC is a United States limited liability company that offers Point of Contact AI. For personal data collected through our websites, Innovations24 LLC is the data controller.
Innovations24 LLC (d/b/a Point of Contact AI)
5900 Balcones Drive, Ste 100
Austin, TX 78731
United States
Privacy contact: privacy@pointofcontact.ai
General contact: info@innovations24.com
We have not appointed a Data Protection Officer, and we are not required to. If you are in the European Economic Area (EEA) or the United Kingdom and wish to raise a data protection matter, please write to privacy@pointofcontact.ai and we will handle your request directly.
Scope
This policy covers the two websites we operate:
- pointofcontact.ai — our marketing website.
- docs.pointofcontact.ai — our product documentation.
It also explains, in The product section below, how personal data is handled in both editions of the Point of Contact application: Self-Hosted, which customers deploy into Azure subscriptions they control, and Hosted, the multi-tenant service we operate for customers. Our role is different in each, so the two are described separately.
This policy does not cover third-party websites we link to. When you follow a link away from our sites, the destination's own privacy practices apply.
What we collect on the websites
We collect very little. There is no account to create, no analytics running, and no tracking.
Contact form (pointofcontact.ai)
When you submit the contact form, we collect the information you provide:
- Name (required)
- Email address (required)
- Company (required)
- Phone number (optional)
- Role (optional)
- Interest (a selection you choose)
- Message (required)
The form is submitted through Web3Forms, a third-party form-relay service, which delivers your submission to our sales inbox by email. A short notice and a link to this policy appear next to the submit button so you know where your information is going before you send it.
Server and security logs
Like any website, ours are served through infrastructure that keeps operational logs — typically your IP address, browser user-agent string, and a timestamp — for delivery, reliability, and security (for example, blocking malicious traffic). These logs are held by our hosting and CDN providers (see Processors below). We do not run our own analytics over them, and we do not build profiles from them.
Functional browser storage
Our sites store a small number of items in your browser to remember your own choices. These are not cookies, they are not used for tracking, and nothing in them is sent to us for analytics. They live on your device and you can clear them at any time.
| Item | Storage type | Site | Purpose | Duration |
|---|---|---|---|---|
poc_cookie_consent | localStorage | pointofcontact.ai | Records that you acknowledged the privacy banner, so it does not reappear | Until you clear it |
sticky_cta_dismissed | sessionStorage | pointofcontact.ai | Keeps a floating call-to-action hidden after you dismiss it | Current browser session |
starlight-theme | localStorage | docs.pointofcontact.ai | Remembers your light/dark reading preference | Until you clear it |
Our fonts are served from our own domain, so displaying a page does not send your data to a font provider.
For more on browser storage and the security cookies our CDN may set, see our Cookie Policy.
Purposes and legal bases
Under the GDPR we must have a lawful basis for each purpose. Here is the full picture for website data:
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Respond to your inquiry and take pre-contractual steps you ask for | Contact form fields | Art. 6(1)(b) — steps at your request before entering a contract; and/or Art. 6(1)(f) — our legitimate interest in responding to inquiries |
| Operate, deliver, and secure the websites | Server/security logs (IP, user-agent, timestamp) | Art. 6(1)(f) — our legitimate interest in a reliable, secure service |
| Remember your functional choices on the site | The three storage items above | Art. 6(1)(f) — our legitimate interest in a working interface; these are strictly necessary and set on your device |
| Meet legal, tax, and record-keeping obligations | Relevant correspondence | Art. 6(1)(c) — compliance with a legal obligation |
Where we rely on legitimate interests, we have considered your rights and expectations; you can object at any time (see Your rights).
What we don't do
To be unambiguous:
- We do not use analytics, tag managers, advertising pixels, or any tracking technology on our websites.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- We do not profile you or make automated decisions that produce legal or similarly significant effects.
- We do not collect special-category or "sensitive" personal data through our websites.
The product ("the Service")
Point of Contact is sold in two editions, and our role in each is very different. Read the one that applies to you. Where a sentence below appears under one edition's heading, it is true of that edition only.
Point of Contact — Self-Hosted
Self-Hosted runs on the customer's infrastructure, not on ours. It is an Azure Marketplace managed application that each customer deploys into an Azure subscription the customer controls.
The customer is the controller. Chat transcripts, visitor messages, and AI prompts and completions are processed by the customer's own Azure resources — Azure Functions, Azure SignalR, Cosmos DB, Key Vault, Azure AI Foundry, and Application Insights — inside the customer's tenant. For that end-user data, the customer is the data controller and Microsoft Azure is the customer's processor.
Our access to a Self-Hosted deployment is just-in-time, never standing. Any elevation is approved by the customer, time-boxed, and logged. Role-based access control (RBAC) deny assignments block our publisher principal from the customer's data plane. The only information that leaves a customer's deployment to us is content-free operational telemetry — a seat count and deployment status. We do not receive, store, or read chat content, visitor identities, or any end-user data from a Self-Hosted deployment.
