For the purposes of this Privacy Statement, the following terms shall have the meanings set out below. Unless otherwise defined, capitalized terms used throughout this Privacy Statement shall have the meanings assigned in this section.
"Account" means an account created to access or administer the Services, including administrative and end-user accounts where applicable.
"Administrative User" means any individual authorized to administer or manage a Sampark deployment, including platform administrators, enterprise administrators, billing administrators, desk administrators, desk agents, support personnel, or any other authorized administrative role.
"AI Features" or "Syntalix" means the AI-powered capabilities provided within Sampark, including functionality such as sentiment analysis, transcription, summaries, and other AI-assisted features that may be enabled for a tenant.
"Applicable Law" means all laws, regulations, regulatory requirements, governmental orders, and legally binding obligations applicable to the processing of personal data, including, where relevant, the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), HIPAA, and other applicable privacy or data protection laws.
"Controller" means the natural or legal person that determines the purposes and means of processing personal data, or an equivalent term under applicable privacy laws.
"Customer" means the organization, enterprise, institution, healthcare provider, educational institution, or other entity that subscribes to, licenses, or deploys Sampark for its users.
"Data Processing Addendum (DPA)" means the contractual agreement governing the processing of personal data between NoteG and a Customer where applicable.
"End User" means an individual authorized to use the Services through a Customer deployment, including agents, participants, consultation attendees, or other users accessing Sampark.
"Organization" means any Customer, enterprise, healthcare provider, educational institution, government entity, or other legal entity using Sampark.
"Personal Data" means any information relating to an identified or identifiable natural person, or any equivalent concept recognized under applicable privacy legislation.
"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, storage, use, disclosure, transmission, analysis, retrieval, deletion, or destruction.
"Processor" means the natural or legal person that processes personal data on behalf of a Controller, or an equivalent term under applicable privacy laws.
"Sampark," "the Service," or "Services" means the enterprise communication and consultation platform, software applications, SDKs, APIs, administrative interfaces, websites, and related services provided by NoteG Technologies Pvt. Ltd.
"Tenant" means an individual customer environment, organization, deployment, or workspace configured within the Sampark platform.
"User" means any individual who accesses or uses the Services, including Administrative Users, End Users, and other authorized individuals.
| Company Name | NoteG Technologies Pvt. Ltd. ("NoteG", "we", "our", or "us") |
| Product Name | Sampark ("Sampark", the "Service", or the "Services") |
| Administrative Portal | https://admin.thesampark.com |
| Privacy and Support Contact | admin@thesampark.com |
| Data Protection Officer (DPO) | Simran Kashyap |
| Date of Joining: | 08 December 2025 |
| Effective Date | 03 July 2026 |
| Last Updated | 03 July 2026 |
Scope and Purpose
This Privacy Statement explains how Sampark receives, collects, uses, processes, stores, shares, retains, and protects personal data when individuals and organizations use Sampark's enterprise communication and consultation platform.
This Privacy Statement is intended to provide transparency regarding our privacy practices, the categories of personal data processed through the Services, the purposes for which such data is processed, the circumstances in which data may be shared, the safeguards applied to protect personal data, and the rights available to individuals under applicable privacy and data protection laws.
This Privacy Statement should be read together with any applicable customer agreement, Data Processing Addendum (DPA), Business Associate Agreement (BAA), or other contractual documentation governing a particular deployment of the Services.
Sampark is an enterprise Software-as-a-Service (SaaS) communication platform designed to support secure communication, collaboration, consultation, and administrative management across multiple deployment models.
Depending on the subscribed plan and tenant configuration, the Services may include:
The availability of individual features may vary depending on the customer's subscription, deployment model, tenant configuration, licensing, or administrative settings.
This Privacy Statement applies to individuals and organizations that interact with Sampark, including but not limited to:
Administrative UsersIndividuals authorized to administer or manage the Services, including:
Individuals using Sampark through a customer deployment, including consultation participants, agents, participants within customer applications, and other authorized users.
Internal PersonnelAuthorized NoteG support personnel and internal developers who may receive limited production access strictly where necessary to perform operational support, maintenance, security, reliability, troubleshooting, or other legitimate business functions.
Sampark is designed for worldwide deployment and may be used by organizations operating across multiple jurisdictions.
