Privacy Policy

1. Sampark Privacy Policy

For the purposes of this Privacy Statement, the following terms shall have the meanings set out below. Unless otherwise defined, capitalized terms used throughout this Privacy Statement shall have the meanings assigned in this section.

"Account" means an account created to access or administer the Services, including administrative and end-user accounts where applicable.

"Administrative User" means any individual authorized to administer or manage a Sampark deployment, including platform administrators, enterprise administrators, billing administrators, desk administrators, desk agents, support personnel, or any other authorized administrative role.

"AI Features" or "Syntalix" means the AI-powered capabilities provided within Sampark, including functionality such as sentiment analysis, transcription, summaries, and other AI-assisted features that may be enabled for a tenant.

"Applicable Law" means all laws, regulations, regulatory requirements, governmental orders, and legally binding obligations applicable to the processing of personal data, including, where relevant, the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), HIPAA, and other applicable privacy or data protection laws.

"Controller" means the natural or legal person that determines the purposes and means of processing personal data, or an equivalent term under applicable privacy laws.

"Customer" means the organization, enterprise, institution, healthcare provider, educational institution, or other entity that subscribes to, licenses, or deploys Sampark for its users.

"Data Processing Addendum (DPA)" means the contractual agreement governing the processing of personal data between NoteG and a Customer where applicable.

"End User" means an individual authorized to use the Services through a Customer deployment, including agents, participants, consultation attendees, or other users accessing Sampark.

"Organization" means any Customer, enterprise, healthcare provider, educational institution, government entity, or other legal entity using Sampark.

"Personal Data" means any information relating to an identified or identifiable natural person, or any equivalent concept recognized under applicable privacy legislation.

"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, storage, use, disclosure, transmission, analysis, retrieval, deletion, or destruction.

"Processor" means the natural or legal person that processes personal data on behalf of a Controller, or an equivalent term under applicable privacy laws.

"Sampark," "the Service," or "Services" means the enterprise communication and consultation platform, software applications, SDKs, APIs, administrative interfaces, websites, and related services provided by NoteG Technologies Pvt. Ltd.

"Tenant" means an individual customer environment, organization, deployment, or workspace configured within the Sampark platform.

"User" means any individual who accesses or uses the Services, including Administrative Users, End Users, and other authorized individuals.

2. Privacy Resources

Company Name NoteG Technologies Pvt. Ltd. ("NoteG", "we", "our", or "us")
Product Name Sampark ("Sampark", the "Service", or the "Services")
Administrative Portal https://admin.thesampark.com
Privacy and Support Contact admin@thesampark.com
Data Protection Officer (DPO) Simran Kashyap
Date of Joining: 08 December 2025
Effective Date 03 July 2026
Last Updated 03 July 2026

3. Privacy Statement

Scope and Purpose

This Privacy Statement explains how Sampark receives, collects, uses, processes, stores, shares, retains, and protects personal data when individuals and organizations use Sampark's enterprise communication and consultation platform.

This Privacy Statement is intended to provide transparency regarding our privacy practices, the categories of personal data processed through the Services, the purposes for which such data is processed, the circumstances in which data may be shared, the safeguards applied to protect personal data, and the rights available to individuals under applicable privacy and data protection laws.

This Privacy Statement should be read together with any applicable customer agreement, Data Processing Addendum (DPA), Business Associate Agreement (BAA), or other contractual documentation governing a particular deployment of the Services.

4. Product Capabilities

Sampark is an enterprise Software-as-a-Service (SaaS) communication platform designed to support secure communication, collaboration, consultation, and administrative management across multiple deployment models.

Depending on the subscribed plan and tenant configuration, the Services may include:

  • Chat and one-to-one messaging
  • Group chat
  • Media sharing
  • File sharing
  • Voice calling
  • Video calling
  • Screen sharing
  • Waiting rooms
  • Scheduled meetings
  • Push notifications
  • AI-powered features (Syntalix)
  • Analytics and administrative reporting
  • Administrative dashboard and management tools
  • Multi-tenant SaaS deployments
  • White-label deployments
  • Dedicated enterprise deployments, including region-specific deployments where available upon customer request

The availability of individual features may vary depending on the customer's subscription, deployment model, tenant configuration, licensing, or administrative settings.

5. Who This Privacy Statement Applies To

This Privacy Statement applies to individuals and organizations that interact with Sampark, including but not limited to:

Administrative Users

Individuals authorized to administer or manage the Services, including:

  • Platform Administrators
  • Enterprise Administrators
  • Billing Administrators
  • Desk Administrators
  • Desk Agents
  • Support Personnel
End Users

Individuals using Sampark through a customer deployment, including consultation participants, agents, participants within customer applications, and other authorized users.

Internal Personnel

Authorized NoteG support personnel and internal developers who may receive limited production access strictly where necessary to perform operational support, maintenance, security, reliability, troubleshooting, or other legitimate business functions.

6. Availability and Hosting

Sampark is designed for worldwide deployment and may be used by organizations operating across multiple jurisdictions.

The Services support deployments in India, the European Union (EU), the United Kingdom (UK), California (United States), and other international regions, subject to customer requirements and applicable law.

Unless otherwise agreed with a customer, Sampark is hosted primarily within India.

Where supported and contractually agreed, regional hosting or dedicated infrastructure may be configured to satisfy customer, regulatory, operational, or contractual requirements.

7. Privacy Roles (Controller and Processor)

The role performed by NoteG in relation to personal data depends on the nature of the deployment, the applicable contractual arrangements, and the manner in which the Services are used.

Standard Sampark Deployments

For Sampark's standard website, administrative platform, and application properties, NoteG Technologies Pvt. Ltd. acts as the default Controller for personal data processed through those properties unless a different allocation of responsibilities is expressly established by contract.

Enterprise, White-Label, Healthcare, and Education Deployments

For enterprise, white-label, healthcare, educational, or other dedicated customer deployments, the customer organization—such as a hospital, educational institution, enterprise, government body, or other organization—typically acts as the Controller for the personal data of its end users.

