Legal

Privacy Policy

Effective: 23 May 2026 Last updated: 28 July 2026 Version: 1.1

Brainam (“Brainam”, “we”, “us” or “our”) is a product operated by Brainam Technologies Private Limited, an Indian company (CIN: U62011DL2026PTC468764). We help businesses build, train, and deploy AI agents that automate customer support, sales outreach, research, and operational workflows. Our products include the Brainam AI agent platform and Doot (doot.brainam.ai), our customer-messaging interface where these agents converse with your customers; both are operated by Brainam Technologies Private Limited and governed by this policy.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and its rules, the EU/UK GDPR, and the CCPA/CPRA. By using Brainam you agree to the practices described below. If you do not agree, please do not use our services.

1.Introduction & who we are

Brainam is operated by Brainam Technologies Private Limited (“the Company”, “Brainam”, “we”, “us”, “our”), an Indian company. We are committed to protecting your privacy. “User”, “you” or “your” refers to any individual who accesses or uses our website or services, including any features, tools, or functionality made available through them.

Operating Office
Plot No. 84, Second Floor A, Block B, Patel Garden, Kakrola, New Delhi, South West Delhi - 110078, Delhi
Registered Office
Plot No. 84, Second Floor A, Block B, Patel Garden, Kakrola, New Delhi, South West Delhi - 110078, Delhi
Website
General Contact
hello@brainam.ai
Privacy & Grievance
grievance@brainam.ai
CIN
U62011DL2026PTC468764

2.Scope of application & updates

This Privacy Policy applies to all users and explains why, how, and when we process personal data to offer and provide our website and services. It also describes the choices available to you regarding the processing of your personal data.

This Privacy Policy is part of, and incorporated into, our Terms & Conditions. Capitalised terms not defined here have the meaning given in our Terms & Conditions. This Privacy Policy does not apply where separate privacy terms are provided.

Our website and services may contain links to third-party websites and may integrate third-party functionality, such as social media plug-ins, tools or APIs, to enhance your experience. We do not control these third parties or how they process your personal data, and their privacy practices may differ from ours. Any personal data you provide or that is processed through such third-party websites or functionality is governed solely by the respective third party’s privacy policy and terms.

We may update this Privacy Policy from time to time to reflect legal changes or enhancements to our website or services. The latest version is always available on our website. The “last updated” date indicates when changes have been made. Material changes will be notified by email and in-product banner at least 30 days before they take effect.

3.Definitions

  • Personal Data / Personal Information — any information that identifies you or can reasonably be linked to you.
  • Data Principal — the individual to whom personal data relates (DPDP Act).
  • Data Fiduciary — the entity that determines the purpose and means of processing personal data — Brainam (Brainam Technologies Private Limited), in respect of customer accounts. Where personal data belongs to a business customer’s own end-users (for example, people who message that business on WhatsApp or Instagram), the business customer is the Data Fiduciary and Brainam acts as its Data Processor (see Section 10).
  • Data Processor / Sub-processor — a third party that processes data on our behalf under contract.
  • Processing — any operation performed on personal data — collection, storage, use, sharing, deletion, etc.
  • Customer — a business or individual that has signed up for a Brainam account, paid or free.

4.Categories of personal data

We may process the following categories of personal data that you provide directly, that are generated through your use of our website or services, or that we receive from third-party services or publicly available sources:

  • Contact data — name, email address, phone number, country or place of residence.
  • Communication data — information contained in communications with us, such as emails, chat messages, support requests, feedback, or other content you voluntarily provide.
  • Account & usage data — pseudonymised user and workspace identifiers, account settings, authentication events, agent and workflow usage metrics, enabled integrations, chip balance and consumption, and billing information.
  • Training content — documents, prompts, sample conversations, knowledge files, images, and any other content you upload to train your AI agents. (Data obtained via Google Workspace APIs — your Sheets, Forms, Calendar, and Drive content — is excluded from this and is never used to train AI agents or any AI/LLM model.)
  • Marketing data — contact preferences, newsletter subscriptions, email engagement, and registrations for events, webinars, or product updates.
  • Traffic & device data — IP address, device and browser type, operating system, language settings, access times, device identifiers and tokens, log files, HTTP request data, feature interactions and associated usage metrics.
  • Integration data — data received from third-party apps you connect (e.g. Google Workspace, WhatsApp, Instagram, Zoho) under the OAuth scopes you authorise.

