Privacy Policy

Effective Date / Date Last Modified:

This Privacy Policy explains how Vamrah LLC (“Vamrah,” “we,” “us,” or “our”) collects, uses, shares, and safeguards information about you when you use our products and services, visit our websites, attend our events, or otherwise interact with us (collectively, the “Services”). Vamrah provides AI-powered automation solutions, including matchRFX, matchHDX, and matchFDX. Our principal place of business is

100 S. Bedford Rd
Suite 340, Mt. Kisco, NY 10549
.
You may contact us at info@vamrah.ai.

If this Policy does not reflect your preferences or you do not agree with it, you should not access or use the Services. Where we provide the Services under contract with an organization (for example, your employer), that organization controls the information processed within the Services. Please review the section titled Notice to End Users for details.

We may update this Policy from time to time. We will post changes on our website and revise the Effective Date above. Your continued use of the Services after we publish changes means you accept the updated Policy.

What this Policy covers

This Policy covers information we collect about you when you interact with Vamrah, including through our websites and applications, in-product experiences, customer support, sales and marketing interactions, and events. It also describes choices available to you regarding our use of information and how you may exercise your rights.

Our role: controller vs. processor

When you use our public websites, receive marketing or sales communications, sign contracts, or open support tickets directly with Vamrah, Vamrah acts as a data controller for that information. When your organization licenses and deploys our products, Vamrah generally acts as a data processor (or service provider), processing personal information on behalf of your organization under your End User License Agreement (EULA), including any Data Processing Terms included or incorporated by reference therein. In those instances, your organization's privacy notice governs the processing inside the Services, and your organization decides what information to submit, store, or integrate.

Information we collect

We collect information about you in three primary ways: information you provide, information collected automatically when you use the Services, and information we receive from other sources.

You provide information when you create or modify an account; set preferences; enter content into the Services; communicate with us (including via support channels); register for or attend events; download white papers or demos; or transact with us. This information typically includes contact details, account credentials, organizational role or title, and content you choose to submit (for example, files uploaded to facilitate an implementation or support request). If you purchase paid Services, billing details are collected and processed by PCI-compliant payment service providers acting on our behalf.

When you use the Services, we collect information automatically, such as device and connection data, IP address, operating system and browser information, referring and exit pages, crash data, and in-Service activity (for example, features used or access time). We also use cookies and similar technologies to provide functionality, maintain your session, remember preferences, enhance performance, and understand usage patterns. Additional details about cookies and controls are provided in our Cookie & Tracking Notice.

We also receive information from other sources. For example, if you authenticate using a single sign-on provider or integrate a third-party service, we obtain information consistent with your settings with that provider. We may also receive business contact details from partners, resellers, and event organizers, or information that is publicly available about your company and role.

Deployments: Vamrah-hosted cloud and customer-hosted/on-premises

Vamrah primarily operates on Microsoft Azure with enterprise-grade security controls. In a Vamrah-hosted deployment, we process operational telemetry to secure, monitor, and improve the Services, and we maintain logs for security, compliance, and support.

In customer-hosted or on-premises deployments, Vamrah does not access your content unless you or your administrator expressly authorize access for support or professional services, or if access is strictly necessary to provide the contracted Services. In those scenarios, any telemetry is limited and configurable by your organization, and Vamrah acts according to your EULA (including its Data Processing Terms) and your documented instructions.

How we use information

We use information to provide, operate, secure, support, and improve the Services; to authenticate users; to process transactions; to personalize experiences; to communicate with you about product updates, releases, and security notices; to deliver onboarding and customer success guidance; to conduct research and development; to detect, investigate, and prevent fraud, abuse, and security incidents; to comply with law; and to enforce agreements and protect our rights.

AI/ML features and automated inferences

Vamrah provides AI-assisted features for content processing and workflow automation. Our features may use (a) models we host, (b) third-party AI services accessed via API, and (c) customer-specific models that we fine-tune using customer-provided data at the customer's direction.

Use of Customer Content. We do not use Customer Content to train generalized or multi-tenant models. Where we rely on third-party AI services, we instruct those providers not to use Customer Content for model training and we require appropriate confidentiality and security safeguards. For any customer-specific fine-tuning, the resulting models and artifacts are dedicated to your organization and are not shared across customers or used to train our base models.

Automated inferences and human oversight. Some features generate automated inferences (e.g., classifications, summaries, or suggestions) to assist users. These features are not designed to make decisions that produce legal or similarly significant effects about an individual, and users remain responsible for reviewing and acting on outputs.

Controls. We maintain logical segregation between base models and any customer-specific fine-tuning extensions.

