Legal

Privacy Policy

Effective Date: September 21, 2026

Version: 1.0

1. Who we are and how this Policy applies

CodeKarma Technologies Private Limited ("CodeKarma", "we", "us" or "our") provides a runtime observability and developer productivity platform for engineering teams (the "Platform") and operates the website at codekarma.ai and related pages (the "Site").

This Policy explains how we collect and use personal data when we act as a controller, data fiduciary or business. This includes personal data relating to Site visitors, customer personnel, authorized Platform users, prospects, suppliers, business contacts and job applicants.

Customer telemetry and other data that a customer submits to, hosts within, or makes available through the Platform, and any data that is produced by the Platform using such data for the customer ("Customer Data") is governed by our customer agreement and Data Processing Addendum. Section 4 (Customer Data and CodeKarma's role) explains our role for Customer Data.

This Policy does not apply to personal data that our customers collect from their own users, employees or systems, except to the limited extent CodeKarma processes that data on the customer's instructions.

2. Personal data we collect

We collect the categories of personal data below. However, the exact data depends on your relationship with us, the way your organization configures the Platform, and the channels through which you interact with CodeKarma:

2.1 Information you or your organization provides.

  • 2.1.1 Contact and business details, such as name, email address, phone number, company, job title, role, country and communication preferences.
  • 2.1.2 Account and authorized-user details, such as login credentials, authentication identifiers or tokens (which may include OAuth tokens), profile photo, organization membership, permissions, preferences and account settings.
  • 2.1.3 Billing and subscription information, such as billing name, billing address, purchase details, subscription tier, invoice information and payment confirmations. Payment card data is handled by our payment processor and is not stored by CodeKarma.
  • 2.1.4 Support and onboarding communications, including email, Slack, Microsoft Teams or other messaging content and handles, support tickets, call notes, attachments, screenshots and logs that you or your organization choose to provide.
  • 2.1.5 Sales, marketing and event information, such as demo requests, waitlist submissions, webinar registrations, product interests and communication preferences.
  • 2.1.6 Recruitment information, such as CV/resume, work history, education, portfolio links, interview notes, references, background-check information where permitted, and communications with us about a role.
  • 2.1.7 Supplier and business-contact details, such as the name, business contact details, role and, where relevant, payment or bank details of suppliers, vendors, partners and other business contacts.

2.2 Information collected automatically.

  • 2.2.1 Site and Platform usage data, including pages or features accessed, clicks, navigation paths, API-call frequency, session times, product settings and feature engagement.
  • 2.2.2 Device and technical data, including IP address, device type, operating system, browser type, unique online identifiers, approximate location inferred from IP address, diagnostic data and security events.
  • 2.2.3 Log and audit data, including authentication events, administrator actions, error logs, access logs and security-monitoring records.
  • 2.2.4 Cookies and similar technologies, as described in Section 5 (Cookies and similar technologies) and in our Cookie Policy.

2.3 Information from third parties.

  • 2.3.1 Your organization or account administrators may provide your name, business contact details, role, permissions and other information needed to provision or manage your account.
  • 2.3.2 Identity providers, single sign-on and authentication services may provide profile and authentication information such as name, email address, profile photo, organization and authentication status.
  • 2.3.3 Payment processors may provide transaction confirmations, billing details and payment status information.
  • 2.3.4 Messaging, collaboration and support platforms may provide handles, workspace names, display names and message content when we communicate through those channels.
  • 2.3.5 Business partners, event organizers, professional networks, publicly available sources and licensed data providers may provide business contact and professional information about prospective customers and other business contacts for B2B sales and marketing, subject to applicable law.
  • 2.3.6 Sales-intelligence, visitor-identification and data-enrichment providers may identify the organization associated with a visit to the Site, and may supplement or verify business contact and professional information we hold, based on online identifiers and technical data such as an IP address.

2.4 Information we generate.

  • 2.4.1 Inferences, such as business preferences and product interests that we infer from your usage and engagement, which we may use to improve our services and tailor our B2B communications.