5.How we use your personal data

The table below summarises our data processing activities, the categories of data involved, and the legal basis under GDPR. Where the DPDP Act applies, processing is based on your consent or as permitted under Section 7 of the Act for legitimate uses.

Purpose Personal data Legal basis (GDPR)
Account creation & service delivery — create & maintain your account, run your AI agents, deliver outputs. Contact, account & usage, training content, integration data. Performance of a contract (Art. 6(1)(b)).
Agent training & inference — storing prompts, knowledge files, conversation history so your agents perform as configured. Training content, account & usage data. Performance of a contract (Art. 6(1)(b)).
Payment processing — chip top-ups, BYOK subscriptions, refunds, invoicing, tax compliance. Contact, billing address, payment details (via Razorpay). Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)).
Product analytics & improvement — aggregated, de-identified usage to fix bugs and improve features. Traffic & device, account & usage data. Legitimate interest (Art. 6(1)(f)).
Support & communications — responding to enquiries, support requests, dispute resolution. Contact, communication, account & usage data. Performance of a contract; legitimate interest.
Newsletter & marketing — product updates, event invites, promotional emails. Contact, marketing data. Consent (Art. 6(1)(a)); legitimate interest.
Security, compliance & legal — IT security, fraud prevention, statutory retention, cooperation with authorities. All categories, as relevant. Legal obligation (Art. 6(1)(c)); legitimate interest.

6.Payment processing

We use Razorpay Software Private Limited as our payment service provider for processing online payments, invoicing, and, where applicable, GST and tax handling. Payment card details are never stored on Brainam servers — they are handled directly by Razorpay, which is PCI-DSS Level 1 compliant.

Information processed for payments includes name, email address, billing address, payment information (e.g. card or UPI details), IP address, transaction data and, where applicable, company-related information. The processing is carried out for the purpose of payment processing, fraud prevention, invoicing and tax compliance.

The payment service provider may act as an independent controller within the meaning of Art. 4(7) GDPR, in particular where it processes payment data in its own name as a so-called “merchant of record.”

Personal data will only be disclosed to third parties if this is necessary for contract processing, required by law, or carried out within the framework of commissioned data processing. Data relevant under commercial and tax law is generally stored for the duration of the applicable statutory retention periods (8 years under Indian law).

7.Email & contact form

Our website provides multiple ways to contact us quickly, including our email addresses and contact form. If you contact us by email or via our contact form, the personal data you provide will be stored automatically. Additional data processed during the contact process serves to prevent misuse of the contact form and to ensure the security of our information technology systems.

The legal basis for the processing of data transmitted in the course of sending an email is Art. 6(1)(b) GDPR. We use the personal data you provide exclusively for the purpose of processing your specific enquiry. The data provided will always be treated confidentially.

The data will be deleted as soon as it is no longer necessary for the purpose for which it was processed — typically when the conversation has ended and the matter has been conclusively clarified.

8.Data processing via our website

Access data in server log files

Every time you visit our website, we automatically store access data in server log files. This includes the date and time of the visit, the amount of data transferred, the name of the requested file, the browser used and its version, the operating system used, the IP address and the referrer URL. The temporary storage of the IP address is necessary to enable the website to be delivered to your device.

This data is evaluated exclusively to ensure permanent and trouble-free operation of the website, to improve its content, to transmit to law enforcement authorities in the event of a cyber-attack, and to ensure the security of our information technology systems — which constitute our legitimate interest in this processing (Art. 6(1)(f) GDPR).

Content delivery network & security provider

Our website uses a content delivery network (CDN) and security service provider for load balancing, protection against denial-of-service (DDoS) attacks, bot detection and safeguarding the integrity and confidentiality of our IT systems. Incoming requests are routed via the provider’s globally distributed edge servers, and access data may be processed by the provider before being forwarded to our servers.

Third-party tools for marketing, analytics & optimisation

When you visit our website, we process data for marketing, statistics, optimisation and IT security, in some cases with the support of service providers. We ask for your consent for this processing through our cookie banner. Detailed information about the cookies and services used can be found via the “Cookie Settings” button at the bottom of the page.

