Terms of Service

Sarama CRM Platform
Provider: Angad Manik, Rebgasse 53, 4058 Basel, Switzerland
Platform: sarama.angad.swiss
Effective Date: 3 September 2026


1. Scope

1.1 These Terms of Service ("Terms") govern the use of the Sarama CRM platform ("Platform"), operated by Angad Manik ("Provider", "we", "us"), with registered address at Rebgasse 53, 4058 Basel, Switzerland.

1.2 By registering for or using the Platform, you agree to these Terms. If you do not agree, you may not use the Platform.

1.3 The Provider reserves the right to amend these Terms at any time. Material changes will be communicated via email at least 30 days before taking effect. Continued use after the effective date constitutes acceptance.

1.4 Individual agreements between the Provider and the customer take precedence over these Terms.

2. Description of Services

2.1 The Platform offers the following features:

2.2 The Provider delivers services to the best of its ability. There is no guarantee of uninterrupted availability (see Section 9).

2.3 The Provider may extend, restrict, or modify Platform functionality at any time, provided core functionality is maintained.

3. Contract Formation and Registration

3.1 Contracting parties may only be legal entities, sole proprietorships, or natural persons aged 16 or older using the Platform for business purposes.

3.2 Registration and sign-in may use email one-time codes, passwords, or passkeys where offered. Password verification is handled by our authentication provider using a one-way hash; Sarama does not store or read plaintext passwords.

3.3 The customer is responsible for the security of their access and all actions taken under their account.

3.4 Each organization ("Org") on the Platform has an owner and may invite additional members with different roles. The owner is liable for the actions of all members of their organization.

3.5 The customer may invite employees and external service providers, such as agencies, consultants or freelancers. Each person must use their own login. The customer must verify that every invitee has a current mandate, grant only the workspace and connected-account permissions needed for that mandate, review them regularly, and revoke them promptly when the mandate ends. An external collaborator acts on the customer’s or its client’s instructions and does not become a sub-processor of the Provider merely because they are invited to a workspace.

4. Pricing and Payment

4.1 The Platform is exclusively paid. There is no free version.

4.2 Subscriptions are priced per seat (per user account in the organization). The monthly charge is the seat price multiplied by the number of seats:

PlanPer seat / monthPer seat / yearStorage per seatIncluded apex domains
BookingCHF 5.00CHF 50.005 GB1
BusinessCHF 29.00CHF 290.005 GB2
Max (full suite) — Founders PriceCHF 75.00CHF 800.005 GB3

4.2c Storage: Each plan includes 5 GB of file storage per seat. An organization’s total storage allowance is 5 GB multiplied by its number of seats, with a minimum of one seat. Storage is shared across the organization and is not partitioned per user. Reducing the number of seats reduces the allowance for future uploads but never deletes data already stored.

4.2d Storage add-ons: Additional storage may be purchased as a separate monthly Stripe subscription, independent of the plan and of the number of seats: +10 GB for CHF 2.00/month, +50 GB for CHF 8.00/month, or +200 GB for CHF 25.00/month. Add-on storage is added to the per-seat allowance and is cancellable at the end of the current monthly period.

4.2e Image copies: Images uploaded to the Platform are automatically stored together with two reduced-size copies (approximately 480 px and 1600 px wide) so that they can be displayed without re-processing on every view. These copies are stored in the same location as the original, count towards the storage allowance, and are deleted together with the original.

4.2b Founders Price guarantee: The Founders Price for the full Sarama plan (CHF 75.00/month or CHF 800.00/year) applies to all customers whose subscription begins on or before 31 December 2026. For these customers, the price is guaranteed for 3 years from the start of their subscription — no price increases apply during this period (Section 4.5 does not apply to the detriment of this guarantee). From 1 January 2027, the regular list price for new subscriptions is CHF 149.00/month or CHF 1’599.00/year.

4.2a Custom domains: Each organization may register a number of its own (apex) domains at no additional cost, as shown in the table in Section 4.2 (Booking: 1, Business: 2, Max: 3). Each additional apex domain costs CHF 120.00 per year, billed annually via Stripe as a separate subscription. Subdomains of a registered apex domain are free. A domain must be verified by DNS record before it can be used to serve Platform content. A domain add-on increases capacity limits for features the plan already includes; it does not unlock a feature that the plan excludes.