2.5 Platform telemetry and Customer Data.

The Platform is designed to collect structural and performance metadata about software environments, such as service names, method or class names, call graphs, latency, error rates and related performance signals. The Platform is not intended to collect request or response payloads, secrets, production database contents or end-user transaction payloads. Structural metadata can be personal data if, for example, names, identifiers, URLs, paths, comments, user IDs or other data configured by a customer identify or relate to an individual. To the extent such data is Customer Data, we process it as described in Section 4 (Customer Data and CodeKarma's role) and in the applicable customer agreement. We do not intentionally collect special-category data or sensitive personal information through the Site or Platform. You should not include that information in support tickets, screenshots, logs or other materials unless we have expressly agreed how it will be handled.

3. How we use personal data

We use personal data for the purposes below. This section describes our processing purposes at a practical level. Region-specific legal grounds, rights and additional disclosures are addressed in Section 13 (Regional terms) where applicable.

  • 3.1 Provide, administer and secure the Site and Platform. We use account details, authentication data, organization details, Platform usage data, support communications and technical logs to provide access, administer accounts, operate the Site and Platform, maintain sessions, authenticate users, apply permissions, troubleshoot issues and protect the Platform.
  • 3.2 Manage customer, billing and commercial relationships. We use contact details, role or title, company information, billing details, invoices, payment confirmations and transaction records to manage customer relationships, subscriptions, procurement, invoicing, payments and related business administration.
  • 3.3 Provide support, onboarding and customer success. We use support tickets, emails, Slack, Microsoft Teams or other messaging content, call notes, screenshots, logs and related metadata supplied by you or your organization to respond to requests, investigate issues, provide onboarding and improve service quality.
  • 3.4 Service and transactional communications. We use your contact and account details to send administrative, service and transactional messages, such as confirmations, security and authentication notices, service and outage updates, billing and renewal notices, and changes to our terms or this Policy. These are not marketing messages, and you cannot opt out of them while you hold an account.
  • 3.5 Improve and develop the Site and Platform. We use usage data, feature engagement, diagnostics, performance signals, aggregated or de-identified data and customer feedback to understand how the Site and Platform are used, maintain and improve functionality, develop features and measure performance.
  • 3.6 Security, fraud prevention and abuse monitoring. We use device, browser, IP address, log, authentication, audit and other technical signals to protect CodeKarma, customers and users, detect misuse, prevent unauthorized access, investigate incidents and maintain the integrity of the Site and Platform.
  • 3.7 Sales, marketing and events. We use business contact details, marketing preferences, form submissions, event registrations and engagement data to respond to requests, manage events, send product and business communications, understand customer and prospect interests and conduct B2B marketing where permitted. You may opt out of marketing communications at any time.
  • 3.8 Recruitment. We use application information, CVs/resumes, work history, education, interview notes, references and background-check information where permitted to assess applications, communicate with candidates and manage recruitment processes.
  • 3.9 Legal compliance and claims. We use relevant records, contracts, communications, logs, transaction records and request records to comply with applicable law, respond to lawful requests, enforce agreements, resolve disputes and protect our rights and the rights of others.
  • 3.10 Aggregated and de-identified data. We may create aggregated or de-identified data from personal data and Customer Data, and may use and retain such data, including without limitation to operate, analyze, secure, improve and develop our business, the Site and the Platform and to produce statistics and benchmarks. Where we maintain data in de-identified form, we will not attempt to re-identify it except as permitted by law, for example to test whether our de-identification measures remain effective.
  • 3.11 Required and optional data. Where personal data must be provided to enter into or perform a contract, create an account, process billing, provide security or comply with law, failure to provide it may prevent us from providing the relevant Site, Platform, support, billing or recruitment process. Marketing information and non-essential cookies are optional.

This Section 3 (How we use personal data) describes processing where CodeKarma acts as a controller. Any use of Customer Data, including to create aggregated or de-identified data under Section 3.10 (Aggregated and de-identified data), is subject to Section 4 (Customer Data and CodeKarma's role) and the applicable customer agreement and Data Processing Addendum.

