Privacy Policy

Effective date: March, 2020

Overview

Forethought Technologies, Inc. (‘Forethought’ or ‘we’ or ‘us’ or ‘our’) gather and process your data in accordance with this Privacy Policy and in compliance with the relevant data protection Regulation and laws. This Privacy Policy provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your data.

Forethought is a Delaware corporation, and is located at 150 Spear Street, Ste. 350, San Francisco, CA 94105, USA. We act as the data processor or sub-processor when processing your data. Our designated Data Protection Officer/Appointed Person is Deon Nicholas, who can be contacted at: security [at] forethought.ai.

What We Do

We are the builders of Agatha™, an intelligent information-retrieval and question-answering engine for the enterprise. Agatha provides the following services:

●   Unified indexing of corporate knowledge bases

●   Natural Language Search + Question Answering of indexed documents

●   Document triaging, including routing, tagging, categorization, spam
detection, escalations and more
●   Automatic response to customer support questions

Agatha accelerates decision making processes and access to information for line-of-business workers.

Forethought operates several websites including www.forethought.ai, www.agatha.ai, and applicable sub-domains. We also offer several apps and integrations for services such as Zendesk, Salesforce. These can be found in the relevant app stores or app marketplaces.

All products, services, websites, apps, and integrations offered by Forethought are herein referred to as “the Services”.

Information That We Collect

We collect and process several different types of information for various purposes to provide and improve the Services. Forethought processes several different types of information to meet our legal, statutory and contractual obligations and to provide you with the Services. We will never collect any unnecessary data and do not process your information in any way, other than as specified in this Privacy Policy. We collect the following types of information:

Personal Data

We may collect certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:

●   Email address
●   First name and last name
●   Phone number
●   Address, State, Province, ZIP/Postal code, City
●   Authentication information (passwords, public keys, API tokens, etc.) ●   Any personal data held in Cookies Data, Document Data, or Usage Data

Document Data

The Services are designed to make it simple for you to access your files, documents, photos, comments, messages, emails, support tickets, and so on (“Document Data”), and to extract information and insights. To make that possible, we store, process, and transmit Document Data as well as information related to it, such as information about the author/sender, permissions/recipients, date created or updated, and so on (“Metadata”).

Usage Data

We may also collect information on how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (or “IP address”), browser type, browser version, the pages of the Services that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

Tracking and Cookies Data

We use cookies and similar tracking technologies to track the activity on the Services and hold certain information.

Cookies are files with small amounts of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze the Services.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we use:

●   Session Cookies. We use Session Cookies to operate our Service.
●   Preference Cookies. We use Preference Cookies to remember your preferences and various settings.
●   Security Cookies. We use Security Cookies for security purposes.

How and When is the Information Collected

We collect and process information on behalf of individuals or and entities that have entered into a Service Agreement for use of our Services (“Clients”). We also collect some information (particularly Usage Data and Tracking & Cookies Data) from individuals or entities that directly interact with the Services, whether registered as Clients or not (“Visitors”).

Your data may be collected if you are:

●   A Visitor or a Client
●   An employee of a Client
●   A customer, vendor, contractor, or service provider of a Client, if you have shared data with that Client for purposes where Client has legitimate reason to use our Services (e.g.: If you share documents with a Client, that Client may use the Services to search the documents.)

We collect information in the following ways:

●   Indexing and processing of Client documents to provide the Services
●   Information specified in Service Agreements, contracts, or other Client documents sent directly to Forethought from Client
●   Cookies and other tracking technologies when using the Services

How We Use Your Personal Data (Legal Basis for Processing)

Forethought takes your privacy very seriously and will never disclose, share or sell your data without your consent; unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this Privacy Policy. Where you have consented to us providing you with promotional offers and marketing, you are free to withdraw this consent at any time.  The purposes and reasons for processing your personal data are detailed below:

●   We collect and process personal data in the performance of a contract
●   We process personal data in the delivery of the Services
●   We analyze personal data such as email address to correctly identify individuals and entities when delivering the Services (for example, identifying the requester of a support ticket in order to find previous tickets by the same requester)
●   We analyze personal data to correctly authenticate and authorize individual users of our products and service (for example, making sure only certain employees can see certain documents surfaced up in our product)
●   If you are a Client or the employee of a Client, we may occasionally send you marketing or informational emails where we have assessed that it is beneficial to you as a customer and in our interests. Such information will be non-intrusive and is processed on the grounds of legitimate interests.

