Skip to content
SANIDHYAMAI LABS

Legal

Privacy Policy

How Sanidhyam AI Labs collects, uses, shares, and protects personal information across our website, SaaS products, and client engagements.

Sanidhyam AI Labs Last updated: July 30, 2026 Effective date: July 30, 2026

Controller / Business: Sanidhyam AI Labs, Ahmedabad (“Sanidhyam,” “we,” “us,” or “our”), operating as Sanidhyam AI Labs. Site: https://www.sanidhyamailabs.com Privacy contact: privacy@sanidhyamailabs.com

This Policy explains how we collect, use, disclose, and protect personal information when you visit our Site, schedule a discovery call, or engage our Custom AI consulting and engineering services.

We design this Policy to support transparency under GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and the Australian Privacy Principles (APPs), among other frameworks applicable to visitors and clients in the USA, Canada, UK, EU, Australia, and the Middle East.

Our Cookie Policy describes cookies and similar technologies in detail.

Table of contents

  1. Who we are & scope
  2. Information we collect
  3. Sources of information
  4. How we use information
  5. Legal bases (GDPR / UK GDPR)
  6. AI interaction data
  7. When we share information
  8. International transfers
  9. Retention
  10. Security
  11. Your rights
  12. Children
  13. US state privacy (CCPA/CPRA & similar)
  14. Canada, UK/EU, Australia notes
  15. Third-party links & products
  16. Changes
  17. Contact & complaints

1. Who we are & scope

Sanidhyam is a B2B production AI engineering agency and SaaS product builder. This Policy covers:

  • Marketing Site and content
  • Contact forms, newsletters, and scheduling (e.g., Calendly)
  • CRM and sales pipeline records
  • SaaS Product accounts and telemetry
  • Project delivery systems used to perform SOWs

Client-as-controller engagements: When we process personal data on your behalf inside a client project or tenant (e.g., your end-user chat logs inside a system we build/host for you), you are typically the controller / business and we act as processor / service provider. Those processing details are governed by your SOW and a Data Processing Agreement (DPA) on request-not solely by this Policy.

Counterly POS and other portfolio products may publish separate product privacy notices. Where you use those products, the product notice applies to product data.

2. Information we collect

2.1 Direct / identity & commercial data

  • Name, email, phone, company, role, country/region
  • Inquiry content and attachments you submit
  • Discovery-call scheduling details and meeting metadata
  • Contract, SOW, and billing contact metadata
  • Payment-related information processed by our payment provider (we do not store full card PAN)
  • Account credentials (stored hashed/salted where we operate authentication)

2.2 Technical & usage data

  • IP address, approximate location (city/region level)
  • Device identifiers, browser type/version, OS
  • Pages viewed, referring/exit URLs, timestamps
  • Diagnostics, crash reports, performance metrics

2.3 AI interaction data

Depending on the product or engagement:

  • Prompts, queries, uploaded context snippets, and tool-call traces you submit to AI features
  • Retrieval metadata (e.g., document IDs, similarity scores)-not a substitute for your source-of-truth documents
  • System telemetry for latency, token usage, error rates, and safety filters
  • Evaluation labels if you participate in quality review

See §6 for training and retention defaults.

2.4 Sensitive data

We do not seek sensitive personal data via marketing forms. Please do not submit special-category data (health, biometric templates, precise geolocation, government IDs, etc.) unless an SOW and DPA expressly cover that processing with appropriate safeguards.

3. Sources of information

  • Directly from you (forms, email, calls, product use)
  • Automatically via cookies, SDKs, and logs (see Cookie Policy)
  • From scheduling, CRM, and analytics tools you interact with on our Site
  • From publicly available professional sources (e.g., company website, LinkedIn) when relevant to B2B outreach, where permitted
  • From your organization if an admin invites you to a SaaS tenant

4. How we use information

We use personal information to:

  • Respond to inquiries and schedule discovery calls
  • Provide, operate, secure, and support SaaS Products and Custom Services
  • Process transactions and send invoices/receipts
  • Personalize non-essential Site experiences where consented
  • Analyze Site and product performance; debug incidents
  • Send service/transactional messages
  • Send marketing communications where permitted (you may opt out anytime)
  • Enforce Terms, prevent abuse/fraud, and protect rights
  • Comply with law, respond to lawful requests, and establish/defend legal claims
  • Conduct limited B2B prospecting consistent with applicable marketing laws

Where GDPR/UK GDPR applies, we rely on:

PurposeTypical basis
Deliver contracted SaaS/Custom Services; manage accountsContract (Art. 6(1)(b))
Site security, fraud prevention, B2B relationship management, product improvement via de-identified telemetryLegitimate interests (Art. 6(1)(f)), balanced against your rights
Non-essential cookies, certain marketing emails, optional demosConsent (Art. 6(1)(a)) - withdraw anytime
Tax, accounting, responding to lawful processLegal obligation (Art. 6(1)(c))

You may object to legitimate-interest processing; see §11.

6. AI interaction data

6.1 Purpose

We process AI interaction data to provide the feature you requested, maintain safety/abuse controls, debug failures, measure quality, and meet contractual obligations.

6.2 Training

Default: We do not use your confidential prompts or Customer Content to train third-party foundation models, unless (a) you opt in in writing, or (b) a provider’s enterprise configuration you select permits it. Providers may still process prompts to return completions under their terms.

We may use aggregated/de-identified metrics to improve reliability.

6.3 Client projects

For Custom Services, treatment of production data (including retention and subprocessors) is defined in the SOW/DPA. Staging datasets should be minimized and scrubbed where feasible.

