Privacy Policy
This policy explains what we collect, why, how long we keep it, and how you get it back or get it deleted. It covers this website and our commercial engagements.
1. Who we are
Kamaan is operated by Kamaan AI Solutions Private Limited, incorporated in India. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we act as a Data Fiduciary in respect of data we collect through this website, and as a Data Processor in respect of client data we handle during an engagement. Where the GDPR applies, the equivalent roles are Controller and Processor.
2. What we collect
| Category | What it includes | Why we collect it | Lawful basis |
|---|---|---|---|
| Enquiry data | Name, work email, company, role, and the answers you give in the Apply form | To assess fit and respond to your enquiry | Consent / legitimate interest |
| Engagement data | Contact details of client personnel, contractual and billing information | To deliver and invoice a contracted engagement | Performance of a contract |
| Client systems data | Whatever your systems contain and your agents process — this may include personal data belonging to your customers or staff | To build and operate the systems you contracted | Processed on your instructions, as Processor |
| Technical data | IP address, browser type, pages visited, referring source | Security, and to understand which pages are useful | Legitimate interest / consent for analytics |
| Communications | Email, Slack and call records with you | Delivery, support and record-keeping | Performance of a contract |
We do not collect special-category or sensitive personal data through this website. We do not knowingly collect data from anyone under 18.
3. Client data during an engagement
This is the section that matters most to a client, so it is stated plainly:
- Your systems stay yours. Wherever the engagement allows it, systems we build are deployed inside your infrastructure or your cloud tenancy, and your data does not leave your control.
- We process on your instructions. Where we do handle your data, we do so as a Processor, only for the purposes set out in the SOW, and never to train general-purpose models.
- Sub-processors are disclosed. Model providers, hosting and observability vendors used on your engagement are named in the SOW before work begins, and you are notified before any change.
- You can take it with you. Prompts, eval benches, workflows and configuration are exportable as JSON or Markdown at any point in the engagement.
- Deletion on exit. On termination we delete or return client data per the timeline in the MSA, and confirm in writing.
4. AI and automated processing
Our work involves large language models. Three commitments follow from that, and they apply to this website and to every engagement:
- We do not submit your personal data to a model provider for the purpose of training that provider's models, and we use enterprise or zero-retention terms with providers where available.
- No agent we deploy makes a legally or similarly significant decision about an individual without a human in the loop. Employment and credit-type decisions are always human.
- Agent actions are logged, attributable and reversible, and that log is available to you.
5. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact, then deleted |
| Engagement and contractual records | Duration of the engagement plus 8 years, per Indian statutory requirements |
| Client systems data | Per the SOW; deleted or returned on termination |
| Website technical logs | 12 months |
| Analytics | Aggregated; no individual-level retention |
6. Your rights
Under the DPDP Act, if you are a Data Principal you may ask us to: confirm what we hold about you and how it is processed; correct or complete inaccurate data; erase data we no longer need; nominate another person to exercise your rights in the event of death or incapacity; and withdraw consent, as easily as you gave it.
If the GDPR applies to you, you additionally have rights of access, portability, restriction of processing, objection to processing based on legitimate interest, and the right to lodge a complaint with your supervisory authority.
To exercise any of these, write to admin@kamaan.ai. We respond within 30 days. If you are a client's customer or employee and your data reached us through a client's systems, please contact that client first — they are the Data Fiduciary, and we will support them in responding to you.
7. Grievance redressal
As required by the DPDP Act and the Information Technology (Reasonable Security Practices) Rules, 2011, our Grievance Officer is:
Mr. Lalit W. Chandna (Head of Support & Admin)
admin@kamaan.ai
103, Subhashish Building, Above Medwell Chemist, Kanakia Road, Mira Road East, Thane, Maharashtra - 401107
We acknowledge grievances within 24 hours and resolve them within 15 days. If you remain dissatisfied, you may complain to the Data Protection Board of India.
8. Security
We apply access control on least-privilege principles, encryption in transit and at rest, secrets management separated from application code, audit logging on agent actions, and annual review of our sub-processors. Our full technical position is on the Security page. No system is perfectly secure, and we do not claim otherwise; we do commit to notifying you and the Data Protection Board of a reportable breach without undue delay.
9. Transfers outside India
Some vendors we rely on — including model providers and hosting — process data outside India. We only use vendors offering appropriate contractual safeguards, and where an engagement requires data residency within India we architect for it and say so in the SOW.
10. Changes
We update this policy as our practices change. The effective date is at the top of this page. Material changes are notified to active clients by email.