The Services support deployments in India, the European Union (EU), the United Kingdom (UK), California (United States), and other international regions, subject to customer requirements and applicable law.
Unless otherwise agreed with a customer, Sampark is hosted primarily within India.
Where supported and contractually agreed, regional hosting or dedicated infrastructure may be configured to satisfy customer, regulatory, operational, or contractual requirements.
The role performed by NoteG in relation to personal data depends on the nature of the deployment, the applicable contractual arrangements, and the manner in which the Services are used.
Standard Sampark DeploymentsFor Sampark's standard website, administrative platform, and application properties, NoteG Technologies Pvt. Ltd. acts as the default Controller for personal data processed through those properties unless a different allocation of responsibilities is expressly established by contract.
Enterprise, White-Label, Healthcare, and Education DeploymentsFor enterprise, white-label, healthcare, educational, or other dedicated customer deployments, the customer organization—such as a hospital, educational institution, enterprise, government body, or other organization—typically acts as the Controller for the personal data of its end users.
In such deployments, NoteG generally processes personal data solely on behalf of, and in accordance with, the documented instructions of the applicable customer, acting as a Processor under the applicable customer agreement and Data Processing Addendum (DPA).
Deployment-Specific ResponsibilitiesThe allocation of Controller and Processor responsibilities may differ depending on the deployment model, contractual commitments, and applicable law.
The specific privacy roles, processing responsibilities, and contractual obligations applicable to a particular deployment are governed by the relevant customer agreement, Data Processing Addendum (DPA), Business Associate Agreement (BAA), or other applicable contractual documentation, where relevant.
Sampark receives and processes personal data that is necessary to provide, operate, secure, maintain, and support the Services. The categories of personal data processed depend on the features used, the customer's deployment configuration, the user's role within the platform, and the manner in which the Services are utilized.
Personal data may be received from the following sources:
The categories of personal data processed are described below.
Depending on a user's role and the configuration established by the applicable organization or tenant, Sampark may process the following account and identity information:
This information is used to establish user identity, authenticate access, associate users with the appropriate organization or tenant, and enable authorized use of the Services.
Sampark implements Role-Based Access Control (RBAC) to manage permissions throughout the platform.
Depending on the deployment and feature in use, role information may include:
Organization RolesRole information is processed solely to determine authorization levels, enforce access controls, manage permissions, and enable functionality appropriate to a user's assigned responsibilities.
When scheduled meeting functionality is used, Sampark processes certain meeting-related information necessary to create, manage, and administer scheduled sessions.
Depending on the deployment and meeting configuration, participant information may include:
This information is used to:
Depending on the features used and the applicable tenant configuration, Sampark may receive, process, and store communications content generated through the Services.
Communications content may include:
Where communications content is stored by the platform, chat and call data are stored in encrypted form within the database.
Sampark supports secure file and media sharing between authorized users.
All file uploads are subject to authorization and validation procedures before being accepted by the platform.
Depending on the upload, associated metadata may include:
Uploaded media may be stored within Amazon Simple Storage Service (Amazon S3) using server-side encryption (AES-256).
When users request access to stored files, downloads are provided through short-lived pre-signed URLs with a default validity period of 900 seconds. Where applicable, these URLs may also be encrypted before being included in API responses returned to client applications.
Meeting recording functionality is available only where it is included within the applicable subscription plan and explicitly enabled for the tenant.
When recording functionality is enabled, recordings are made available through the administrative dashboard.
Recording data is stored using encryption, and access is protected through:
Only authorized users with the necessary permissions may access recording-related functionality.
Where Syntalix has been enabled for a tenant, Sampark may process communications content to generate AI-assisted outputs.
Depending on the enabled features, AI-generated outputs may include:
Additional information regarding AI processing, safeguards, and customer responsibilities is provided in the AI-Powered Features (Syntalix) section of this Privacy Statement.
Sampark provides administrative analytics and reporting capabilities intended to assist organizations in understanding platform usage and operational activity.
Depending on the tenant's configuration and enabled features, analytics may include:
Administrative reporting may also include aggregate information and operational listings, such as:
Analytics are intended to support operational administration, reporting, and platform management.
To maintain the security, integrity, availability, and reliable operation of the Services, Sampark processes certain diagnostic, security, and audit-related information.