4. Customer Data and CodeKarma's role

Customers control Customer Data. Our customers decide whether and how to deploy the Platform, which environments to connect, what telemetry to collect, which integrations or AI-assisted features to enable, how the Platform is configured, and who may access the resulting outputs. Where Customer Data contains personal data, the customer is generally the controller, data fiduciary, business or equivalent entity under applicable privacy law, and CodeKarma processes that Customer Data only as described in the applicable customer agreement and any Data Processing Addendum, including as processor, data processor, service provider or contractor where applicable.

The Platform can be deployed differently (SaaS or BYOC) and the deployment model affects what Customer Data CodeKarma may receive or access. In a CodeKarma-hosted deployment, Customer Data may be transmitted to and processed in CodeKarma-managed infrastructure and by our service providers or sub-processors as necessary to provide, secure, support and maintain the Platform. In a BYOC or customer-managed deployment, the Platform is designed to operate within the customer's own cloud environment, and CodeKarma does not ordinarily receive Customer Data unless the customer enables data transmission to CodeKarma, grants support access, shares logs or screenshots, enables an integration, requests managed services, or otherwise makes Customer Data available to us.

Customers may enable third party AI-assisted features or integrations involving third-party AI providers selected or configured by the customer. Where this occurs, data may be sent to that provider under the customer's account, credentials or agreement with that provider. The customer is responsible for ensuring that the provider's terms, security settings and data-protection arrangements are appropriate for the data the customer chooses to process through those features.

Customers are responsible for providing any notices, obtaining any consents, and maintaining any legal bases or permissions required for their collection and use of Customer Data. Authorized users should direct privacy requests about their organization's use of the Platform to their organization. We will assist customers with such requests as required by our agreement with them and applicable law.

5. Cookies and similar technologies

We use cookies and similar technologies to operate the Site and Platform, maintain sessions, remember preferences, measure usage, improve performance and protect security. We set non-essential cookies only where you have accepted them, and you can withdraw your acceptance at any time as described in our Cookie Policy.

Our Cookie Policy identifies the cookies and similar technologies we use, their purposes, duration and providers, how you can control them, and any that may involve sharing personal information with third parties.

You can adjust browser settings to block or delete cookies. Some essential cookies are necessary for the Site or Platform to work and cannot be disabled.

6. How we share personal data

We share personal data only as needed for the purposes described in this Policy or as otherwise permitted by law. We may share your personal data with the categories of recipients below:

  • 6.1 Service providers and sub-processors. We use vendors for hosting, infrastructure, analytics, security, authentication, communications, support, CRM, billing, payment processing, recruitment and professional services. They may process personal data only to provide services to us or our customers and must protect it under contractual obligations.
  • 6.2 Payment processors. Payment card and payment-method details are collected and processed by payment processors under their own terms and privacy notices.
  • 6.3 Your organization. If you access the Platform through an employer or other organization, account administrators may access account, usage, audit and support information relating to your use of the Platform.
  • 6.4 Affiliates. We may share personal data within the CodeKarma group for business operations, customer support, security, administration and service delivery.
  • 6.5 Professional advisers. We may share information with lawyers, auditors, insurers, accountants and other advisers where necessary for ordinary business, compliance, transactions or claims.
  • 6.6 Corporate transactions. We may disclose or transfer personal data in connection with a merger, financing, acquisition, reorganization, sale of assets or similar corporate transaction, subject to appropriate protections.
  • 6.7 Legal, safety and compliance. We may disclose personal data where required by law, legal process or public-authority request, or where we reasonably believe disclosure is necessary to protect rights, safety and security, prevent fraud or enforce agreements.
  • 6.8 With consent or at your direction. We may share personal data with third parties where you or your organization direct us to do so or where you have given consent, such as for a customer reference or case study.
  • 6.9 Analytics and business-intelligence providers. We disclose online identifiers and technical data, such as an IP address, page address and referrer, to the providers of the analytics and business-intelligence technologies described in our Cookie Policy, including sales-intelligence and visitor-identification providers. These providers determine their own use of that data under their own privacy notices.
  • 6.10 Analytics and business-intelligence technologies. The technologies referred to in Section 6.9 (Analytics and business-intelligence providers) are not essential to the Site. They operate only where you accept non-essential cookies, and you may withdraw your acceptance at any time as described in Section 5 (Cookies and similar technologies). Where applicable law treats a disclosure of this kind as a "sale" or "sharing" of personal data, we will honor the opt-out rights that apply to it and recognize opt-out preference signals, including Global Privacy Control, where required by applicable law. Where applicable US state law gives these terms a specific meaning, additional detail is set out in Section 13.3 (California) and Section 13.4 (Other US state privacy rights).
  • 6.11 Advertising. We do not share personal data for cross-context behavioral advertising, we do not process personal data for targeted advertising, and we do not use advertising, retargeting or ad-measurement technologies on the Site.