9.Google API Services — Limited Use Disclosure

Brainam’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We use Google user data only to provide and improve user-facing features that are prominent in the Brainam interface (such as reading and writing rows in your Google Sheets, reading your Google Form responses, creating and updating events on your Google Calendar, and handling the Google Drive files that Brainam itself creates).
  • We do not use Google user data for serving advertisements.
  • We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with the user’s explicit consent.
  • Any Google user data passed transiently to third-party AI sub-processors (e.g., Anthropic, OpenAI, Google) is sent solely to execute the specific action you initiate, under API terms that prohibit those providers from using it to train or improve their models. We do not store this data, and it is not used for any purpose beyond returning your requested result. For deployments requiring strict data residency, Brainam can run entirely on a locally-hosted model so that no Google user data leaves your environment.
  • We do not allow humans to read Google user data unless: (a) we have the user’s affirmative agreement for specific messages, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and used for internal operations in accordance with applicable privacy laws.

OAuth scopes we may request

We only request the scopes required to power the integration you enable:

  • https://www.googleapis.com/auth/spreadsheets — read and write rows in your Google Sheets on your behalf.
  • https://www.googleapis.com/auth/forms.body — create and edit your Google Forms.
  • https://www.googleapis.com/auth/forms.responses.readonly — read the responses submitted to your Google Forms.
  • https://www.googleapis.com/auth/calendar.events — view, create, and update events on your Google Calendar.
  • https://www.googleapis.com/auth/drive.file — access only the specific Google Drive files that Brainam creates or you open with it (not your whole Drive).
  • openid, userinfo.email, userinfo.profile — for sign-in only.

Brainam does not request access to Gmail or to your entire Google Drive. Your AI agent uses this data only to work with the Google Sheets, Forms, Calendar events, and Drive files you direct it to within Brainam.

You can revoke any of these permissions at any time at myaccount.google.com/permissions.

10.Meta Platforms & data deletion instructions

When you connect a Meta product to Brainam, we strictly comply with the Meta Platform Terms, Meta Developer Policies, the Meta Business Messaging Policy, and the WhatsApp Business Solution Terms.

What we access

  • Facebook / Instagram — Facebook Page and connected Instagram Business/Creator account metadata, and permission to publish posts and captions that you have reviewed and approved. Brainam does not read, send, or automate Instagram or Facebook direct messages.
  • WhatsApp Business — messages sent and received through the WhatsApp Business Cloud API, your end-customers’ phone numbers and WhatsApp profile names, business profile details, and message status callbacks.

We access and process this data strictly through official Meta APIs — the WhatsApp Business Cloud API and, where you connect them, the Instagram Graph API and Facebook Pages API. For WhatsApp we request the permissions whatsapp_business_messaging and whatsapp_business_management, used exclusively to route and respond to your customers’ messages and to manage the WhatsApp Business Account you connect. For Instagram and Facebook content publishing, we request instagram_basic, instagram_content_publish, pages_show_list, pages_read_engagement, and pages_manage_posts, used exclusively to publish the posts and captions that you have explicitly reviewed and approved within Brainam — not for direct messaging or unsolicited outreach. We request only the permissions required for the integrations you actually enable.

We use this data solely to operate the AI agent you have configured — for example, to reply to a customer message, log a conversation, or trigger a workflow.

Our role — controller vs processor

When you (a Brainam business customer) connect your own WhatsApp Business or Instagram/Facebook account — including through Meta’s Embedded Signup flow inside Brainam, where you attach your own WhatsApp Business Account and phone number without leaving our product — you remain the controller / Data Fiduciary of your end-customers’ personal data (their phone numbers, profile names, and message content). For that end-customer data, Brainam acts only as your Data Processor, processing it strictly on your documented instructions to operate the AI agent you configured, and never for our own purposes.

Consent & opt-in

You are responsible for obtaining and maintaining any consent or opt-in required from your end-customers before you message them. In particular, a clear opt-in is required before sending business-initiated (template) WhatsApp messages, as required by the WhatsApp Business Messaging Policy; replies you send within the messaging window opened by a customer’s own inbound message do not require prior opt-in. Brainam provides tools to capture opt-in and retains a record of each opt-in (identifier, timestamp, and source) so that consent is auditable, and will not send a business-initiated message to a recipient who has no recorded opt-in.

No AI-model training on Meta data

Data obtained through your WhatsApp, Instagram, or Facebook integrations — including your end-customers’ message content and phone numbers — is never used to train, fine-tune, or improve any AI or LLM model. Where such data is passed transiently to an AI sub-processor to generate a reply or action you initiated, it is sent solely for that purpose, under API terms that prohibit training on it, and is not retained by that provider for training.