Such information may include:
Audit logs are maintained using an append-only audit trail designed to minimize the logging of content-like information by filtering sensitive fields wherever applicable.
Sampark uses server-side session management supported by opaque identifiers stored within browser cookies.
The platform currently utilizes the following session cookies:
These cookie values contain only randomly generated session identifiers (UUIDs) and do not directly store personal information such as names, email addresses, phone numbers, user roles, authentication tokens, or similar account information.
Session state is maintained on the server, while the cookie functions solely as a reference to the corresponding server-side session.
When customers integrate the Sampark React JS SDK, certain tokens and session-related artifacts are stored within the browser's localStorage to support SDK initialization, authenticated API requests, and session continuity.
Depending on the implementation, local storage may contain:
Customers integrating the React JS SDK are responsible for implementing appropriate application-level security controls to help mitigate risks associated with browser-based storage.
Sampark may process information submitted in connection with customer support, technical assistance, product feedback, and administration of the Services.
Such information may include:
Support-related information is processed solely for purposes including customer assistance, issue resolution, service improvement, operational support, and administration of the Services.
Sampark processes personal data only for purposes that are necessary to provide, maintain, secure, support, and improve the Services, fulfill contractual obligations, comply with applicable legal requirements, and operate the platform in accordance with customer instructions where NoteG acts as a data processor.
The purposes for which personal data is processed depend on the features used, the deployment model, the customer's configuration, and the role performed by NoteG as either a Controller or Processor, as applicable.
Sampark processes personal data to provide the core functionality of the Services and to enable authorized users to access and use platform features.
This includes processing personal data to:
Personal data processed for these purposes is limited to what is reasonably necessary to deliver the requested Services.
Where meeting recording functionality is included within the customer's subscription plan and enabled for the applicable tenant, Sampark processes personal data necessary to:
Recording functionality is available only where enabled by the customer or tenant administrator.
Where Syntalix has been enabled for a tenant, Sampark processes communications content to generate AI-assisted outputs requested by the customer.
Depending on the enabled functionality, processing may be performed to provide:
AI processing is performed only for tenants where the feature has been enabled as part of the applicable plan and configuration.
Additional information regarding AI processing is provided in the AI-Powered Features (Syntalix) section of this Privacy Statement.
Sampark processes personal data to generate administrative analytics, operational dashboards, reports, and statistical information intended to assist organizations in managing their deployments.
Processing for these purposes may include:
Analytics are intended to support administrative oversight, operational management, capacity planning, and platform administration.
Sampark processes personal data as necessary to maintain the security, integrity, availability, and reliability of the Services.
This processing includes implementing technical and organizational measures designed to protect the platform and its users, including:
Security-related processing is also performed to detect, investigate, prevent, and respond to unauthorized access, abuse, misuse, malicious activity, and other security events affecting the Services.
Personal data may be processed to provide customer support, respond to technical inquiries, investigate reported issues, resolve service-related problems, and respond to privacy-related requests.
Where applicable, Sampark may also process personal data to deliver transactional communications necessary for operation of the Services, including verification workflows and authentication-related notifications where such functionality has been enabled.
Personal data may be processed where necessary to:
Processing for these purposes is performed only where permitted or required under applicable law.
Sampark does not sell customer personal data.
Personal data may be shared only in the circumstances described below and only where such sharing is necessary for the operation of the Services, required by law, authorized by the customer, or otherwise permitted under applicable contractual and legal obligations.
Where Sampark is deployed by an organization, personal data may be accessible to authorized administrators acting on behalf of that organization.
Access is provided in accordance with:
Administrators are responsible for managing user access and administrative activities within their respective deployments.
Sampark utilizes selected infrastructure and service providers that support the operation, delivery, and maintenance of the Services.
Current categories of subprocessors include:
| Provider / Category | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud storage for media and files using Amazon S3 with server-side encryption |
| Google Firebase Cloud Messaging (FCM) | Delivery of push notifications |
| Email delivery infrastructure | Delivery of transactional emails, including OTP and verification messages |
| Razorpay | Payment processing for applicable billing workflows within the administrative platform |
These providers process information only to the extent necessary to provide the applicable services supporting Sampark's operations.
The list of subprocessors may be updated from time to time. Where required by applicable law, customer agreements, or contractual commitments, material changes will be communicated through the appropriate notification mechanisms.
