Privacy Policy
Last Updated: July 20, 2026
Effective Date: July 18, 2026
1. Introduction
Sangaas Technologies Private Limited ("Sangaas," "we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your personal information when you use our website and the Sangaas AI Employee platform, where you discover, scope, and implement AI Employees with a live industry expert.
This policy complies with applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 (DPDP Act), the UK GDPR and Data Protection Act 2018, the European Union's General Data Protection Regulation (GDPR), Singapore's Personal Data Protection Act 2012 (PDPA), Hong Kong's Personal Data (Privacy) Ordinance (PDPO), the California Consumer Privacy Act (CCPA), New York's SHIELD Act, and other relevant privacy regulations.
2. Data Controller Information
Sangaas Technologies Private Limited
Email: support@sangaas.com
Website: https://sangaas.com
3. Data Protection Officer
In line with Singapore's PDPA and as a matter of good practice everywhere we operate, we designate the following contact point as our Data Protection Officer for all privacy-related matters: support@sangaas.com.
4. Information We Collect
4.1 Personal Information You Provide
- Account Information: Full name, email address, and phone number, collected when you sign in and complete onboarding
- Business Profile: Job role, industry, business name, website, and your familiarity with AI, so your AI Employee is scoped to your actual situation
- Task Description: The job you describe when you request your AI Employee Success Rate Score, and anything you share with your expert during a Consultation
- Payment Information: Billing details for paid plans, handled entirely by our payment processor (Paddle) — we never see or store your card details
Please do not include special category data (such as health records, government ID numbers, or financial account numbers) in your task description or anything else you share with us. We only ask for what's needed to scope and implement the specific job you describe.
4.2 Information Automatically Collected
- Device Information: IP address, browser type, device identifiers, operating system
- Usage Data: Pages visited, time spent, and how you interact with the platform, collected via our analytics provider, PostHog
- Advertising Data: If you arrive via a LinkedIn ad or are a LinkedIn member, LinkedIn's Insight Tag shares limited browser and membership data with us to measure ad performance and build advertising audiences. See Section 12 for details
- Cookies: An essential session cookie that keeps you signed in, plus analytics cookies from PostHog and advertising cookies from LinkedIn. See Section 12 for details
- Bot Protection: When you sign in, Cloudflare Turnstile checks that you're human before we send a login code — this shares limited browser signals with Cloudflare
4.3 How We Use AI to Generate Your Plan
Your task description and business profile are sent to our AI provider, Anthropic, solely to generate your AI Employee Success Rate Score and Strategic Implementation Document. Anthropic's API terms specify that data submitted through the API is not used to train their models. We don't maintain a separate AI training programme, and we don't use your task description or plan content for any purpose beyond generating your output and, where relevant, delivering your Consultation.
5. How We Use Your Information
5.1 Primary Purposes
- Service Delivery: Generate your AI Employee Success Rate Score and Strategic Implementation Document, and run your live 1-1 expert sessions over Zoom
- Account & Access: Authenticate you, keep you signed in, and apply the free-tier cooldown fairly
- Communication: Respond to inquiries, provide support by email, and send updates about your plan or sessions
- Payment Processing: Handle transactions and billing through our payment processor, Paddle
5.2 Secondary Purposes (With Your Consent)
- Service Improvement: Analyse usage patterns via PostHog to improve the platform
- Marketing: Send promotional materials or updates relevant to your AI Employee, where you haven't opted out
Every marketing message includes a clear way to opt out, and we stop on request — consistent with Hong Kong PDPO's direct marketing requirements as well as general good practice.
6. Legal Basis for Processing
- Consent: For marketing communications and non-essential analytics
- Contract Performance: To deliver our services and fulfil our obligations to you
- Legitimate Interest: For service improvement, security, and fraud prevention
- Legal Compliance: To comply with applicable laws and regulations
7. Data Sharing and Disclosure
7.1 Third-Party Service Providers
- Supabase: Hosts our database and handles authentication
- Paddle: Processes payments as our merchant of record — we never receive your card details
- Anthropic: Generates your AI Employee Success Rate Score and Strategic Implementation Document
- Zoom: Hosts your live 1-1 expert sessions
- PostHog: Provides product analytics (EU-hosted)
- LinkedIn: Provides advertising analytics and conversion tracking via its Insight Tag
- Cloudflare: Provides bot protection on our login page
7.2 Legal Disclosure
We may disclose your information if required by law, court order, or to protect our rights, property, or safety, or that of our users or the public.
