Privacy notice
What this service records about you
This service issues TomoPilot instrument access codes to Tomocube staff and registered partners. It is operated by Tomocube Inc. This notice applies to everyone who signs in.
Data we process
| Data | Who | Why |
|---|---|---|
| Email address, display name, Microsoft account identifier (oid) | Staff | Sign-in and role assignment via Microsoft 365 |
| Email address, name, company, contract expiry date | Partners | Registration by Tomocube and one-time login codes |
| Sign-in attempts, login-code requests, IP address, time | Everyone | Abuse prevention (rate limits, lockouts) and security investigations |
| Which code group and 12-hour window you viewed, and when | Everyone | Audit trail for instrument access. The code values themselves are never stored. |
Retention
- Audit entries (including IP addresses): 365 days, then deleted automatically.
- One-time login codes: deleted one day after they expire. Only a keyed hash is ever stored.
- Sessions: deleted at sign-out or expiry (staff 12 h, partners 4 h, or 60 min idle).
- Partner registrations: kept while the partnership is active; disabled records are retained for the audit trail.
Where it lives and who sees it
Data is stored on Tomocube's web hosting account (Hostinger) in a database only this service can reach. Staff with the Administrator role can view the audit log and partner registrations. Data is not sold or shared with third parties beyond the hosting and Microsoft sign-in providers needed to run the service.
Your choices
Partners may ask their Tomocube contact to correct or disable their registration at any time. Questions about this notice: contact Tomocube Precision Division support.
Last updated 2026-09-08.