Enterprise customers, white-label customers, and other organizations may configure integrations with third-party systems or services.
Where a customer elects to enable such integrations, personal data shared through those integrations is governed by:
NoteG does not determine how customer-configured third-party integrations process information after it has been shared pursuant to the customer's instructions.
Personal data may be disclosed where necessary to:
Such disclosures are made only where permitted or required by applicable law.
Access to personal data within Sampark depends upon the user's assigned role, the applicable tenant configuration, the features being used, and the permissions established by authorized administrators.
Where applicable, access to sensitive administrative functionality may also be protected through Multi-Factor Authentication (MFA).
Depending on the deployment, personal data may be accessed by the following categories of individuals:
You may access personal data associated with your own account and communications, together with communications shared with participants who are authorized to access those interactions.
Authorized tenant administrators may access personal data within the scope of the permissions assigned to their administrative role and consistent with the applicable tenant configuration.
Administrative access is intended to support platform administration, operational management, user management, and other authorized administrative functions.
Authorized NoteG support personnel and internal developers may receive limited access to production environments only where such access is necessary to:
Such access is limited to what is reasonably necessary for the applicable purpose.
Where meeting recording functionality has been enabled, authorized administrators may access recording-related information through the administrative dashboard and analytics interfaces, subject to:
Syntalix provides AI-powered capabilities within Sampark that may assist organizations by generating analytical outputs from communications content where the feature has been enabled for the applicable tenant.
Depending on the enabled functionality, Syntalix may provide:
Syntalix is enabled on a tenant-by-tenant basis according to the customer's subscription plan and configuration.
AI-powered functionality is not enabled by default across all deployments.
In-House ProcessingAI-powered processing is performed using NoteG's in-house capabilities.
No External AI ProcessingCustomer communications content is not transmitted outside NoteG's infrastructure for AI processing.
No Solely Automated DecisionsSyntalix does not make solely automated decisions that produce legal effects or similarly significant effects concerning individuals within the meaning of Article 22 of the GDPR.
AI-generated outputs are intended solely to provide informational assistance and support human review, operational workflows, and administrative reporting.
AI Output Disclaimer and Human OversightAI-generated outputs, including sentiment analysis, transcriptions, summaries, and similar analytical content, are generated using automated processing techniques and are intended solely to assist authorized users and administrators.
Although reasonable efforts are made to produce useful outputs, AI-generated content may not always be complete, accurate, current, or free from errors.
Customers and authorized users remain responsible for exercising independent judgment and reviewing AI-generated outputs before relying upon them for operational, administrative, healthcare, educational, compliance, business, or other decision-making purposes.
AI-generated outputs should not be considered a substitute for professional judgment, independent verification, or human review.
Except to the extent required by applicable law or expressly agreed in writing, NoteG makes no representation or warranty regarding the accuracy, completeness, or suitability of AI-generated outputs for any specific purpose. Customers remain responsible for decisions, actions, and omissions arising from their use of AI-generated outputs and for ensuring that such outputs are used in accordance with applicable laws, regulations, contractual obligations, and internal organizational policies.
Where Syntalix is enabled, communications content is processed solely for the purpose of providing the AI-powered functionality requested by the applicable tenant. The applicable lawful basis for processing and the respective Controller or Processor role depend upon the deployment model and are governed by the relevant customer agreement and Data Processing Addendum (DPA), where applicable.
Sampark is used for telehealth and healthcare consultation use cases. Depending on the deployment and manner in which the Services are used, communications content processed through the platform may include health-related information.
Such information may constitute special-category personal data under the GDPR and sensitive personal data under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Enterprise Healthcare DeploymentsFor healthcare deployments, the customer organization—such as a hospital, clinic, healthcare provider, or health platform—typically acts as the Controller for health-related information and determines the applicable lawful basis and processing instructions.
In these deployments, NoteG generally acts as a Processor, processing personal data solely in accordance with the customer's documented instructions and the applicable customer agreement, including a HIPAA Business Associate Agreement (BAA), where required.
HIPAASampark is designed to support enterprise security and compliance practices and may be deployed in a manner aligned with HIPAA requirements, subject to appropriate customer configuration, administrative controls, and contractual commitments.
A HIPAA Business Associate Agreement (BAA) is available for eligible customers.
