Data collection, security, and transaction privacy terms.
Version3.0
Effective1 January 2026
Last updated8 September 2026
Length26 sections · 138 clauses
Read this with the Terms & Conditions
This policy explains how personal data is handled across every KaamGPT workspace and application. It forms part of the Terms & Conditions, which govern the commercial relationship — including the strictly non-refundable transactions policy. Transaction and invoice records described in Section 16 are retained for statutory periods and cannot be deleted on request, and no data-deletion request alters the finality of a payment already made.
KaamGPT ('KaamGPT', 'we', 'us', 'our') operates a multi-tenant business workspace from Bangalore, India. This Privacy Policy describes how personal data is collected, used, disclosed, transferred, secured, retained and deleted when a company uses our platform, when its employees sign in to a workspace, and when an individual receives a message, a call or a booking link sent through it.
The policy covers the web application at kaamgpt.com and every workspace beneath it, the administrator console, the mobile applications, the public APIs and webhooks, the AI voice runtime, the marketing and messaging infrastructure, file storage, the document tools and the public marketing site.
Two different relationships are described here, and it matters which one you are in. When a company puts its employee records, its customer contacts and its message content into a workspace, that company decides what is processed and why: it is the Data Fiduciary, and KaamGPT is its processor. When you deal with us directly — your account, your invoices, your support tickets, our own security and marketing — KaamGPT is the Data Fiduciary. Section 3 sets out the split, and Section 18 explains where an employee or a contact should send a request.
This policy is written to be read alongside the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and the rules made under them, and includes additional disclosures in Section 24 for individuals in the EEA, the United Kingdom and California.
1. Scope of this policy
What this policy covers, and the few things it does not.
1.1
Who is covered. This policy applies to: company administrators and billing contacts; employees and other users of a workspace; individuals whose details appear in a customer's records, such as leads, customers, candidates, guests and vendors; recipients of messages, emails and calls sent through the platform; visitors to our public website; and anyone who contacts our support desk.
1.2
What is covered. It covers every category of personal data listed in Section 4, however collected — typed into a form, imported from a file, captured by a mobile application, generated by use of the Service, received from a payment gateway or messaging provider, or produced by an AI feature.
1.3
What is not covered. It does not cover: the independent privacy practices of a customer whose workspace you belong to; third-party websites and applications you reach through a link; a provider account you connect under your own contract; or data you choose to publish yourself.
1.4
Part of the Terms. This policy forms part of the KaamGPT Terms & Conditions. Defined terms used here — Workspace, User, Administrator, Customer Data, Application, Third-Party Service — have the meanings given in Section 2 of those Terms.
1.5
Changes. The version and 'last updated' date at the top of the page identify the operative text. Section 25 explains how changes are notified.
2. Definitions used in this policy
The vocabulary of Indian data protection law, in plain terms.
2.1
Key terms.
'Personal data' means any data about an individual who is identifiable by or in relation to that data.
'Processing' means any operation performed on personal data — collection, storage, use, sharing, indexing, alteration, retrieval, transmission, erasure and everything in between.
'Data Principal' means the individual to whom personal data relates (the 'data subject' in other laws).
'Data Fiduciary' means the person who determines the purpose and means of processing (the 'controller' in other laws).
'Data Processor' means a person who processes personal data on behalf of a Data Fiduciary.
'Sub-processor' means a third party engaged by us to process personal data in order to deliver part of the Service.
'Consent Manager' has the meaning given in the Digital Personal Data Protection Act, 2023.
'Personal data breach' means any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data.
2.2
Reading the tables. Where this policy sets out a table of purposes, sub-processors, retention periods or cookies, that table is part of the policy and is maintained as our practices change.
3. Who is responsible for what
The workspace owner decides; we execute. Both roles carry duties.
3.1
You as Data Fiduciary. A company that operates a workspace determines what personal data it puts into KaamGPT, why, for how long, who inside the company may see it, and whom it contacts. That company is the Data Fiduciary for that data and is responsible for notices, consents, lawful bases, accuracy, and the rights of the individuals concerned.
3.2
KaamGPT as Data Processor. For workspace content we act on the customer's documented instructions — the Terms & Conditions plus the customer's own configuration of the Service. We do not sell workspace content, do not use it to advertise to anyone, and do not disclose it except as described in Section 12.
