Privacy Policy
Version 1.1. Last updated: 11 September 2026.
Published in English, Russian and Uzbek. The English text prevails if the versions differ.
1. In short
We are a monitoring company. We hold very little about you personally, and we hold it because we have to run your account, not because we want to profile you.
- We do not ask for your phone number, tax number, passport details or payment card. Card details never reach us; they go to the payment provider.
- We do not sell personal data, and we do not use it for advertising.
- We do not use cookies for tracking, and we run no analytics, no session recording and no advertising trackers.
- Your data is stored on servers in the Republic of Uzbekistan.
- The telemetry you send us is yours. We look at it only when you ask us to, or when we are fixing a fault.
The rest of this document is the detail.
2. Who is responsible
"BEATAI LABS" LLC, TIN 312569409, Toshkent shahri, Mirobod tumani, Yuksalish MFY, Kuylik-3 mavzesi, 37-uy, 26-xonadon, Republic of Uzbekistan, is the operator of the Tracepo platform.
Our role depends on the data:
- For account data - who you are, how you use the product, what we bill you - we decide why and how it is processed. We are the controller (in the terms of the Law of the Republic of Uzbekistan No. ZRU-547, the operator).
- For telemetry you send us - we hold and process it on your instructions and for your purposes. There you are the controller and we are the processor. The terms of that processing are in the Data Processing Agreement.
Contact for any privacy question, including access, correction and deletion requests: support@tracepo.io.
Responsibility for the processing of personal data rests with the management of the company. There is no separate representative you have to address: a message to support@tracepo.io reaches the people who can act on your request.
3. What we collect about you
3.1 When you create an account
| What | Why |
|---|---|
| Name you give us | to show who is in the organisation |
| Email address | to identify you, sign you in, send account and billing notices |
| Password | stored only as a bcrypt hash; we cannot read it |
| Country you select at sign-up | it decides your billing currency and nothing else |
| Organisation name | to identify your workspace |
| Whether you agreed to product news | to know if we may email you about the product |
If you sign in with Google, Google gives us your email address. Nothing else.
3.2 While you use the product
| What | Why |
|---|---|
| Session tokens | to keep you signed in |
| A record of when you were active, in five-minute buckets, and which part of the product you used | to understand product usage and to support you |
| IP addresses and request details in our server logs | security, fault diagnosis, abuse prevention |
| Email delivery records: recipient address, kind of message, outcome, error text | to answer "did that message reach the customer?" |
| Email addresses you add as alert recipients | to deliver the alerts you configured |
We should be plain about one of these. We keep an activity journal. It records, per five-minute interval, that a given person was active, in which part of the product, and how many actions they took. We use it to see whether registered customers actually work in the product and to help you when you ask. We do not record what you typed, what you searched for, or what you looked at.
If you add somebody else's email address as an alert recipient, you are responsible for telling them. We send that address a confirmation before we ever deliver an alert to it.
3.3 When you pay
We record what you bought, when, how much, in what currency, the payment status and the payment provider's transaction identifier. We never see or store your card details. Those go directly to the payment provider.
3.4 About the hosts you monitor
When you install the Tracepo agent, we record the machine identifier (from /etc/machine-id), the hostname, the operating system, the architecture and the agent version. This is inventory about machines, and we treat it as your Customer Data. It can relate to a person if the machine is somebody's personal computer, which is why we mention it here.
3.5 Telemetry
Everything else you send into the Service is telemetry. Today the Service accepts host metrics from our agent, which contain no personal data. As we release support for traces and logs, telemetry may contain whatever your systems put into it.
We do not inspect, mine or profile your telemetry. We do not use it to train anything. Our staff access it only in the circumstances in section 6.
The rules about what you may send us are in the Terms of Service, section 4.2.
4. What we do not do
We do not use cookies to track you. Our marketing site and product set no tracking cookies at all. The product stores a few things in your browser's local storage - your session token, your theme, your table layout preferences. That never leaves your browser and never reaches us as a profile.
We run no product analytics, no session recording, no heatmaps, no advertising pixels and no third-party trackers of any kind.
We do not sell, rent or share personal data for anyone else's marketing.
We do not make decisions about you by automated means that produce legal effects.
5. Why we are allowed to process it
- To perform our contract with you: running your account, delivering the Service, billing you, supporting you.
- Because you consented: product news by email. You can withdraw consent at any time, in your profile settings or through the unsubscribe link. Withdrawing it does not stop service messages about security, billing or availability.
- For our legitimate interests: keeping the Service secure, preventing abuse, understanding how the product is used, defending legal claims. We do this only where it does not override your rights.
- To comply with the law: tax and accounting records, and lawful requests from state authorities.
6. Who can see your data
Inside our company. Access to customer data is limited to a small group of administrators who have signed confidentiality undertakings. They access customer data only when you ask us to look at something, or while we are diagnosing an incident. Ordinary staff have no access.