4.3 Billing occurs in advance (monthly or yearly according to the chosen plan) via the payment provider Stripe. Stripe's terms apply.

4.4 AI usage: own API keys are required (BYOK). Every AI feature of the Platform runs on an AI provider account that the customer supplies and controls. The customer deposits their own API key per provider; AI calls to that provider run on the customer’s own account with that provider, and the customer is billed by that provider directly. An AI feature for which the organization has supplied no key cannot run. The Provider does not resell, rebill or mark up model capacity, and there is no Provider-operated fallback key for customer AI traffic. This applies equally to Marketplace agents: an agent installed from the Marketplace runs on the installing customer’s own key, never on the creator’s and never on the Provider’s.

4.4b No prepaid Marketplace credits. One-time Marketplace purchases are charged at checkout through Stripe. Usage-based creator markups accrue as the buyer uses a Marketplace agent and are periodically charged to the buyer’s saved Stripe payment method. The prompt safety review is included in the Sarama subscription and has no separate charge. The retired credit ledger may remain in historical billing records but no longer funds or gates any Platform feature.

4.4a Marketplace fees and authorization for usage charges: For paid Marketplace content, the creator sets the price. For one-time purchases, the Provider retains a platform fee of 20% of the sale price; 80% goes to the creator. For usage-based creator markups on Marketplace agents, the Provider likewise retains 20% of the markup; 80% goes to the creator. By installing and using a listing with a usage markup, the buyer authorizes the Provider to initiate off-session charges to the payment method saved with Stripe. Charges are assessed weekly; small amounts may carry forward until the billing threshold is reached. Each amount equals the aggregate creator markups incurred during the period, calculated from the listing’s disclosed markup and the measured or, where the provider price is unavailable, conservatively estimated model cost. If Stripe requires authentication or a payment fails, the Provider may notify the buyer and request completion or replacement of the payment method. Creator payouts are processed via Stripe Connect on a weekly basis with a 14-day security hold; the minimum payout amount is USD 25.

4.5 Price changes will be communicated at least 30 days before taking effect. In the event of a price increase, the customer has a special right of termination at the end of the current billing period.

4.6 All prices are exclusive of value-added tax (VAT) unless otherwise stated.

4.7 In the event of payment default, the Provider is entitled to suspend access to the Platform after a reminder with a 14-day grace period.

5. Customer Obligations

5.1 The customer agrees to:

5.2 The customer is the Controller for personal data uploaded or connected for its own purposes. Where the customer processes for a third-party Controller, the customer acts as that party’s Processor. The Provider acts as Processor or Sub-processor as set out in Section 8.4.

5.3 Responsibility for customer actions and content: The customer acts in its own name or, where duly authorized, on behalf of its client. All content the customer creates, uploads, publishes, or distributes via the Platform — including emails and campaigns, social media posts, forms, websites, chatbot responses, and Marketplace content — remains the responsibility of the customer and, where applicable, its client. The Provider provides technical infrastructure only, does not review customer content before publication, has no general monitoring obligation (Art. 8 Regulation (EU) 2022/2065 — DSA), and is not responsible for the actions or omissions of customers or their organization members.

5.3a The customer indemnifies the Provider against all third-party claims arising from the customer’s use of the Platform or from content published or distributed by the customer via the Platform, including violations of data protection law, advertising and competition law, platform terms of third parties, personality rights, or intellectual property law, including reasonable legal defense costs.

5.4 The customer must deposit their own API keys for the third-party AI services they wish to use (Anthropic, OpenAI, Google, Mistral, etc.); without a key, the corresponding AI features cannot run (see Section 4.4). The customer selects the provider, contracts with it, pays it, and accepts its terms — including whether that provider may use the customer’s data for model training, which the Provider can neither control nor influence. The Provider assumes no liability for misuse of these keys by third parties where the misuse is not attributable to the Provider.

6. API Keys and Security Responsibility

6.1 The Platform stores customer-provided API keys for third-party services in encrypted form (AES-256-GCM). Despite encryption, absolute security cannot be guaranteed.

