Sanidhyam AI Labs Last updated: July 30, 2026 Effective date: July 30, 2026
Controller / Business: Sanidhyam AI Labs, Ahmedabad (“Sanidhyam,” “we,” “us,” or “our”), operating as Sanidhyam AI Labs. Site: https://www.sanidhyamailabs.com Privacy contact: privacy@sanidhyamailabs.com
This Policy explains how we collect, use, disclose, and protect personal information when you visit our Site, schedule a discovery call, or engage our Custom AI consulting and engineering services.
We design this Policy to support transparency under GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and the Australian Privacy Principles (APPs), among other frameworks applicable to visitors and clients in the USA, Canada, UK, EU, Australia, and the Middle East.
Our Cookie Policy describes cookies and similar technologies in detail.
Table of contents
- Who we are & scope
- Information we collect
- Sources of information
- How we use information
- Legal bases (GDPR / UK GDPR)
- AI interaction data
- When we share information
- International transfers
- Retention
- Security
- Your rights
- Children
- US state privacy (CCPA/CPRA & similar)
- Canada, UK/EU, Australia notes
- Third-party links & products
- Changes
- Contact & complaints
1. Who we are & scope
Sanidhyam is a B2B production AI engineering agency and SaaS product builder. This Policy covers:
- Marketing Site and content
- Contact forms, newsletters, and scheduling (e.g., Calendly)
- CRM and sales pipeline records
- SaaS Product accounts and telemetry
- Project delivery systems used to perform SOWs
Client-as-controller engagements: When we process personal data on your behalf inside a client project or tenant (e.g., your end-user chat logs inside a system we build/host for you), you are typically the controller / business and we act as processor / service provider. Those processing details are governed by your SOW and a Data Processing Agreement (DPA) on request-not solely by this Policy.
Counterly POS and other portfolio products may publish separate product privacy notices. Where you use those products, the product notice applies to product data.
2. Information we collect
2.1 Direct / identity & commercial data
- Name, email, phone, company, role, country/region
- Inquiry content and attachments you submit
- Discovery-call scheduling details and meeting metadata
- Contract, SOW, and billing contact metadata
- Payment-related information processed by our payment provider (we do not store full card PAN)
- Account credentials (stored hashed/salted where we operate authentication)
2.2 Technical & usage data
- IP address, approximate location (city/region level)
- Device identifiers, browser type/version, OS
- Pages viewed, referring/exit URLs, timestamps
- Diagnostics, crash reports, performance metrics
2.3 AI interaction data
Depending on the product or engagement:
- Prompts, queries, uploaded context snippets, and tool-call traces you submit to AI features
- Retrieval metadata (e.g., document IDs, similarity scores)-not a substitute for your source-of-truth documents
- System telemetry for latency, token usage, error rates, and safety filters
- Evaluation labels if you participate in quality review
See §6 for training and retention defaults.
2.4 Sensitive data
We do not seek sensitive personal data via marketing forms. Please do not submit special-category data (health, biometric templates, precise geolocation, government IDs, etc.) unless an SOW and DPA expressly cover that processing with appropriate safeguards.
3. Sources of information
- Directly from you (forms, email, calls, product use)
- Automatically via cookies, SDKs, and logs (see Cookie Policy)
- From scheduling, CRM, and analytics tools you interact with on our Site
- From publicly available professional sources (e.g., company website, LinkedIn) when relevant to B2B outreach, where permitted
- From your organization if an admin invites you to a SaaS tenant
4. How we use information
We use personal information to:
- Respond to inquiries and schedule discovery calls
- Provide, operate, secure, and support SaaS Products and Custom Services
- Process transactions and send invoices/receipts
- Personalize non-essential Site experiences where consented
- Analyze Site and product performance; debug incidents
- Send service/transactional messages
- Send marketing communications where permitted (you may opt out anytime)
- Enforce Terms, prevent abuse/fraud, and protect rights
- Comply with law, respond to lawful requests, and establish/defend legal claims
- Conduct limited B2B prospecting consistent with applicable marketing laws
5. Legal bases (GDPR / UK GDPR)
Where GDPR/UK GDPR applies, we rely on:
| Purpose | Typical basis |
|---|---|
| Deliver contracted SaaS/Custom Services; manage accounts | Contract (Art. 6(1)(b)) |
| Site security, fraud prevention, B2B relationship management, product improvement via de-identified telemetry | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| Non-essential cookies, certain marketing emails, optional demos | Consent (Art. 6(1)(a)) - withdraw anytime |
| Tax, accounting, responding to lawful process | Legal obligation (Art. 6(1)(c)) |
You may object to legitimate-interest processing; see §11.
6. AI interaction data
6.1 Purpose
We process AI interaction data to provide the feature you requested, maintain safety/abuse controls, debug failures, measure quality, and meet contractual obligations.
6.2 Training
Default: We do not use your confidential prompts or Customer Content to train third-party foundation models, unless (a) you opt in in writing, or (b) a provider’s enterprise configuration you select permits it. Providers may still process prompts to return completions under their terms.
We may use aggregated/de-identified metrics to improve reliability.
6.3 Client projects
For Custom Services, treatment of production data (including retention and subprocessors) is defined in the SOW/DPA. Staging datasets should be minimized and scrubbed where feasible.