7. International transfers

We may process personal data in countries other than the country where you are located, including where CodeKarma entities, infrastructure providers and service providers operate.

For transfers from the EEA or the United Kingdom, we rely on appropriate safeguards such as European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, adequacy regulations or other lawful transfer mechanisms.

For transfers from India, we transfer personal data outside India in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions, conditions or rules notified by the Central Government of India.

8. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide and secure the Site and Platform, manage accounts and customer relationships, maintain business and financial records, comply with legal obligations, resolve disputes, enforce agreements and protect our rights.

The specific retention period depends on the category of data, the purpose for which it is processed, the terms of our agreement with you or your organization, applicable legal, tax, accounting and regulatory requirements, security needs and relevant limitation periods. For Customer Data, the applicable customer agreement, Data Processing Addendum or order form may set additional retention, return or deletion requirements.

We delete, anonymize or de-identify personal data when it is no longer reasonably necessary for the relevant purpose, unless we are required or permitted to retain it for legal, security, dispute-resolution, audit or compliance reasons, including where retention is necessary in connection with actual, threatened or anticipated legal proceedings, investigations, regulatory requests or a legal hold. Backup copies may persist for a limited period until overwritten in the ordinary course, subject to appropriate access controls.

9. Security and breach notification

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration and disclosure. These measures may include access controls, encryption, logging, monitoring, vulnerability management, least-privilege controls, vendor diligence and incident-response procedures. For more information about our security measures, contact us using Section 14 (Contact and complaints).

If we become aware of a personal data breach affecting personal data for which we are responsible, we will assess it and notify regulators, affected individuals, customers or other parties as required by applicable law. Where we process Customer Data as a processor, we will notify the affected customer as required by the customer agreement and applicable law.

Please use strong authentication, protect your credentials, configure the Platform appropriately and promptly notify us of suspected unauthorized access.

10. Your rights and choices

Depending on where you live and which law applies, you may have rights to access, correct, update, delete, restrict, object to or receive a portable copy of your personal data. You may also have rights to withdraw consent, opt out of certain marketing or advertising uses, limit use of sensitive personal information, nominate another person to exercise rights, or complain to a regulator. Additional region-specific information is set out in Section 13 (Regional terms).

To exercise rights for personal data that CodeKarma controls, contact us using Section 14 (Contact and complaints). We may need to verify your identity and may ask for information needed to process the request. We will respond within the period required by applicable law.

If your request relates to Customer Data controlled by your employer or another customer, please contact that organization first. We will assist the customer as required by our agreement and applicable law.

You may opt out of marketing emails by using the unsubscribe link in those emails or by contacting us. We may still send non-marketing service, security, legal and account communications.

We do not make solely automated decisions that produce legal or similarly significant effects on individuals. The Platform primarily generates analytical insights about code, infrastructure and software performance; where its outputs relate to individuals, they are configured and controlled by the customer as described in Section 4 (Customer Data and CodeKarma's role). If our own use of personal data for automated decision-making changes, we will update this Policy and provide any notices, safeguards or choices required by law.

11. Children

The Site and Platform are intended for business users and are not directed to children. We do not knowingly collect personal data from individuals under 18. If you believe a child has provided personal data to us, contact us and we will take appropriate steps to delete it.

12. Changes to this Policy

We may update this Policy from time to time to reflect changes in our services, practices or legal obligations. We will post the updated Policy on the Site and update the effective date.

If we make material changes, we will take reasonable steps to bring them to your attention, such as a prominent notice on the Site. Where consent is required for a material change in processing, we will obtain it before relying on that change.