3.3
KaamGPT as Data Fiduciary. We are the Data Fiduciary for: account registration and authentication data; billing, invoicing and tax records; support correspondence; security, abuse and audit telemetry; website analytics; and our own marketing lists.
3.4
Employees of a customer. If you use KaamGPT because your employer or client gave you a login, your employer decides what is recorded about you in that workspace, including attendance, leave, payroll and performance records. Requests about that data should go to your employer first; Section 18 explains what we can and cannot do directly.
3.5
Recipients of messages. If you received an email, a WhatsApp message or an automated call sent through KaamGPT, the business named in the message is the sender and the Data Fiduciary for that contact record. We can identify the sending workspace to that business and to a competent authority, and will forward your request to the sender.
3.6
Joint obligations. Both parties must maintain reasonable security safeguards, cooperate on incident handling, and respond to lawful requests. Nothing in this policy transfers a customer's own compliance obligations to us.
4. Personal data we collect
Every category held by the platform, by source and purpose.
4.1
Account and workspace data. Name, work email address, mobile number, password hash, company name, workspace slug, job title, role and permissions, profile photograph, language and timezone preferences, notification settings, and the identity of the Administrator who invited each user.
4.2
Employee and HR records. Where a customer enables the HR applications: employee code, department, designation, reporting line, joining and exit dates, salary structure and payroll components, statutory identifiers entered by the employer, leave balances and requests, shift rosters, documents uploaded to a personnel file, appraisal and performance notes, assets issued, and letters and certificates generated.
4.3
Attendance and location data. Check-in and check-out timestamps, device identifier, selfie or photograph where the employer enables it, and geographic coordinates captured at the moment of a check-in or a field visit where the employer enables location attendance. Location is captured at those events; the platform does not track a device continuously in the background.
4.4
Contacts, leads and CRM records. Names, phone numbers, email addresses, company names, addresses, tags, notes, deal values, pipeline stages, activity history, uploaded lists and the source of each record as recorded by the customer.
4.5
Communications content and metadata. Message bodies, templates, subject lines, attachments, sender identity, recipient identifiers, campaign names, scheduling data, delivery, bounce, read, click and unsubscribe events, error codes returned by providers, and conversation threads held in the inbox features.
4.6
Voice and AI data. For AI calling: the number dialled, call start and end times, duration, connection and disposition status, the audio recording where recording is enabled by the customer, the transcript, the AI agent configuration and prompts, and the structured outcome extracted from the conversation.
4.7
Files and documents. Files uploaded to Drive, PDFs processed by the document tools, invoices and bills generated, images and media attached to records, and their file metadata such as name, size, type, version history and the user who uploaded them.
4.8
Billing and transaction data. Plan and subscription details, invoice line items, GSTIN and tax registration details, billing address, wallet ledger entries, credit purchases and consumption, gateway transaction identifiers, payment status, the last four digits and instrument type reported by the gateway, and refund-request correspondence. We never receive or store full card numbers, CVV codes, UPI PINs or net-banking credentials.
4.9
Support and correspondence. Emails, tickets, chat transcripts, call notes, screenshots and diagnostic information you send us, and our replies.
4.10
Technical and log data. IP address, user agent, device model and operating system, application version, session and refresh token identifiers, login timestamps and outcomes, pages and API endpoints accessed, request identifiers, performance timings, crash reports and audit-log entries recording who changed what and when.
4.11
Cookies and similar technologies. As described in Section 11, including strictly necessary session cookies and, on the public website only, limited analytics identifiers.
4.12
Data from other sources. Verification results and dispute information from payment gateways; delivery, quality-rating and policy-enforcement signals from messaging providers; publicly available business information used to verify a company; and referrals from partners where you asked to be contacted.
4.13
What we ask you not to store. Do not store in the Service: full payment card data; passwords for other systems; biometric templates; or regulated health records, unless a written agreement covering that use is in place. See clause 18.4 of the Terms.
5. Why we process personal data
Each purpose, and the basis it rests on.
5.1
Purposes and bases.
