forethought

Privacy Policy

Effective date: June 29, 2018

Overview

Forethought Technologies, Inc. (‘Forethought’ or ‘we’ or ‘us’ or ‘our’) gather and process your data in accordance with this Privacy Policy and in compliance with the relevant data protection Regulation and laws. This Privacy Policy provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your data.

Forethought is a Delaware corporation, and is located at 927 Industrial Avenue, Palo Alto, CA 94303, USA. We act as the data processor or sub-processor when processing your data. Our designated Data Protection Officer/Appointed Person is Deon Nicholas, who can be contacted at: security [at] forethought.ai.

What We Do

We are the builders of Agatha™, an intelligent information-retrieval and question-answering engine for the enterprise. Agatha provides the following services:

Agatha accelerates decision making processes and access to information for line-of-business workers.

Forethought operates several websites including www.forethought.ai, www.agatha.ai, and applicable sub-domains. We also offer several apps and integrations for services such as Zendesk, Slack, Salesforce, and Google Chrome, Android and/or iOS. These can be found in the relevant app stores or app marketplaces.

All products, services, websites, apps, and integrations offered by Forethought are herein referred to as “the Services”.

Information That We Collect

We collect and process several different types of information for various purposes to provide and improve the Services. Forethought processes several different types of information to meet our legal, statutory and contractual obligations and to provide you with the Services. We will never collect any unnecessary data and do not process your information in any way, other than as specified in this Privacy Policy. We collect the following types of information:

Personal Data

We may collect certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:

Document Data

The Services are designed to make it simple for you to access your files, documents, photos, comments, messages, emails, support tickets, and so on (“Document Data”), and to extract information and insights. To make that possible, we store, process, and transmit Document Data as well as information related to it, such as information about the author/sender, permissions/recipients, date created or updated, and so on (“Metadata”).

Usage Data

We may also collect information on how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (or “IP address”), browser type, browser version, the pages of the Services that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

Tracking & Cookies Data

We use cookies and similar tracking technologies to track the activity on the Services and hold certain information.

Cookies are files with small amounts of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze the Services.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we use:

How and When is the Information Collected

We collect and process information on behalf of individuals or and entities that have entered into a Service Agreement for use of our Services (“Clients”). We also collect some information (particularly Usage Data and Tracking & Cookies Data) from individuals or entities that directly interact with the Services, whether registered as Clients or not (“Visitors”).

Your data may be collected if you are:

We collect information in the following ways:

How We Use Your Personal Data (Legal Basis for Processing)

Forethought takes your privacy very seriously and will never disclose, share or sell your data without your consent; unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this Privacy Policy. Where you have consented to us providing you with promotional offers and marketing, you are free to withdraw this consent at any time.  The purposes and reasons for processing your personal data are detailed below:

Your Rights

You have the right to access any personal information that Forethought processes about you and to request information about:


If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to do so as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.

You also have the right to request erasure of your personal data or to restrict processing (where applicable) in accordance with the data protection laws; as well as to object to any direct marketing from us. Where applicable, you have the right to data portability of your information and the right to be informed about any automated decision-making we may use.

If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.

Sharing and Disclosing Your Personal Information

We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this Privacy Policy or where there is a legal requirement.

Forethought uses third-parties to provide the below services and business functions; however, all processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this Privacy Policy, the data protection laws and any other appropriate confidentiality and security measures.

Amazon Web Services, Inc.

We use Amazon Web Services, Inc. (“AWS”) to store and process Client information, and to provide supporting physical and digital infrastructure for our services.

Zendesk, Inc.

We use Zendesk, Inc. (Zendesk) for Client account administration and support, as well as a sub-processor for processing Client information. We offer an integration for Zendesk to allow Client users to interact with our products and services via Zendesk.

Salesforce.com, inc.

We use Salesforce.com, inc. (Salesforce) for Client account administration, customer relation management and support, as well as a sub-processor for processing Client information. We offer an integration for Salesforce to allow Client users to interact with our products and services via Salesforce.

Google LLC and its affiliates

We use tools offered by Google LLC and its affiliates (collectively “Google”) for internal company communication, authentication / authorization (SSO), productivity tools, and for sharing information. We use Google Gmail, Calendar, Hangouts/Meet, Drive, Docs, Sheets, Slides, Sites, and other products collectively called “G Suite”.

Xero, Inc.

We use Xero, Inc. (“Xero”) for accounting and invoicing. Information may be shared or stored within Xero to process orders, fulfill contracts, and to meet business and legal requirements.

Slack Technologies, Inc.

We use Slack Technologies, Inc. (“Slack”) for internal company communication.

Cloudflare, Inc.

Cloudflare, Inc. (“Cloudflare”) provides content distribution, security and DNS services for web traffic transmitted to and from the Services. This allows Forethought to efficiently manage traffic and secure the Services. All information (including personal data) contained in web traffic transmitted to and from the Services is transmitted through Cloudflare’s systems, but Cloudflare does not have access to this information.

Safeguarding Measures

Forethought takes your privacy seriously and takes every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including: SSL & TLS, restricted access with 2-factor authentication, machine and web application firewalls, anti-virus/malware, and logging. Please contact security [at] forethought [dot] ai for more information about our security practices.

Data Storage and Transfer

Forethought’s servers are located in the United States. Your personal data is stored in various AWS regions, and replicated across regions for backup purposes. We take steps to protect your data and comply with the relevant data protection laws. Forethought does not transfer your data outside of the US, except in the case where transfer outside of the US is strictly necessary to provide you the service (e.g.: you are a user, and are accessing the website from outside of the US) or to comply with relevant laws.

Consequences of Not Providing Your Data

You are not obligated to provide your personal information to Forethought, however, as this information is required for legitimate interests such as to provide you with our services and products,  we will not be able to offer some/all our services without it.

Legitimate Interests

As noted in the ‘How We Use Your Personal Data’ section of this Privacy Policy, we occasionally process your personal information under the legitimate interests’ legal basis. We use the legitimate interests’ legal basis for processing all data given to us by Clients in order to provide the services and products, and have identified that our interests correspond to legitimate interests of the Client (who is the “Data Controller” or “Data Processor”).

How Long We Keep Your Data

Forethought only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations.

Upon termination of a Client account for any reason (such as account termination, nonpayment, or customer deletion of the account), all personal data received from that customer will be deleted in 1 week and all records purged after 30 days. This process is subject to applicable legal requirements. We do not delete or purge any information required for legal, contractual or accounting obligations.

Contact

For any security or privacy related comments or questions, please contact us at security [at] forethought.ai. You may also contact us by mail at:

Forethought Technologies, Inc.

927 Industrial Avenue

Palo Alto, CA 94303

Forethought only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with the supervisory authority.