In such deployments, NoteG generally processes personal data solely on behalf of, and in accordance with, the documented instructions of the applicable customer, acting as a Processor under the applicable customer agreement and Data Processing Addendum (DPA).

Deployment-Specific Responsibilities

The allocation of Controller and Processor responsibilities may differ depending on the deployment model, contractual commitments, and applicable law.

The specific privacy roles, processing responsibilities, and contractual obligations applicable to a particular deployment are governed by the relevant customer agreement, Data Processing Addendum (DPA), Business Associate Agreement (BAA), or other applicable contractual documentation, where relevant.

8. What Personal Data Do We Receive?

Sampark receives and processes personal data that is necessary to provide, operate, secure, maintain, and support the Services. The categories of personal data processed depend on the features used, the customer's deployment configuration, the user's role within the platform, and the manner in which the Services are utilized.

Personal data may be received from the following sources:

  • Data provided directly by users, such as when users sign in, create or update a profile, schedule a meeting, send messages, share files or media, or contact our support team.
  • Data generated through use of the Services, including chat and call records, meeting events, analytics, and AI-generated outputs where AI-powered features have been enabled for the applicable tenant.
  • Data received from devices, browsers, applications, and integrations, including push notification tokens, network-related information, and diagnostic data required for service operation and troubleshooting.

The categories of personal data processed are described below.

9. Account and Identity Data

Depending on a user's role and the configuration established by the applicable organization or tenant, Sampark may process the following account and identity information:

  • User identifiers, including Sampark user IDs and/or customer application user IDs.
  • Organization identifiers.
  • Application identifiers.
  • Display information, such as names used within chats, meetings, and other communication features. For chat media uploads, the uploader's display name is stored in encrypted form within the database.
  • Verification and authentication status, including information relating to email verification processes and One-Time Password (OTP) authentication flows where such functionality has been enabled.

This information is used to establish user identity, authenticate access, associate users with the appropriate organization or tenant, and enable authorized use of the Services.

10. Authorization and Role Data

Sampark implements Role-Based Access Control (RBAC) to manage permissions throughout the platform.

Depending on the deployment and feature in use, role information may include:

Organization Roles
  • Admin
  • Billing
  • Desk Admin
  • Desk Agent
Group Chat Roles
  • Owner
  • Admin
  • Moderator
  • Participant
Application Session Roles
  • NONE
  • AGENT
  • PARTICIPANT
  • AGENT_PARTICIPANT

Role information is processed solely to determine authorization levels, enforce access controls, manage permissions, and enable functionality appropriate to a user's assigned responsibilities.

11. Meeting and Scheduling Data

When scheduled meeting functionality is used, Sampark processes certain meeting-related information necessary to create, manage, and administer scheduled sessions.

Depending on the deployment and meeting configuration, participant information may include:

  • User ID
  • Host indicator

This information is used to:

  • Schedule meetings.
  • Identify meeting hosts.
  • Determine host permissions.
  • Generate meeting URLs.
  • Manage participant access and meeting entry permissions.

12. Communications Content

Depending on the features used and the applicable tenant configuration, Sampark may receive, process, and store communications content generated through the Services.

Communications content may include:

  • One-to-one chat messages.
  • Group chat messages.
  • Files and media shared through chat.
  • Voice and video call metadata.
  • Meeting metadata, including call type, communication mode, call status, timestamps, and duration.

Where communications content is stored by the platform, chat and call data are stored in encrypted form within the database.

13. Chat Files and Media

Sampark supports secure file and media sharing between authorized users.

All file uploads are subject to authorization and validation procedures before being accepted by the platform.

Depending on the upload, associated metadata may include:

  • File ID
  • Original filename
  • File size
  • MIME type
  • Message ID
  • Room ID
  • Uploader ID
  • Other operational attributes required for platform functionality

Uploaded media may be stored within Amazon Simple Storage Service (Amazon S3) using server-side encryption (AES-256).

When users request access to stored files, downloads are provided through short-lived pre-signed URLs with a default validity period of 900 seconds. Where applicable, these URLs may also be encrypted before being included in API responses returned to client applications.

14. Meeting Recordings

Meeting recording functionality is available only where it is included within the applicable subscription plan and explicitly enabled for the tenant.

When recording functionality is enabled, recordings are made available through the administrative dashboard.

Recording data is stored using encryption, and access is protected through:

  • Role-based access controls.
  • Multi-Factor Authentication (MFA), where applicable.

Only authorized users with the necessary permissions may access recording-related functionality.

15. AI-Generated Outputs (Where Syntalix Is Enabled)

Where Syntalix has been enabled for a tenant, Sampark may process communications content to generate AI-assisted outputs.

Depending on the enabled features, AI-generated outputs may include:

  • Sentiment analysis.
  • Transcriptions.
  • Summaries.

Additional information regarding AI processing, safeguards, and customer responsibilities is provided in the AI-Powered Features (Syntalix) section of this Privacy Statement.

16. Analytics and Usage Data

Sampark provides administrative analytics and reporting capabilities intended to assist organizations in understanding platform usage and operational activity.

Depending on the tenant's configuration and enabled features, analytics may include:

  • User analytics.
  • Chat analytics.
  • Call analytics.
  • Scheduled meeting analytics.
  • Call recording analytics.

Administrative reporting may also include aggregate information and operational listings, such as:

  • Participant counts.
  • Message distribution metrics.
  • Call distribution metrics.
  • Call duration metrics.
  • Recording metadata, including room ID, start time, duration, communication mode, status, call type, and output file references.

Analytics are intended to support operational administration, reporting, and platform management.

17. Diagnostic, Security, and Audit Data

To maintain the security, integrity, availability, and reliable operation of the Services, Sampark processes certain diagnostic, security, and audit-related information.

Such information may include:

  • IP addresses.
  • Request metadata used for security controls, rate limiting, abuse prevention, troubleshooting, and operational diagnostics.
  • Security event information, including authentication failures, authorization failures, access denials, and rate-limit events.
  • Audit log events generated through platform operations.

Audit logs are maintained using an append-only audit trail designed to minimize the logging of content-like information by filtering sensitive fields wherever applicable.