Purpose
Data used
Basis
Creating and running a workspace, authenticating users, applying permissions
Account, workspace, technical
Performance of contract
Delivering the applications a customer has enabled — attendance, HR, CRM, billing, storage, calendar
Employee, attendance, contacts, files
Processing on the customer's instructions
Sending emails, WhatsApp messages, SMS and AI calls at a customer's instruction
Contacts, communications, voice
Processing on the customer's instructions
Metering usage, billing, invoicing and tax compliance
Billing, transaction, technical
Contract and legal obligation
Preventing fraud, spam, abuse and unauthorised access
Technical, communications metadata, billing
Legitimate use and legal obligation
Providing support and investigating reported faults
Support, technical, minimum workspace data
Contract
Maintaining security, backups, audit logs and continuity
Technical, audit
Legal obligation and legitimate use
Improving reliability, quality and safety of the platform
Aggregated and de-identified signals
Legitimate use
Telling customers about service changes, incidents and billing
Account contacts
Contract
Marketing our own products to business contacts
Marketing list
Consent, withdrawable at any time
Meeting statutory retention, responding to lawful requests, defending claims
Billing, audit, communications records
Legal obligation
5.2
No unrelated use. We do not use workspace content for purposes unrelated to providing the Service, do not sell personal data, do not share it with data brokers, and do not use it for advertising or profiling of individuals for third parties.
5.3
Change of purpose. If we ever need to process personal data for a new purpose that is not compatible with those listed, we will update this policy and, where required, obtain consent before doing so.
6. Notice, consent and withdrawal
How consent is taken, and what happens when it is withdrawn.
6.1
Notice. Where we collect personal data directly and rely on consent, we give a clear notice describing the data, the purpose, how a request can be made and how a complaint can be raised with the Data Protection Board of India.
6.2
Consent for workspace content. For personal data a customer uploads or generates, the customer is responsible for giving notice and obtaining consent from the individuals concerned, including employees, candidates, customers and message recipients.
6.3
Withdrawal. Consent may be withdrawn at any time, as easily as it was given, by writing to the Grievance Officer or by using the mechanism provided in the relevant interface. Withdrawal takes effect prospectively and does not affect processing already carried out lawfully.
6.4
Consequence of withdrawal. Where consent is necessary to provide a feature, withdrawing it may make that feature unavailable. Where processing rests on contract or a legal obligation — for example invoicing and statutory records — withdrawal does not stop it.
6.5
Consent Managers. Where a Consent Manager registered under the Digital Personal Data Protection Act, 2023 is used to give, manage or withdraw consent, we will honour instructions received through it in accordance with that Act.
6.6
Records. We keep records of consent taken through our own interfaces. Customers must keep records of consent taken through theirs, as required by clause 15.3 of the Terms.
7. Messages, campaigns and recipients
What happens to a contact list, and what a recipient can ask for.
7.1
Sending on instruction. When a customer runs a campaign, we process the recipient list only to queue, personalise, submit, deliver, retry and report on that campaign, and to enforce suppression, opt-out and abuse controls.
7.2
Suppression data. Unsubscribes, bounces, complaints and stop requests are stored so that the recipient is not contacted again by that workspace. Suppression records are kept even after a contact is deleted, because deleting them would allow the same person to be contacted again.
7.3
Tracking. Where a customer enables open and click tracking, opens and clicks are recorded with a timestamp, an approximate location derived from IP, and the device or client reported by the recipient's software. Customers must disclose this in their own privacy notice.
7.4
Content review. We do not read message content for commercial purposes. Automated checks screen for malware, phishing, banned content and abuse signals, and a human may review a specific message where a complaint, a provider escalation or a legal request requires it.
7.5
Provider sharing. Recipient identifiers and message content are necessarily shared with the delivery provider for the channel chosen by the customer, which processes them under its own terms and policies.
7.6
Recipient requests. A recipient may write to us to identify the sending business, to be added to a platform-level suppression list for that sender, or to have their request forwarded. We will act within the periods in Section 17.
8. AI processing, recordings and training
How prompts, recordings and transcripts are handled.
8.1
What is sent to a model. When an AI feature runs, the prompt, the relevant workspace content and configuration necessary to produce the result are transmitted to the model provider selected for that feature, under contractual confidentiality and processing terms.
8.2
Training. We do not use identifiable Customer Data — message content, call recordings, transcripts, documents, contacts or HR records — to train publicly shared foundation models. Aggregated, de-identified operational signals such as latency, error rates, feature usage and classification outcomes are used to improve reliability and safety.
