Privacy Policy — EU General Data Protection Regulation (GDPR)

Sarama CRM Platform
Controller: Angad Manik Beratung fur Strategie und Projekte, Rebgasse 53, 4058 Basel, Switzerland
Data Protection Contact: Angad Bank (ehemals Manik), impact@angad.swiss
Platform: sarama.angad.swiss
Effective Date: 12 June 2026


1. Introduction

This Privacy Policy explains how Angad Manik Beratung fur Strategie und Projekte ("we", "us", "Controller") processes personal data in connection with the Sarama CRM platform ("Platform") in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").

We act in two capacities:


2. Data Protection Contact

Angad Bank (ehemals Manik)
Rebgasse 53, 4058 Basel, Switzerland
Email: impact@angad.swiss

You may contact the DPO for any questions regarding data protection.


3. Categories of Personal Data We Collect

3.1 Account & Authentication Data

DataPurposeLegal Basis
Email addressAccount creation, OTP/OAuth authenticationArt. 6(1)(b) — contract performance
User IDInternal identificationArt. 6(1)(b) — contract performance
Organization detailsMulti-tenant accessArt. 6(1)(b) — contract performance
Membership rolesAccess controlArt. 6(1)(b) — contract performance

3.2 Billing Data (processed by Stripe)

DataPurposeLegal Basis
Payment methodSubscription billingArt. 6(1)(b) — contract performance
Transaction historyInvoicing, credit trackingArt. 6(1)(c) — legal obligation
Credit balanceAI usage billingArt. 6(1)(b) — contract performance

3.3 Customer-Uploaded Data (we process as Processor)

DataPurposeLegal Basis
Contact records (name, email, phone, address, job title, company, social URLs, date of birth, custom fields)CRM functionalityArt. 6(1)(b)/Art. 28 — processing on behalf of Controller (customer)
Company recordsCRM functionalityArt. 6(1)(b)/Art. 28
Deal and pipeline dataSales managementArt. 6(1)(b)/Art. 28
Email content (sent/received)Email integrationArt. 6(1)(b)/Art. 28
Form submissions (all field data, UTM params, referrer, page URL)Lead captureArt. 6(1)(b)/Art. 28
Calendar eventsSchedulingArt. 6(1)(b)/Art. 28
Workflow configurationsAutomationArt. 6(1)(b)/Art. 28

3.4 Tracking & Analytics Data

DataPurposeLegal Basis
IP address (email opens/clicks)Email campaign analyticsArt. 6(1)(f) — legitimate interest of customer
User agent (email opens/clicks)Device analyticsArt. 6(1)(f) — legitimate interest of customer
Click URLsCampaign performanceArt. 6(1)(f) — legitimate interest of customer
Form submission metadata (IP, user agent, referrer)Fraud prevention, analyticsArt. 6(1)(f) — legitimate interest

3.5 AI & Chat Data

DataPurposeLegal Basis
Conversation messagesAI agent interactionArt. 6(1)(b) — contract performance
AI model API keys (encrypted)AI functionalityArt. 6(1)(b) — contract performance

When an AI agent reads or edits content on your behalf, it acts only within your own organisation and within the acting user’s permissions. Agents never receive your encrypted API keys, and they cannot access another customer’s data.

3.6 Integration Credentials

DataPurposeLegal Basis
OAuth tokens (Gmail, Outlook, Calendar)Email/calendar syncArt. 6(1)(b) — contract performance
IMAP/SMTP credentials (encrypted at rest)Email integrationArt. 6(1)(b) — contract performance
Social account OAuth tokens (Facebook Pages, Instagram, LinkedIn, TikTok — encrypted at rest)Social media publishing & engagement analyticsArt. 6(1)(b) — contract performance, customer-initiated
Marketing analytics OAuth tokens (Google Analytics, Google Ads, Google Tag Manager, Meta Ads — encrypted at rest)Importing the customer’s own marketing performance dataArt. 6(1)(b) — contract performance, customer-initiated

3.7 Audit & Security Data

DataPurposeLegal Basis
Audit log entries (user ID, action, resource, timestamp)Security, complianceArt. 6(1)(f) — legitimate interest, Art. 6(1)(c) — legal obligation

3.8 Social Publishing & Marketing Performance Data

DataPurposeLegal Basis
Social post content (captions, hashtags, media) and publishing schedulePublishing to the customer’s connected Facebook Pages, Instagram, LinkedIn and TikTok accounts at the customer’s directionArt. 6(1)(b)/Art. 28 — processing on behalf of the customer
Post engagement metrics (impressions, reach, likes, comments, shares, views)Performance reporting on the customer’s own postsArt. 6(1)(b)/Art. 28 — customer-initiated retrieval
Marketing metrics imported from the customer’s own accounts (Google Analytics 4 sessions/users/conversions, Google Ads and Meta Ads campaign impressions/clicks/spend, Google Tag Manager container inventory)Aggregated marketing reporting and AI-assisted analysis inside the PlatformArt. 6(1)(b)/Art. 28 — customer-initiated import

Social and marketing integrations are strictly customer-initiated: the customer connects their own accounts via OAuth, tokens are stored encrypted, and the customer can disconnect at any time, which stops all retrieval. We only access the data of accounts the customer explicitly connected; we never read other users’ data on those platforms.