Where a BAA applies, NoteG addresses applicable HIPAA contractual obligations, including safeguards, breach notification obligations, and subprocessor requirements.
Other Healthcare DeploymentsFor healthcare deployments not governed by HIPAA, the applicable Controller—typically the customer organization—is responsible for establishing an appropriate lawful basis for processing health-related or other special-category personal data in accordance with applicable law.
Individuals seeking information regarding the processing of their health information should contact their healthcare provider or the organization that provisioned their access to Sampark, in addition to contacting NoteG at admin@thesampark.com.
This Privacy Statement does not constitute legal advice. Customers remain responsible for ensuring that their use of Sampark complies with HIPAA and all other applicable legal and regulatory requirements. Customers are encouraged to obtain independent legal advice regarding their obligations under the laws applicable to the jurisdictions in which they deploy or use the Services.
Sampark is committed to respecting applicable privacy and data protection rights. Subject to applicable law, the nature of the deployment, and NoteG's role as either a Controller or Processor, individuals may exercise certain rights regarding their personal data.
Privacy requests may be submitted by contacting us at admin@thesampark.com.
Depending on the applicable law and the circumstances of the processing, you may request to:
Because Sampark is a multi-tenant enterprise platform that is frequently deployed and administered by customer organizations, certain privacy requests may need to be coordinated with the applicable customer or tenant administrator. In many deployments, the customer organization acts as the Controller for end-user personal data, while NoteG acts as a Processor on the customer's documented instructions.
Accordingly, the fulfillment of certain requests may be subject to:
Where NoteG processes personal data solely on behalf of a customer, we may direct the requester to the appropriate customer organization or assist the customer in responding to the request in accordance with our contractual obligations.
Sampark is designed primarily for enterprise use and may also be deployed by educational institutions and organizations that provide services involving minors.
The applicable age at which parental or guardian consent may be required varies depending upon the jurisdiction in which the Services are used.
India (Digital Personal Data Protection Act, 2023)Under the Digital Personal Data Protection Act, 2023 (DPDP Act), a "child" is an individual who is under 18 years of age.
Where applicable, processing a child's personal data requires verifiable parental consent in accordance with the DPDP Act and applicable rules. The DPDP Act also restricts tracking and targeted advertising directed toward children.
European Economic Area (EEA) and United KingdomWithin the European Economic Area and the United Kingdom, the age below which parental consent may be required for information society services generally ranges between 13 and 16 years of age, depending on the applicable jurisdiction.
United States (COPPA)Where the Children's Online Privacy Protection Act (COPPA) applies, additional protections apply to the processing of personal information relating to children under the age of 13.
Education DeploymentsWhere Sampark is deployed by schools, colleges, universities, educational institutions, or other education providers, the applicable educational organization generally acts as the Controller for student personal data, while NoteG acts as a Processor on the organization's documented instructions.
Additional information regarding education deployments is provided in the Children's Education Privacy Statement contained within this Privacy Statement.
Sampark retains personal data only for as long as necessary to provide the Services, fulfill contractual commitments, comply with applicable legal obligations, support legitimate business operations, and maintain the security, integrity, and reliability of the platform.
The retention period applicable to a particular category of personal data depends upon several factors, including:
Where supported by the applicable deployment, customers may configure shorter or longer retention periods for certain categories of data in accordance with their operational requirements and applicable law.
Implemented Retention Details| Data Type | Retention |
|---|---|
| Administrative session cookie | Maximum lifetime of 12 hours (opaque identifier only; session state maintained server-side) |
| Application session cookie | Maximum lifetime of 30 days (opaque identifier only; session state maintained server-side) |
| File download links | Short-lived pre-signed URLs with a default validity period of 900 seconds |
| Audit logs | Configurable; default retention of 2,190 days (6 years), unless modified through environment configuration |
| Chat content, call content, and meeting recordings | Governed by the applicable tenant plan, customer agreement, and configured retention settings |
Specific retention periods applicable to communications content, recordings, and other tenant-configurable data categories are documented in the applicable customer-facing plan documentation, contractual agreements, and the Data Processing Addendum (DPA), where applicable.
NoteG maintains technical and organizational security measures designed to protect personal data against unauthorized access, disclosure, alteration, destruction, and other security risks.
If a personal data breach occurs, NoteG will respond in accordance with applicable law, contractual commitments, and the nature of the affected deployment.