7. When we share information
We do not sell personal information for money. We may disclose information to:
7.1 Service providers / subprocessors
Categories include:
| Category | Examples (illustrative) |
|---|---|
| Cloud infrastructure | AWS, Google Cloud, Azure, Vercel |
| AI model & vector APIs | OpenAI, Anthropic, Google, Pinecone, and similar |
| CRM & email | HubSpot or equivalent |
| Scheduling | Calendly or equivalent |
| Analytics | Google Analytics, Mixpanel, Plausible, or similar |
| Payments | Stripe |
| Collaboration | Email/workspace tools used by our team |
| Professional advisors | Lawyers, accountants, insurers (under confidentiality) |
We require processors to protect data and use it only on our instructions (or your instructions when we are processor).
7.2 Corporate events
In connection with merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality.
7.3 Legal & safety
Where required by law or necessary to protect rights, safety, or security.
7.4 With your direction
Integrations you enable, or disclosures you request.
Sub-processor updates: For processor engagements, we will provide a mechanism to receive notice of material sub-processor changes as described in the DPA (email list or portal).
8. International transfers
We may process and store information in the United States and other countries where we or our processors operate. Those countries may have different data-protection laws than your home jurisdiction.
For transfers of EEA/UK personal data to countries without an adequacy decision, we implement appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, plus supplementary measures where warranted. Copies of relevant clauses may be requested at privacy@sanidhyamailabs.com (commercially sensitive annexes may be redacted).
9. Retention
We retain personal information only as long as needed for the purposes above, including:
| Data type | Typical retention |
|---|---|
| Marketing inquiries / lead records | Up to 24 months after last meaningful contact, unless a relationship continues or you request deletion earlier |
| Contract/billing records | 7 years (or longer if required by tax/accounting law) |
| SaaS account data | Life of account + up to 90 days after closure for backup wind-down (unless DPA requires shorter/longer) |
| Security logs | Generally 90-365 days |
| AI debug logs (marketing/demo environments) | Short-lived; typically ≤ 30 days unless needed for an active incident |
| Client project production logs | Per SOW/DPA |
We may retain limited information as required for legal claims, disputes, or compliance.
10. Security
We implement administrative, technical, and organizational measures appropriate to risk, including:
- Encryption in transit (TLS) and at rest (AES-256 or cloud-equivalent)
- Access controls, least privilege, and authentication for internal systems
- Logging and monitoring of production systems
- Vendor due diligence for material subprocessors
- Employee confidentiality obligations
No method of transmission or storage is 100% secure. You are responsible for safeguarding credentials and configuring your tenant integrations securely.
11. Your rights
Depending on your location, you may have rights to:
- Access / know what we hold
- Correct inaccurate data
- Delete / erase (subject to legal exceptions)
- Portability of data you provided
- Restrict or object to certain processing
- Withdraw consent where processing is consent-based
- Appeal a refusal (where required by US state law)
- Lodge a complaint with a supervisory authority
How to exercise: Email privacy@sanidhyamailabs.com with the subject “Privacy Request,” and tell us which right you seek. We will verify your identity reasonably and respond within the time required by law (generally 30 days under GDPR; 45 days under CCPA/CPRA, extendable as permitted).
Authorized agents (CCPA/CPRA) must provide proof of authority. We will not discriminate against you for exercising privacy rights.
12. Children
Our Site and Services are directed to businesses and professionals. We do not knowingly collect personal information from children under 16 (or under 13 where that is the applicable US standard). If you believe we have collected such data, contact us for deletion.
13. US state privacy (CCPA/CPRA & similar)
If you are a California resident (and for analogous US state laws where applicable):
Categories collected (last 12 months)
Identifiers; commercial information; internet/electronic activity; professional information; and inferences drawn from the above-for the purposes in §4.
Sale / sharing
We do not sell personal information for monetary consideration. We may “share” personal information for cross-context behavioral advertising if we run advertising pixels-only with consent where required. You may opt out via our cookie banner controls and by emailing privacy@sanidhyamailabs.com with “Do Not Sell or Share.”
We do not use or disclose sensitive personal information for purposes that require a separate CPRA right-to-limit notice beyond what is necessary to provide Services you request.
Shine the Light
California residents may request certain information about disclosure to third parties for their direct marketing; email privacy@sanidhyamailabs.com.
14. Canada, UK/EU, Australia notes
- Canada (PIPEDA): We collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, with consent where required (express or implied as appropriate for B2B).
- UK/EU: See legal bases (§5), transfers (§8), and rights (§11). EU users may contact their local DPA; UK users may contact the ICO.
- Australia (APPs): We manage personal information in line with the APPs, including notice, purpose limitation, and cross-border disclosure safeguards. Complaints may be escalated to the OAIC if unresolved.
Middle East clients should review any additional notices in their SOW for local localization requirements (e.g., DIFC/ADGM/KSA PDPL where applicable).
15. Third-party links & products
The Site may link to third-party sites, app stores, or portfolio products (including Counterly). Their privacy practices are governed by their own policies.
16. Changes
We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted on the Site or communicated by email where appropriate. Continued use after the effective date constitutes acknowledgment of the updated Policy.
17. Contact & complaints
Privacy requests & DPO/privacy lead: privacy@sanidhyamailabs.com Legal: legal@sanidhyamailabs.com Postal: Sanidhyam AI Labs, Ahmedabad
If you have an unresolved concern, you may contact your local data protection authority (EEA), the ICO (UK), OPC (Canada), OAIC (Australia), or other applicable regulator.
*This Policy is a compliance-oriented draft for Sanidhyam AI Labs. Have qualified privacy counsel review before publishing, especially for DPIAs, DPA templates, and advertising stack configuration.*