4. Data We Do NOT Collect


5. Recipients and Sub-processors

We share personal data with the following categories of recipients:

Sub-processorServiceLocationData TransferredSafeguards
Supabase (AWS)Database, authentication, file storageZurich, SwitzerlandAll platform dataCH adequacy — data stays in Switzerland
StripePayment processingUSABilling dataEU-US Data Privacy Framework, Standard Contractual Clauses
AnthropicAI model provider (Claude)USAChat messages (via customer API keys)Standard Contractual Clauses, customer-initiated transfer
OpenAIAI model provider (GPT)USAChat messages (via customer API keys)Standard Contractual Clauses, customer-initiated transfer
Google AIAI model provider (Gemini)USA/EUChat messages (via customer API keys)Standard Contractual Clauses, customer-initiated transfer
Gmail API / Outlook APIEmail syncUSAEmail content (via customer OAuth)Standard Contractual Clauses, customer-initiated
Google Calendar / Outlook CalendarCalendar syncUSACalendar events (via customer OAuth)Standard Contractual Clauses, customer-initiated
Meta PlatformsFacebook/Instagram publishing, page & ads insights (Graph API)USA/EUPost content, engagement & ad metrics of the customer’s connected accountsStandard Contractual Clauses, customer-initiated transfer
LinkedInPost publishing & share statisticsUSA/EUPost content and engagement metrics of connected accountsStandard Contractual Clauses, customer-initiated transfer
TikTokVideo publishing & video statisticsUSA/EU/SGVideo content and engagement metrics of connected accountsStandard Contractual Clauses, customer-initiated transfer
Google (Analytics Data / Ads / Tag Manager APIs)Import of the customer’s own marketing metricsUSA/EUAggregated web/ads performance metrics of connected propertiesStandard Contractual Clauses, customer-initiated transfer
Google (Analytics)Website usage analyticsUSA/EUPage views, session duration, device info, IP address (anonymized), cookies (_ga, _gid)EU-US Data Privacy Framework; consent-gated
Cloudflare (Turnstile)CAPTCHA / bot protectionUSA/EUIP address, browser attributes, cookiesEU-US Data Privacy Framework, Standard Contractual Clauses
Microsoft (Entra ID)OAuth authentication (optional)USA/EUEmail, name, account IDEU-US Data Privacy Framework, Standard Contractual Clauses
Google (OAuth)OAuth authentication (optional)USA/EUEmail, name, account IDEU-US Data Privacy Framework, Standard Contractual Clauses

Important: AI model API calls use the customer's own API keys. We do not control or have access to the customer's accounts with these providers. The customer initiates these data transfers and is responsible for the terms with those providers.


6. International Data Transfers

6.1 Our primary infrastructure is hosted by Supabase in Zurich, Switzerland. Switzerland has been granted an adequacy decision by the European Commission (Commission Implementing Decision (EU) 2024/2272).

6.2 For sub-processors located in the USA, we rely on:

6.3 AI model transfers are customer-initiated: the customer provides their own API keys and chooses which models to use. We facilitate the technical connection but the customer controls the data flow.


7. Data Retention

Data CategoryRetention Period
Account dataDuration of contract + 30 days for export
Billing/transaction data10 years (Swiss commercial law, OR Art. 958f)
Customer-uploaded CRM dataDuration of contract + 30-day export window
Email tracking eventsDuration of contract
AI chat messagesDuration of contract
Audit logs2 years
OAuth/API tokens (email, calendar, social, marketing)Until revoked/disconnected by customer or contract end
Social engagement & marketing metricsDuration of contract
Form submissionsDuration of contract

After contract termination and the 30-day export window, all customer data is permanently deleted unless retention is required by law.


8. Your Rights Under the GDPR

As a data subject, you have the following rights:

RightDescriptionHow to Exercise
Access (Art. 15)Obtain a copy of your personal dataEmail impact@angad.swiss
Rectification (Art. 16)Correct inaccurate dataEmail or self-service in Platform
Erasure (Art. 17)Request deletion of your dataEmail impact@angad.swiss
Restriction (Art. 18)Restrict processing in certain casesEmail impact@angad.swiss
Portability (Art. 20)Receive your data in machine-readable formatEmail impact@angad.swiss
Objection (Art. 21)Object to processing based on legitimate interestEmail impact@angad.swiss
Withdraw Consent (Art. 7(3))Withdraw consent at any time (does not affect prior lawfulness)Email impact@angad.swiss
Complaint (Art. 77)Lodge a complaint with a supervisory authorityContact your local DPA

For contacts stored by our customers: If you are a contact in a customer's CRM, please direct your request to that customer (the Controller). We will assist the customer in fulfilling the request as Processor.

We respond to data subject requests within 30 days. Complex requests may be extended by an additional 60 days with notification.


9. Security Measures

We implement the following technical and organizational measures pursuant to Art. 32 GDPR:

Technical Measures:

Organizational Measures:


10. Data Processing Agreement (DPA)

For customers who require a formal Data Processing Agreement under Art. 28 GDPR, we provide a DPA upon request. Contact impact@angad.swiss.

The DPA covers:


11. Data Breach Notification

In the event of a personal data breach:


12. Automated Decision-Making

The Platform does not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects data subjects (Art. 22 GDPR).

AI-generated content is provided as suggestions to the customer's users, who retain full control over any actions taken.


13. Children's Data

The Platform is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that data from a child has been collected, we will delete it promptly.


14. Email Tracking Transparency

Our Platform enables customers to track email opens and clicks. As Processor, we provide the technical mechanism. The customer (Controller) is responsible for:

We filter Apple Mail Privacy Protection opens (IP range 17.x.x.x) to improve accuracy.


15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect. The current version is always available at sarama.angad.swiss/site/privacy.


16. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority. Given our Swiss establishment, the lead authority is:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern, Switzerland
https://www.edoeb.admin.ch

For EU data subjects, you may also contact your local Data Protection Authority.


17. Contact

For any privacy-related inquiries:

Angad Manik Beratung fur Strategie und Projekte
Angad Bank (ehemals Manik) — Data Protection Contact
Rebgasse 53, 4058 Basel, Switzerland
Email: impact@angad.swiss


Last updated: 12 June 2026