Data deletion instructions (Meta requirement)

Under Meta Platform Terms, you have the right to request deletion of data we have obtained via Meta integrations. To request deletion of your Meta-sourced data:

1. Email grievance@brainam.ai with the subject “Meta Data Deletion Request” and include the Facebook Page ID, Instagram username, or WhatsApp Business Account ID associated with your Brainam account; or

2. Visit brainam.ai/data-deletion, fill in the form, and select “Meta-sourced data only.”

We will confirm receipt within 48 hours and complete deletion within 30 days, after which we will email you a confirmation reference number.

Upon receiving a Meta Data Deletion Request, or when you disconnect your Meta or WhatsApp account from Brainam, we purge all associated OAuth tokens, end-customer conversation logs, and cached profile data from our primary databases and instruct our sub-processors accordingly within 30 days, retaining only records we are legally required to keep.

11.Disclosure, sub-processors & international transfers

We may share personal data with carefully selected service providers that support our business operations. Where such service providers process personal data on our behalf, we conclude data processing agreements pursuant to Article 28 GDPR, ensuring that personal data is processed solely in accordance with our instructions and in compliance with applicable data protection standards.

Current sub-processors

Sub-processor Purpose Data category Region
Anthropic (Claude) LLM inference for agents Prompts & relevant context USA
OpenAI LLM inference, embeddings Prompts & relevant context USA
Google (Gemini API) LLM inference, multimodal Prompts & relevant context USA / EU
Razorpay Payment processing Billing & payment data India
MongoDB Atlas Primary database hosting All stored data (encrypted) Singapore / India
Render Application hosting Application traffic Singapore
Cloudflare CDN, DDoS protection, edge security Traffic & device data Global
Resend / SES Transactional email delivery Contact data USA
PostHog Product analytics Pseudonymised usage data EU
Sentry Error and crash reporting Diagnostic data USA

We update this list as our infrastructure changes. The current list is always available on this page. Enterprise customers can subscribe to advance notification of changes by writing to grievance@brainam.ai.

Disclosures required by law

We may disclose personal data where required by law or where such disclosure is necessary to comply with legal obligations or lawful requests by public authorities, courts, or law enforcement agencies, to enforce our commercial contracts, to investigate potential violations, to prevent or address fraud, security, or technical issues, or to protect our rights, property, users, or the public.

International transfers

Some of the recipients listed above are located outside India, the European Union (EU) or the European Economic Area (EEA), in particular in the United States. Where personal data is transferred to third countries, such transfers are carried out only where permitted under Articles 44 et seq. GDPR and are subject to appropriate safeguards. These include adequacy decisions such as the EU–U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs) approved by the European Commission, and additional technical and organisational measures such as encryption and access controls.

What we do not do

We do not sell your personal information. We do not rent it. We do not share it for cross-context behavioural advertising.

12.Use of cookies

Our website may use so-called cookies (small text files stored in your browser or on your device) and similar tracking technologies such as pixels or scripts. Cookies contain information about the current or last visit to our website. If cookies do not contain an exact expiration date they are stored only temporarily and are automatically deleted when you close your browser. Cookies with an expiration date will remain stored until the specified date or until you delete them manually.

We may use three types of cookies:

  • Essential cookies — required for the functionality of our website (authentication, session). These cannot be disabled.
  • Functional & performance cookies — help us improve your experience (preferences, language).
  • Analytics & advertising cookies — enable anonymous product usage analytics. We do not use cross-site advertising cookies.

You can update or withdraw your cookie preferences at any time via the “Cookie Settings” button. You can further configure, block, and delete cookies in your browser settings. If you delete all cookies, some functions of our website or services may not display correctly.

13.Automated decision-making & use of AI

We do not make decisions about you that are based solely on automated processing (including profiling) and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. If we were to introduce such automated decision-making in exceptional cases in the future, we will inform you in advance where required by law and ensure appropriate safeguards are in place — including your right to obtain human intervention, to express your point of view and to contest the decision.

Brainam itself is an AI-powered platform: the agents you configure may make automated decisions on your behalf (for example, replying to a customer message). These decisions are made within the scope and rules you define, and you remain accountable for the outputs of agents in your workspace.

14.AI model training boundaries

This section is critical. Please read it carefully.