Suspected privacy or security incidents may be reported to:
admin@thesampark.com
Where applicable, breach notifications may include the following:
GDPR and UK GDPRWhere required under the GDPR or UK GDPR, NoteG will notify the competent supervisory authority within the applicable statutory timeframe after becoming aware of a personal data breach.
Where required by applicable law, affected individuals will also be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
India (Digital Personal Data Protection Act, 2023)Where applicable under the DPDP Act and related rules, NoteG will notify the Data Protection Board of India and affected Data Principals without undue delay, in accordance with applicable legal requirements.
HIPAAFor deployments operating under a Business Associate Agreement (BAA), breach notification obligations are performed in accordance with the applicable BAA and HIPAA requirements.
Incident ResponseOur incident response procedures are designed to support the timely identification, assessment, containment, investigation, remediation, documentation, and notification of security incidents, consistent with applicable legal obligations and contractual commitments.
We may update this Privacy Statement from time to time to reflect changes in:
When material changes are made to this Privacy Statement, we will update the Effective Date and Last Updated date shown at the beginning of this document.
Where appropriate, notice of material changes may also be provided through the Sampark website, administrative interfaces, customer communications, or other appropriate channels, consistent with applicable law and contractual obligations.
The most current version of this Privacy Statement supersedes all previous versions and governs the collection, use, disclosure, retention, and protection of personal data from the date it becomes effective.
This section supplements the Privacy Statement and applies to individuals located within the European Economic Area (EEA) and, where applicable, the United Kingdom.
Where personal data is processed in connection with the Services and the GDPR or UK GDPR applies, NoteG processes personal data in accordance with the applicable legal requirements and the respective roles of the parties as Controller or Processor.
Depending on the nature of the processing activity and the deployment model, Sampark processes personal data under one or more of the following lawful bases:
Performance of a ContractProcessing is necessary to provide, operate, maintain, and support the Services requested by a customer organization or an authorized user, including fulfilling contractual obligations under the applicable customer agreement.
Legitimate InterestsProcessing is necessary for NoteG's legitimate interests in operating, securing, maintaining, improving, and protecting the Services, including preventing fraud, abuse, unauthorized access, and other activities that may affect the security, integrity, or reliability of the platform, provided that such interests are not overridden by the rights and freedoms of the data subject.
ConsentWhere required by applicable law, personal data is processed based on the individual's consent for specific processing activities. Where processing relies on consent, such consent may be withdrawn in accordance with applicable legal requirements.
Legal ObligationProcessing may also be necessary to comply with applicable laws, regulatory requirements, lawful governmental requests, court orders, or other legal obligations.
Special-Category Personal DataWhere the processing involves special-category personal data, including health-related information, the applicable Controller is responsible for determining the appropriate lawful basis and Article 9 condition under the GDPR.
For enterprise healthcare deployments, NoteG generally processes such personal data solely as a Processor acting on the documented instructions of the applicable customer.
By default, Sampark is hosted in India. Depending on customer requirements and deployment configurations, regional hosting may also be available.
Where personal data originating from the European Economic Area or the United Kingdom is transferred to India or another jurisdiction that has not received an adequacy decision under applicable law, NoteG implements appropriate safeguards to support lawful international data transfers.
Such safeguards may include:
Deployment-specific transfer mechanisms, subprocessors, technical safeguards, and transfer-related documentation are described in the applicable customer agreement, Data Processing Addendum (DPA), and associated transfer impact assessment materials where applicable.
Subject to the GDPR, UK GDPR, and other applicable laws, individuals may have rights regarding the processing of their personal data, including the right to:
Requests relating to these rights may be submitted to:
admin@thesampark.com
Where applicable, individuals may also lodge a complaint with the competent supervisory authority in their jurisdiction.
This section supplements the Privacy Statement for individuals who are protected under applicable United States state privacy laws, including the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable state privacy legislation.
Depending upon the manner in which Sampark is used and the applicable tenant configuration, the categories of personal information described below may be collected and processed for the purposes identified in this Privacy Statement.
Depending on the Services used and customer configuration, Sampark may process the following categories of personal information:
IdentifiersWhere applicable, Sampark may process sensitive personal information, including:
The categories of information processed depend upon the Services used and the applicable deployment configuration.