6.2 Rotation: Customers are strongly advised to rotate API keys at least every 90 days. The Provider may send reminders but does not guarantee enforcement.

6.3 In the event of a security incident at the Provider or its sub-processors (particularly Supabase), the Provider will:

6.4 The Provider is not liable for damages resulting from failure to follow rotation recommendations or from security breaches at third-party providers (Anthropic, OpenAI, Google, Stripe).

6.5 OAuth tokens for email and calendar integrations are stored encrypted via Supabase Vault. The customer may revoke authorization at any time through the respective third-party provider.

7. Intellectual Property

7.1 The Platform, including design, code, documentation, and trademarks, is the intellectual property of the Provider.

7.2 The customer receives a non-exclusive, non-transferable, revocable right of use for the duration of the contractual relationship.

7.3 Content entered by the customer on the Platform (contact data, emails, campaigns, etc.) remains the property of the customer. The Provider receives a right of use solely for contract performance.

7.4 Content published by the customer via the Marketplace (agents, skills, templates) is made available under the license chosen by the customer.

8. Data Protection and Processing

8.1 The processing of personal data is governed by our Privacy Policy, which forms an integral part of these Terms.

8.2 The Platform infrastructure is operated via Supabase in the Zurich (Switzerland) region.

8.3 The customer is responsible for:

8.4 Data Processing Agreement (Art. 28 GDPR / Art. 9 nDSG)

Where the Provider processes personal data on behalf of the customer (particularly contact data, form submissions, email content, and authorized social Page activity), the following provisions apply as a Data Processing Agreement (DPA):

Processing chain: Where the customer determines the purposes and means of processing, the customer is the Controller and the Provider is its Processor. Where the customer processes personal data for a third-party client that is the Controller, the customer acts as that client’s Processor and appoints the Provider as a Sub-processor. In that case, the customer warrants that it has a binding agreement meeting Art. 28 GDPR, the client’s documented instructions and prior specific or general written authorization to appoint the Provider; the customer must pass applicable instructions, data-subject requests, security requirements, deletion requests and objections concerning further sub-processors to the Provider without undue delay. A workspace invitation or technical account permission alone is not evidence of this authority.

(a) Subject matter and duration: The processing covers the storage, management, and provision of personal data supplied or connected by the customer for the duration of the contractual relationship, subject to the shorter platform-specific limits in Sections 10 and 11a.

(b) Nature and purpose: CRM functionality, email integration, campaign management, form processing, calendar integration, social publishing and Page-performance reporting, and AI-powered features as described in Section 2. LinkedIn member activity used for Page management is kept outside AI features.

(c) Categories of data subjects: Contacts, leads, customers, business partners, organization members and invited external collaborators, authorized social-account administrators, and people who interact with the customer’s connected social Page posts.

(d) Categories of personal data: Name, email, phone, address, occupation, company, social media URLs, custom fields, email content, form submissions and calendar entries; organization membership and account-level social permissions; permission-policy records containing actor and target-user identifiers, the permission key and prior/new values; and social-review records containing actor identifiers, event type, timestamps, notes, content revision, the canonical representation of the reviewed content/destination/settings and its digest. For authorized LinkedIn Page management this also includes the authenticated administrator member’s person URN, name and, when returned, public profile URL/avatar for authorization display and identity linking. Comment data includes the text, actor identifier/type, timestamps and reaction counts and, when LinkedIn returns them inline with a comment, the commenter’s first and last name, headline, public profile URL and avatar. Sarama makes no separate commenter-profile lookup. Comment activity and inline commenter profile fields are processed transiently only for the connector and are not persistently stored.

(e) Obligations of the Provider as Processor:

(f) Data breach notification: The Provider will notify the customer without undue delay and in any event no later than 48 hours after becoming aware of a personal data breach. The 48-hour figure is an outer limit: it does not displace the duty under Art. 33(2) GDPR to notify as soon as the Provider is aware, and the Provider does not treat it as a period it is entitled to use. With that notification, and thereafter as the information becomes available, the Provider will supply what the customer needs for its own notification under Art. 33(3) GDPR and will assist the customer under Art. 28(3)(f) GDPR, including with any communication to data subjects under Art. 34 GDPR.