8.3
Recordings and transcripts. Call recordings and transcripts are stored in the workspace that made the call, are retained under that customer's configuration and the schedule in Section 16, and are available for export and deletion by that customer.
8.4
Recording consent. The customer placing a call is responsible for every consent and notice required before a call is recorded or transcribed, including all-party consent where the recipient's jurisdiction requires it.
8.5
Human review. A member of our team may review a specific AI interaction only to diagnose a reported fault, to investigate abuse, or where required by law, under logged and restricted access.
8.6
Accuracy. AI output is probabilistic and may be wrong. It is not a source of truth about any individual, and decisions materially affecting a person must not be made on AI output alone. See Section 17 of the Terms.
8.7
Automated decisions. We do not make automated decisions producing legal or similarly significant effects on an individual. A customer that configures such a decision inside its workspace is responsible for the safeguards required by the law applicable to it.
9. Attendance, location and workforce monitoring
The most sensitive workspace data, and the limits on it.
9.1
Event-based capture. Location is captured at discrete events — a check-in, a check-out, a field-visit log — and only when the employer has enabled that feature and the device has granted permission. There is no continuous background tracking.
9.2
Employer configuration. Whether attendance requires a selfie, a geofence, a device binding or an IP restriction is decided by the employer, not by us.
9.3
Employee notice. The employer is responsible for informing employees what is captured, why, who can see it and for how long it is kept, as required by applicable employment and data protection law.
9.4
Device permissions. Location and camera permissions are granted on the device and can be withdrawn there. Withdrawing them may make attendance capture impossible, which is a matter between the employee and the employer.
9.5
Access inside a workspace. Attendance and location records are visible to users the employer has authorised. We do not expose one company's attendance data to any other company.
10. How data reaches us
Direct entry, imports, devices, providers and generated records.
10.1
From you. When you register, configure a workspace, invite users, enter records, upload a file or list, run a campaign, raise a ticket, or make a payment.
10.2
From your devices. Automatically through your browser or mobile application — technical data, session data, crash reports, and the attendance signals described in Section 9.
10.3
From your colleagues. An Administrator or manager may create your user record and enter data about you before you first sign in.
10.4
From providers. Payment gateways return transaction status and dispute information; messaging providers return delivery, error, quality and policy-enforcement signals; telephony providers return call disposition data.
10.5
Generated by the Service. Audit trails, metering records, ledger entries, derived analytics, AI outputs and system notifications are created by the platform as it runs.
11. Cookies and similar technologies
What is set, why, and what you can turn off.
11.1
Categories.
Category
Purpose
Can it be refused?
Strictly necessary
Session and refresh tokens, workspace selection, CSRF protection, load balancing
No — the Service cannot run without them
Preference
Theme, language, sidebar and table layout, last-used filters
Yes, by clearing site data; some settings will reset each visit
Security
Device recognition for sign-in risk checks, abuse and bot mitigation
No, while an account is active
Analytics (public website only)
Aggregate page views and traffic sources to improve the marketing site
Yes, through your browser controls or the consent banner where shown
11.2
No third-party advertising. We do not run third-party advertising trackers, cross-site advertising pixels or data-broker tags inside the signed-in workspace.
11.3
Local storage. The application stores limited data in browser local storage — session state, cached lists, drafts and preferences — so that screens load quickly and unsent work is not lost. Clearing site data removes it.
11.4
Do Not Track. Browsers send Do Not Track signals inconsistently and there is no accepted standard for honouring them; we therefore do not respond to them, and instead limit tracking as described above.
11.5
Customer tracking. Open and click tracking inside a customer's own campaigns is that customer's processing, configured by them and disclosed in their own privacy notice.
12. Sharing and disclosure
The only people who see your data, and why.
12.1
Inside the platform. Workspace content is visible to users of that workspace according to the roles and permissions its Administrators configure, and to no other customer. Tenant isolation is enforced in the database itself, not only in the interface.
12.2
Our personnel. Access by our staff is limited to those who need it for operations, security or support, is granted on a least-privilege basis, is logged, and is subject to confidentiality obligations that survive their engagement.
12.3
Sub-processors. We engage the following categories of sub-processor. Each is bound by written terms requiring confidentiality, security measures and processing limited to our instructions.