AI does not train on customer data. Prompts and completions stay within the customer's Azure tenant. The Azure AI platform does not use customer inputs or outputs to train its models. We do not train, fine-tune, or evaluate any model using customer data.
The anonymous widget. The Self-Hosted chat widget stores nothing persistent in a visitor's browser — only an in-memory session token that disappears when the tab closes. Visitor sign-in is not part of Self-Hosted; it is a Hosted feature, described below.
Because our access to a Self-Hosted deployment is just-in-time, approved by the customer and time-boxed, requests to access, correct, or delete data held inside such a deployment should be directed to the customer operating it. We will reasonably assist customers who ask for help responding.
Point of Contact — Hosted
We operate this edition. Point of Contact — Hosted is a multi-tenant service that we run in Microsoft Azure, in an Azure subscription we own, in the United States. The conversation record is stored there — on infrastructure we operate, not the customer's.
What the record holds. For each customer we store sessions and messages (visitor text, AI replies, agent and system messages, and timestamps); files uploaded by signed-in visitors, kept in Azure Blob Storage we operate and never sent to the AI model, where a submitted file also has a backup copy that is deleted after 28 days; the visitor's display identity where the customer enables sign-in (name, email address, Microsoft Entra External ID object id, and preferred contact type); agent identity taken from the customer's Microsoft Entra tenant (object id, email address, display name, tenant id, role, and group membership); session metadata (page URL, widget id, the handling agent, and transfers); AI-derived conversation topics where the customer runs Topic Analysis; Marketplace subscription records (purchaser and beneficiary email address, object and tenant ids, plan, and quantity); a sanitized audit log that carries no message content; and operational telemetry that carries no message content.
Two things we deliberately do not keep: an agent's presence in Microsoft Teams is read from Microsoft Graph and held in memory for less than a minute, and a visitor's IP address is used in memory for rate limiting only. Neither is stored.
Roles. For Hosted end-user data, the customer is the data controller and Innovations24 is the customer's processor. Microsoft Azure (Microsoft Corporation) is our sub-processor for hosting, in the United States. No party outside Microsoft receives customer data. The Azure AI Foundry project, Microsoft Entra tenant, and Microsoft Teams that a customer connects are the customer's own resources, not third parties we hand data to.
Who can reach the record. Our operations staff can access the conversation record in order to support the customer. We state that plainly rather than imply otherwise: on Hosted the record sits in our environment, and the people who run the service can read it. Access is limited to the staff who need it, and it is governed by the controls described under Security below.
Model processing happens in the customer's Azure AI Foundry project. Every prompt and completion is processed by the Azure AI Foundry project the customer connects — connecting one is required on every plan — and Microsoft bills the customer for that usage. We do not train, fine-tune, or evaluate any model using customer data.
The trial agent. Until a customer connects their Foundry project, a publisher-funded trial AI agent, which runs in an Azure AI Foundry project of ours, is available for testing — limited to 100 messages or 14 days, and reachable only from the authenticated Teams dashboard. It is never reachable from the customer's website widget.
Visitor sign-in. Optional visitor sign-in (Microsoft Entra External ID) is available on Hosted. Where a customer enables it, the visitor's browser holds an MSAL token cache and a pocai:widget:authAt timestamp in localStorage; credentials are entered in the customer's directory and never reach us. That directory is configured and controlled by the customer, not by us.
How long we keep it. The conversation record is kept until the customer asks us to delete it or the customer's subscription ends. There is no automatic purge, and today there is no self-service retention window and no self-service export: deletion and export are carried out by our operations team when a customer asks. Uploaded files are deleted when their owner or the customer's team deletes them, and a submitted file's backup copy is deleted after 28 days. The sanitized audit log expires after 400 days.
Requests from individuals. Because the customer is the controller, requests to access, correct, or delete Hosted end-user data are handled by the customer whose website or Teams tab the conversation took place on. We assist that customer as their processor, and on their instruction we can delete or export an individual's records. If you do not know which customer to write to, email privacy@pointofcontact.ai and we will route your request to the right one.
Processors and sub-processors
We use a small number of providers to run our websites, relay contact-form messages, and operate Point of Contact — Hosted. Each processes data only to provide its service to us.
| Provider | Role | Where |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, and DDoS protection for pointofcontact.ai; DNS/proxy in front of docs.pointofcontact.ai. Sees IP addresses in transit; may set strictly-necessary security cookies (e.g., __cf_bm) for bot mitigation. | United States, with global edge network |
| Web3Forms | Relays contact-form submissions from pointofcontact.ai to our sales inbox by email. | United States |
| Microsoft Azure (Microsoft Corporation) | Hosts docs.pointofcontact.ai (Azure Static Web Apps). Separately, the underlying platform on which customers run a Self-Hosted deployment in their own subscriptions — where the customer, not us, is the controller. | United States / customer-selected region |
| Microsoft Azure (Microsoft Corporation) | Hosting for Point of Contact — Hosted: the application, the conversation record, and uploaded files run in an Azure subscription we operate. Microsoft is our sub-processor for that service, and the customer is the controller. | United States |
If we add or change a processor that handles website personal data, we will update this list.