(g) Sub-processors: The current list of sub-processors is available in the Privacy Policy. The customer will be informed of changes at least 14 days in advance and has a right of objection.

9. Availability and Disclaimer

9.1 No availability guarantee: The Platform is provided "as is" and "as available". The Provider makes no guarantee of uninterrupted, error-free, or secure availability.

9.2 Scheduled maintenance will be announced in advance where possible.

9.3 The Provider is not liable for outages caused by third-party services (Supabase, Stripe, AI providers), force majeure, cyberattacks, or circumstances beyond its control.

9.4 Exclusion of indirect damages: The Provider is in no case liable for indirect damages, consequential damages, lost profits, data loss, business interruption, or reputational damage, regardless of whether it was informed of the possibility of such damages.

9.5 Limitation of liability: Subject to Section 9.6, the Provider’s total liability arising from or in connection with this agreement is limited, in the aggregate for all events occurring within any 12-month period, to the fees actually paid by the customer to the Provider in the 12 months preceding the first event in that period giving rise to liability.

9.6 What is not limited, and cannot be: Sections 9.4 and 9.5 do not apply, and no other exclusion or limitation in these Terms applies, to:

9.7 If a limitation fails: The limitations in Sections 9.4 to 9.6 are set at the lowest level the Provider considers enforceable, and no lower. If a court or authority holds any of them invalid or unenforceable in whole or in part, that limitation applies to the maximum extent the applicable law permits rather than falling away entirely, and the remaining limitations are unaffected.

9a. Right of Withdrawal for EU Consumers

9a.1 Consumers resident in the European Union have the right to withdraw from the contract within 14 days without giving reasons (Directive 2011/83/EU, Art. 9).

9a.2 The withdrawal period begins on the day of contract formation (registration).

9a.3 To exercise the right of withdrawal, send a clear statement (e.g., by email) to: impact@angad.swiss. No template is required; an informal statement is sufficient.

9a.4 In the event of an effective withdrawal, we will refund all payments received without delay, no later than 14 days from receipt of the withdrawal declaration, using the same payment method.

9a.5 This section applies exclusively to natural persons who use the Platform for purposes that are predominantly outside their commercial, business, trade, or professional activity.

10. Termination

10.1 Either party may terminate the contract at any time at the end of the current billing period.

10.2 The Provider may terminate the contract without notice in the event of:

10.3 After contract termination:

10.4 Fees already paid are not refunded unless the termination is initiated by the Provider without cause attributable to the customer. In this case, a pro-rata refund for the unused period will be issued.

11. Email Tracking and Campaigns

11.1 The Platform offers email open and click tracking via tracking pixels and link rewriting. This captures IP address, user agent, and timestamp of recipients.

11.2 The customer is solely responsible for informing their recipients about tracking and obtaining the required consents.

11.3 The Provider provides an unsubscribe function. The customer is required to include it in their emails.

11.4 The Provider is not liable for damages arising from email tracking for the customer or third parties, particularly in the absence of recipient consent.

11a. Social Media Publishing and Connected Accounts

11a.1 The Platform allows an account owner, or a client-side administrator expressly authorized by that owner, to connect social media accounts (Facebook Pages, Instagram, LinkedIn, TikTok, YouTube) and marketing accounts (Google Analytics, Google Ads, Google Tag Manager, Meta Ads) via their own provider authorization, publish content and retrieve performance data. Where client_required approval is used, the connector must be the client or its authorized client-side administrator; an agency, freelancer or other external service provider uses delegated account permissions and must not connect the client’s account in its own capacity. Access tokens are stored encrypted. Only the original connector may disconnect the account and delete Sarama’s local token and connection for the workspace. Any other member, including an organization owner, can remove only their own delegated non-approval capabilities; approval authority must be revoked by the connector. The credential is never transferred to another member. Provider-side authorization is separate and must be revoked in the provider’s settings where Sarama cannot safely revoke it programmatically, including LinkedIn.

11a.2 The customer warrants that it and each invited service provider have a current mandate from the owner of every connected account, and that connecting and using the account complies with the respective platform terms. For LinkedIn, an agency or other external social-media manager may act as an Authorized Client only where the applicable LinkedIn Page Account Manager has authorized it; it must act within that authorization, its client agreement and the client’s directions. The customer must retain suitable evidence of authority and provide it on reasonable request.

