Loading Navbar...

Privacy Policy

Last updated: January 2026

1. Introduction

Shambho (“we”, “our”, “us”) operates Simplagents and provides an AI agent design and management platform. This Privacy Policy explains how we process personal data in compliance with GDPR and aligned with SOC 2 principles.

2. Data Controller

Simplagents acts as a Data Controller for account and billing data, and as a Data Processor for customer data processed through AI agents.

3. Data We Collect

We collect account and business information (name, email, organization details), customer content and agent data (inputs, configurations, logs), and technical usage data such as IP address, browser type, system logs, and performance metrics.

4. Lawful Basis for Processing (GDPR)

We process personal data based on contractual necessity, legitimate interests (security and service improvement), legal obligations, and user consent where required.

5. How We Use Data

Data is used strictly to operate and maintain the platform, execute AI agents as configured, provide support, ensure security, and meet legal and compliance requirements. We do not sell data, use it for advertising, or train general-purpose AI models on customer data.

6. Data Retention & Deletion

Customer data is retained only for the duration of the business relationship. Upon termination, data is deleted within 30 days unless legally required otherwise. Data export or deletion can be requested at any time.

7. Data Security (SOC 2 Aligned)

We implement safeguards aligned with SOC 2 Trust Principles, including role-based access control, encryption, audit logging, monitoring, incident response procedures, and vendor risk management.

8. Subprocessors

We use vetted subprocessors such as cloud hosting, analytics, and payment providers. All subprocessors are contractually bound to equivalent data protection obligations.

9. International Data Transfers

Where data is processed outside your country, we rely on lawful transfer mechanisms such as Standard Contractual Clauses (SCCs) or other GDPR-approved safeguards.

10. Your Rights (GDPR)

You have the right to access, correct, delete, restrict or object to processing, request data portability, and withdraw consent. Requests are fulfilled within 30 days.

11. Incident & Breach Notification

In the event of a data breach, we will notify affected customers and regulators as required by applicable law.

Contact

For privacy-related questions or GDPR requests:

privacy@shambho.ai