7. When we share information

We do not sell personal information for money. We may disclose information to:

7.1 Service providers / subprocessors

Categories include:

CategoryExamples (illustrative)
Cloud infrastructureAWS, Google Cloud, Azure, Vercel
AI model & vector APIsOpenAI, Anthropic, Google, Pinecone, and similar
CRM & emailHubSpot or equivalent
SchedulingCalendly or equivalent
AnalyticsGoogle Analytics, Mixpanel, Plausible, or similar
PaymentsStripe
CollaborationEmail/workspace tools used by our team
Professional advisorsLawyers, accountants, insurers (under confidentiality)

We require processors to protect data and use it only on our instructions (or your instructions when we are processor).

7.2 Corporate events

In connection with merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality.

Where required by law or necessary to protect rights, safety, or security.

7.4 With your direction

Integrations you enable, or disclosures you request.

Sub-processor updates: For processor engagements, we will provide a mechanism to receive notice of material sub-processor changes as described in the DPA (email list or portal).

8. International transfers

We may process and store information in the United States and other countries where we or our processors operate. Those countries may have different data-protection laws than your home jurisdiction.

For transfers of EEA/UK personal data to countries without an adequacy decision, we implement appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, plus supplementary measures where warranted. Copies of relevant clauses may be requested at privacy@sanidhyamailabs.com (commercially sensitive annexes may be redacted).

9. Retention

We retain personal information only as long as needed for the purposes above, including:

Data typeTypical retention
Marketing inquiries / lead recordsUp to 24 months after last meaningful contact, unless a relationship continues or you request deletion earlier
Contract/billing records7 years (or longer if required by tax/accounting law)
SaaS account dataLife of account + up to 90 days after closure for backup wind-down (unless DPA requires shorter/longer)
Security logsGenerally 90-365 days
AI debug logs (marketing/demo environments)Short-lived; typically ≤ 30 days unless needed for an active incident
Client project production logsPer SOW/DPA

We may retain limited information as required for legal claims, disputes, or compliance.

10. Security

We implement administrative, technical, and organizational measures appropriate to risk, including:

  • Encryption in transit (TLS) and at rest (AES-256 or cloud-equivalent)
  • Access controls, least privilege, and authentication for internal systems
  • Logging and monitoring of production systems
  • Vendor due diligence for material subprocessors
  • Employee confidentiality obligations

No method of transmission or storage is 100% secure. You are responsible for safeguarding credentials and configuring your tenant integrations securely.

11. Your rights

Depending on your location, you may have rights to:

  • Access / know what we hold
  • Correct inaccurate data
  • Delete / erase (subject to legal exceptions)
  • Portability of data you provided
  • Restrict or object to certain processing
  • Withdraw consent where processing is consent-based
  • Appeal a refusal (where required by US state law)
  • Lodge a complaint with a supervisory authority

How to exercise: Email privacy@sanidhyamailabs.com with the subject “Privacy Request,” and tell us which right you seek. We will verify your identity reasonably and respond within the time required by law (generally 30 days under GDPR; 45 days under CCPA/CPRA, extendable as permitted).

Authorized agents (CCPA/CPRA) must provide proof of authority. We will not discriminate against you for exercising privacy rights.

12. Children

Our Site and Services are directed to businesses and professionals. We do not knowingly collect personal information from children under 16 (or under 13 where that is the applicable US standard). If you believe we have collected such data, contact us for deletion.

13. US state privacy (CCPA/CPRA & similar)

If you are a California resident (and for analogous US state laws where applicable):

Categories collected (last 12 months)

Identifiers; commercial information; internet/electronic activity; professional information; and inferences drawn from the above-for the purposes in §4.

Sale / sharing

We do not sell personal information for monetary consideration. We may “share” personal information for cross-context behavioral advertising if we run advertising pixels-only with consent where required. You may opt out via our cookie banner controls and by emailing privacy@sanidhyamailabs.com with “Do Not Sell or Share.”

We do not use or disclose sensitive personal information for purposes that require a separate CPRA right-to-limit notice beyond what is necessary to provide Services you request.

Shine the Light

California residents may request certain information about disclosure to third parties for their direct marketing; email privacy@sanidhyamailabs.com.

14. Canada, UK/EU, Australia notes

  • Canada (PIPEDA): We collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, with consent where required (express or implied as appropriate for B2B).
  • UK/EU: See legal bases (§5), transfers (§8), and rights (§11). EU users may contact their local DPA; UK users may contact the ICO.
  • Australia (APPs): We manage personal information in line with the APPs, including notice, purpose limitation, and cross-border disclosure safeguards. Complaints may be escalated to the OAIC if unresolved.

Middle East clients should review any additional notices in their SOW for local localization requirements (e.g., DIFC/ADGM/KSA PDPL where applicable).

The Site may link to third-party sites, app stores, or portfolio products (including Counterly). Their privacy practices are governed by their own policies.

16. Changes

We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted on the Site or communicated by email where appropriate. Continued use after the effective date constitutes acknowledgment of the updated Policy.

17. Contact & complaints

Privacy requests & DPO/privacy lead: privacy@sanidhyamailabs.com Legal: legal@sanidhyamailabs.com Postal: Sanidhyam AI Labs, Ahmedabad

If you have an unresolved concern, you may contact your local data protection authority (EEA), the ICO (UK), OPC (Canada), OAIC (Australia), or other applicable regulator.

*This Policy is a compliance-oriented draft for Sanidhyam AI Labs. Have qualified privacy counsel review before publishing, especially for DPIAs, DPA templates, and advertising stack configuration.*

Formal notices: legal@sanidhyamailabs.com · Privacy: privacy@sanidhyamailabs.com

Book a scoping call