Privacy Policy
Effective date: October 29, 2025
1. Data Controller
KarmaCX ("we," "us," or "our") is the data controller for personal data collected through our website karma-bot.com and our AI-powered customer support automation services.
2. Information We Collect
2.1 Personal Information You Provide
- Contact information: name, email address, company name, phone number
- Account information: login credentials, user preferences, security settings
- Communication data: messages sent through contact forms, support tickets, emails
- Demo interactions: inputs provided during product demonstrations
- Billing information: company details for invoicing (we do not store payment card data)
- Customer support data: conversation transcripts, resolution data, customer interaction history
- Protected Health Information (PHI): if applicable, handled under separate HIPAA Business Associate Agreement
2.2 Information Collected Automatically
- Usage data: pages visited, time spent, click patterns, referral sources, feature usage metrics
- Device information: IP address (anonymized for analytics), browser type, device type, operating system
- Cookies and tracking technologies (see Section 15: Cookie Policy)
- Log files: error logs, access logs, system performance data, security event logs
- Unique identifiers: session IDs, device identifiers (for California residents, see Section 9)
2.3 Third-Party Sources
We may receive information from public databases for business contact verification purposes and from integrated third-party services (CRM systems, helpdesk platforms) with your authorization.
2.4 AI-Generated Data
Our AI systems process customer support conversations and may generate insights, categorizations, and response suggestions. This AI-generated data is specific to your organization and is not shared across customers. AI processing is performed by industry-standard providers including OpenAI and Anthropic under data processing agreements that prohibit training on your data.
3. How We Use Your Information
We process your personal data for the following purposes:
- Providing and maintaining our AI customer support services
- Processing payments and billing (monthly billing based on resolution volume)
- Communicating with you about our services
- Providing customer support
- Improving our services through analytics
- Ensuring security and preventing fraud
- Complying with legal obligations
- Marketing communications (with your consent)
4. Legal Basis for Processing (GDPR)
We process your personal data based on:
- Contract performance: To provide services you have requested
- Legitimate interests: For analytics, security, and business operations
- Consent: For marketing communications and non-essential cookies
- Legal compliance: To comply with applicable laws and regulations
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your data with:
5.1 Service Providers (Subprocessors)
We engage the following categories of service providers under strict data processing agreements:
- AI service providers: OpenAI, Anthropic (for AI processing with contractual prohibitions on training)
- Cloud hosting providers: Vercel, AWS (data encryption in transit and at rest)
- Analytics services: Google Analytics, Vercel Analytics (IP anonymization enabled)
- Email communication services (with encryption in transit)
- Payment processing services (for billing purposes only, PCI-DSS compliant)
A complete and current list of subprocessors is available upon request. We provide 30 days' notice before adding new subprocessors, and you may object to such changes.
5.2 Legal Requirements
We may disclose your information when required by law, court order, legal process, or to protect our rights, property, and safety. We will notify you of legal demands for your data unless prohibited by law or court order.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred. We will provide notice and ensure the receiving party honors this Privacy Policy.
6. Data Retention
We retain your personal data for the following periods:
- Account data: Duration of service relationship plus 3 years
- Billing records: 7 years for tax and accounting purposes
- Support communications: 5 years for quality assurance
- Website analytics: 26 months (Google Analytics default)
- Marketing data: Until consent is withdrawn or 3 years of inactivity
7. Data Security
We implement comprehensive technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security program includes:
7.1 Technical Security Measures
- Encryption: TLS 1.3 for data in transit, AES-256 encryption for data at rest
- Access controls: Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), principle of least privilege
- Network security: Firewalls, intrusion detection/prevention systems (IDS/IPS), DDoS protection
- Application security: Secure coding practices, regular vulnerability assessments, penetration testing
- Data isolation: Customer data is logically isolated and cannot be accessed by other customers
- Security monitoring: Security Information and Event Management (SIEM), continuous monitoring, automated alerts
7.2 Organizational Security Measures
- SOC 2 Type II certification: Annual third-party security audits against AICPA Trust Services Criteria
- Staff training: Mandatory security and privacy training for all personnel
- Background checks: Conducted on all personnel with access to customer data
- Vendor management: Due diligence and contractual security requirements for all subprocessors
- Incident response: Documented procedures for security incident detection, response, and notification
- Business continuity: Disaster recovery and backup procedures tested regularly
7.3 Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Our notification will include the nature of the breach, affected data categories, likely consequences, and remedial measures taken.
8. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), UK, or Switzerland, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data and information about how it is processed
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data
- Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten") under certain circumstances
- Right to Restriction (Article 18): Request limitation of processing in specific situations
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format (JSON or CSV)
- Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent for consent-based processing at any time
- Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority
- Rights Related to Automated Decision-Making (Article 22): Not be subject to decisions based solely on automated processing that produce legal effects
To exercise these rights, contact us at support@karma-bot.comwith "GDPR Rights Request" in the subject line. We will respond within 30 days (extendable by 2 months for complex requests). We may require identity verification before processing your request to protect your data security.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
9.1 Your California Rights
- Right to Know: Request disclosure of personal information collected, used, disclosed, or sold in the past 12 months
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt-out of the sale or sharing of personal information (we do not sell personal information)
- Right to Limit: Limit use and disclosure of sensitive personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights
9.2 Categories of Personal Information
We collect and process the following categories of personal information:
- Identifiers (name, email, IP address)
- Commercial information (purchase history, billing records)
- Internet/network activity (browsing history, interactions with our service)
- Professional information (company name, job title)
- Inferences (preferences, characteristics derived from your activity)
9.3 Exercising California Rights
To exercise your California privacy rights, contact us at support@karma-bot.comwith "California Privacy Request" in the subject line. We will verify your identity and respond within 45 days. You may designate an authorized agent to make requests on your behalf by providing written authorization.
Notice: We do not sell personal information and have not sold personal information in the past 12 months. We do not share personal information for cross-context behavioral advertising.
10. HIPAA Compliance
For customers processing Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA), KarmaCX acts as a Business Associate and enters into a separate Business Associate Agreement (BAA).
- PHI is encrypted using AES-256 encryption at rest and TLS 1.3 in transit
- Access to PHI is restricted to authorized personnel only
- We implement administrative, physical, and technical safeguards required by HIPAA Security Rule
- Audit logs track all access to PHI
- BAA includes required provisions under 45 CFR § 164.314(a)
To request a Business Associate Agreement, contact us at support@karma-bot.com.
11. AI System Transparency (EU AI Act)
KarmaCX uses artificial intelligence systems to provide customer support automation. In accordance with the EU Artificial Intelligence Act, we provide the following transparency information:
11.1 AI System Classification
Our AI system is classified as a limited-risk AI system under the EU AI Act. It generates customer support responses and requires transparency obligations but is not considered high-risk.
11.2 AI Processing Details
- Purpose: Automated customer support response generation and conversation management
- AI Providers: OpenAI (GPT models), Anthropic (Claude models)
- Training Data: AI models are pre-trained by providers; your data is NOT used to train models for other customers
- Human Oversight: Optional approval workflows available; confidence thresholds for automated responses
- Limitations: AI may produce inaccurate responses; human escalation available for complex queries
- Transparency: End users can be notified they are interacting with an AI system
11.3 AI Accuracy and Limitations
While our AI achieves high accuracy on common support queries, it may occasionally produce incorrect or inappropriate responses. We implement confidence scoring, approval workflows, and human escalation to mitigate these risks. You maintain full control over whether AI responses are automatically sent or require human review.
12. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through the following mechanisms:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms with data importers
- Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
- Transfer Impact Assessments: We assess risks for transfers to third countries
- Supplementary Measures: Technical safeguards including encryption and access controls
Upon request, we can provide copies of the safeguards we have in place for international data transfers.
13. Data Processing Records (GDPR Article 30)
As required by GDPR Article 30, we maintain records of processing activities. Key information includes:
- Controller: KarmaCX, karma-bot.com
- Processing purposes: AI customer support automation, analytics, billing, security
- Data categories: Contact data, account data, usage data, customer support data
- Data subject categories: Website visitors, customers, customer support end-users
- Recipients: Cloud providers, AI services, analytics providers (see Section 5.1)
- International transfers: EEA to US with SCCs
- Retention periods: See Section 6
- Security measures: Encryption, access controls, SIEM (see Section 7)
14. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience and analyze usage patterns:
14.1 Cookie Categories
- Essential cookies: Required for website functionality (authentication, security)
- Analytics cookies: Google Analytics, Vercel Analytics (with IP anonymization)
- Preference cookies: Remember your settings and preferences
14.2 Managing Cookies
You can control cookies through your browser settings. Disabling essential cookies may affect website functionality. For analytics cookies, you can opt-out through our cookie consent banner or browser settings.
15. Demo Data Disclaimer
Our interactive chat demo uses sample data for demonstration purposes only. Do not enter personal, confidential, or sensitive information in the demo. Demo interactions may be stored temporarily and are automatically deleted within 24 hours.
16. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal data, please contact us immediately.
17. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email or website notice at least 30 days before the changes take effect. The "Last updated" date at the top of this policy reflects the most recent revision.
18. Contact Us & Data Protection Officer
For any privacy-related questions, to exercise your rights under this policy, or to contact our Data Protection Officer, please reach us at:
Email: support@karma-bot.com
Data Protection Officer: support@karma-bot.com
EU Representative: For GDPR matters, you may also contact our EU representative (contact details available upon request).