18. Cookies and Session Identifiers

Sampark uses server-side session management supported by opaque identifiers stored within browser cookies.

The platform currently utilizes the following session cookies:

  • sampark_admin_session_id — administrative session identifier.
  • sampark_session_id — application user session identifier.

These cookie values contain only randomly generated session identifiers (UUIDs) and do not directly store personal information such as names, email addresses, phone numbers, user roles, authentication tokens, or similar account information.

Session state is maintained on the server, while the cookie functions solely as a reference to the corresponding server-side session.

19. Browser Local Storage (React JS SDK)

When customers integrate the Sampark React JS SDK, certain tokens and session-related artifacts are stored within the browser's localStorage to support SDK initialization, authenticated API requests, and session continuity.

Depending on the implementation, local storage may contain:

  • sampark_access_token
  • sampark_refresh_token
  • sampark_renew_token
  • sampark_loggedin_user (containing the user ID and display name)

Customers integrating the React JS SDK are responsible for implementing appropriate application-level security controls to help mitigate risks associated with browser-based storage.

20. Support, Feedback, and Website Data

Sampark may process information submitted in connection with customer support, technical assistance, product feedback, and administration of the Services.

Such information may include:

  • Information submitted through communications sent to admin@thesampark.com.
  • Troubleshooting information and diagnostic artifacts necessary to investigate and resolve reported issues, limited to what is reasonably required for that purpose.
  • Product feedback, bug reports, feature requests, and issue reports submitted through available support or product communication channels.
  • Standard request metadata generated through interactions with the administrative website and application interfaces.

Support-related information is processed solely for purposes including customer assistance, issue resolution, service improvement, operational support, and administration of the Services.

21. How Do We Use Personal Data?

Sampark processes personal data only for purposes that are necessary to provide, maintain, secure, support, and improve the Services, fulfill contractual obligations, comply with applicable legal requirements, and operate the platform in accordance with customer instructions where NoteG acts as a data processor.

The purposes for which personal data is processed depend on the features used, the deployment model, the customer's configuration, and the role performed by NoteG as either a Controller or Processor, as applicable.

22. Provide and Operate the Services

Sampark processes personal data to provide the core functionality of the Services and to enable authorized users to access and use platform features.

This includes processing personal data to:

  • Create, maintain, and manage server-side user sessions referenced through opaque session cookies.
  • Authenticate users and verify user identity using supported authentication mechanisms.
  • Authorize access through role-based access controls.
  • Deliver one-to-one chat and group chat functionality.
  • Enable media and file sharing.
  • Provide voice and video calling.
  • Support screen sharing functionality.
  • Operate waiting rooms.
  • Schedule and manage meetings.
  • Provide administrative dashboard functionality.
  • Deliver other features available under the applicable subscription plan and tenant configuration.

Personal data processed for these purposes is limited to what is reasonably necessary to deliver the requested Services.

23. Enable Meeting Recordings (Where Configured and Purchased)

Where meeting recording functionality is included within the customer's subscription plan and enabled for the applicable tenant, Sampark processes personal data necessary to:

  • Generate meeting recordings.
  • Store recording outputs using encrypted storage.
  • Make recordings available through the administrative dashboard.
  • Enforce access controls using role-based permissions and Multi-Factor Authentication (MFA), where applicable.

Recording functionality is available only where enabled by the customer or tenant administrator.

24. Provide AI-Powered Features (Where Enabled)

Where Syntalix has been enabled for a tenant, Sampark processes communications content to generate AI-assisted outputs requested by the customer.

Depending on the enabled functionality, processing may be performed to provide:

  • Sentiment analysis.
  • Speech transcription.
  • Conversation summaries.

AI processing is performed only for tenants where the feature has been enabled as part of the applicable plan and configuration.

Additional information regarding AI processing is provided in the AI-Powered Features (Syntalix) section of this Privacy Statement.

25. Analytics and Administrative Reporting

Sampark processes personal data to generate administrative analytics, operational dashboards, reports, and statistical information intended to assist organizations in managing their deployments.

Processing for these purposes may include:

  • Generating user analytics.
  • Producing chat and messaging analytics.
  • Producing call and meeting analytics.
  • Providing scheduled meeting reports.
  • Generating call recording analytics.
  • Supporting operational reporting through dashboard views and administrative listings.

Analytics are intended to support administrative oversight, operational management, capacity planning, and platform administration.

26. Security, Integrity, and Fraud Prevention

Sampark processes personal data as necessary to maintain the security, integrity, availability, and reliability of the Services.

This processing includes implementing technical and organizational measures designed to protect the platform and its users, including:

  • Security headers.
  • Rate limiting.
  • Input validation and sanitization.
  • Cross-Origin Resource Sharing (CORS) allow-list enforcement.
  • Audit logging practices designed to reduce the logging of message content and other sensitive information.

Security-related processing is also performed to detect, investigate, prevent, and respond to unauthorized access, abuse, misuse, malicious activity, and other security events affecting the Services.

27. Support and Customer Communications

Personal data may be processed to provide customer support, respond to technical inquiries, investigate reported issues, resolve service-related problems, and respond to privacy-related requests.

Where applicable, Sampark may also process personal data to deliver transactional communications necessary for operation of the Services, including verification workflows and authentication-related notifications where such functionality has been enabled.

28. Legal Compliance and Enforcement

Personal data may be processed where necessary to:

  • Comply with applicable laws, regulations, governmental requests, or legal obligations.
  • Respond to lawful requests from competent authorities.
  • Enforce customer agreements, contractual obligations, platform policies, and applicable terms.
  • Detect, prevent, investigate, or address fraudulent, unlawful, harmful, or unauthorized activities affecting the Services, our customers, or other users.

Processing for these purposes is performed only where permitted or required under applicable law.

29. How Do We Share Personal Data?

Sampark does not sell customer personal data.

Personal data may be shared only in the circumstances described below and only where such sharing is necessary for the operation of the Services, required by law, authorized by the customer, or otherwise permitted under applicable contractual and legal obligations.

