Privacy policy
This is a pre-launch version of our privacy policy, provided for pilot customers. It will be updated when Hotam is incorporated.
Hotam ("we") provides Hotam, a service that helps managed service providers ("MSPs") prove that the work they did for their clients was completed correctly, by comparing what was supposed to be done with what their systems report. This policy explains what personal information we handle, why, and your choices.
Two kinds of data, two roles
- Account data about the people who use Hotam (MSP staff). For this data we decide how it is used: we are the controller.
- Customer data that Hotam reads from an MSP's systems about the MSP's clients, for example the names and sign-in names of a client's employees. The MSP decides what Hotam reads and why; we process it only on the MSP's instructions, under our Data Processing Agreement. For this data the MSP is the controller and we are the processor. If you are an employee of an MSP's client, please contact that MSP first; we will help them answer you.
What we collect
Account data
- Email address and display name of each person invited to an MSP's Hotam account.
- Role in the account (owner, admin, technician, viewer) and sign-in times.
- Actions taken in Hotam, kept in an audit log (for example "ran QA on project X").
- Messages you send us through our website forms (name, email, company, message).
Customer data (read from the MSP's systems, read-only)
- From the MSP's PSA: project names and descriptions, and the client each belongs to.
- From Microsoft 365: user names and sign-in names, whether each account is enabled, assigned licenses, whether a user is registered for multi-factor authentication, domains, and license change records (who changed a license and when).
- From other connected systems: for example device names and agent status from an RMM, and the names of documentation records.
- The results Hotam calculates from this data (passed, failed, unknown, and the evidence behind each).
People sign in with a password and a code from an authenticator app. Passwords are kept only as salted hashes by our sign-in provider (Supabase Auth); Hotam's application never sees or stores them in readable form. The credentials an MSP enters to connect its systems are encrypted before they are stored and are used only to read those systems.
How we use it
- To provide the service: sign you in, read the MSP's systems as the MSP configured, compare expected and observed state, and show and report the results.
- To keep the service secure: audit logs, detecting misuse, investigating incidents.
- To support the MSP when it asks, including read-only support sessions that are time-limited and recorded in the MSP's audit log.
- To answer your messages.
We do not sell personal information. We do not use customer data to advertise, and we do not use it to train AI models.
AI
When a person in an MSP's account asks for a scope analysis, the project's scope text is sent to Anthropic (Claude) to suggest requirements. Nothing else is sent to an AI service, and an AI never decides a result: results come from fixed rules comparing data.
Who we share it with
Only the service providers that run Hotam for us (sub-processors), each for the purpose listed:
- Supabase: Database and sign-in. Location: United States (US East, North Virginia).
- Vercel: Hosting the application. Location: United States and its edge network.
- Anthropic: Suggesting requirements from scope text, only when a person asks. Location: United States.
- Resend: Sending emails: sign-in emails and messages from our website forms. Location: United States.
- Sentry: Error monitoring, when it is on, with personal data and secrets removed before sending. Location: Not in use yet; this list will name its region when it is.
We may disclose information if the law requires it, and will tell the affected MSP when we lawfully can.
How long we keep it
- Account and customer data: while the MSP's account is active, then deleted after the account closes, unless the law requires us to keep it longer.
- Evidence and results keep their history while the account is active so an MSP can prove past work; the MSP decides when to close its account.
- Backups: automatic backups are not in place yet. When they are, this policy will say how long they are kept.
Security
Data is encrypted in transit. Each MSP's data is kept apart from every other MSP's by the application and by the database itself. Connection credentials are encrypted with a key held only by the server. Access by our staff is limited by role and recorded. See our security page for details.
Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, and to object to some uses. For account data, contact us at hello@hotam.io. For customer data about you held for an MSP, contact the MSP; we will assist them.
Children
Hotam is a business service and is not directed to children.
Changes
We will post changes here and tell account owners by email before material changes take effect.
Contact
Hotam, hello@hotam.io.