7.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
8. Data Security
We implement technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
- SSL/TLS encryption for all data transmissions
- Row-level database security, so your data is only ever readable by you and our systems, never by other users
- Column-level restrictions on sensitive fields (like payment status), writable only by our verified backend, never directly by a user's browser
- Access controls limiting who on our team can see your data
In the event of a data breach affecting your personal information, we will notify affected users and, where required, the relevant regulator (including under New York's SHIELD Act and other applicable breach notification laws) without undue delay.
9. Data Retention
- Active Users: Data retained while you use our services and for a reasonable period after your last activity, so you can pick up where you left off
- Payment Records: Retained for 7 years for tax and accounting purposes
- Analytics: Retained per our analytics provider's (PostHog's) standard retention period
- Advertising Data: Retained per LinkedIn's standard retention period for Insight Tag data
- Marketing Data: Deleted upon unsubscribe or opt-out
10. Your Rights
We offer the following rights to all users globally, as a matter of policy — including in jurisdictions like Hong Kong and New York, where local law does not require the full set:
✓ Access Rights
Request a copy of your personal data we hold
✓ Correction Rights
Update or correct inaccurate information
✓ Deletion Rights
Request deletion of your personal data
✓ Portability Rights
Receive your data in a structured format
✓ Objection Rights
Object to certain processing activities
✓ Consent Withdrawal
Withdraw consent for marketing or analytics
How to Exercise Your Rights
To exercise any of these rights, contact us at support@sangaas.com. We will respond within 30 days for DPDP and PDPA requests, and 1 month for GDPR (EU and UK) requests.
11. International Data Transfers
Several of our service providers (Supabase, Paddle, Anthropic, Zoom, PostHog, LinkedIn) operate internationally, so your personal data may be transferred to and processed in countries other than your country of residence. Where required, we rely on:
- Standard Contractual Clauses (SCCs) for EU data transfers, and the UK International Data Transfer Addendum for UK data transfers
- Adequacy decisions where available
- Data Processing Agreements with our service providers
- Comparable safeguards for transfers from Singapore, consistent with the PDPA's transfer limitation obligation
For Hong Kong users: we follow the PCPD's recommended cross-border transfer safeguards as a matter of best practice.
12. Cookies and Tracking Technologies
We keep cookie usage minimal:
- Essential Cookies: A session cookie from Supabase that keeps you signed in. The platform doesn't function without this one.
- Analytics Cookies: Set by PostHog to understand how the platform is used. If you're signed in, these are linked to your account (name and email) so we can improve the product for real usage patterns.
- Advertising Cookies: Set by LinkedIn's Insight Tag to measure the performance of our LinkedIn ad campaigns and, if you're a LinkedIn member, to build advertising audiences. See LinkedIn's own privacy policy for how it handles this data.
We don't currently run a cookie consent banner. You can block cookies in your browser settings, opt out of LinkedIn's ad tracking through your LinkedIn account settings, or contact us at support@sangaas.com to opt out of analytics or advertising tracking.
13. Children's Privacy
Our services are designed for business leaders aged 18 and above. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will delete it immediately.
14. Complaints and Supervisory Authorities
If you have concerns about how we handle your personal data, you can file a complaint with the relevant supervisory authority:
- India: Data Protection Board of India
- EU: Your local Data Protection Authority
- UK: Information Commissioner's Office (ICO)
- Singapore: Personal Data Protection Commission (PDPC)
- Hong Kong: Office of the Privacy Commissioner for Personal Data (PCPD)
- California: California Attorney General's Office
- New York: New York Attorney General's Office
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and, where appropriate, by email. Changes will be effective 30 days after posting unless a longer notice period is required by law.
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: support@sangaas.com
Website: https://sangaas.com
This Privacy Policy is governed by Indian law and complies with DPDP Act 2023, UK GDPR, EU GDPR, Singapore PDPA, Hong Kong PDPO, CCPA, New York SHIELD Act, and other applicable privacy regulations.