Skip to content
Samantrix
Legal

Privacy Policy

What we collect, why, who sees it, how long we keep it — and the things we have decided never to collect at all.

Last updated 1 August 2026

01Overview and our role

This policy explains how Samantrix Technologies (“Samantrix”) handles personal data across samantrix.galyan.in, the Samantrix web application, our desktop applications and related services.

Our role depends on the context, and the distinction matters:

  • As a processor. For data inside a customer’s workspace — employee profiles, messages, presence, attendance records, recordings — the employing organisation is the controller and decides what is collected and why. We process it on their documented instructions.
  • As a controller. For our website, marketing, sales enquiries, billing and account administration, we determine the purposes ourselves and act as controller.

If you are an employee with a question about your workspace data, your employer is the right first point of contact. We will always support them in responding to you.

02What we collect

Account and profile data. Name, work email, job title, department, avatar configuration, assigned desk and role within the workspace.

Presence and attendance data. Sign-in and sign-out times, which floor, room or zone an avatar occupies, status (active, in a meeting, away, focused) and idle time as determined by your workspace’s away-from-keyboard settings.

Communication content. Chat messages, threads, reactions, file attachments, and — only where a host explicitly starts a recording — meeting recordings and their transcripts.

Workplace records. Task cards and their history, leave applications and approvals, postal box submissions, and audit log entries for administrative actions.

Integration data. Where an administrator connects a Git provider, identity provider, calendar or payroll system, the metadata that integration returns within the approved scopes. For repository integrations this is event metadata such as commit messages, authors, timestamps and pull request states — not source code.

Technical data. IP address, device and operating system, application version, connection quality metrics, crash reports and diagnostic logs.

Website and enquiry data. Pages viewed, aggregated analytics, and the details you submit when you contact us or request a demo.

03What we deliberately do not collect

This section is a product commitment as much as a privacy statement. Samantrix does not, and will not:

  • Log keystrokes or capture what you type outside the application.
  • Take periodic screenshots of your screen or webcam.
  • Track which other applications or websites you use, or how long you spend in them.
  • Generate individual productivity scores, activity ratings or behavioural rankings of employees.
  • Record audio or video without a host explicitly starting a recording and every participant seeing a persistent indicator.
  • Sell personal data, or share it with advertising networks.

Presence in a shared space — the same information a colleague would have by looking across a room — is the only workplace signal the platform collects.

04Why we use it, and our legal bases

  • To provide the Services — rendering the office, routing voice and video, delivering messages, recording attendance and processing leave. Legal basis: performance of a contract, or the controller’s instructions where we act as processor.
  • To keep the platform secure — authentication, abuse prevention, audit logging and incident investigation. Legal basis: legitimate interests and legal obligation.
  • To support and improve the product — diagnosing faults, understanding aggregate feature usage and improving performance. Legal basis: legitimate interests.
  • To administer subscriptions — billing, renewals and account correspondence. Legal basis: contract and legal obligation.
  • For marketing to business contacts — responding to enquiries and sending occasional product updates. Legal basis: consent or legitimate interests, with an unsubscribe link in every message.

We do not use customer workspace content to train machine learning models. Where a feature uses automated processing — such as generating a transcript — it operates only on the specific content it was invoked on and only where the workspace has enabled it.

05Who we share data with

Within your workspace. Colleagues see what the office makes visible — your avatar, presence status, profile and the conversations you take part in. Administrators and managers see attendance and leave records according to the permissions your organisation configures.

Sub-processors. We use a small number of vetted providers for cloud hosting, media routing, email delivery, error monitoring and payment processing. Each is bound by a written agreement, processes data only on our instructions, and is subject to security review. A current list is available on request from privacy@samantrix.com.

Integrations you enable. Data flows to and from third-party systems only when an administrator connects them, and only within the approved scopes.

Legal and corporate. We may disclose data where legally required, to protect rights and safety, or in connection with a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy.

06International transfers and data residency

We operate in multiple regions. Where personal data is transferred outside its country of origin, we rely on appropriate safeguards such as standard contractual clauses, together with technical measures including encryption in transit and at rest.

Enterprise customers can request regional data residency so that workspace data is stored and processed within a specified region. Contact us before onboarding if this is a requirement.

07How long we keep it

  • Workspace content — messages, recordings, transcripts, tasks and attendance records are retained according to the retention policy your administrator configures.
  • After an account is deprovisioned — the individual profile is deactivated immediately; content they contributed is retained under the workspace policy.
  • After a subscription ends — customer data remains exportable for 30 days, then is deleted or anonymised.
  • Technical logs — retained for up to 90 days, except security and audit logs which follow the tier’s audit retention period.
  • Billing records — retained as long as tax and accounting law requires.

08Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive a portable copy, and to withdraw consent where processing is based on it.

Inside the product, every employee can already see their own full attendance record — including how idle time was classified — and can raise a correction request that a manager reviews.

For workspace data, please contact your employer as the controller. For data where we are the controller, write to privacy@samantrix.com and we will respond within 30 days. You also have the right to complain to your local data protection authority.

09How we protect it

Application traffic is encrypted with TLS 1.3, media streams use encrypted transport, and data is encrypted at rest. Access to production systems is restricted, logged and reviewed, and every administrative action inside a workspace is recorded in an audit log.

Our full technical and organisational measures are described on the security page. Report a suspected vulnerability to security@samantrix.com.

10Cookies and website analytics

Our website uses a minimal set of cookies and similar technologies:

  • Strictly necessary — session integrity, security and load balancing. These cannot be switched off.
  • Preferences — remembering choices such as your selected platform on the download page.
  • Analytics — aggregated, privacy-respecting measurement of page visits so we know which content is useful. We do not use advertising or cross-site tracking cookies.

You can block or delete cookies in your browser settings; strictly necessary cookies are required for the site to function correctly.

11Children

The Services are workplace software intended for use by employees and contractors. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If we learn we have, we will delete it.

12Changes and contact

We may update this policy as the product and the law evolve. Material changes will be announced by email or in-product notice at least 30 days before they take effect, and the date at the top of this page will always reflect the current version.

Privacy enquiries and data subject requests: privacy@samantrix.com. General enquiries: hello@samantrix.com.

This policy describes our practices in plain language. It is not legal advice. Organisations needing a signed data processing agreement, a sub-processor list or a completed privacy questionnaire can request one from privacy@samantrix.com.