Category
Used for
Typical providers
Cloud hosting and databases
Running the application, storing workspace records
Managed PostgreSQL and container hosting, including Supabase and Google Cloud Platform
Object storage and delivery
Files, media, exports, backups, static assets
Cloudflare R2 and Cloudflare edge services
Messaging and telephony
WhatsApp, SMS and voice delivery
Meta Cloud API, MSG91, licensed telecom operators
Email delivery
Transactional and campaign email
Authenticated SMTP and email delivery providers assigned to your workspace
Payments
Collecting subscription and wallet payments, invoicing
Razorpay, Cashfree and bank payment gateways
AI inference
Assistants, summarisation, extraction, AI voice agents
Enterprise AI model endpoints under contractual processing terms
Operational tooling
Error monitoring, uptime checks, ticketing
Providers bound by equivalent confidentiality and security terms
12.4
Payment gateways. Payment credentials are collected by the gateway on its own pages or SDK. We receive only the transaction reference, status, instrument type, masked identifier and any dispute information.
12.5
Legal disclosure. We may disclose personal data where required by Applicable Law or by a binding order, summons, warrant or direction from a court, regulator, telecom authority or law-enforcement agency, or where necessary to establish, exercise or defend a legal claim. Where we are legally permitted to do so, we will inform the affected customer before disclosing.
12.6
Safety and abuse. We may disclose the minimum information necessary to prevent or investigate fraud, spam, abuse, threats to life or safety, or a serious security incident, including to a provider whose network is affected.
12.7
Business transfer. If KaamGPT is involved in a merger, acquisition, restructuring, financing or sale of assets, personal data may be transferred to the counterparty subject to this policy or a policy no less protective, and affected customers will be notified.
12.8
Aggregated information. We may publish aggregated, de-identified statistics that cannot reasonably be linked back to any workspace or individual.
12.9
No sale of personal data. We do not sell personal data, do not rent contact lists, and do not share workspace content with data brokers or advertising networks.
12.10
Change of sub-processor. The list in clause 12.3 changes as providers are added or replaced. Material changes are reflected here, and enterprise customers with a signed agreement receive notice as that agreement requires.
13. Where data is stored and cross-border transfers
Primary storage, and the safeguards when data crosses a border.
13.1
Primary storage. Production databases and object storage for the platform are hosted in data centres operated by our cloud providers, with the primary region selected for latency and availability. Backups are stored in the same or an adjacent region under the same protections.
13.2
Transfers. Some sub-processors — including messaging, AI inference and monitoring providers — process data outside India. Transfers are made only to countries not restricted by the Central Government under the Digital Personal Data Protection Act, 2023, and under contractual safeguards.
13.3
Safeguards. Transfer safeguards include written processing terms, confidentiality obligations, encryption in transit, restriction to the purpose of the Service, and, for European personal data, standard contractual clauses or another recognised transfer mechanism.
13.4
Localisation requests. Customers with regulatory localisation requirements should contact us before onboarding; specific hosting arrangements are handled under a signed enterprise agreement and may attract additional charges.
14. How we protect personal data
The measures in place, and the honest limits of them.
14.1
Technical measures.
TLS encryption for all data in transit, with modern cipher suites and HSTS on our domains;
encryption at rest for databases, object storage and backups;
tenant isolation enforced at the database layer, so a query cannot cross a company boundary;
hashed and salted password storage, short-lived access tokens and rotatable refresh sessions;
role-based access control with per-application permissions, and API keys scoped to a workspace;
audit logging of administrative actions, exports, permission changes and authentication events;
automated backups with restore testing, and infrastructure monitoring with alerting;
dependency scanning, code review and staged deployment before changes reach production.
14.2
Organisational measures.
least-privilege administrative access, granted for a purpose and reviewed periodically;
confidentiality obligations in every employment and contractor agreement;
security and privacy training for personnel with access to production systems;
documented incident response, with defined roles and escalation paths;
vendor assessment before a sub-processor is engaged.
14.3
Your part. Use strong unique passwords, enable available multi-factor options, keep Administrator rights to a minimum, remove leavers promptly, rotate API keys, and protect the email accounts that can reset your credentials.
14.4
No absolute guarantee. No internet-facing system can be guaranteed immune from compromise. We do not warrant absolute security, and you accept that residual risk when you use the Service.