Outside our company. We use a small number of service providers. Each of them receives the minimum they need. The complete, current list, what each receives and where it is processed, is at Subprocessors. We publish changes 30 days before a new provider starts.
State authorities. We disclose data to the competent authorities of the Republic of Uzbekistan only where the law requires it and only on a properly issued demand, such as a court order or an investigator's decision. We disclose the minimum the demand covers, and we tell you that it happened unless the demand itself forbids us to. We do not give any government direct or unsupervised access to our systems.
Business transfer. If our business is sold or merged, data may transfer with it, under the protections of this policy. We will tell you.
7. Where your data lives
Your account data and all telemetry are stored in the Republic of Uzbekistan, on infrastructure operated by a licensed data centre provider in Uzbekistan.
Under Uzbek law, mandatory localisation applies to biometric data, genetic data and telecom subscriber data. We hold none of those. We keep everything in Uzbekistan anyway, because that is where our customers are.
Some limited data does leave the country, and we would rather say so plainly than hide it in a list:
- email addresses pass through our outbound email provider, in the United States, whenever we send you a message;
- your email address reaches the international payment provider when you pay in US dollars;
- your email address reaches Google if you choose to sign in with Google.
Nothing else leaves Uzbekistan. No telemetry leaves Uzbekistan. Details are at Subprocessors.
These transfers rest on two things: your consent, which you give by accepting this Policy and by choosing to pay in US dollars or to sign in with Google, and the contractual commitments of the recipients to protect the data to a standard no lower than the one required by Article 27-1 of the Law of the Republic of Uzbekistan No. ZRU-547. Where you are subject to the GDPR, we sign the European Commission's Standard Contractual Clauses on request.
8. How long we keep it
| Data | Kept for |
|---|---|
| Account: name, email, organisation | while your account exists |
| Password hash | while your account exists |
| Session tokens | until they expire or you sign out |
| Activity journal and daily-active records | while your account exists; deleted together with your organisation |
| Email delivery log | while your account exists; deleted together with your organisation |
| Payment records | as long as tax and accounting law requires |
| Server logs with IP addresses | 30 days |
| Telemetry | the retention period of your plan, shown in your account |
| Telemetry after suspension for non-payment | 30 days from suspension, then deleted; see the Billing and Refund Policy |
9. Your rights
You may ask us to:
- tell you what we hold about you and give you a copy;
- correct anything wrong or incomplete;
- delete your data;
- stop or limit processing that relies on our legitimate interests;
- withdraw consent to product news, at any time;
- receive your data in a machine-readable form.
Write to support@tracepo.io. We may need to check who you are before we act. We answer within 1 to 14 working days.
Deletion, precisely. When you ask us to delete, we remove the data from our live systems within 1 to 14 working days. Copies inside backups are not deleted immediately; they disappear when the backup rotates. Until then those copies are not used for anything and stay protected by this policy. We keep whatever we must keep by law, such as accounting records for payments you made.
You can also delete your organisation yourself from the account settings. That removes your organisation's data from the product and deletes its telemetry.
If you think we have handled your data wrongly, tell us first at support@tracepo.io. You may also complain to the authorised body for personal data protection in the Republic of Uzbekistan.
10. Security
What we actually do:
- traffic between you and the Service is protected with TLS; traffic between our internal components runs inside a private network;
- passwords are stored only as bcrypt hashes;
- the secret half of an ingestion key pair is never stored - only its SHA-256 hash - and it is shown to you exactly once, when it is created;
- tenants are isolated at the database level, by row policies, not by a filter in application code;
- the product has role-based access control: owner, admin, editor, viewer;
- the operator back-office is reachable only over VPN and reads the product database in read-only mode;
- the agent packages we distribute are cryptographically signed, and so are the package repository indexes;
- our builds run static analysis, dependency scanning, secret detection and container scanning;
- data is encrypted at rest;
- we take regular encrypted backups.
No system is perfectly secure. We do not claim any certification we do not hold.
If a security incident affects your personal data, we will tell you without undue delay and in any case within 72 hours of becoming aware of it, and we will tell you what happened, what it affects and what we are doing.
11. Children
The Service is for adults working in a professional capacity. We do not knowingly collect data about anyone under 18. If you believe we have, write to support@tracepo.io and we will delete it.
12. Changes to this policy
We may update this policy. The version number and date at the top always tell you which version you are reading.
If a change materially affects your rights, we will tell you by email at least 30 days before it takes effect, and we will keep the previous version available so you can see what changed. Minor corrections take effect when published.
13. Contact
"BEATAI LABS" LLC Toshkent shahri, Mirobod tumani, Yuksalish MFY, Kuylik-3 mavzesi, 37-uy, 26-xonadon, Republic of Uzbekistan TIN 312569409 Email: support@tracepo.io Phone: +998 (93) 625-24-54