SAM.AI by Carmaa — Legal
Privacy Policy
How we collect, use, share, and protect personal data — aligned with GDPR and India's DPDP Act 2023.
Carmaa Technologies Private Limited (“Carmaa”, “we”, “us”) operates SAM.AI, an AI sales-and-marketing platform. This Privacy Policy explains how we collect, use, share, and protect personal data, and the rights available to individuals. It is designed to align with the EU/UK General Data Protection Regulation (GDPR), the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”), and the Information Technology Act, 2000 and the SPDI Rules, 2011 (India).
1. Two Roles — Please Read This First
SAM.AI is a multi-tenant platform. Our role under data-protection law depends on whose data is involved:
- When we handle data about our business customers (account holders, their staff/users) — e.g. names, work emails, login data, billing data — we act as a controller and this Policy governs.
- When our business customer uses SAM.AI to process data about their customers/contacts (e.g. people who message the customer’s WhatsApp, leads, bookings) — the business customer is the controller and we are the processor. That processing is governed by our Data Processing Addendum (DPA) and the customer’s own privacy notice. If you are an End User/Contact and want to exercise rights over your data, please contact the business you interacted with; we will assist them as their processor.
2. Personal Data We Collect
(a) From business customers (we are controller):
- Account & profile: name, email, phone, business name, type, address/city, business hours, role.
- Authentication: hashed passwords, login tokens, Google sign-in identifiers (where used).
- Billing: plan, transaction identifiers, GSTIN (if provided), and payment status. We do not store full card numbers — card payments are handled by Razorpay.
- Support & communications: tickets, emails, and messages you send us.
- Usage & device data: log data, IP address, browser/device info, and product-usage events.
(b) Customer Data processed on a customer’s behalf (we are processor):
Depending on how the business customer configures SAM.AI, this may include their Contacts’ names, phone numbers, email addresses, message/conversation content, lead details, booking details, and uploaded media. The business customer decides what data to collect and why.
(c) Connected-service data:
Where a customer connects Third-Party Services, we process the tokens and data needed to operate them. Access tokens and keys are stored encrypted.
3. How and Why We Use Personal Data
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Run the AI agent, store conversations/leads/bookings, sync calendars, publish LinkedIn posts | Contract (Art. 6(1)(b)); for processor data, the customer’s instructions |
| Billing & account management | Process Subscriptions, prevent fraud, send service notices | Contract; Legal obligation |
| Security & integrity | Authentication, abuse prevention, logging, webhook signature checks | Legitimate interests (Art. 6(1)(f)); Legal obligation |
| Support | Respond to tickets and queries | Contract; Legitimate interests |
| Product improvement | Aggregated/diagnostic analytics to improve reliability | Legitimate interests |
| Legal compliance | Tax, accounting, responding to lawful requests | Legal obligation |
| Marketing to business customers | Service updates and offers (you can opt out) | Consent / Legitimate interests |
We do not sell personal data. We do not use the content of a customer’s Contacts’ conversations to train our own models.
4. AI Processing
The AI agent processes conversation content to generate replies and capture leads. Where a customer uses their own AI-provider key (e.g. Google Gemini), the relevant content is sent to that AI provider under the provider’s terms; the customer is responsible for that relationship.
5. How We Share Personal Data
We share personal data only as needed to run the Service:
- Subprocessors / service providers — cloud hosting (AWS), payment processing (Razorpay), and the integrations a customer enables (Meta/WhatsApp, Google, LinkedIn, the customer’s AI provider). See the Subprocessors List.
- Professional advisers, auditors, insurers — under confidentiality.
- Authorities — where required by law or to protect rights, safety, or the Service.
- Business transfers — in a merger, acquisition, or asset sale, subject to this Policy.
6. Payments
Payments are processed by Razorpay. We receive transaction status and identifiers but do not collect or store full card/bank credentials; those are handled by Razorpay under its PCI-DSS-compliant systems.
7. Security
We implement reasonable technical and organisational measures, including:
- Encryption in transit (TLS) and encryption at rest; secrets, access tokens and AI keys are held in AWS Secrets Manager, encrypted with AWS KMS.
- Tenant isolation — each active business customer’s AI workload runs in its own container, and per-customer data is stored in separate, access-controlled data stores.
- Access controls — role-based access (super-admin / customer / read-only), least-privilege cloud IAM, and authenticated, signature-verified webhooks.
- Logging & monitoring and a security-incident process.
- Hosting in AWS (Asia Pacific – Mumbai,
ap-south-1).
8. Data Retention
- Account & billing records — for the life of the account and thereafter as needed for legal/tax purposes (typically up to 8 years for financial records).
- Customer Data processed as processor — retained per the customer’s configuration; deleted or returned on termination per the DPA and Data Deletion & Retention Policy (export window of 30 days, then deletion).
- Logs — retained for a limited period (e.g. 30 days) for security and operations.
9. International Transfers
We host primarily in India (AWS Mumbai). Some subprocessors or integrations (e.g. Meta, Google, LinkedIn) may process data outside your country. Where personal data of EU/UK individuals is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent.
10. Your Rights
Subject to applicable law, individuals may have the right to: access, correct/update, delete, restrict or object to processing, data portability, and withdraw consent; and, under the DPDP Act, the right to nominate and to grievance redressal. Under GDPR you may also lodge a complaint with a supervisory authority.
- Business customers (we are controller): contact us at techcarmaa@gmail.com.
- End Users/Contacts (we are processor): please contact the business you interacted with; we will support them in fulfilling your request.
11. Data Breaches
If a personal-data breach occurs, we will act promptly to investigate and mitigate and will notify affected controllers/customers, individuals, and authorities where and within the timeframes required by law.
12. Children
The Service is for business use and not directed to children. We do not knowingly collect personal data from children. Business customers must not use SAM.AI to collect children’s data without lawful consent.
13. Cookies
The portal and website use cookies/local storage for authentication and basic functionality. See our Cookie Policy for details and choices.
14. Grievance / Data Protection Officer
In accordance with the IT Act / SPDI Rules and the DPDP Act, you may contact our Grievance Officer / DPO:
Grievance Officer, Carmaa Technologies Private Limited
Email: techcarmaa@gmail.com · Phone: +91 70425 55401
Address: 197 Tea Estate, Near Bhadri Guest House, Banjarawala, Dehradun - 248001, Uttarakhand, India
15. Changes
We may update this Policy. We will post the new version with a revised “Last updated” date and, for material changes, provide additional notice.
16. Contact
Carmaa Technologies Private Limited
Email: techcarmaa@gmail.com · Phone: +91 70425 55401
197 Tea Estate, Near Bhadri Guest House, Banjarawala, Dehradun - 248001, Uttarakhand, India
Carmaa Technologies Private Limited · CIN: U45403UT2025PTC019812 · PAN: AANCC0341C · GSTIN: 05AANCC0341C1Z9
DPIIT Recognition No.: DIPP223487 · MSME (Udyam): UDYAM-UK-05-0116928
197 Tea Estate, Near Bhadri Guest House, Banjarawala, Dehradun – 248001, Uttarakhand, India
Email: techcarmaa@gmail.com · Phone: +91 70425 55401