Privacy Policy
Last Updated: January 31, 2025
This privacy policy states how we process users' data at Data I Am, Inc. hereafter referred to as (“Data I Am,” “we,” “us,” or “our”). We welcome you to Data I Am. Data security is of paramount importance to us. Generally, our product may be used without the provision of any personal data; however, if a data subject (hereinafter “you” or “user”) wishes to utilize certain enterprise services available through our product, the processing of personal data may become necessary. In instances where such processing is required and no statutory basis exists, we shall typically seek your consent.
The processing of personal data—such as a data subject’s name, address, email address, or telephone number—will at all times be conducted in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and any other applicable country-specific data protection laws. Through this data protection policy, we seek to inform the general public about the nature, scope, and purpose of the personal data we collect, use, and process, and to advise data subjects of the rights afforded to them under these statutes.
As the controller, we have implemented a range of technical and organizational measures designed to ensure the highest possible level of protection for personal data processed via this product. It should be noted, however, that internet-based data transmissions may inherently contain security gaps, and absolute protection cannot be guaranteed.
1. Data Protection
We follow industry best practices to protect your data from unauthorized access and threats.
We ensure encryption throughout the data lifecycle, from collection to storage and transmission.
Any data shared with third-party integrations is anonymized and masked before processing.
We remain dedicated to securing your data and continually review and improve our security measures.
2. Information We Collect
2.1 Personal Data You Provide
We collect the personal data that you voluntarily share with us. This may include:
Name
Email address
Password
Single Sign-On (SSO) credentials (e.g., from Salesforce, Google, or any other SSO providers we may add in the future)
We do not collect any other personal information unless you choose to provide it.
2.2 Usage Data
Whenever you browse our site, certain details may be collected automatically. Examples include:
IP address
Browser type and version
Operating system
Referring URLs
Pages visited and links clicked
Date and time of your visit
These details are often gathered using cookies or similar tracking tools. See Section 10 for more information.
3. How We Use Your Information
We use personal data for the following purposes:
Account Management: To facilitate sign-up and sign-in processes, including via Salesforce Identity and Google Single Sign On (SSO).
Service Delivery: To provide, maintain, and improve our services, including the use of OpenAI’s API for data processing where necessary (e.g., for analytics or AI-driven features).
Communication: To contact you regarding updates, marketing, promotions, or other relevant information. You may opt out at any time.
Compliance and Security: To comply with applicable laws and regulations, respond to legal processes or lawful requests, and safeguard our rights and those of third parties.
4. Legal Basis for Processing (GDPR)
For the individual of European Union (EU) or the United Kingdom (UK), we rely on these legal grounds for handling your personal data:
Consent: When you explicitly agree to data processing (e.g., for marketing communications).
Legitimate Interests: When we have a valid reason to process data (like improving services, safeguarding security or preventing fraud) that is not outweighed by your personal rights.
Contractual Necessity: When data processing is required for a contract we have with you or to take steps you request before forming a contract.
Legal Obligations: Where processing is necessary for us to comply with a legal or regulatory obligation.
5. Your California Privacy Rights (CCPA)
For California residents, the CCPA grants specific rights:
Right to Know: Request details about the personal data we’ve collected and shared in the last 12 months.
Right to Delete: Ask us to remove your personal data, subject to certain exceptions.
Right to Opt Out of Sales: Opt out of having your personal data sold. (We do not sell personal data as defined by the CCPA.)
Right to Non-Discrimination: We will not treat you unfairly for exercising your privacy rights.
To use any of these rights, get in touch using the details in Section 14.
6. GDPR Data Subject Rights
If you are in the EU or UK, you have the following rights under GDPR:
Right of Access: To request information about the personal data we hold about you.
Right to Rectification: To request that we correct any inaccuracies in your personal data.
Right to Erasure (“Right to be Forgotten”): To request deletion of your personal data, subject to certain exceptions.
Right to Restrict Processing: To request that we limit the processing of your personal data in specific circumstances.
Right to Data Portability: To receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object: To object to our processing of your personal data under certain conditions, including for direct marketing purposes.
Please contact us using the details in Section 14 to exercise your rights.
7. Data Retention
We do not retain personal data (PII) for more than 15 working days after user requests for termination of services, unless a longer retention period is required by law or is necessary to fulfill legitimate business interests (such as account management, complying with legal obligations, resolving disputes, or enforcing our agreements). After the applicable retention period, we will securely delete or anonymize your data.
8. Sharing Your Information
We do not share your personal data with external parties except under the following circumstances:
OpenAI and Salesforce
OpenAI: We anonymize your data before sending it to OpenAI. Therefore, no personal data is shared with OpenAI unless you explicitly include user data in your submission.
