SAM.AI by Carmaa — Legal
Data Processing Addendum (DPA)
Governs Carmaa's processing of personal data on the Customer's behalf — most important for EU/EEA/UK customers, good practice for all.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Carmaa Technologies Private Limited (“Carmaa”, “Processor”) and the customer (“Customer”, “Controller”) and governs Carmaa’s processing of Personal Data on the Customer’s behalf when providing SAM.AI.
“Data Protection Laws” means all applicable laws relating to personal data, including the GDPR/UK GDPR and the Digital Personal Data Protection Act, 2023 (India) and the IT Act, 2000 / SPDI Rules, 2011.
1. Roles
1.1 The Customer is the Controller / Data Fiduciary of Personal Data contained in Customer Data. Carmaa is the Processor / Data Processor, processing Personal Data only on the Customer’s documented instructions.
1.2 The Customer is responsible for the lawfulness of the Personal Data and of its instructions, and for providing all required notices to and obtaining all required consents from Data Subjects (including any WhatsApp opt-in).
2. Scope & Instructions
2.1 Carmaa processes Personal Data only: (a) to provide and support the Service; (b) per the Customer’s documented instructions; and (c) as required by law (in which case Carmaa will inform the Customer unless legally prohibited).
2.2 Carmaa will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
3. Details of Processing
- Subject matter: provision of the AI sales-and-marketing Service.
- Duration: the term of the Customer’s Subscription, plus the export/deletion window.
- Nature & purpose: receiving, storing, transmitting, and processing Personal Data to operate the WhatsApp AI agent, lead/booking management, retargeting, calendar sync, LinkedIn automation, and analytics, as configured by the Customer.
- Types of Personal Data: as determined by the Customer, typically Contacts’ names, phone numbers, email addresses, message/conversation content, lead and booking details, and uploaded media.
- Categories of Data Subjects: the Customer’s customers, leads, contacts, and prospects.
4. Confidentiality
Carmaa ensures persons authorised to process Personal Data are bound by confidentiality and process Personal Data only as instructed.
5. Security
Carmaa implements appropriate technical and organisational measures, including encryption in transit and at rest, secrets/keys stored in AWS Secrets Manager (KMS-encrypted), tenant isolation, role-based access, least-privilege cloud IAM, signature-verified webhooks, and logging/monitoring, appropriate to the risk.
6. Subprocessors
6.1 The Customer authorises Carmaa to engage subprocessors to provide the Service. Current subprocessors are listed in the Subprocessors List (e.g. AWS, Razorpay, Meta/WhatsApp, Google, LinkedIn, the Customer’s chosen AI provider).
6.2 Carmaa will impose data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance.
6.3 Carmaa will give notice of intended additions/changes to subprocessors. The Customer may object on reasonable data-protection grounds; the parties will work in good faith to address the concern.
7. Data Subject Requests
Taking into account the nature of the processing, Carmaa will assist the Customer with appropriate technical and organisational measures (insofar as possible) to respond to Data Subjects exercising their rights. If Carmaa receives a request directly, it will refer the Data Subject to the Customer.
8. Assistance
Carmaa will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security/breach obligations.
9. Personal-Data Breach
Carmaa will notify the Customer without undue delay after becoming aware of a Personal-Data breach affecting the Customer’s Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations.
10. Deletion or Return
On termination or expiry, and on the Customer’s request, Carmaa will delete or return Customer’s Personal Data within the period stated in the Data Deletion & Retention Policy (export window of 30 days, then deletion in the ordinary course), except to the extent retention is required by law.
11. Audits
Carmaa will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice, confidentiality, frequency limits, and not compromising other customers’ security.
12. International Transfers
Where Carmaa transfers Personal Data across borders on the Customer’s behalf, it will ensure an appropriate transfer mechanism (such as Standard Contractual Clauses) where required by Data Protection Laws. Primary hosting is in AWS Mumbai (ap-south-1).
13. Liability & Precedence
Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict between this DPA and the Terms regarding processing of Personal Data, this DPA prevails.
Annex A — Processing Summary
See §3 above.
Annex B — Security Measures
Encryption in transit (TLS) and at rest; secrets/keys in AWS Secrets Manager (KMS); per-tenant container isolation and separated data stores; role-based access control and least-privilege IAM; authenticated, signature-verified webhooks; monitoring, logging, and incident response; backups with point-in-time recovery for primary data stores.
Annex C — Subprocessors
See the Subprocessors List.
Contact: Carmaa Technologies Private Limited · techcarmaa@gmail.com · +91 70425 55401 · 197 Tea Estate, Near Bhadri Guest House, Banjarawala, Dehradun - 248001, Uttarakhand, India
Carmaa Technologies Private Limited · CIN: U45403UT2025PTC019812 · PAN: AANCC0341C · GSTIN: 05AANCC0341C1Z9
DPIIT Recognition No.: DIPP223487 · MSME (Udyam): UDYAM-UK-05-0116928
197 Tea Estate, Near Bhadri Guest House, Banjarawala, Dehradun – 248001, Uttarakhand, India
Email: techcarmaa@gmail.com · Phone: +91 70425 55401