11a.3 Content is published in the name of and on behalf of the connected account owner or client, which may differ from the customer contracting with Sarama. The customer and the connected account owner remain responsible for the content’s legality (including advertising labels, intellectual property and personality rights), required approvals and compliance with the respective platform’s content rules.

11a.3a Connected-account capabilities to prepare, approve, post, schedule and view analytics are assigned separately. Under client_required, only the connector or a client-side person expressly granted approval permission may approve; the person requesting review cannot approve the same revision. Approval applies only to the current content revision, destination, media and provider settings represented by the stored canonical approval payload and its digest. A material edit invalidates approval and requires a new review. Approval does not itself grant posting or scheduling permission, and Sarama rechecks the applicable active permission and exact approval before execution. After approval, either the client or a delegated service provider with the applicable posting or scheduling permission may execute the publication.

11a.3b For access control, dispute handling and security, Sarama records connected-account permission grants and changes, approval-mode changes, review requests and decisions, actor and relevant target-user identifiers, permission key, prior/new values, notes, timestamps, the content revision, the canonical representation of the reviewed content/destination/settings and its digest. These append-only permission and review audit records are retained for no more than two years, subject to an earlier applicable account, contract, deletion-request or platform-specific deletion deadline.

11a.4 The Provider has no influence on the availability, functionality, or decisions of third-party platforms. The Provider is in particular not liable for rejected or deleted posts, restricted reach, account suspensions or terminations by platform operators, API changes, or inaccurate metrics provided by third-party platforms.

11a.5 Imported marketing data (e.g., from Google Analytics or Meta Ads) is retrieved exclusively from accounts connected by the customer and is presented without warranty as to accuracy or completeness; it originates from the respective provider.

11a.6 LinkedIn Marketing Data is used only to publish/manage the connected customer’s authorized LinkedIn accounts and to provide LinkedIn account performance reporting to that customer. Sarama keeps LinkedIn reporting separately viewable from other platforms. Through r_basicprofile and /v2/me, Sarama processes the authenticated administrator member’s person URN, name and, when returned, public profile URL/avatar only to link that member’s authorizations and display who authorized the connection. LinkedIn member data is not exported, added to CRM contacts or leads, combined with other platforms, used for advertising, sales or recruiting, or sent to AI enrichment. Comment activity and profile fields LinkedIn returns inline with a comment — actor identifier/type, first and last name, headline, public profile URL and avatar — are processed live only for the LinkedIn connector associated with the Page. Sarama makes no separate commenter-profile lookup, and these data are not persisted.

11a.7 Platform-specific storage and deletion requirements apply in addition to the general periods in these Terms. Other-member profile data may not be stored; any temporary cache introduced in the future must expire within 24 hours, and any temporary cache of member social activity must expire within 48 hours. Sarama’s current comment path persists neither. For LinkedIn, Page administration/reporting metrics are retained for no more than one year. Authenticated Page profile data and administrator-member identity display fields are refreshed or purged within eight weeks; the person URN remains as the grant identifier while the authorization exists. Stored Marketing Data is deleted within ten days or less after customer-service cessation or a customer/Account Manager request. LinkedIn-requested data is deleted by LinkedIn’s specified deadline, which may be sooner, and all Member Data is deleted immediately if Marketing API Program participation or access terminates. The general GDPR response period of up to 30 days does not extend these operational deadlines.

12. AI Features

12.1 The Platform enables the use of third-party AI models (Anthropic, OpenAI, Google, Mistral, etc.) exclusively via API keys the customer provides (BYOK, see Section 4.4). The Provider does not operate model accounts on the customer’s behalf and does not resell model capacity.

12.2 The Provider has no control over the outputs of AI models. AI-generated content may contain errors, inaccuracies, or inappropriate content.

12.3 No guarantee for AI outputs: The customer is solely responsible for reviewing and using AI-generated content. The Provider makes no warranty as to the accuracy, completeness, or suitability of AI outputs.

