Privacy Policy
Effective Date / Date Last Modified:
This Privacy Policy explains how Vamrah LLC (“Vamrah,” “we,” “us,” or “our”) collects, uses, shares, and safeguards information about you when you use our products and services, visit our websites, attend our events, or otherwise interact with us (collectively, the “Services”). Vamrah provides AI-powered automation solutions, including matchRFX, matchHDX, and matchFDX. Our principal place of business is
100 S. Bedford RdSuite 340, Mt. Kisco, NY 10549.
You may contact us at info@vamrah.ai.
If this Policy does not reflect your preferences or you do not agree with it, you should not access or use the Services. Where we provide the Services under contract with an organization (for example, your employer), that organization controls the information processed within the Services. Please review the section titled Notice to End Users for details.
We may update this Policy from time to time. We will post changes on our website and revise the Effective Date above. Your continued use of the Services after we publish changes means you accept the updated Policy.
What this Policy covers
This Policy covers information we collect about you when you interact with Vamrah, including through our websites and applications, in-product experiences, customer support, sales and marketing interactions, and events. It also describes choices available to you regarding our use of information and how you may exercise your rights.
Our role: controller vs. processor
When you use our public websites, receive marketing or sales communications, sign contracts, or open support tickets directly with Vamrah, Vamrah acts as a data controller for that information. When your organization licenses and deploys our products, Vamrah generally acts as a data processor (or service provider), processing personal information on behalf of your organization under your End User License Agreement (EULA), including any Data Processing Terms included or incorporated by reference therein. In those instances, your organization's privacy notice governs the processing inside the Services, and your organization decides what information to submit, store, or integrate.
Information we collect
We collect information about you in three primary ways: information you provide, information collected automatically when you use the Services, and information we receive from other sources.
You provide information when you create or modify an account; set preferences; enter content into the Services; communicate with us (including via support channels); register for or attend events; download white papers or demos; or transact with us. This information typically includes contact details, account credentials, organizational role or title, and content you choose to submit (for example, files uploaded to facilitate an implementation or support request). If you purchase paid Services, billing details are collected and processed by PCI-compliant payment service providers acting on our behalf.
When you use the Services, we collect information automatically, such as device and connection data, IP address, operating system and browser information, referring and exit pages, crash data, and in-Service activity (for example, features used or access time). We also use cookies and similar technologies to provide functionality, maintain your session, remember preferences, enhance performance, and understand usage patterns. Additional details about cookies and controls are provided in our Cookie & Tracking Notice.
We also receive information from other sources. For example, if you authenticate using a single sign-on provider or integrate a third-party service, we obtain information consistent with your settings with that provider. We may also receive business contact details from partners, resellers, and event organizers, or information that is publicly available about your company and role.
Deployments: Vamrah-hosted cloud and customer-hosted/on-premises
Vamrah primarily operates on Microsoft Azure with enterprise-grade security controls. In a Vamrah-hosted deployment, we process operational telemetry to secure, monitor, and improve the Services, and we maintain logs for security, compliance, and support.
In customer-hosted or on-premises deployments, Vamrah does not access your content unless you or your administrator expressly authorize access for support or professional services, or if access is strictly necessary to provide the contracted Services. In those scenarios, any telemetry is limited and configurable by your organization, and Vamrah acts according to your EULA (including its Data Processing Terms) and your documented instructions.
How we use information
We use information to provide, operate, secure, support, and improve the Services; to authenticate users; to process transactions; to personalize experiences; to communicate with you about product updates, releases, and security notices; to deliver onboarding and customer success guidance; to conduct research and development; to detect, investigate, and prevent fraud, abuse, and security incidents; to comply with law; and to enforce agreements and protect our rights.
AI/ML features and automated inferences
Vamrah provides AI-assisted features for content processing and workflow automation. Our features may use (a) models we host, (b) third-party AI services accessed via API, and (c) customer-specific models that we fine-tune using customer-provided data at the customer's direction.
Use of Customer Content. We do not use Customer Content to train generalized or multi-tenant models. Where we rely on third-party AI services, we instruct those providers not to use Customer Content for model training and we require appropriate confidentiality and security safeguards. For any customer-specific fine-tuning, the resulting models and artifacts are dedicated to your organization and are not shared across customers or used to train our base models.