Personal information is processed for purposes including:
Sampark does not sell customer personal information.
Sampark also does not share personal information for cross-context behavioral advertising.
Where customers choose to enable integrations with third-party systems, any sharing of information through those integrations occurs pursuant to the customer's configuration and applicable contractual arrangements.
Where applicable under the CCPA, CPRA, or other U.S. state privacy laws, individuals may have rights including:
Because Sampark does not sell personal information or share personal information for cross-context behavioral advertising, requests to opt out of such activities are generally not applicable.
Privacy requests may be submitted to:
admin@thesampark.com
Where required by applicable law, qualifying requests relating to the limitation of the use or disclosure of sensitive personal information will be honored in accordance with legal requirements.
Where permitted under applicable law, requests may be submitted by an authorized agent acting on behalf of an individual.
Authorized agents may be required to provide written authorization or other information reasonably necessary to verify both the identity of the individual and the authority of the authorized agent before the request is fulfilled.
Requests from authorized agents may be submitted to:
admin@thesampark.com
NoteG will not unlawfully discriminate against any individual for exercising rights available under applicable privacy laws.
The exercise of privacy rights will not result in discriminatory treatment except as otherwise permitted by applicable law.
This section applies where Sampark is deployed by schools, colleges, universities, educational institutions, or other organizations providing educational services involving students, including minors.
For education deployments, the applicable educational institution or organization generally acts as the Controller for student personal data.
NoteG acts as a Processor, processing student personal data solely in accordance with the documented instructions of the applicable educational organization and the governing customer agreement and Data Processing Addendum (DPA).
Depending upon the deployment configuration, Sampark may process:
Student personal data is processed for purposes including:
Student personal data may be shared only as necessary:
Authorized educational administrators may access information made available through the administrative dashboards, reporting interfaces, analytics tools, and other features enabled for their deployment, subject to role-based permissions and applicable access controls.
Requests relating to student personal data may be submitted to:
admin@thesampark.com
Depending on the deployment, requests may also be handled through the administrative processes established by the applicable educational institution.
Under India's Digital Personal Data Protection Act, 2023, verifiable parental consent is required before processing the personal data of a child.
Educational institutions and other education customers are responsible for obtaining any parental or guardian consents required under applicable law before using the Services.
NoteG does not engage in tracking or targeted advertising directed toward children.
This section supplements the Privacy Statement for individuals whose personal data is processed in India and addresses applicable requirements under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and any applicable rules issued thereunder.
Sampark is operated by NoteG Technologies Pvt. Ltd. and, unless otherwise agreed with a customer, is hosted in India by default.
The processing of personal data through Sampark is governed by applicable Indian laws, including the Digital Personal Data Protection Act, 2023 (DPDP Act), together with any other applicable legal or regulatory requirements.
This section should be read together with the remainder of this Privacy Statement.
The categories of personal data processed through Sampark are described in the "What Personal Data Do We Receive?" section of this Privacy Statement.
Depending on the Services used and the applicable deployment, these categories may include:
Personal data is processed for the purposes described throughout this Privacy Statement.
Where applicable under the DPDP Act, processing may be based upon:
The applicable lawful basis depends upon the nature of the deployment, the purpose of processing, and the role performed by NoteG or the applicable customer.
Subject to the DPDP Act and applicable legal requirements, Data Principals may have rights including:
Requests relating to these rights may be submitted to:
admin@thesampark.com
Where required, requests may be subject to identity verification and other applicable legal or contractual requirements.
Privacy-related grievances concerning the processing of personal data under the DPDP Act may be submitted to:
Email: admin@thesampark.com
We will acknowledge and address grievances in accordance with the requirements of the DPDP Act and applicable rules.
Where a formal Grievance Officer is appointed, NoteG will publish the name and designation of the appointed Grievance Officer through the appropriate communication channels.
Where applicable under the DPDP Act, Data Principals may also approach the Data Protection Board of India for remedies available under applicable law.
Information regarding breach notification practices is provided in the Data Breach Notification section of this Privacy Statement.
Where required under the DPDP Act and applicable rules, NoteG will notify the Data Protection Board of India and affected Data Principals without undue delay.
Unless otherwise agreed with a customer, personal data is stored and processed in India by default.
Regional hosting may be configured where supported and requested by the customer.