13. Regional terms

The terms below apply only where the relevant regional law applies. They supplement the rest of this Policy and, if there is a conflict, control for individuals in the relevant jurisdiction. They mainly address personal data for which CodeKarma is responsible as controller, data fiduciary, business or equivalent entity. Customer Data that we process on a customer's behalf is addressed in Section 4 (Customer Data and CodeKarma's role) and in the applicable customer agreement and Data Processing Addendum:

13.1 EEA and United Kingdom.

This Section 13.1 (EEA and United Kingdom) applies where and to the extent that EU or UK data-protection law applies to CodeKarma's processing of personal data of individuals located in those regions.

  • 13.1.1 Controller. Where CodeKarma acts as controller, the controller is the CodeKarma entity identified in Section 1 (Who we are and how this Policy applies). For Customer Data, the customer is generally the controller and CodeKarma (or an affiliate) processes that data in accordance with Section 4 (Customer Data and CodeKarma's role) and the applicable customer agreement and Data Processing Addendum.
  • 13.1.2 Legal bases. Where EU GDPR or UK GDPR applies and CodeKarma acts as controller, our legal bases include performance of a contract, compliance with legal obligations, consent where required, and legitimate interests where appropriate. Legitimate interests may include operating, securing, improving and developing a B2B software service, managing customer and prospect relationships, conducting limited B2B marketing where permitted, and protecting legal rights. Where we rely on legitimate interests, you may object to the processing where the law gives you that right.
  • 13.1.3 Rights. Subject to conditions and exceptions under applicable law, you may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority.
  • 13.1.4 Complaints. You may complain to your local supervisory authority. In the UK, this is the Information Commissioner's Office. We encourage you to contact us first so we can try to resolve the issue.
  • 13.1.5 International transfers. Transfers are handled as described in Section 7 (International transfers).

13.2 India.

This Section 13.2 (India) applies to individuals in India where the Digital Personal Data Protection Act, 2023 and related rules apply to CodeKarma's processing of their personal data.

  • 13.2.1 Data Fiduciary. Where CodeKarma determines the purposes and means of processing personal data of Data Principals in India, CodeKarma Technologies Private Limited is the Data Fiduciary. For Customer Data, the customer is generally the Data Fiduciary and CodeKarma (or an affiliate) processes that data as a Data Processor under the customer agreement and Data Processing Addendum.
  • 13.2.2 Grounds for processing. We process personal data based on consent or certain legitimate uses permitted by the DPDPA, including when you provide your personal data for a specified purpose.
  • 13.2.3 Withdrawal of consent. Where processing is based on consent, you may withdraw consent as easily as it was given, subject to legal or contractual consequences explained at the time of withdrawal.
  • 13.2.4 Rights. You may request information about processing, correction, completion, updating or erasure of personal data, grievance redressal, and nomination of another person to exercise your rights in the event of death or incapacity.
  • 13.2.5 Response time. We will respond to rights requests and grievances within the period required by law, which may be up to 90 days for applicable DPDPA requests.
  • 13.2.6 Complaints to the Board. If you are not satisfied with our response to a grievance, you may complain to the Data Protection Board of India after first exhausting the grievance redressal process described in this Policy.
  • 13.2.7 Children. We do not knowingly process children's personal data. If we are required to process personal data of a child, we will obtain verifiable parental or guardian consent unless an exception applies.
  • 13.2.8 Breach notification. Where required, we will notify affected Data Principals and the Data Protection Board of India of a personal data breach in the manner and timeframe prescribed by law.