30. With Your Organization and Authorized Administrators

Where Sampark is deployed by an organization, personal data may be accessible to authorized administrators acting on behalf of that organization.

Access is provided in accordance with:

  • The administrator's assigned permissions.
  • The applicable tenant configuration.
  • The organization's administrative policies.
  • Role-based access controls implemented within the platform.

Administrators are responsible for managing user access and administrative activities within their respective deployments.

31. With Service Providers (Subprocessors)

Sampark utilizes selected infrastructure and service providers that support the operation, delivery, and maintenance of the Services.

Current categories of subprocessors include:

Provider / Category Purpose
Amazon Web Services (AWS) Cloud storage for media and files using Amazon S3 with server-side encryption
Google Firebase Cloud Messaging (FCM) Delivery of push notifications
Email delivery infrastructure Delivery of transactional emails, including OTP and verification messages
Razorpay Payment processing for applicable billing workflows within the administrative platform

These providers process information only to the extent necessary to provide the applicable services supporting Sampark's operations.

The list of subprocessors may be updated from time to time. Where required by applicable law, customer agreements, or contractual commitments, material changes will be communicated through the appropriate notification mechanisms.

32. With Third Parties Under Customer Direction

Enterprise customers, white-label customers, and other organizations may configure integrations with third-party systems or services.

Where a customer elects to enable such integrations, personal data shared through those integrations is governed by:

  • The customer's configuration.
  • The applicable contractual arrangements.
  • The customer's own privacy practices and policies.

NoteG does not determine how customer-configured third-party integrations process information after it has been shared pursuant to the customer's instructions.

33. For Legal, Safety, and Protection Purposes

Personal data may be disclosed where necessary to:

  • Comply with applicable law.
  • Respond to lawful governmental or regulatory requests.
  • Protect the rights, property, security, or integrity of NoteG, Sampark, customers, users, or the public.
  • Investigate suspected unlawful activity.
  • Enforce contractual obligations, platform policies, or applicable terms of service.

Such disclosures are made only where permitted or required by applicable law.

34. Who Can See, Share, and Process My Personal Data?

Access to personal data within Sampark depends upon the user's assigned role, the applicable tenant configuration, the features being used, and the permissions established by authorized administrators.

Where applicable, access to sensitive administrative functionality may also be protected through Multi-Factor Authentication (MFA).

Depending on the deployment, personal data may be accessed by the following categories of individuals:

35. You and the Individuals With Whom You Communicate

You may access personal data associated with your own account and communications, together with communications shared with participants who are authorized to access those interactions.

36. Tenant Administrators

Authorized tenant administrators may access personal data within the scope of the permissions assigned to their administrative role and consistent with the applicable tenant configuration.

Administrative access is intended to support platform administration, operational management, user management, and other authorized administrative functions.

37. NoteG Support Personnel and Internal Developers

Authorized NoteG support personnel and internal developers may receive limited access to production environments only where such access is necessary to:

  • Provide customer support.
  • Investigate technical issues.
  • Maintain platform security.
  • Ensure service reliability.
  • Fulfill contractual obligations.
  • Perform other legitimate operational activities.

Such access is limited to what is reasonably necessary for the applicable purpose.

38. Access to Meeting Recordings

Where meeting recording functionality has been enabled, authorized administrators may access recording-related information through the administrative dashboard and analytics interfaces, subject to:

  • Tenant-specific permissions.
  • Role-based access controls.
  • Multi-Factor Authentication (MFA), where applicable.

39. AI-Powered Features (Syntalix)

Syntalix provides AI-powered capabilities within Sampark that may assist organizations by generating analytical outputs from communications content where the feature has been enabled for the applicable tenant.

Depending on the enabled functionality, Syntalix may provide:

  • Sentiment analysis.
  • Speech transcription.
  • Conversation summaries.
Key Practices Opt-In Per Tenant

Syntalix is enabled on a tenant-by-tenant basis according to the customer's subscription plan and configuration.

AI-powered functionality is not enabled by default across all deployments.

In-House Processing

AI-powered processing is performed using NoteG's in-house capabilities.

No External AI Processing

Customer communications content is not transmitted outside NoteG's infrastructure for AI processing.

No Solely Automated Decisions

Syntalix does not make solely automated decisions that produce legal effects or similarly significant effects concerning individuals within the meaning of Article 22 of the GDPR.

AI-generated outputs are intended solely to provide informational assistance and support human review, operational workflows, and administrative reporting.

AI Output Disclaimer and Human Oversight

AI-generated outputs, including sentiment analysis, transcriptions, summaries, and similar analytical content, are generated using automated processing techniques and are intended solely to assist authorized users and administrators.

Although reasonable efforts are made to produce useful outputs, AI-generated content may not always be complete, accurate, current, or free from errors.

Customers and authorized users remain responsible for exercising independent judgment and reviewing AI-generated outputs before relying upon them for operational, administrative, healthcare, educational, compliance, business, or other decision-making purposes.

AI-generated outputs should not be considered a substitute for professional judgment, independent verification, or human review.

Except to the extent required by applicable law or expressly agreed in writing, NoteG makes no representation or warranty regarding the accuracy, completeness, or suitability of AI-generated outputs for any specific purpose. Customers remain responsible for decisions, actions, and omissions arising from their use of AI-generated outputs and for ensuring that such outputs are used in accordance with applicable laws, regulations, contractual obligations, and internal organizational policies.

Where Syntalix is enabled, communications content is processed solely for the purpose of providing the AI-powered functionality requested by the applicable tenant. The applicable lawful basis for processing and the respective Controller or Processor role depend upon the deployment model and are governed by the relevant customer agreement and Data Processing Addendum (DPA), where applicable.

40. Health and Special-Category Data

Sampark is used for telehealth and healthcare consultation use cases. Depending on the deployment and manner in which the Services are used, communications content processed through the platform may include health-related information.

Such information may constitute special-category personal data under the GDPR and sensitive personal data under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

Enterprise Healthcare Deployments

For healthcare deployments, the customer organization—such as a hospital, clinic, healthcare provider, or health platform—typically acts as the Controller for health-related information and determines the applicable lawful basis and processing instructions.