How we share information

We are not in the business of selling personal information. We share information in the following contexts: with our service providers (subprocessors) who support hosting, storage, security, analytics, communications, payments, and customer support; with professional advisors (legal, audit, and compliance); with our corporate affiliates and with a successor organization in connection with a merger, acquisition, or similar transaction; and with government authorities or third parties when required by law, court order, or to protect rights, safety, or the integrity of the Services. We may share aggregated or de-identified insights that cannot reasonably be used to identify you.

We maintain a current list of subprocessors and will provide notice of material changes consistent with our contractual commitments.

If you link or integrate third-party services (for example, identity providers, document repositories, or collaboration tools), you direct those providers to receive and process information as described in their privacy policies and your administrator's configuration. Our websites and Services may include links or plugins to third-party sites and social networks; your interactions with those features are governed by the privacy notices of the companies providing them.

Managed accounts and Notice to End Users

If the Services are made available to you through an organization (for example, your employer), that organization administers your account and determines its settings and controls. Administrators may manage user provisioning; reset passwords; install or disable integrations; access logs and certain content submitted in shared workspaces; and otherwise control your use of the Services consistent with your organization's policies. Privacy questions about data inside your organization's tenant should be directed to your administrator.

How we store and secure information

We use data hosting service providers in the United States and, where applicable, other regions selected by customers. We implement administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, role-based access controls, network segmentation, vulnerability management, and logging and monitoring. No system is impenetrable, and the security of information transmitted over the Internet can never be guaranteed; please use strong passwords, protect your credentials, and notify us promptly of any suspected unauthorized access at security@vamrah.ai.

Vamrah's security program may include third-party attestations or certifications.

How long we keep information

We retain information for as long as needed to provide the Services, to comply with legal obligations, to resolve disputes, to enforce agreements, and for other legitimate and lawful business purposes. Retention periods vary by data category and context. For example, we may retain hosted application logs for a defined period for security and troubleshooting; billing and contract records for periods required by law; and marketing records for a reasonable period following your last interaction, unless you opt out sooner. We may also anonymize or aggregate information for longer-term analytics.

How to access and control your information; your rights

Depending on where you live, you may have rights to request access to information we hold about you, to request corrections, to request deletion, to object or restrict certain processing, to withdraw consent where processing is based on consent, or to request portability of information in a structured, commonly used format. You can submit requests to privacy@vamrah.ai. We will verify your identity before fulfilling a request and, where we process information on behalf of your organization, we will refer your request to that organization for handling.

You may control certain communications from us, including marketing emails, by using unsubscribe links in messages or by contacting us at privacy@vamrah.ai. We will continue to send essential transactional or security communications. Browser “Do Not Track” signals are not yet standardized, and our Services do not currently respond to them; you can use the cookie controls described in our Cookie & Tracking Notice.

California privacy notice (CCPA/CPRA)

If you are a California resident, you have rights to know, access, correct, delete, and to opt out of certain “sales” or “sharing” of personal information as defined by California law. Vamrah does not sell personal information in the ordinary sense of selling data for money. To submit a request, email privacy@vamrah.ai with the subject line “CCPA Request.” You may designate an authorized agent; we will require proof of authorization and identity. Vamrah will not discriminate against you for exercising your rights.

Nevada privacy notice

We do not sell personal information as defined under Nevada law. Nevada residents may submit a request directing us not to sell certain information at privacy@vamrah.ai with the subject line “Nevada Opt-Out.”

EEA/UK privacy notice (GDPR/UK GDPR)

Where the GDPR/UK GDPR applies, Vamrah processes personal data based on one or more of the following legal bases: contractual necessity to provide the Services you or your organization requested; legitimate interests (such as securing and improving the Services, balanced against your rights and freedoms); compliance with legal obligations; and your consent, where required (for example, certain marketing or non-essential cookies, which you may withdraw at any time).

You have the right to lodge a complaint with your local supervisory authority.

Product-specific notes: healthcare and financial data

For matchHDX engagements that include handling protected health information, we do so under a signed Business Associate Agreement and apply safeguards consistent with HIPAA and applicable state laws.

For matchFDX engagements that include handling nonpublic personal information subject to GLBA or similar financial privacy laws, we implement safeguards appropriate to those frameworks and process data according to your organization's documented instructions and your EULA (including its Data Processing Terms).

Children's privacy

The Services are not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact privacy@vamrah.ai so we may take appropriate steps to delete it.

Changes to this Policy

We may revise this Policy from time to time. We will post the updated Policy with a new Effective Date and, where required by law, provide advance notice or request your consent to material changes. If you disagree with any changes, you should stop using the Services and, if applicable, work with your administrator to deactivate your account.

Contact us

If you have questions about this Policy or our privacy practices, please contact:

Email: privacy@vamrah.ai
Security incidents: security@vamrah.ai