14.5
Reporting a vulnerability. Report suspected vulnerabilities to support@kaamgpt.com. Please do not access another tenant's data, degrade the Service, or exfiltrate personal data while testing.
15. Personal data breaches
What we do, whom we tell, and how quickly.
15.1
Detection and containment. On detecting a suspected breach we contain the incident, preserve evidence, assess the categories and volume of data affected, and identify the workspaces concerned.
15.2
Notification to customers. We notify affected customers without undue delay after confirming a breach affecting their workspace, describing what happened, the data involved, the likely consequences, the steps taken, and what the customer should do.
15.3
Notification to authorities. We notify the Data Protection Board of India and any other competent authority where required, within the time limits prescribed, and comply with directions issued by CERT-In, including incident reporting within the prescribed hours and log-retention requirements.
15.4
Notification to individuals. Where we are the Data Fiduciary and the breach is likely to result in significant harm, we notify affected individuals directly. Where we are the processor, the customer is responsible for notifying the individuals in its workspace, with our assistance.
15.5
Records. We maintain a record of breaches, their effects and the remedial action taken, and make it available to a competent authority on request.
16. How long data is kept
The retention schedule, and the records that cannot be deleted on request.
16.1
Principle. Personal data is kept for as long as it is needed for the purpose it was collected for, for as long as a workspace remains active, and thereafter only where a statutory obligation, a limitation period or an active dispute requires it.
16.2
Schedule.
Data
Retention
Reason
Active workspace content — employees, contacts, records, files
While the workspace is active, plus the export window in clause 25.6 of the Terms
Providing the Service
Deleted records inside an active workspace
Removed from production on deletion; purged from backups within about 90 days
Backup rotation
Terminated workspace
Production data deleted or anonymised within about 30 days of the export window closing
Providing the Service
Message and campaign logs, delivery reports
24 months, unless a shorter period is configured by the customer
Security, CERT-In directions and incident investigation
Support correspondence
36 months
Service history and dispute defence
Marketing list entries
Until consent is withdrawn, plus a suppression record
Consent
Backups
Rolling cycle, typically expiring within 90 days
Continuity
16.3
Financial records cannot be deleted on request. Invoices, transaction references, wallet ledgers and tax records are retained for the statutory period stated above and are not deleted on a data-deletion request, because we are legally required to keep them. Their retention is separate from, and does not affect, the strictly non-refundable transactions policy in Section 10 of the Terms — no deletion request, account closure or data erasure creates any right to a refund.
16.4
Anonymisation. Where a record is needed for statistics, capacity planning or fraud modelling after its retention period, it is irreversibly anonymised rather than kept in identifiable form.
16.5
Legal hold. Where data is subject to an investigation, a lawful request, or an actual or threatened claim, it is retained until that matter is resolved, notwithstanding the schedule above.
17. Your rights
What you can ask for, how to ask, and how long it takes.
17.1
Rights available.
Access — a summary of the personal data we process about you and the processing activities involved;
Correction, completion and updating — to have inaccurate or incomplete data put right;
Erasure — to have data deleted where it is no longer needed and no legal obligation requires it;
Withdrawal of consent — where processing rests on consent;
Grievance redressal — to complain to our Grievance Officer and receive a response;
Nomination — to nominate another individual to exercise your rights in the event of your death or incapacity;
Objection and restriction, data portability, and freedom from solely automated decisions, where the law applicable to you provides them (see Section 24).
17.2
How to exercise. Write to the Grievance Officer at support@kaamgpt.com from the email address on the account, describing the request and the workspace it relates to. Where the request comes from a different address, we may ask for information sufficient to verify identity.
17.3
Verification. We verify requests before acting on them, because acting on an unverified request is itself a data breach. Verification information is used only for that purpose and is deleted afterwards.
17.4
Timelines. We acknowledge requests within 48 hours and respond substantively within 30 days. Where a request is complex or numerous, we may extend the period once, telling you why before the original period ends.
17.5
Fees. Requests are handled free of charge. A manifestly excessive or repetitive request, or a request for extensive historical reconstruction, may attract a reasonable administrative charge, notified before any work starts.
