Privacy Policy
Last updated: June 4, 2026
This Privacy Policy explains how KramaAI (“we,” “us”) collects, uses, and protects personal information when you visit our website, request a demo, or use KramaAI BMS on behalf of your organization.
1. Who this applies to
- Website visitors who submit contact or demo forms.
- Business customers (operators) who license KramaAI BMS.
- End users whose data your organization loads into the BMS—parents, guardians, staff, and children enrolled in programs.
2. Information we collect
Depending on how you interact with us, we may process:
- Contact details (name, work email, organization, number of centers, demo preferences).
- Account and role information for licensed deployments.
- Operational and billing data your team enters: memberships, schedules, attendance, transactions, child profiles linked to guardian accounts, and support tickets.
- Technical logs (IP address, browser type, device identifiers, security events) necessary to operate and protect the Services.
3. How we use information
We use personal information to provide and improve the Services, respond to sales and support requests, secure accounts, meet legal obligations, and—where permitted—send product updates relevant to your relationship with us. We do not sell personal information.
4. Children’s data (kids centers & enrichment)
KramaAI BMS is used by operators who serve minors. In those deployments:
- Child profiles are created and managed under a parent or guardian account controlled by your organization.
- We process children’s data only on your instructions as the operator, to deliver scheduling, attendance, billing, and safeguarding workflows you configure.
- Operators are responsible for obtaining any required parental consent and for publishing their own center-facing privacy notices.
- We support data-minimization practices: collect only fields needed for enrollment, check-in, and billing; restrict staff roles via RBAC; and honor export and deletion requests per your Data Processing Agreement.
Where U.S. state laws such as COPPA apply, you—not KramaAI—determine whether parental consent is required for your programs; we provide tooling and contractual commitments to help you meet those obligations.
5. Sharing and subprocessors
We share data with infrastructure and communications providers that help us host the Services (for example, cloud hosting, email delivery, payment processors you connect such as Stripe, and form notification providers for marketing inquiries). A current subprocessor list is available on request at privacy@kramaai.com.
6. Retention and security
We retain information for as long as needed to provide the Services and as required by law or your agreement. We apply encryption in transit, access controls, audit logging, and role-based permissions within the product.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal information. Website visitors may contact privacy@kramaai.com. End users of a center should contact that operator first; operators may submit data subject requests to us under the Data Processing Agreement.
8. International transfers
If data is transferred across borders, we use appropriate safeguards such as standard contractual clauses where required.
9. Changes
We may update this policy and will post the revised version with a new “Last updated” date.