In these deployments, NoteG generally acts as a Processor, processing personal data solely in accordance with the customer's documented instructions and the applicable customer agreement, including a HIPAA Business Associate Agreement (BAA), where required.

HIPAA

Sampark is designed to support enterprise security and compliance practices and may be deployed in a manner aligned with HIPAA requirements, subject to appropriate customer configuration, administrative controls, and contractual commitments.

A HIPAA Business Associate Agreement (BAA) is available for eligible customers.

Where a BAA applies, NoteG addresses applicable HIPAA contractual obligations, including safeguards, breach notification obligations, and subprocessor requirements.

Other Healthcare Deployments

For healthcare deployments not governed by HIPAA, the applicable Controller—typically the customer organization—is responsible for establishing an appropriate lawful basis for processing health-related or other special-category personal data in accordance with applicable law.

Individuals seeking information regarding the processing of their health information should contact their healthcare provider or the organization that provisioned their access to Sampark, in addition to contacting NoteG at admin@thesampark.com.

This Privacy Statement does not constitute legal advice. Customers remain responsible for ensuring that their use of Sampark complies with HIPAA and all other applicable legal and regulatory requirements. Customers are encouraged to obtain independent legal advice regarding their obligations under the laws applicable to the jurisdictions in which they deploy or use the Services.

41. Privacy Rights and Choices

Sampark is committed to respecting applicable privacy and data protection rights. Subject to applicable law, the nature of the deployment, and NoteG's role as either a Controller or Processor, individuals may exercise certain rights regarding their personal data.

Privacy requests may be submitted by contacting us at admin@thesampark.com.

Depending on the applicable law and the circumstances of the processing, you may request to:

  • Access the personal data relating to you that is processed through the Services.
  • Correct, update, or rectify inaccurate or incomplete personal data.
  • Request deletion or erasure of personal data, where applicable and legally permissible.
  • Request restriction of processing, where such a right is available under applicable law.
  • Object to certain processing activities, where applicable.
  • Request portability of personal data where such right is provided by applicable law.
  • Obtain information regarding the processing, use, disclosure, and sharing of your personal data.

Because Sampark is a multi-tenant enterprise platform that is frequently deployed and administered by customer organizations, certain privacy requests may need to be coordinated with the applicable customer or tenant administrator. In many deployments, the customer organization acts as the Controller for end-user personal data, while NoteG acts as a Processor on the customer's documented instructions.

Accordingly, the fulfillment of certain requests may be subject to:

  • Applicable contractual obligations.
  • Legal and regulatory requirements.
  • Retention obligations.
  • Security requirements.
  • Audit obligations.
  • Billing and operational requirements.
  • Verification of the requester's identity and authority.

Where NoteG processes personal data solely on behalf of a customer, we may direct the requester to the appropriate customer organization or assist the customer in responding to the request in accordance with our contractual obligations.

42. Children

Sampark is designed primarily for enterprise use and may also be deployed by educational institutions and organizations that provide services involving minors.

The applicable age at which parental or guardian consent may be required varies depending upon the jurisdiction in which the Services are used.

India (Digital Personal Data Protection Act, 2023)

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), a "child" is an individual who is under 18 years of age.

Where applicable, processing a child's personal data requires verifiable parental consent in accordance with the DPDP Act and applicable rules. The DPDP Act also restricts tracking and targeted advertising directed toward children.

European Economic Area (EEA) and United Kingdom

Within the European Economic Area and the United Kingdom, the age below which parental consent may be required for information society services generally ranges between 13 and 16 years of age, depending on the applicable jurisdiction.

United States (COPPA)

Where the Children's Online Privacy Protection Act (COPPA) applies, additional protections apply to the processing of personal information relating to children under the age of 13.

Education Deployments

Where Sampark is deployed by schools, colleges, universities, educational institutions, or other education providers, the applicable educational organization generally acts as the Controller for student personal data, while NoteG acts as a Processor on the organization's documented instructions.

Additional information regarding education deployments is provided in the Children's Education Privacy Statement contained within this Privacy Statement.

43. Retention

Sampark retains personal data only for as long as necessary to provide the Services, fulfill contractual commitments, comply with applicable legal obligations, support legitimate business operations, and maintain the security, integrity, and reliability of the platform.

The retention period applicable to a particular category of personal data depends upon several factors, including:

  • The customer's subscription plan.
  • Tenant-specific configuration.
  • Applicable contractual obligations.
  • Legal and regulatory requirements.
  • Security requirements.
  • Audit and compliance obligations.

Where supported by the applicable deployment, customers may configure shorter or longer retention periods for certain categories of data in accordance with their operational requirements and applicable law.

Implemented Retention Details
Data Type Retention
Administrative session cookie Maximum lifetime of 12 hours (opaque identifier only; session state maintained server-side)
Application session cookie Maximum lifetime of 30 days (opaque identifier only; session state maintained server-side)
File download links Short-lived pre-signed URLs with a default validity period of 900 seconds
Audit logs Configurable; default retention of 2,190 days (6 years), unless modified through environment configuration
Chat content, call content, and meeting recordings Governed by the applicable tenant plan, customer agreement, and configured retention settings

Specific retention periods applicable to communications content, recordings, and other tenant-configurable data categories are documented in the applicable customer-facing plan documentation, contractual agreements, and the Data Processing Addendum (DPA), where applicable.

44. Data Breach Notification

NoteG maintains technical and organizational security measures designed to protect personal data against unauthorized access, disclosure, alteration, destruction, and other security risks.

If a personal data breach occurs, NoteG will respond in accordance with applicable law, contractual commitments, and the nature of the affected deployment.

Suspected privacy or security incidents may be reported to:

admin@thesampark.com

Where applicable, breach notifications may include the following:

GDPR and UK GDPR

Where required under the GDPR or UK GDPR, NoteG will notify the competent supervisory authority within the applicable statutory timeframe after becoming aware of a personal data breach.

