Privacy Policy
Effective date: September 19, 2026
This Privacy Policy explains how [Company Legal Name] (“Vaam”, “we”, “us”) collects, uses, and safeguards information in connection with the Vaam AI receptionist platform (the “Service”). It applies to our website, dashboard, embeddable chat widget, and messaging integrations.
1. Our two roles
As a controller, we determine how we handle information about the businesses that sign up for Vaam (“Customers”) — for example account and billing details.
As a processor, we handle information about a Customer’s own end-users (“End Users”) — for example the people who chat with a Customer’s receptionist — strictly on that Customer’s behalf and instructions. For End-User data, the Customer is the controller and their own privacy policy governs; this policy describes our processing on their behalf.
2. Information we collect
Customer account data
- Name, email, and password (stored only as a secure hash).
- Business profile you configure: business name, services, hours, policies, tone, and settings.
- Billing information, processed by our payment provider (we do not store full card details).
End-User conversation data (processed for the Customer)
- Messages exchanged with the receptionist across the web widget and connected channels — WhatsApp, Messenger, Instagram, Telegram, and voice calls.
- Booking details a person provides — such as name, email, phone, and appointment notes.
- Basic technical metadata (e.g. IP address, user agent, page URL) used for security and rate limiting.
Usage & technical data
- Log data, feature usage, token counts, and diagnostics used to operate and improve the Service.
3. How we use information
- To provide the Service — generate receptionist replies, check availability, and create bookings.
- To send transactional messages such as booking confirmations and notifications.
- To secure the Service — prevent abuse, apply rate limits, and detect fraud.
- To operate and improve the Service, including support and analytics.
- To comply with legal obligations.
We do not sell personal information, and we do not use End-User conversation content to train our own models.
4. AI processing
Receptionist replies are generated using third-party large-language-model providers. Message content needed to produce a reply is sent to the selected provider under agreements that restrict use of the data to providing the service. A reply is generated by automated means; Customers are responsible for the configuration of their receptionist and, where appropriate, human oversight.
5. Subprocessors
We rely on the following service providers to run Vaam. Each processes data only as needed to provide their service to us, and channel or AI providers are engaged only where a Customer has enabled that channel or model.
| Provider | Purpose |
|---|---|
| MongoDB Atlas | Database hosting |
| Vercel | Application hosting & delivery |
| Google (Gemini, Calendar) | AI model inference & optional calendar sync |
| OpenAI | AI model inference |
| Anthropic | AI model inference |
| Retell | Voice calls (when the voice add-on is enabled) |
| Meta Platforms (WhatsApp, Messenger, Instagram) | Messaging channels (when connected) |
| Telegram | Messaging channel (when connected) |
| Resend | Transactional email delivery |
| Stripe / Paddle | Payments & billing |
When a business connects its own account with another provider (for example Twilio for SMS, Slack, HubSpot, Shopify, WooCommerce or its own Meta app), data needed for that feature is sent to that provider under the business's own agreement with it; those providers act for the business, not for Vaam.
A current list is available on request. We aim to give notice of material changes to our subprocessors. Business customers can review our Data Processing Addendum.
6. Data retention
We retain Customer account data for as long as the account is active, and End-User conversation and booking data for as long as needed to provide the Service to the Customer, unless a shorter or longer period is required by law or requested by the Customer. On account closure we delete or anonymize data within a commercially reasonable period.
7. Security
We use industry-standard measures to protect information, including encryption in transit (TLS) and encryption at rest for sensitive secrets such as connected-account tokens and API keys. No method of transmission or storage is completely secure, but we work to protect your information and continually improve our safeguards.
8. International transfers
We and our subprocessors may process information in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Customers can exercise many of these directly in the dashboard. For requests about End-User data, please contact the relevant business (Customer); we will assist them as their processor. To make a request to us, use the contact details below.
10. Cookies
We use strictly necessary cookies to keep you signed in and to secure the Service. We do not use advertising cookies.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
12. Changes
We may update this policy from time to time. Material changes will be posted here with a revised effective date.
13. Contact
Questions or requests: privacy@vaam.app
[Company Legal Name], [Registered Address], [Country].