17.6
Refusal. We may decline a request in whole or in part where the law permits — for example where it would infringe another person's rights, where a statutory retention obligation applies, or where the request is manifestly unfounded. We will explain the reason and your right to complain.
17.7
Duties of a Data Principal. Under the Digital Personal Data Protection Act, 2023 you must not impersonate another person when making a request, must not suppress material information, and must not file a false or frivolous complaint.
18. Employees, recipients and customers of our customers
If your data is in someone else's workspace, start with them.
18.1
Route the request correctly. Where your data sits inside a customer's workspace, that customer decides what is held and why. Send your request to that organisation, which can access, correct, export and delete the record directly using the tools in the product.
18.2
What we do. If you write to us about data in a customer's workspace, we will identify the customer where we lawfully can, forward your request to them without undue delay, and tell you that we have done so. We will not amend or delete another organisation's records on your instruction alone, unless required by law.
18.3
Messages you received. For a message, email or call you received, tell us the sender, the date and the number or address contacted. We can add a platform-level suppression so that the sending workspace cannot contact you again, and we will act on it regardless of what the sender does.
18.4
Escalation. If the organisation does not respond, you may raise a grievance with us under Section 26 and, if still unresolved, with the Data Protection Board of India or the supervisory authority applicable to you.
19. Children and persons with a guardian
The platform is not for children.
19.1
Not for children. The Service is a business product and is not directed at children. We do not knowingly collect personal data of a child under 18 through registration, and users must be 18 or older.
19.2
Data uploaded by a customer. A customer must not upload personal data of a child, or of a person with a lawful guardian, without the verifiable consent of the parent or guardian required by the Digital Personal Data Protection Act, 2023 and any other applicable law.
19.3
No tracking or targeting. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
19.4
Removal. If we learn that a child's personal data has been collected without the required consent, we will delete it promptly. Report such a case to the Grievance Officer.
20. Marketing and communications from us
Which of our emails you can switch off, and which you cannot.
20.1
Service communications. Security alerts, billing notices, incident and maintenance notifications, policy updates and product-critical announcements are sent for as long as your account is active. They are part of the Service and are not marketing.
20.2
Marketing. Product news, offers and educational content are sent only with consent or to a business contact who requested information, and every such email carries a one-click unsubscribe.
20.3
Preferences. Marketing preferences can be changed at any time from the link in any marketing email or by writing to support@kaamgpt.com. Unsubscribing takes effect within 72 hours.
20.4
Testimonials and logos. We use a customer name or logo publicly only as permitted by clause 21.3 of the Terms, and will remove it on written request.
21. Third-party sites, apps and integrations
Where our responsibility ends.
21.1
Links. Our site and product contain links to third-party sites and documentation. Their privacy practices are their own, and we are not responsible for them.
21.2
Connections you authorise. When you connect a third-party account, key or number, you authorise the exchange of the data necessary for that integration to work. That provider's own policy governs what it does with the data.
21.3
Provider policies. Where you use a channel governed by a provider policy — including the WhatsApp Business Messaging Policy and the Meta Platform Terms — that policy applies to your use of the channel in addition to this one.
21.4
Revoking a connection. Disconnecting an integration stops future exchange. Data already shared with that provider is governed by its policy and its retention practices, and must be dealt with directly with it.
22. Payments, invoices and transaction records
How financial data is handled — and what it does not entitle you to.
22.1
Card and UPI data. Card numbers, CVV values, UPI PINs and net-banking credentials are entered on the payment gateway's own interface and never reach KaamGPT systems. We receive only the transaction reference, status, instrument type and masked identifier.
22.2
Why we keep transaction records. Transaction records are processed to raise invoices, apply credits to a wallet, meter usage, comply with GST and income-tax obligations, satisfy gateway and anti-money-laundering requirements, prevent fraud, and defend disputes and chargebacks.
22.3
Chargeback evidence. If a chargeback or payment dispute is raised, we may submit invoices, acceptance records, access logs, metering records and delivery reports to the gateway, the bank or an adjudicating authority as evidence.
22.4
Non-refundable transactions. Payments made to KaamGPT are strictly non-refundable under Section 10 of the Terms & Conditions, in every circumstance and irrespective of anything. Nothing in this Privacy Policy — including the retention, deletion and erasure provisions — creates, implies or supports any right to a refund, credit, set-off or reversal.