Where required by applicable law, affected individuals will also be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

India (Digital Personal Data Protection Act, 2023)

Where applicable under the DPDP Act and related rules, NoteG will notify the Data Protection Board of India and affected Data Principals without undue delay, in accordance with applicable legal requirements.

HIPAA

For deployments operating under a Business Associate Agreement (BAA), breach notification obligations are performed in accordance with the applicable BAA and HIPAA requirements.

Incident Response

Our incident response procedures are designed to support the timely identification, assessment, containment, investigation, remediation, documentation, and notification of security incidents, consistent with applicable legal obligations and contractual commitments.

45. Changes to This Privacy Statement

We may update this Privacy Statement from time to time to reflect changes in:

  • The Services.
  • Applicable laws and regulations.
  • Security practices.
  • Operational processes.
  • Product functionality.
  • Contractual or regulatory requirements.

When material changes are made to this Privacy Statement, we will update the Effective Date and Last Updated date shown at the beginning of this document.

Where appropriate, notice of material changes may also be provided through the Sampark website, administrative interfaces, customer communications, or other appropriate channels, consistent with applicable law and contractual obligations.

The most current version of this Privacy Statement supersedes all previous versions and governs the collection, use, disclosure, retention, and protection of personal data from the date it becomes effective.

46. European Data Protection Specific Information

This section supplements the Privacy Statement and applies to individuals located within the European Economic Area (EEA) and, where applicable, the United Kingdom.

Where personal data is processed in connection with the Services and the GDPR or UK GDPR applies, NoteG processes personal data in accordance with the applicable legal requirements and the respective roles of the parties as Controller or Processor.

47. Lawful Bases for Processing (GDPR / UK GDPR)

Depending on the nature of the processing activity and the deployment model, Sampark processes personal data under one or more of the following lawful bases:

Performance of a Contract

Processing is necessary to provide, operate, maintain, and support the Services requested by a customer organization or an authorized user, including fulfilling contractual obligations under the applicable customer agreement.

Legitimate Interests

Processing is necessary for NoteG's legitimate interests in operating, securing, maintaining, improving, and protecting the Services, including preventing fraud, abuse, unauthorized access, and other activities that may affect the security, integrity, or reliability of the platform, provided that such interests are not overridden by the rights and freedoms of the data subject.

Consent

Where required by applicable law, personal data is processed based on the individual's consent for specific processing activities. Where processing relies on consent, such consent may be withdrawn in accordance with applicable legal requirements.

Legal Obligation

Processing may also be necessary to comply with applicable laws, regulatory requirements, lawful governmental requests, court orders, or other legal obligations.

Special-Category Personal Data

Where the processing involves special-category personal data, including health-related information, the applicable Controller is responsible for determining the appropriate lawful basis and Article 9 condition under the GDPR.

For enterprise healthcare deployments, NoteG generally processes such personal data solely as a Processor acting on the documented instructions of the applicable customer.

48. International Data Transfers

By default, Sampark is hosted in India. Depending on customer requirements and deployment configurations, regional hosting may also be available.

Where personal data originating from the European Economic Area or the United Kingdom is transferred to India or another jurisdiction that has not received an adequacy decision under applicable law, NoteG implements appropriate safeguards to support lawful international data transfers.

Such safeguards may include:

  • European Commission Standard Contractual Clauses (EU SCCs), as incorporated into the applicable Global Data Processing Addendum (DPA).
  • UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses, where applicable.

Deployment-specific transfer mechanisms, subprocessors, technical safeguards, and transfer-related documentation are described in the applicable customer agreement, Data Processing Addendum (DPA), and associated transfer impact assessment materials where applicable.

49. Rights of Individuals

Subject to the GDPR, UK GDPR, and other applicable laws, individuals may have rights regarding the processing of their personal data, including the right to:

  • Request access to personal data.
  • Request correction or rectification of inaccurate personal data.
  • Request deletion or erasure of personal data.
  • Request restriction of processing.
  • Object to certain processing activities.
  • Request data portability, where applicable.

Requests relating to these rights may be submitted to:

admin@thesampark.com

Where applicable, individuals may also lodge a complaint with the competent supervisory authority in their jurisdiction.

50. California and Other U.S. State Privacy Notice

This section supplements the Privacy Statement for individuals who are protected under applicable United States state privacy laws, including the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable state privacy legislation.

51. Notice at Collection

Depending upon the manner in which Sampark is used and the applicable tenant configuration, the categories of personal information described below may be collected and processed for the purposes identified in this Privacy Statement.

52. Categories of Personal Information Collected

Depending on the Services used and customer configuration, Sampark may process the following categories of personal information:

Identifiers
  • User identifiers.
  • Session identifiers.
  • Organization identifiers.
  • Application identifiers.
Contact Information
  • Name.
  • Email address.
  • Mobile number, where used for meeting scheduling or related functionality.
Communications Content
  • Chat messages.
  • Shared files and media.
  • Call and meeting events.
  • Meeting recordings, where recording functionality has been enabled.
Internet, Network, Device, and Usage Information
  • Usage analytics.
  • Diagnostic information.
  • Network-related information necessary for operation of the Services.
Security and Audit Information
  • Security event logs.
  • Authentication-related information.
  • Audit logs.
  • Operational security records.
Sensitive Personal Information

Where applicable, Sampark may process sensitive personal information, including:

  • Account credentials.
  • Mobile numbers.
  • Health-related communications processed through telehealth deployments.

The categories of information processed depend upon the Services used and the applicable deployment configuration.

53. Purposes for Collection and Use

Personal information is processed for purposes including:

  • Providing, operating, maintaining, and securing the Services.
  • Delivering administrative dashboards, analytics, and reporting.
  • Providing AI-powered functionality where enabled, including sentiment analysis, transcription, and summaries.
  • Providing customer support, troubleshooting, and operational assistance.
  • Detecting, preventing, investigating, and responding to fraud, abuse, unauthorized activity, and other security-related events.
  • Complying with applicable legal obligations.

54. Sale and Sharing of Personal Information

Sampark does not sell customer personal information.

Sampark also does not share personal information for cross-context behavioral advertising.