Salesforce: We only integrate with Salesforce if you request it (e.g., for sign-in or to fetch specific data from your Salesforce account).
Sign-In Integrations: We utilize Salesforce Identity and Google SSO for account authentication.
Business Changes: In the event of a merger, acquisition, bankruptcy, or transfer of assets, personal data may be included in the transferred assets.
Legal Requirements: We may disclose data if required to do so by law, court order, or other legal mandates, or to protect our rights or those of third parties.
All third parties are legally bound by their legal obligations under their particular privacy policy ensuring they process user personal data as per the laws they adhere to.
9. International Transfers
If you access our services from outside the United States, please be aware that your personal data may be transferred to—and stored on—servers located in different countries. While these jurisdictions may not have equivalent data protection laws to those in your home country, we take steps to protect your data in accordance with this Privacy Policy. However, we do not currently have specific contractual mechanisms in place (like Standard Contractual Clauses) with every third-party provider.
10. Cookies & Tracking Technologies
We use cookies, web beacons, and similar tools to:
Enable essential product and features
Analyze usage patterns for service enhancements
Customize and improve your user experience
You can adjust your browser settings to reject cookies, although some parts of our product may not work properly if you do so.
11. Children’s Privacy
Our services are not designed for children under the age of 16 (or the relevant age in certain jurisdictions). We do not knowingly collect data from minors. If you believe a child has inadvertently provided personal information, please let us know so we can promptly remove that data.
12. Security Measures
We use reasonable security measures to protect your data from unauthorized access, alteration, or destruction. Despite our efforts, no method of data transmission or storage is completely secure.
13. Changes to This Privacy Policy
We may modify this Privacy Policy occasionally to reflect adjustments in our services or to comply with new laws and standards. Any updates will appear on this page, along with a revised “Last Updated” date. By continuing to use our services after any changes, you acknowledge your acceptance of the new terms.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please reach out to us at support@dataiam.com
15. Third-Party Integrations
15.1 Third-Party Privacy Policies
We encourage you to review the privacy policies of any external services we integrate with, such as OpenAI, Salesforce and Google. We do not control their data handling, so make sure you understand how they process your information.
15.2 Use of OpenAI’s API
We may use OpenAI’s API for tasks like analytics or AI-driven functionalities. We limit what data is shared with OpenAI and have put in place legal and technical safeguards to maintain compliance with relevant data protection laws (including the GDPR and CCPA).
15.3 Data Processing Agreements
Please note that we do not maintain specialized data processing agreements with these providers. We use their services under their standard terms, and any data handling they perform is subject to their respective privacy policies. We encourage you to review these policies to understand how your personal data may be used by third-party providers.
15.4 Cookie and Consent Mechanisms
If you are located in the EU, UK, or elsewhere with cookie consent requirements, please review Section 10 on how and why we use cookies. You may see a cookie banner or other consent tools to manage your preferences.
15.5 Data Minimization and Retention
Retention After Termination: We retain personal data for 15 working days after you request the termination of services. Refer to section 7 for more details.
During Active Use: We only keep user-supplied data for 48 hours to enable you to obtain insights from ongoing processing. This timeframe may be extended if you schedule future tasks.
Deletion Policy: We keep user-supplied data for 48 hours to enable you to obtain insights from ongoing processing. If a user schedules a job for a future date, the 48-hour period begins once that job is executed.
15.6 Legal Basis for Processing and Compliance
In accordance with the General Data Protection Regulation (GDPR), we rely on various legal grounds under Article 6(1). These include: (a) obtaining explicit consent for a specific processing purpose; (b) processing necessary for the performance of a contract or pre-contractual steps; (c) processing required to fulfill a legal obligation; (d) processing to protect the vital interests of a data subject or another natural person; (e) processing necessary for tasks carried out in the public interest or the exercise of official authority; and (f) processing justified by our legitimate interests or those of a third party, provided such interests do not override the fundamental rights and freedoms of the data subject. Where “special categories” of personal data (e.g., health, religious, or political information) are involved, Article 9 GDPR imposes stricter requirements that may necessitate explicit consent or other specific justifications (such as the establishment, exercise, or defense of legal claims). Under the California Consumer Privacy Act (CCPA), we further commit to safeguarding the personal data of California residents by providing the right to know what personal information is collected, the right to request deletion, and the right to opt out of the “sale” of personal data, as well as ensuring these individuals are not denied services or charged different prices for exercising their rights. Through these frameworks—GDPR and CCPA—we aim to process personal data lawfully, transparently, and proportionately, respecting both the sensitivity of the data and the rights and freedoms of individuals.
By continuing to use our product and services, you confirm that you have read, understood, and agree with this Privacy Policy, including any recommendations or details about our third-party integrations.