12.4 Chat conversations with AI agents are stored on the Platform and transmitted to the respective AI providers. The customer is responsible for not entering confidential or sensitive data into AI chats that should not be transmitted to third-party providers.

12.5 Marketplace content (agents, skills, templates) is created by third parties. The Provider does not review it for accuracy or security as a matter of course. A creator may optionally purchase an automated prompt safety review of their own listing’s instructions, whose verdict — including failures — is published on the listing together with the full review history. That review is an automated check of the creator’s own instructions for a defined set of risks on a defined date. It is not a certification, not a warranty of behaviour and not a guarantee against misuse, and it is bound to the exact text reviewed: editing any reviewed input removes the mark.

12.6 AI Transparency (Regulation (EU) 2024/1689 — EU AI Act): Content produced by the Platform’s AI features is machine-generated. The Provider does not train its own models: every generation runs on a model the customer connects with its own provider account, so the model providers are the providers of those general-purpose models. For the AI features built on top of them — agents, agentic teams, the chat assistant and content generation — the Provider acts as the provider of that AI system and the customer acts as its deployer. Deployer duties, including the Article 50(1) and 50(4) disclosures owed to the people the customer reaches, sit with the customer, because only the customer knows the context, audience and purpose of a given workflow. The customer is required to inform recipients and third parties when AI-generated content is shared, particularly in emails, campaigns, and public forms, and AI-generated content must not be presented as human-created where a labeling obligation exists. The Provider offers supporting mechanisms — an AI-interaction notice in the first layer of the consent banner, and a disclosure appended to AI-assisted content published through the CMS — which are described, with their limits, on our EU AI Act page. Those mechanisms assist the customer; they do not transfer the customer’s deployer duties to the Provider.

13. Marketplace

13.1 The Provider operates a Marketplace where customers can publish and purchase AI agents, skills, teams, and bundles.

13.2 The Provider acts as an intermediary and is not a party to agreements concluded between creators and users.

13.3 The Provider makes no warranty for Marketplace content. Use is at the customer's own risk.

13.4 Pricing: The creator sets the price. The Platform retains 20% as a platform fee; 80% goes to the creator.

13.5 Reviews must be truthful and factual. The Provider reserves the right to remove abusive reviews.

13.6 Reporting illegal content (Regulation (EU) 2022/2065 -- Digital Services Act): Users may report illegal Marketplace content via email to impact@angad.swiss. Reports must include the contested content, the reason for the complaint, and the reporter's contact details. The Provider will review reports promptly and inform the reporter of the decision taken.

14. Forms and Public Endpoints

14.1 The Platform provides the ability to create publicly accessible forms and landing pages. These are accessible without authentication.

14.2 The customer is responsible for complying with all data protection requirements for their forms, particularly:

14.3 Form submissions are stored on behalf of the customer and are subject to the same data protection provisions.

14a. Selling Your Own Products Through the Platform

14a.1 What the feature is. A customer may connect its own Stripe account to the Platform (one Stripe connection per organization) and select prices from that account to be offered on its own booking pages and by its own chatbots. The Platform stores an encrypted copy of the customer’s Stripe API key, keeps a read-only snapshot of the selected prices, and creates a Stripe payment link in the customer’s own Stripe account, using the customer’s own key. What the Platform shows a visitor is that link.

14a.2 The customer is the seller. The customer is the merchant of record for every such sale. The contract for the product or service is concluded between the customer and its buyer. The Provider is not a party to it, is not a reseller, agent, or marketplace operator for these sales, and gives no warranty about the goods or services sold.

14a.3 The Provider never holds the money. The payment is made on a Stripe-hosted page belonging to the customer’s own Stripe account and settles to that account. The Provider adds no application fee, takes no commission, uses no Stripe Connect destination or transfer for these sales, and at no point receives, holds, routes, or has access to the funds. This is different from the Marketplace (Section 13), where the Provider does act as a platform and does retain a fee.

14a.4 Card data. Card details and other payment credentials are collected by Stripe on its own hosted page. The Provider does not receive them and does not store them. If the customer enables Stripe synchronisation, the Platform stores a minimal projection of the customer’s own Stripe records — customer identifier, email and name, description, status, amount, currency and timestamp. Where the customer runs the customer import, the name on the Stripe customer record is written to a CRM contact as a first and last name. Payment instruments, billing addresses and tax identifiers are deliberately not copied.