Your Rights

You have the right to access any personal information that Forethought processes about you and to request information about:

●   What personal data we hold about you
●   The purposes of the processing
●   The categories of personal data concerned
●   The recipients to whom the personal data has/will be disclosed
●   How long we intend to store your personal data for
●   If we did not collect the data directly from you, information about the source

If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to do so as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.

You also have the right to request erasure of your personal data or to restrict processing (where applicable) in accordance with the data protection laws; as well as to object to any direct marketing from us. Where applicable, you have the right to data portability of your information and the right to be informed about any automated decision-making we may use.

If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.

Sharing and Disclosing Your Personal Information

We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this Privacy Policy or where there is a legal requirement.

Forethought uses third-parties to provide the below services and business functions; however, all processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this Privacy Policy, the data protection laws and any other appropriate confidentiality and security measures.

Amazon Web Services, Inc.

We use Amazon Web Services, Inc. (“AWS”) to store and process Client information, and to provide supporting physical and digital infrastructure for our services.

Google Cloud Platform

We use Google Cloud Platform (“GCP”) to train machine learned models for research and development purposes. Some of these models are exported and deployed in AWS to support our services.

Zendesk, Inc.

We use Zendesk, Inc. (Zendesk) for Client account administration and support, as well as a sub-processor for processing Client information. We offer an integration for Zendesk to allow Client users to interact with our products and services via Zendesk.

Salesforce.com, Inc.

We use Salesforce.com, inc. (Salesforce) for Client account administration, customer relation management and support, as well as a sub-processor for processing Client information. We offer an integration for Salesforce to allow Client users to interact with our products and services via Salesforce.

Google LLC and its affiliates

We use tools offered by Google LLC and its affiliates (collectively “Google”) for internal company communication, authentication / authorization (SSO), productivity tools, and for sharing information. We use Google Gmail, Calendar, Hangouts/Meet, Drive, Docs, Sheets, Slides, Sites, and other products collectively called “G Suite”.

Xero, Inc.

We use Xero, Inc. (“Xero”) for accounting and invoicing. Information may be shared or stored within Xero to process orders, fulfill contracts, and to meet business and legal requirements.

Slack Technologies, Inc.

We use Slack Technologies, Inc. (“Slack”) for internal company communication.

Cloudflare, Inc.

Cloudflare, Inc. (“Cloudflare”) provides content distribution, security and DNS
services for web traffic transmitted to and from the Services. This allows Forethought to efficiently manage traffic and secure the Services. All information (including personal data) contained in web traffic transmitted to and from the Services is transmitted through Cloudflare’s systems, but Cloudflare does not have access to this information.

Safeguarding Measures

Forethought takes your privacy seriously and takes every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including: SSL & TLS, restricted access with 2-factor authentication, machine and web application firewalls, anti-virus/malware, and logging. Please contact security [at] forethought [dot] ai for more information about our security practices.

Data Storage and Transfer

Forethought’s servers are located in the United States. Your personal data is stored in various AWS regions, and replicated across regions for backup purposes. We take steps to protect your data and comply with the relevant data protection laws. Forethought does not transfer your data outside of the US, except in the case where transfer outside of the US is strictly necessary to provide you the service (e.g.: you are a user, and are accessing the website from outside of the US) or to comply with relevant laws.

Consequences of Not Providing Your Data

You are not obligated to provide your personal information to Forethought, however, as this information is required for legitimate interests such as to provide you with our services and products,  we will not be able to offer some/all our services without it.

Legitimate Interests

As noted in the ‘How We Use Your Personal Data’ section of this Privacy Policy, we occasionally process your personal information under the legitimate interests’ legal basis. We use the legitimate interests’ legal basis for processing all data given to us by Clients in order to provide the services and products, and have identified that our interests correspond to legitimate interests of the Client (who is the “Data Controller” or “Data Processor”).


How Long We Keep Your Data

Forethought only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations.

Upon termination of a Client account for any reason (such as account termination, nonpayment, or customer deletion of the account), all personal
data received from that customer will be deleted in 1 week and all records purged after 30 days. This process is subject to applicable legal requirements. We do not delete or purge any information required for legal, contractual or accounting obligations.

Contact

For any security or privacy related comments or questions, please contact us at security [at] forethought.ai. You may also contact us by mail at:

Forethought Technologies, Inc.
150 Spear Street, Ste. 350,
San Francisco, CA 94105

Forethought only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with the supervisory authority.