Privacy and Data Handling Policy
Version 2.0 · Last updated: 2024-11-03 · Owner: Andrés Bruzzoni
1. Data Controller
SAMU LLC ("SAMU.AI"), registered in the State of Delaware (Filing Number: 2679071), is the data controller for the personal data we collect and process through our website and application.
2. Scope of This Policy
This Privacy Policy governs the collection, processing and storage of personal data in connection with the use of SAMU.AI's services. We are committed to complying with the privacy and data protection laws in force in the jurisdictions where we operate, as well as to following the Data Protection Principles of the Red Iberoamericana de Protección de Datos (RIPD) (Ibero-American Data Protection Network).
3. Data Protection Officer (DPO)
SAMU.AI has appointed a Data Protection Officer (DPO) to oversee compliance with privacy and data protection regulations, as well as to serve as the point of contact between SAMU.AI, its clients and the data protection authorities. Identity of the DPO: Jonathan Saul Sosin — privacy@samu.ai. Duties of the DPO: 1. Compliance Oversight: Monitor SAMU.AI's compliance with local and international data protection regulations. 2. Management of User Requests: Facilitate and coordinate the exercise of data subjects' rights (access, rectification, cancellation, objection, portability and restriction of processing). 3. Advice to SAMU.AI: Provide guidance on best practices and obligations in the handling of personal data. 4. Relationship with Authorities: Act as the point of contact with the data protection authorities in the jurisdictions in which we operate. 5. Security Incident Management: Advise SAMU.AI on the management of data security incidents and ensure that response procedures are effective.
4. Data Classification
SAMU.AI classifies personal data and other types of information according to their level of sensitivity and legal requirements: Confidential Data (highly sensitive data that requires the highest levels of protection, such as personal identification data, financial data, trade secrets and sensitive or special category data under the GDPR), Restricted Data (information that requires significant protection and access limited to employees who need the information to carry out their responsibilities) and Public Data (information intended for public consumption that may be freely distributed outside SAMU.AI).
5. SAMU.AI's Role in Data Processing
SAMU.AI plays different roles in the processing of personal data depending on how such data is obtained and processed. When SAMU.AI is the Data Controller: in situations where SAMU.AI interacts directly with users and obtains their explicit consent to process their personal data. When SAMU.AI is the Data Processor: in situations where SAMU.AI draws on the conversations and data provided by its clients, it acts as Data Processor on behalf of the client. In these cases, the client is the Data Controller and SAMU.AI complies with the processing requirements established in the contract, without using the data for any other purpose.
6. Clients' Responsibility for Obtaining Consent
When SAMU.AI acts as Data Processor of personal data on behalf of its clients, the clients are responsible for obtaining the informed and explicit consent of their employees, end users or other individuals whose personal data may be processed through our platforms. The consent obtained must be explicit as to the fact that their communications, including calls, emails and other types of information exchange, will be processed and stored on the SAMU.AI platform. This notice must include the specific purpose of the processing, the duration of the storage of this data at SAMU.AI and a clear reference to this privacy policy.
7. Data Handling by Classification
Confidential Data: access limited to authorized employees and roles; use of encryption, multi-factor authentication and strict protection measures. Devices containing this data must be securely wiped at the end of their use. Restricted Data: access restricted to employees who need the information for business functions. Any transfer to third parties must be approved and carried out under contract. Public Data: does not require special protection or handling controls, as it is freely accessible.
8. Data Labeling
All confidential data must be labeled as "Confidential" in documents and printed copies to ensure appropriate handling, as well as its proper storage and secure destruction when it is no longer needed.
9. Storage and Security of Conversations and Emails
SAMU.AI retains the conversations and emails shared by clients solely for the specific purposes defined in the service agreement. This data will be subject to the technical and organizational security measures necessary to protect it against unauthorized access, alteration, loss or disclosure. SAMU.AI will not use this data for any other purpose without the prior consent of the client and of the data subject, unless required by law.
10. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Once the data is no longer needed, it will be securely deleted. Data in physical format will be destroyed by shredding or other secure methods.
11. Legal Requirements and Exceptions
In certain cases, SAMU.AI may be subject to legal proceedings that require the retention of data beyond the established periods. These records will be exempt from any other requirement specified within this policy and will be retained in accordance with the requirements identified by legal counsel.
12. Rights of Data Subjects
In compliance with local regulations, SAMU.AI guarantees users the exercise of the following rights: Access (the right to know what personal data we hold), Rectification (to request the update or correction of inaccurate or incomplete data), Cancellation and Objection (the right to request the deletion or suspension of the processing of their data), Portability (the right to receive the data in a structured, commonly used format) and Restriction of Processing (the right to restrict the processing of data under certain circumstances). To exercise these rights: privacy@samu.ai
13. International Data Transfers
SAMU.AI will ensure that any transfer of personal data to third countries is carried out in accordance with the required levels of protection, applying contractual clauses or agreements that ensure the confidentiality and security of the data.
14. Use of Cookies and Similar Technologies
SAMU.AI uses cookies and similar technologies on its website to improve the user experience, analyze traffic and understand how users interact with our content. Types of cookies we use: Essential (necessary for the basic functioning of the site), Performance (help us understand how users interact with the site), Functionality (allow user preferences to be remembered) and Marketing (used to deliver relevant ads to the user and measure the effectiveness of advertising campaigns). Users may manage their cookie preferences at any time through their browser settings.
15. SAMU.AI's Commitment
SAMU.AI is committed to maintaining the confidentiality and security of personal data and to handling all habeas data requests with the utmost respect and diligence. This commitment extends to all company processes that involve the handling of personal data.
16. Data Security
We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, alteration, loss or improper disclosure.
17. Changes to This Policy
This Policy may be amended to reflect updates to our services or regulatory changes. Users will be notified of any significant modification through our usual communication channels.
18. Contact
For questions or concerns about this Policy or about the processing of your personal data, contact us at: privacy@samu.ai