Where customers choose to enable integrations with third-party systems, any sharing of information through those integrations occurs pursuant to the customer's configuration and applicable contractual arrangements.

55. California and Other U.S. State Privacy Rights

Where applicable under the CCPA, CPRA, or other U.S. state privacy laws, individuals may have rights including:

  • The right to know the categories and specific pieces of personal information collected.
  • The right to request deletion of personal information.
  • The right to request correction of inaccurate personal information.
  • The right to receive information regarding the categories of personal information collected, the sources from which the information was obtained, the purposes for which it is processed, and the categories of recipients with whom it is disclosed.
  • The right to request limitation of the use and disclosure of sensitive personal information, where applicable under law.
  • The right to opt out of the sale or sharing of personal information for cross-context behavioral advertising.

Because Sampark does not sell personal information or share personal information for cross-context behavioral advertising, requests to opt out of such activities are generally not applicable.

Privacy requests may be submitted to:

admin@thesampark.com

Where required by applicable law, qualifying requests relating to the limitation of the use or disclosure of sensitive personal information will be honored in accordance with legal requirements.

56. Authorized Agents

Where permitted under applicable law, requests may be submitted by an authorized agent acting on behalf of an individual.

Authorized agents may be required to provide written authorization or other information reasonably necessary to verify both the identity of the individual and the authority of the authorized agent before the request is fulfilled.

Requests from authorized agents may be submitted to:

admin@thesampark.com

57. Non-Discrimination

NoteG will not unlawfully discriminate against any individual for exercising rights available under applicable privacy laws.

The exercise of privacy rights will not result in discriminatory treatment except as otherwise permitted by applicable law.

58. Children's Education Privacy Statement

This section applies where Sampark is deployed by schools, colleges, universities, educational institutions, or other organizations providing educational services involving students, including minors.

59. Privacy Roles

For education deployments, the applicable educational institution or organization generally acts as the Controller for student personal data.

NoteG acts as a Processor, processing student personal data solely in accordance with the documented instructions of the applicable educational organization and the governing customer agreement and Data Processing Addendum (DPA).

60. What Personal Data Do We Collect From Students?

Depending upon the deployment configuration, Sampark may process:

  • Student user identifiers.
  • Organization identifiers.
  • Application identifiers.
  • Meeting participation information.
  • Meeting scheduling information.
  • Chat messages.
  • Shared files and media.
  • Administrative usage analytics.
  • Diagnostic information.
  • Security logs.
  • Audit logs.

61. How Do We Use Student Personal Data?

Student personal data is processed for purposes including:

  • Providing educational communication and collaboration services.
  • Operating and securing the Services.
  • Preventing abuse and unauthorized access.
  • Investigating and resolving technical issues.
  • Providing administrative reporting and analytics to authorized educational administrators.

62. How Do We Share Student Personal Data?

Student personal data may be shared only as necessary:

  • With authorized school administrators, teachers, staff, or other educational personnel who have appropriate permissions.
  • With service providers (subprocessors) that support the operation of the Services and are engaged under appropriate contractual safeguards.

63. What Student Information Can Educational Organizations Access?

Authorized educational administrators may access information made available through the administrative dashboards, reporting interfaces, analytics tools, and other features enabled for their deployment, subject to role-based permissions and applicable access controls.

64. Review, Correction, and Deletion of Student Information

Requests relating to student personal data may be submitted to:

admin@thesampark.com

Depending on the deployment, requests may also be handled through the administrative processes established by the applicable educational institution.

65. Children Under 18 (India) and Other Applicable Age Thresholds

Under India's Digital Personal Data Protection Act, 2023, verifiable parental consent is required before processing the personal data of a child.

Educational institutions and other education customers are responsible for obtaining any parental or guardian consents required under applicable law before using the Services.

NoteG does not engage in tracking or targeted advertising directed toward children.

66. India Privacy Statement

This section supplements the Privacy Statement for individuals whose personal data is processed in India and addresses applicable requirements under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and any applicable rules issued thereunder.

Sampark is operated by NoteG Technologies Pvt. Ltd. and, unless otherwise agreed with a customer, is hosted in India by default.

67. Applicable Law

The processing of personal data through Sampark is governed by applicable Indian laws, including the Digital Personal Data Protection Act, 2023 (DPDP Act), together with any other applicable legal or regulatory requirements.

This section should be read together with the remainder of this Privacy Statement.

68. What Personal Data Do We Process?

The categories of personal data processed through Sampark are described in the "What Personal Data Do We Receive?" section of this Privacy Statement.

Depending on the Services used and the applicable deployment, these categories may include:

  • User and organization identifiers.
  • Contact information.
  • Communications content.
  • Analytics and usage information.
  • Security and audit logs.
  • Health-related information processed in telehealth deployments, where applicable.

69. Purposes and Lawful Grounds

Personal data is processed for the purposes described throughout this Privacy Statement.

Where applicable under the DPDP Act, processing may be based upon:

  • Consent.
  • Legitimate uses recognized under applicable law, including employment-related purposes or safeguarding purposes where applicable.
  • Processing necessary for the performance of contractual obligations.
  • Compliance with applicable legal obligations.

The applicable lawful basis depends upon the nature of the deployment, the purpose of processing, and the role performed by NoteG or the applicable customer.

70. Rights of Data Principals

Subject to the DPDP Act and applicable legal requirements, Data Principals may have rights including:

  • The right to obtain information regarding the personal data being processed.
  • The right to request correction or updating of inaccurate personal data.
  • The right to request erasure of personal data, where applicable.
  • The right to seek grievance redressal.
  • The right of nomination, allowing another individual to exercise applicable rights in the event of the Data Principal's death or incapacity.

Requests relating to these rights may be submitted to:

admin@thesampark.com

Where required, requests may be subject to identity verification and other applicable legal or contractual requirements.

71. Grievance Redressal

Privacy-related grievances concerning the processing of personal data under the DPDP Act may be submitted to:

Email: admin@thesampark.com

We will acknowledge and address grievances in accordance with the requirements of the DPDP Act and applicable rules.