22.5
Retention. Financial records are retained for 8 financial years as stated in clause 16.2 and are excluded from erasure requests for that period.
23. Analytics, profiling and automated decisions
What is measured, and what is never decided by a machine alone.
23.1
Product analytics. We measure feature usage, performance and error rates in aggregate to decide what to fix and what to build. These measurements are not used to build a profile of an individual for any third party.
23.2
Fraud and abuse scoring. Signals such as signup patterns, sending behaviour, complaint rates and payment anomalies are used to detect fraud and abuse. Where such a signal leads to a restriction, an Administrator can ask for a human review by writing to support@kaamgpt.com.
23.3
No solely automated significant decisions. We do not take decisions producing legal or similarly significant effects on an individual by automated means alone. A customer that configures such a decision in its own workspace is responsible for the required safeguards.
23.4
Customer-side profiling. Lead scoring, segmentation and campaign targeting configured by a customer are that customer's processing, and must be disclosed in that customer's own privacy notice.
24. Additional regional disclosures
Extra rights for individuals in the EEA, the UK and California.
24.1
EEA and United Kingdom — legal bases. Where the GDPR or UK GDPR applies, we rely on: performance of a contract for account and service delivery; legal obligation for tax, accounting and security reporting; legitimate interests for security, fraud prevention, service improvement and business-to-business marketing, balanced against your rights; and consent where consent is required, withdrawable at any time.
24.2
EEA and United Kingdom — rights. You additionally have the rights of access, rectification, erasure, restriction, objection (including to direct marketing at any time), portability, and the right not to be subject to a solely automated decision with legal or similarly significant effect. You may also complain to your local supervisory authority.
24.3
EEA and United Kingdom — transfers and processing terms. Where we act as processor for a European customer, a data processing addendum incorporating the standard contractual clauses is available on request to support@kaamgpt.com. International transfers are made under those clauses or another recognised mechanism.
24.4
California. In the preceding 12 months we have collected the categories of personal information described in Section 4 for the business purposes in Section 5, disclosed to the sub-processor categories in clause 12.3. We do not sell or share personal information as those terms are defined by the CCPA, and we do not offer financial incentives for personal information.
24.5
California rights. Residents of California may request to know, delete or correct personal information, and may not be discriminated against for exercising those rights. Requests go to support@kaamgpt.com and are handled under Section 17. An authorised agent may act on your behalf with written authorisation and identity verification.
24.6
Other jurisdictions. Where another data protection law applies to you and grants a right not listed here, we will honour it to the extent required by that law.
25. Changes to this policy
How this document is amended and how you are told.
25.1
Updates. We update this policy as the Service, our sub-processors, our security practices or the law change. The version and 'last updated' date at the top of this page identify the operative text.
25.2
Material changes. For a change that materially affects how personal data is used, we will give reasonable advance notice by email to Administrators or by an in-product notice before it takes effect.
25.3
Continued use. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy, save where consent is legally required, in which case consent will be sought separately.
25.4
Previous versions. Earlier versions are available from support@kaamgpt.com on request.
26. Grievance Officer and contact
Who to write to, and what happens next.
26.1
Grievance Officer. In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, grievances relating to the processing of personal data may be addressed to the Grievance Officer using the details below.
26.2
What to include. Please include your name, the workspace concerned, the email address or phone number the data relates to, a description of the concern, and any reference such as an invoice number, campaign name or message date.
26.3
Response. We acknowledge within 48 hours and endeavour to resolve within 30 days. If more time is needed, we will explain why and give a revised date before the original period expires.
26.4
Escalation. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India, or to the supervisory authority in your jurisdiction where another law applies to you.
Contact
Data Fiduciary
KaamGPT
Grievance Officer
Legal & Privacy Desk, KaamGPT
Email
support@kaamgpt.com
Helpline
+91 79767 82366
Address
KaamGPT, Bangalore, India
Response target
Acknowledged in 48 hours, resolved within 30 days
By creating a workspace, accepting an invitation, or continuing to use KaamGPT, you confirm that you have read this Privacy Policy and understand how personal data is processed, shared, retained and protected, and that it forms part of the Terms & Conditions.
This policy is published by KaamGPT for its own service and is not legal advice to you. If you are a customer, your own privacy notice to your employees and contacts remains your responsibility.