13.3 California.

This Section 13.3 (California) applies to California residents only to the extent CodeKarma is a "business" subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), and only for personal information we handle as a business. It does not apply to Customer Data that we process on behalf of a customer as a service provider or contractor. In the prior 12 months, we have collected the following categories of personal information:

Category (prior 12 months) Examples and sources Purposes Disclosures and retention
Identifiers Examples: name, business email, IP address, online identifiers and account identifiers. Sources: you, your organization, identity providers, licensed data providers and your device/browser. Provide services, accounts, support, security, marketing and legal compliance. Disclosed to service providers, affiliates, your organization and authorities where required. Retained as described in Section 8 (Retention).
Customer records and commercial information Examples: billing address, subscription information, transaction history and payment confirmations. Sources: you, your organization and payment providers. Billing, subscription management, accounting and legal compliance. Disclosed to payment processors, service providers, affiliates and authorities where required. Retained as described in Section 8 (Retention).
Professional or employment-related information Examples: job title, employer, role, business contact details and candidate information. Sources: you, your organization, professional sources, licensed data providers and recruiters/referees. Account administration, support, sales, events and recruitment. Disclosed to service providers, affiliates, your organization and recruiters/referees where applicable. Retained as described in Section 8 (Retention).
Internet or network activity Examples: Site and Platform usage, feature interactions, log data, API usage and device/browser data. Sources: your device/browser, the Platform, and security or analytics providers. Operate, secure, troubleshoot and improve the Site and Platform. Disclosed to hosting, analytics, security and support providers, affiliates and your organization. Retained as described in Section 8 (Retention).
Geolocation Examples: approximate location inferred from IP address. Sources: your device/browser or service providers. Security, fraud prevention, localization and analytics. Disclosed to service providers and affiliates. Retained as described in Section 8 (Retention).
Inferences Examples: business preferences and product interests inferred from usage or engagement. Sources: derived from interactions with us. Improve services and tailor B2B communications. Disclosed to service providers and affiliates. Retained as described in Section 8 (Retention).
Sensitive personal information Examples: account log-in credentials or authentication tokens, if treated as sensitive personal information under California law. We do not seek to collect precise geolocation, government identifiers, racial or ethnic origin, health, biometric, union, religious, sexual-life or similar sensitive data. Sources: you, identity providers and authentication systems. Account access, authentication and security only. Disclosed to service providers supporting authentication, security and hosting. Retained as described in Section 8 (Retention).
Audio, electronic and visual information Examples: recordings or notes of demo, sales or support calls and webinars, and related communications. Sources: you and other participants, where such sessions are recorded or noted with notice. Support, sales, product demonstrations, onboarding, training and quality assurance. Disclosed to communications, meeting and support service providers and affiliates. Retained as described in Section 8 (Retention).

Identifiers and internet or network activity described in the table above may be disclosed to analytics and business-intelligence providers as described in Section 6 (How we share personal data).

We do not share personal information for cross-context behavioral advertising, and we do not knowingly sell or share the personal information of consumers under 16. Our use of analytics and business-intelligence technologies is described in Section 6 (How we share personal data). To the extent any such use constitutes a sale of personal information, California residents may opt out as described in that Section and in our Cookie Policy.

California residents may have the right to know, access, delete, correct, opt out of sale or sharing, limit use or disclosure of sensitive personal information where applicable, and not be discriminated against for exercising CCPA rights. To submit a request, contact us using Section 14 (Contact and complaints). You may use an authorized agent as permitted by law.

We do not use or disclose sensitive personal information to infer characteristics or for purposes requiring a right to limit under the CCPA; we use it only for permitted purposes such as account authentication, security and service delivery.

13.4 Other US state privacy rights.

Residents of certain other US states, under applicable state privacy law and subject to its conditions and exceptions, have rights to confirm whether we process their personal data, access it, correct it, delete it, obtain a portable copy, and opt out of the sale of personal data, targeted advertising and certain profiling. To exercise these rights, contact us using Section 14 (Contact and complaints). We do not engage in targeted advertising or in profiling to which an opt-out applies. To the extent we engage in the sale of personal data, we will give effect to your opt-out and recognize opt-out preference signals where required by applicable law.

14. Contact and complaints

For privacy questions, rights requests or complaints, contact us at:

Email: privacy@codekarma.tech

Grievance Officer: Anantharam Vanchi Prakash, CodeKarma Technologies Private Limited, reachable at the email above.

CodeKarma Technologies Private Limited: HD 197, WeWork Vaishnavi Signature, Outer Ring Road, Bellandur, Bengaluru, Karnataka 560103, India.