Where a formal Grievance Officer is appointed, NoteG will publish the name and designation of the appointed Grievance Officer through the appropriate communication channels.

72. Data Protection Board of India

Where applicable under the DPDP Act, Data Principals may also approach the Data Protection Board of India for remedies available under applicable law.

73. Breach Notification

Information regarding breach notification practices is provided in the Data Breach Notification section of this Privacy Statement.

Where required under the DPDP Act and applicable rules, NoteG will notify the Data Protection Board of India and affected Data Principals without undue delay.

74. Hosting and Security

Unless otherwise agreed with a customer, personal data is stored and processed in India by default.

Regional hosting may be configured where supported and requested by the customer.

Security measures implemented by Sampark include, among other things:

  • Role-based access controls.
  • Encryption for stored communications.
  • Secure session management.
  • Security monitoring.
  • Audit logging practices.

Additional information regarding security controls is provided in the Security Measures section of this Privacy Statement.

75. Cookie Statement

What Are Cookies?

Cookies are small text files that are stored on a user's device by a web browser.

Sampark currently uses cookies primarily to support authentication, session management, and the secure operation of the Services.

76. Cookies Used by Sampark

1. Administrative Session Cookie

Cookie Name sampark_admin_session_id
Purpose Maintains authenticated administrative sessions, supports restoration of server-side session state, and facilitates administrative session API response encryption.
Stored Value A randomly generated opaque session identifier (UUID).
Characteristics HTTPOnly
Secure in production
SameSite=None in production
SameSite=Lax in non-production environments
Maximum lifetime of 12 hours
2. Application Session Cookie
Cookie Name sampark_session_id
Purpose Maintains authenticated application user sessions and supports restoration of server-side session state.
Stored Value A randomly generated opaque session identifier (UUID).
Characteristics HTTPOnly
SameSite=Lax
Maximum lifetime of 30 days

77. What Our Cookies Do Not Store

The cookie values used by Sampark do not directly store:

  • User names.
  • Email addresses.
  • Mobile numbers.
  • Organization names.
  • User roles.
  • Authentication tokens.
  • Other personal information.

Session information is maintained on the server. Cookie values function solely as identifiers used to reference the corresponding server-side session.

78. Cookie Categories

Category Description
Core / Necessary Session cookies required for authentication and operation of authenticated platform functionality.
Technical Performance Supports operational reliability, diagnostics, and security-related platform functionality.
Enhanced Functionality Supports session restoration and administrative response encryption functionality.
Analytics Platform analytics are provided through administrative reporting. The session cookies described above are not advertising analytics cookies. Should additional analytics cookies be introduced in the future, this Cookie Statement and applicable consent mechanisms will be updated where required by law.
Social Media Not currently implemented.
Advertising Not currently implemented.

79. Managing Cookies

Users may manage or disable cookies through their browser settings.

Disabling cookies may affect authentication, session management, and other functionality required for the proper operation of the Services.

80. Global Privacy Control (GPC)

Where applicable, Sampark honors Global Privacy Control (GPC) signals in a manner consistent with applicable law and our cookie practices.

81. Do Not Track (DNT)

Certain browsers transmit "Do Not Track" (DNT) signals.

Because there is currently no universally accepted industry standard governing responses to DNT signals, Sampark continues to use necessary session cookies required for the operation and security of the Services.

82. Contact Us

Questions, privacy requests, or concerns regarding this Privacy Statement may be submitted to:

Email: admin@thesampark.com

83. Revisions

This Privacy Statement and the accompanying Cookie Statement may be updated from time to time to reflect changes to our Services, legal obligations, operational practices, or cookie usage.

Where material changes are made, we will update the applicable revision dates and provide notice where required by applicable law or contractual commitments.

84. Industry-Specific Deployments

Healthcare

Sampark supports telehealth and healthcare use cases.

Additional information regarding the processing of health-related information, HIPAA, and healthcare deployments is provided in the Health and Special-Category Data section of this Privacy Statement.

A HIPAA Business Associate Agreement (BAA) is available for eligible customers.

Education

Information relating to education deployments, student privacy, and the processing of student personal data is provided in the Children's Education Privacy Statement contained within this Privacy Statement.

85. Global Privacy Framework

Framework Reference
GDPR European Data Protection Specific Information
UK GDPR European Data Protection Specific Information
CCPA / CPRA California and Other U.S. State Privacy Notice
Digital Personal Data Protection Act, 2023 (India) India Privacy Statement
Global Data Processing Addendum (DPA) Available for eligible enterprise customers and incorporates the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) and/or UK Addendum, where applicable.
Subprocessors Current subprocessors are identified in the How Do We Share Personal Data? section of this Privacy Statement and may be updated as service providers change.
Transfer Impact Assessments Deployment-specific information relating to international transfers, subprocessors, safeguards, and applicable transfer mechanisms is documented within the applicable Data Processing Addendum (DPA) and associated transfer impact assessment materials, where applicable.

86. Government Requests

Where required by applicable law, Sampark may respond to lawful requests received from courts, regulators, law enforcement agencies, or other competent governmental authorities.

Requests are evaluated and handled in accordance with applicable legal obligations, contractual commitments, and established security practices.

87. Security Measures

Sampark implements technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

Current security measures include:

  • Role-based access controls.
  • Server-side session management using opaque cookie identifiers.
  • Secure cookie configurations, including HTTPOnly, Secure (where applicable), and SameSite protections.
  • Encryption for stored chat and call data.
  • Amazon S3 server-side encryption for stored media and files.
  • Short-lived pre-signed URLs for secure file downloads.
  • Encrypted delivery of file URLs to client applications, where applicable.
  • Platform hardening measures, including rate limiting, input sanitization, security headers, restrictive Cross-Origin Resource Sharing (CORS) policies, and secure error handling.
  • Audit logging practices designed to minimize the recording of message content and other sensitive information.

Subject to applicable confidentiality obligations, security assessment summaries, penetration testing summaries, and certain security documentation may be made available under a Non-Disclosure Agreement (NDA) or through other controlled access arrangements upon request.