Security measures implemented by Sampark include, among other things:
Additional information regarding security controls is provided in the Security Measures section of this Privacy Statement.
What Are Cookies?
Cookies are small text files that are stored on a user's device by a web browser.
Sampark currently uses cookies primarily to support authentication, session management, and the secure operation of the Services.
1. Administrative Session Cookie
| Cookie Name | sampark_admin_session_id |
| Purpose | Maintains authenticated administrative sessions, supports restoration of server-side session state, and facilitates administrative session API response encryption. |
| Stored Value | A randomly generated opaque session identifier (UUID). |
| Characteristics |
HTTPOnly Secure in production SameSite=None in production SameSite=Lax in non-production environments Maximum lifetime of 12 hours |
| Cookie Name | sampark_session_id |
| Purpose | Maintains authenticated application user sessions and supports restoration of server-side session state. |
| Stored Value | A randomly generated opaque session identifier (UUID). |
| Characteristics |
HTTPOnly SameSite=Lax Maximum lifetime of 30 days |
The cookie values used by Sampark do not directly store:
Session information is maintained on the server. Cookie values function solely as identifiers used to reference the corresponding server-side session.
| Category | Description |
|---|---|
| Core / Necessary | Session cookies required for authentication and operation of authenticated platform functionality. |
| Technical Performance | Supports operational reliability, diagnostics, and security-related platform functionality. |
| Enhanced Functionality | Supports session restoration and administrative response encryption functionality. |
| Analytics | Platform analytics are provided through administrative reporting. The session cookies described above are not advertising analytics cookies. Should additional analytics cookies be introduced in the future, this Cookie Statement and applicable consent mechanisms will be updated where required by law. |
| Social Media | Not currently implemented. |
| Advertising | Not currently implemented. |
Users may manage or disable cookies through their browser settings.
Disabling cookies may affect authentication, session management, and other functionality required for the proper operation of the Services.
Where applicable, Sampark honors Global Privacy Control (GPC) signals in a manner consistent with applicable law and our cookie practices.
Certain browsers transmit "Do Not Track" (DNT) signals.
Because there is currently no universally accepted industry standard governing responses to DNT signals, Sampark continues to use necessary session cookies required for the operation and security of the Services.
Questions, privacy requests, or concerns regarding this Privacy Statement may be submitted to:
Email: admin@thesampark.com
This Privacy Statement and the accompanying Cookie Statement may be updated from time to time to reflect changes to our Services, legal obligations, operational practices, or cookie usage.
Where material changes are made, we will update the applicable revision dates and provide notice where required by applicable law or contractual commitments.
Healthcare
Sampark supports telehealth and healthcare use cases.
Additional information regarding the processing of health-related information, HIPAA, and healthcare deployments is provided in the Health and Special-Category Data section of this Privacy Statement.
A HIPAA Business Associate Agreement (BAA) is available for eligible customers.
EducationInformation relating to education deployments, student privacy, and the processing of student personal data is provided in the Children's Education Privacy Statement contained within this Privacy Statement.
| Framework | Reference |
|---|---|
| GDPR | European Data Protection Specific Information |
| UK GDPR | European Data Protection Specific Information |
| CCPA / CPRA | California and Other U.S. State Privacy Notice |
| Digital Personal Data Protection Act, 2023 (India) | India Privacy Statement |
| Global Data Processing Addendum (DPA) | Available for eligible enterprise customers and incorporates the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) and/or UK Addendum, where applicable. |
| Subprocessors | Current subprocessors are identified in the How Do We Share Personal Data? section of this Privacy Statement and may be updated as service providers change. |
| Transfer Impact Assessments | Deployment-specific information relating to international transfers, subprocessors, safeguards, and applicable transfer mechanisms is documented within the applicable Data Processing Addendum (DPA) and associated transfer impact assessment materials, where applicable. |
Where required by applicable law, Sampark may respond to lawful requests received from courts, regulators, law enforcement agencies, or other competent governmental authorities.
Requests are evaluated and handled in accordance with applicable legal obligations, contractual commitments, and established security practices.
Sampark implements technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Current security measures include:
Subject to applicable confidentiality obligations, security assessment summaries, penetration testing summaries, and certain security documentation may be made available under a Non-Disclosure Agreement (NDA) or through other controlled access arrangements upon request.