14a.5 What is sent to Stripe with a purchase link. The payment link itself carries only the customer’s organization identifier and a source marker. A booking page passes no visitor data at all. A chatbot passes the chat session identifier so the customer can reconcile a sale to a conversation; it does not pass the visitor’s email address.

14a.6 Customer responsibilities. The customer is solely responsible for its own Stripe agreement and compliance with Stripe’s terms; for the lawfulness of what it sells; for its own terms of sale, pricing, taxes and VAT, invoicing, delivery, warranty, refunds, chargebacks and consumer-law obligations (including any statutory right of withdrawal owed to its own buyers); and for the privacy notice shown to its own buyers. The customer indemnifies the Provider against third-party claims arising from these sales in accordance with Section 5.3a.

14a.7 Correct-account safeguard. A purchase link is served only while it can be shown to belong to the Stripe connection currently stored for the organization. If the customer replaces or removes its Stripe key, existing links stop being served and the affected items must be selected again; where technically possible, orphaned links are deactivated. This protects buyers and the customer from payments being routed to a Stripe account the customer has left, and it means a key rotation temporarily interrupts selling.

14a.8 Data protection roles. The sales contract is between the customer and its own buyer. Stripe is the settlement platform. The Provider is the infrastructure platform and is not a party to the sale, is not the merchant of record, is not a payment service provider, payment intermediary or money transmitter for it, and at no point holds, transmits, routes or controls the funds. The data protection roles follow from that:

What the Platform sends to Stripe, precisely. On the payment link object itself, two values: the customer’s organization identifier, and a marker recording that the Platform created the link. Per buyer, at most two further values, and only where the surface supplies them — a pre-filled email address, and a reconciliation reference:

What the Provider does not receive. Card numbers and other payment credentials, the buyer’s billing address, and the buyer’s tax identifiers. Where the customer enables Stripe synchronisation the Provider stores only the projection described in Section 14a.4 of the customer’s own Stripe records, from which those three are deliberately excluded.

The notice owed to the buyer is the customer’s. Because the customer is the controller of the sale, the privacy notice owed to the buyer is the customer’s to write and to publish; the Provider cannot write it. The booking page and the chatbot are surfaces the Provider renders on the customer’s behalf, so the customer must make its own privacy notice reachable from any such surface on which it offers products for sale.

15. Severability Clause

If any provision of these Terms is invalid or unenforceable, the remaining provisions shall remain unaffected. The invalid provision shall be replaced by a valid provision that most closely reflects the economic purpose of the invalid provision.

16. Governing Law and Jurisdiction

16.1 These Terms are governed exclusively by the laws of Switzerland, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and conflict of law provisions.

16.2 The exclusive place of jurisdiction for all disputes arising from or in connection with these Terms is Basel-Stadt, Switzerland.

16.3 Consumer protection jurisdiction rules of EU member states remain unaffected to the extent mandatorily applicable. Mandatory provisions of the law of the state in which a consumer has their habitual residence likewise remain unaffected.

16.3a These Terms are designed to satisfy both Swiss law (in particular the Swiss Code of Obligations and the revised Federal Act on Data Protection, FADP/nDSG) and mandatory EU law (in particular GDPR, Directive 2011/83/EU on consumer rights, the Digital Services Act, and the EU AI Act).

16.4 Online Dispute Resolution (ODR): The European Commission provides a platform for online dispute resolution: https://ec.europa.eu/consumers/odr. We are neither obligated nor willing to participate in dispute resolution proceedings before a consumer arbitration body.

16.5 Language versions: These Terms are published in several languages. In the event of a discrepancy between versions, this English version prevails. This does not affect mandatory provisions of the law of the state in which a consumer has their habitual residence, nor mandatory rules requiring particular information to be provided in a specific language. The German, Spanish and Italian versions are maintained section-for-section with this one.

17. Contact

For questions regarding these Terms, please contact:

Angad Manik
Angad Bank Manik
Rebgasse 53, 4058 Basel, Switzerland
Email: impact@angad.swiss
Website: angad.swiss


Last updated: 3 September 2026