Automated inferences and human oversight. Some features generate automated inferences (e.g., classifications, summaries, or suggestions) to assist users. These features are not designed to make decisions that produce legal or similarly significant effects about an individual, and users remain responsible for reviewing and acting on outputs.
Controls. We maintain logical segregation between base models and any customer-specific fine-tuning extensions.
Managed accounts and Notice to End Users
If the Services are made available to you through an organization (for example, your employer), that organization administers your account and determines its settings and controls. Administrators may manage user provisioning; reset passwords; install or disable integrations; access logs and certain content submitted in shared workspaces; and otherwise control your use of the Services consistent with your organization's policies. Privacy questions about data inside your organization's tenant should be directed to your administrator.
How we store and secure information
We use data hosting service providers in the United States and, where applicable, other regions selected by customers. We implement administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, role-based access controls, network segmentation, vulnerability management, and logging and monitoring. No system is impenetrable, and the security of information transmitted over the Internet can never be guaranteed; please use strong passwords, protect your credentials, and notify us promptly of any suspected unauthorized access at security@vamrah.ai.
Vamrah's security program may include third-party attestations or certifications.
How long we keep information
We retain information for as long as needed to provide the Services, to comply with legal obligations, to resolve disputes, to enforce agreements, and for other legitimate and lawful business purposes. Retention periods vary by data category and context. For example, we may retain hosted application logs for a defined period for security and troubleshooting; billing and contract records for periods required by law; and marketing records for a reasonable period following your last interaction, unless you opt out sooner. We may also anonymize or aggregate information for longer-term analytics.
How to access and control your information; your rights
Depending on where you live, you may have rights to request access to information we hold about you, to request corrections, to request deletion, to object or restrict certain processing, to withdraw consent where processing is based on consent, or to request portability of information in a structured, commonly used format. You can submit requests to privacy@vamrah.ai. We will verify your identity before fulfilling a request and, where we process information on behalf of your organization, we will refer your request to that organization for handling.
You may control certain communications from us, including marketing emails, by using unsubscribe links in messages or by contacting us at privacy@vamrah.ai. We will continue to send essential transactional or security communications. Browser “Do Not Track” signals are not yet standardized, and our Services do not currently respond to them; you can use the cookie controls described in our Cookie & Tracking Notice.
California privacy notice (CCPA/CPRA)
If you are a California resident, you have rights to know, access, correct, delete, and to opt out of certain “sales” or “sharing” of personal information as defined by California law. Vamrah does not sell personal information in the ordinary sense of selling data for money. To submit a request, email privacy@vamrah.ai with the subject line “CCPA Request.” You may designate an authorized agent; we will require proof of authorization and identity. Vamrah will not discriminate against you for exercising your rights.
Nevada privacy notice
We do not sell personal information as defined under Nevada law. Nevada residents may submit a request directing us not to sell certain information at privacy@vamrah.ai with the subject line “Nevada Opt-Out.”
EEA/UK privacy notice (GDPR/UK GDPR)
Where the GDPR/UK GDPR applies, Vamrah processes personal data based on one or more of the following legal bases: contractual necessity to provide the Services you or your organization requested; legitimate interests (such as securing and improving the Services, balanced against your rights and freedoms); compliance with legal obligations; and your consent, where required (for example, certain marketing or non-essential cookies, which you may withdraw at any time).
You have the right to lodge a complaint with your local supervisory authority.
Product-specific notes: healthcare and financial data
For matchHDX engagements that include handling protected health information, we do so under a signed Business Associate Agreement and apply safeguards consistent with HIPAA and applicable state laws.
For matchFDX engagements that include handling nonpublic personal information subject to GLBA or similar financial privacy laws, we implement safeguards appropriate to those frameworks and process data according to your organization's documented instructions and your EULA (including its Data Processing Terms).
Children's privacy
The Services are not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact privacy@vamrah.ai so we may take appropriate steps to delete it.
Changes to this Policy
We may revise this Policy from time to time. We will post the updated Policy with a new Effective Date and, where required by law, provide advance notice or request your consent to material changes. If you disagree with any changes, you should stop using the Services and, if applicable, work with your administrator to deactivate your account.
Contact us
If you have questions about this Policy or our privacy practices, please contact:
Email: privacy@vamrah.ai
Security incidents: security@vamrah.ai