1. Scope & Overview
Autometa, Inc. (“Autometa”, “we”, “us”, or “our”) builds precision SaaS products including Synkly (our real-time social watch-party and gaming platform) and Autometa CRM (our AI-native business management platform).
This Privacy Policy governs the collection, use, disclosure, and protection of personal data and customer information across our websites (including autometa.in and autometa.in), desktop and web applications, APIs, and associated services (collectively, the “Services”).
By accessing or using our Services, you acknowledge that you have read and understood the practices described herein. If you do not agree with our policies, please discontinue use of our Services immediately.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically during your use of the Services, and information provided by third-party integrations.
A. Information You Provide Directly
- Account Registration: Full name, email address, password hash, company name, job role, and billing address.
- Workspace & CRM Data: Leads, customer contacts, sales pipelines, custom records, communication logs, payroll records, and employee attendance logs entered into Autometa CRM.
- Synkly Social & Room Data: Room titles, shared video URLs, group text chat messages, live reactions, game sessions, and voice chat participation.
- Communications & Support: Inquiries sent via our contact forms, customer support tickets, feedback forms, and email correspondence.
- Billing & Payment: Payment card details, billing contacts, and VAT/tax IDs (processed securely by our payment processor, Stripe; we do not store raw card numbers).
B. Information Collected Automatically
- Device & Network Telemetry: IP address, browser type and version, operating system, device identifiers, and network connection latency.
- Product Usage & Performance: Feature interactions, error logs, session durations, real-time sync latency metrics, and API request volumes.
- Cookies & Local Storage: Essential session tokens, user preference flags (e.g. theme or timezone settings), and security verification nonces.
3. AI Features & Data Isolation Guarantee
Autometa CRM and Synkly incorporate AI capabilities (e.g., smart email drafting, lead scoring, pipeline summarization, and workflow triggers). When you interact with an AI-assisted feature:
- Data payloads sent to our AI processing pipeline are encrypted in transit and isolated to your specific organization tenant.
- We partner with enterprise LLM providers under strict B2B zero-data-retention (ZDR) agreements. Your inputs and generated outputs are neither logged for model training nor shared across accounts.
- All AI outputs are suggestions provided for human review and decision-making. You maintain full ownership and editorial control over all generated content.
4. How We Use Information & Legal Bases
Under the General Data Protection Regulation (GDPR) and applicable data privacy frameworks, we process personal data under the following legal bases:
- Performance of Contract: Provisioning user accounts, authenticating sessions, processing payments, syncing real-time rooms, executing workflow automations, and delivering customer support.
- Legitimate Interests: Monitoring service health, preventing fraudulent activity, optimizing database performance, hardening infrastructure security, and improving user experience.
- Compliance with Legal Obligations: Retaining financial transaction records for statutory accounting and responding to lawful governmental requests.
- Consent: Sending voluntary product update newsletters or marketing communications (which can be revoked at any time via the unsubscribe link).
6. International Data Transfers
Autometa operates infrastructure globally. If you access our Services from the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in countries outside your jurisdiction.
For such transfers, we rely on legally recognized transfer mechanisms including the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and verified adequacy decisions to ensure an equivalent standard of protection.
7. Data Retention & Account Deletion
We retain your personal data and CRM records only for as long as necessary to fulfill the purposes outlined in this policy or as required by law:
- Active Accounts: Your workspace and account data are retained continuously while your subscription remains active.
- Account Closure & Deletion: Upon workspace deletion or explicit customer request, active database records are permanently purged within 30 days. Encrypted database backups are cycled out and destroyed within 60 days.
- Financial Records: Invoicing and payment transaction logs are retained for statutory tax compliance periods (typically 7 years).
8. Your Rights & Privacy Choices
Depending on your location (including GDPR in Europe and CCPA/CPRA in California), you have significant rights regarding your personal data:
- Right of Access: Request a full copy of all personal information we maintain about you.
- Right to Rectification: Correct inaccurate, incomplete, or outdated personal information directly inside your account profile.
- Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your personal data and customer workspaces.
- Right to Data Portability: Export your leads, contacts, deals, and settings in structured JSON or CSV format at any time.
- Right to Object & Restrict Processing: Opt out of non-essential communications or restrict processing under certain conditions.
To exercise any of these rights, contact our Data Protection team at privacy@autometa.in. We respond to all verified requests within 30 days.
9. Security Measures & Encryption Standards
We employ defense-in-depth technical and organizational controls to protect customer records against unauthorized access, alteration, disclosure, or destruction:
- Encryption in Transit: TLS 1.3 enforced across all public endpoints and APIs with modern cipher suites and Strict Transport Security (HSTS).
- Encryption at Rest: All database stores, object storage, and backups are encrypted using AES-256 with managed key rotation.
- Access Governance: Granular Role-Based Access Control (RBAC), mandatory Multi-Factor Authentication (MFA) for internal staff, and detailed audit trails.
Detailed security documentation is available at our Security & Trust Center .
11. Children’s Privacy
Our Services are designed for business teams, professionals, and general audiences aged 13 and above (or 16 in certain European jurisdictions). We do not knowingly collect or solicit personal information from children under 13. If you believe a minor has registered an account without guardian consent, please contact us immediately so we can promptly delete the data.
12. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our products, legal standards, or operational practices. Material updates will be communicated via prominent in-app notification or email before changes take effect. Continued use of our Services after the effective date constitutes your agreement to the updated policy.
13. Contact Information & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy or our privacy practices, please contact our Data Protection Officer (DPO):
Data Protection Office
Autometa, Inc.
Attn: Data Privacy & Compliance
Email: privacy@autometa.in
General Legal: legal@autometa.in