14.1 We do not train foundation models on your data

Brainam does not use your training content, conversations, prompts, or uploaded files to train, fine-tune, or otherwise improve any general-purpose foundation model (such as Claude, GPT, Gemini, or any open-source model).

14.2 Your data stays in your workspace

The training content you upload is used exclusively to power your own AI agents in your own Brainam workspace. It is logically isolated from every other customer’s data.

14.3 Third-party AI sub-processors

When your agent runs, prompts and necessary context are sent to one or more AI providers for inference. We work with Anthropic, OpenAI and Google. We rely on these providers’ API terms, which state that data sent through their APIs is not used to train their models (Anthropic: zero-retention API; OpenAI: API data not used for training; Google: Gemini API data not used for training).

14.4 Improving Brainam’s own components

We may use aggregated, de-identified signals (such as “X% of agents fail at step Y”) to improve Brainam’s own routing, retries, and chip-billing logic. We do not read individual prompts or outputs for this purpose, and no customer content leaves your workspace in identifiable form.

15.How long we keep your data

We store your personal information for no longer than necessary for the purposes for which it was processed, including to satisfy any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests.

Data type Retention period
Account dataUntil you delete the account, plus 90 days for backup expiry.
Training content & knowledge filesUntil you delete them or close the account.
Conversation logs12 months by default; configurable per agent.
Billing & tax records8 years (Indian statutory requirement).
Security & access logs12 months.
Marketing preferencesUntil you opt out.
De-identified aggregate dataIndefinite.

16.Data deletion requests

To delete your Brainam account and all associated data:

Deletion is completed within 30 days, except for records we are legally required to retain (e.g. tax invoices for 8 years).

17.Your rights under data protection laws

17.1 Under the DPDP Act, 2023 (India)

As a Data Principal you have the right to:

  • Access the personal data we hold about you.
  • Correction and erasure of inaccurate or no-longer-required data.
  • Grievance redressal through our Grievance Officer (Section 21).
  • Nominate another person to exercise your rights in the event of death or incapacity.
  • Withdraw consent at any time, without affecting prior lawful processing.

17.2 Under GDPR / UK GDPR

  • Right to access your data (Art. 15).
  • Right to correct your data (Art. 16).
  • Right to have your data deleted (Art. 17).
  • Right to restrict processing (Art. 18).
  • Right to data portability (Art. 20).
  • Right to object to processing (Art. 21).
  • Right to withdraw consent (Art. 7(3)).
  • Right to lodge a complaint with a supervisory authority (Art. 77).

17.3 Under CCPA / CPRA (California)

You have the right to know, delete, correct, and opt out of any “sale” or “sharing” of personal information — though Brainam does not sell or share personal information for cross-context behavioural advertising.

17.4 How to exercise your rights

Email grievance@brainam.ai or use the in-product Privacy & Data page. We will respond within 30 days (or earlier where law requires).

18.Children’s privacy

Brainam is intended for business use by adults (18+). We do not knowingly collect personal data from children under 18. If you become aware that a child has provided us with personal information, please contact grievance@brainam.ai and we will delete it.

19.Security

We protect your data with:

  • TLS 1.2+ encryption in transit.
  • AES-256 encryption at rest.
  • Role-based access control and least-privilege administration.
  • Encrypted secrets vault for OAuth tokens and API keys.
  • Regular vulnerability scanning and dependency patching.
  • Audit logs for all admin actions.

No system is ever 100% secure. If we become aware of a personal data breach that is likely to affect you, we will notify you and the relevant authority within the timelines required by law (within 72 hours under DPDP and GDPR). For more detail see our Security page.

20.Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email and in-product banner at least 30 days before they take effect. The latest version is always available at brainam.ai/privacy, with the “Effective Date” and “Version” updated at the top.

21.Grievance Officer (India / DPDP)

In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021, the following officer has been appointed to address your concerns:

Grievance Officer
Sachin Arora
Email
grievance@brainam.ai
Office Address
Brainam Technologies Private Limited,
Plot No. 84, Second Floor A, Block B, Patel Garden, Kakrola, New Delhi, South West Delhi - 110078, Delhi
Response Time
Acknowledgement within 48 hours; resolution within 30 days.

If you are not satisfied with our response, you may approach the Data Protection Board of India under the DPDP Act, 2023.

22.Contact us

General Queries
hello@brainam.ai
Privacy & Data Rights
grievance@brainam.ai
Security Disclosures
security@brainam.ai
Billing
hello@brainam.ai