We take your privacy seriously. This policy explains what data we collect, why we collect it, and how we protect it — including why we technically cannot read your documents.
SamVault Ltd ("SamVault", "we", "us") is the data controller for personal data processed through the SamVault platform. We are registered in India and comply with applicable data protection legislation including the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023 (DPDPA).
This Privacy Policy applies to all users of the SamVault website and application. By using the Service, you acknowledge the data practices described in this policy.
| Category | Data collected | Legal basis |
|---|---|---|
| Account data | First name, last name, email address, phone number, hashed password, account plan | Contract performance |
| Encryption metadata | Key derivation salt (hex string — no personal content) | Contract performance |
| Document metadata | Filename, file size, MIME type, category, tags, upload timestamp | Contract performance |
| Document content | Encrypted ciphertext only — we cannot read the content | Contract performance |
| Activity log | Action type, timestamps, IP address, user agent | Legitimate interests (security) |
| Usage analytics | Page views, session data via Google Analytics (anonymised) | Legitimate interests (service improvement) |
| Communications | Support emails and contact form submissions | Legitimate interests / consent |
We use your personal data only for the following purposes:
We do not use your data for advertising, profiling, or automated decision-making with legal or similarly significant effects.
SamVault uses a zero-knowledge encryption architecture. Here is what this means for your data:
We retain your data only for as long as necessary for the purposes outlined in this policy:
You may request early deletion of your data by exercising your right to erasure (see Section 7).
Under the Digital Personal Data Protection Act 2023 (DPDPA) and applicable Indian law, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@samvault.com. We will respond within 30 days. You also have the right to lodge a complaint with the appropriate data protection authority in your jurisdiction.
We implement the following technical and organisational measures to protect your data:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users without undue delay, in accordance with applicable data protection law.
Your encrypted data is stored in secure cloud data centres. Some service providers (including Google Analytics) may process data outside India. Where this occurs, we ensure appropriate safeguards are in place.
Where data is transferred outside India, we ensure appropriate safeguards are in place, including contractual protections with service providers and compliance with applicable cross-border data transfer requirements under Indian law.
The Service is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at privacy@samvault.com and we will delete it promptly.
For any privacy-related questions, data subject requests, or concerns, please contact:
To raise a concern with the relevant data protection authority in India, please contact the Data Protection Board of India once established under the DPDPA 2023, or the Ministry of Electronics and Information Technology (MeitY).