International transfers
We are based in the United States, and the providers above process data in the United States. If you contact us from the EEA, the United Kingdom, or Switzerland, your information will be transferred to and processed in the US.
Point of Contact — Hosted runs in Microsoft Azure in the United States, so the data that service holds — the conversation record, uploaded files, and the identity details listed above — is stored in the United States. A customer outside the United States should account for that transfer in its own privacy notice.
Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum), and — where a provider is certified — the EU-U.S. Data Privacy Framework. For example, Cloudflare, Inc. is certified under the Data Privacy Framework. This certification belongs to the provider; Innovations24 does not claim its own certification.
Data retention
We keep website personal data only as long as we need it, and no longer:
- Contact-form submissions and sales correspondence — kept while we handle your inquiry and any relationship that follows. If nothing comes of it, we delete or archive within about 24 months of our last contact.
- Server and security logs — held by our hosting and CDN providers under their operational defaults (short-lived). We do not keep our own separate copy for analysis.
- Functional browser storage — stored on your own device;
sticky_cta_dismissedclears at the end of the session, andpoc_cookie_consentandstarlight-themepersist until you clear them. - Records we must keep by law — retained for the period the relevant law requires (for example, tax and accounting rules).
Product data is retained differently in each edition:
- Point of Contact — Self-Hosted — data inside a deployment is retained according to the customer's own configuration in the customer's Azure subscription; reaching it at all requires a just-in-time elevation the customer approves.
- Point of Contact — Hosted — the conversation record is kept until the customer asks us to delete it or the customer's subscription ends. There is no automatic purge, and today there is no self-service retention window and no self-service export; our operations team performs deletion and export on the customer's request. Uploaded files are deleted when their owner or the customer's team deletes them, and a submitted file's backup copy is deleted after 28 days. The sanitized audit log expires after 400 days.
Your rights
If you are in the EEA or the UK (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), where applicable.
- Restrict or object to processing based on our legitimate interests.
- Data portability for data you provided to us.
- Withdraw consent where we relied on it, without affecting prior processing.
- Lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
To exercise any of these, email privacy@pointofcontact.ai. We may need to verify your identity, and we will respond within the time the law allows (generally one month under the GDPR).
If you are a California resident (CCPA/CPRA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the purposes, and who we share it with.
- Delete personal information we collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of.
- Limit the use of sensitive personal information. We do not collect sensitive personal information through our websites, so this does not apply.
- Non-discrimination — we will not treat you differently for exercising your rights.
To submit a request, email privacy@pointofcontact.ai with the subject line "California Privacy Request." You may use an authorized agent, who must provide proof of authorization. We will verify your request and respond within the timeframe the CCPA requires (generally 45 days, extendable once where reasonably necessary).
Other U.S. states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable privacy laws have similar rights to access, correct, delete, and port their data, and to opt out of sale and targeted advertising (neither of which we do). Email privacy@pointofcontact.ai with your state of residence, and we will respond as that state's law requires.
We honor requests globally
Wherever you live, if you send us a privacy request we can reasonably act on, we will — we do not limit these rights to any one region.
Children
Our websites and product are intended for businesses, not for children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@pointofcontact.ai and we will delete it.
Security
We keep our security measures proportionate to the little data our websites handle:
- Encryption in transit — our websites are served over TLS (HTTPS).
- Least-privilege access — only the people who need to respond to inquiries can reach the sales inbox that receives contact-form messages.
- Minimal collection — the strongest protection is not holding data we do not need, and our sites collect almost none.
- Platform security — we rely on the security posture of Cloudflare and Microsoft Azure for the infrastructure they provide.
For a Self-Hosted deployment, customer data is protected inside the customer's own tenant by RBAC deny assignments on our publisher principal, Azure Managed Identity authentication, and secrets held in the customer's own Azure Key Vault. Any platform compliance certifications (for example, Azure's SOC and ISO attestations) belong to Microsoft, not to Innovations24, and apply to the extent the customer enables them.
For Point of Contact — Hosted, which we run ourselves: traffic is encrypted in transit with TLS 1.2 or higher; data is encrypted at rest by Azure; the customer's agents sign in with Microsoft Entra ID single sign-on; access within our environment is governed by Azure role-based access control and managed identities; and secrets are held in Azure Key Vault. Customers do not receive standing access to our infrastructure. As described under The product, our own operations staff can reach the conversation record in order to support the customer.
No method of transmission or storage is perfectly secure. If we become aware of a breach affecting personal data we control, we will notify affected individuals and authorities as the law requires.
Changes to this policy
We may update this policy to reflect changes in our practices or the law. When we do, we will revise the "Last updated" date above and, for material changes, provide a more prominent notice. Your continued use of our websites after an update takes effect means you accept the revised policy.
Contact us
Innovations24 LLC (d/b/a Point of Contact AI)
5900 Balcones Drive, Ste 100
Austin, TX 78731
United States
Privacy: privacy@pointofcontact.ai
General: info@innovations24.com