For questions about how we process your personal data, or to raise a grievance (including under India's Digital Personal Data Protection Act, 2023), please contact us at the email above. We will acknowledge and address grievances within the period required by applicable law.

Schedule Call View Platform

Contact Us

codekarma.ai

curl https://codekarma.ai/privacy-policy.md

Legal

# Privacy Policy — CodeKarma

> How CodeKarma Technologies Private Limited collects and uses personal data across its Site and Platform.

## metadata

path
/privacy-policy/
effective_date
September 21, 2026
version
1.0
contact_email
privacy@codekarma.tech

## 1. Who we are and how this Policy applies

> CodeKarma Technologies Private Limited provides a runtime observability and developer productivity platform (the "Platform") and operates codekarma.ai (the "Site"). This Policy covers personal data we handle as a controller, data fiduciary or business — Site visitors, customer personnel, authorized users, prospects, suppliers, business contacts and job applicants. Customer Data is governed by the customer agreement and Data Processing Addendum (see Section 4).

## 2. Personal data we collect

> Information you or your organization provide (contact, account, billing, support, sales/marketing, recruitment, supplier details); information collected automatically (usage, device/technical, log/audit, cookies); information from third parties (organization, identity providers, payment processors, messaging platforms, business partners, sales-intelligence/visitor-identification providers); information we generate (inferences); and Platform telemetry and Customer Data.

## 3. How we use personal data

> To provide, administer and secure the Site and Platform; manage customer, billing and commercial relationships; provide support and onboarding; send service and transactional communications; improve and develop the Site and Platform; security and fraud prevention; sales, marketing and events; recruitment; legal compliance and claims; and to create aggregated or de-identified data. Marketing and non-essential cookies are optional.

## 4. Customer Data and CodeKarma's role

> Customers control Customer Data and are generally the controller/data fiduciary/business. CodeKarma processes Customer Data only per the customer agreement and DPA, including as processor/service provider. Deployment model (SaaS or BYOC) affects what Customer Data CodeKarma receives.

## 5. Cookies and similar technologies

> We use cookies and similar technologies to operate the Site and Platform, maintain sessions, remember preferences, measure usage, improve performance and protect security. Non-essential cookies are set only where you accept them. See our Cookie Policy at codekarma.ai/cookie-policy.

## 6. How we share personal data

> With service providers and sub-processors, payment processors, your organization, affiliates, professional advisers, in corporate transactions, for legal/safety/compliance, with consent or at your direction, and with analytics and business-intelligence providers. We do not share personal data for cross-context behavioral advertising or targeted advertising.

## 7. International transfers

> We may process personal data in other countries. For EEA/UK transfers we rely on Standard Contractual Clauses, the UK IDTA/Addendum, adequacy or other lawful mechanisms. For India, transfers follow the DPDP Act, 2023.

## 8. Retention

> We retain personal data only as long as reasonably necessary for the purposes described, subject to legal, tax, accounting, security and dispute-resolution requirements, then delete, anonymize or de-identify it.

## 9. Security and breach notification

> We use technical and organizational measures to protect personal data and will notify regulators, individuals or customers of a personal data breach as required by applicable law.

## 10. Your rights and choices

> Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port your personal data, withdraw consent, opt out of marketing, and complain to a regulator. Contact us via Section 14. We do not make solely automated decisions with legal or similarly significant effects.

## 11. Children

> The Site and Platform are for business users and not directed to children. We do not knowingly collect personal data from individuals under 18.

## 12. Changes to this Policy

> We may update this Policy and will post the updated version and effective date. For material changes we will take reasonable steps to notify you and obtain consent where required.

## 13. Regional terms

> Region-specific terms for the EEA and UK (13.1), India (13.2), California (13.3) and other US states (13.4), which supplement and, where in conflict, control for individuals in those jurisdictions.

## 14. Contact and complaints

> Privacy questions, rights requests or complaints: privacy@codekarma.tech. Grievance Officer: Anantharam Vanchi Prakash, CodeKarma Technologies Private Limited, HD 197, WeWork Vaishnavi Signature, Outer Ring Road, Bellandur, Bengaluru, Karnataka 560103, India.

Human Agent