LEGAL
Privacy Policy
Last updated: September 10, 2026
Rambit SAS ("Rambit AI", "we", "us") builds, deploys, and manages AI agents for businesses. This policy explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you have. It covers our website at rambit.co, our client dashboards and sign-in, and the AI agents we operate on behalf of our clients across channels such as WhatsApp, web chat, and email.
1. Who is responsible for your data
Rambit SAS, NIT 901.442.697-8, a company incorporated in Colombia with registered address at Carrera 24B, Bogotá 111411, Colombia, is the data controller for personal data we collect through our website, our marketing activities, and our own client accounts. You can reach us at contacto@rambit.co for any privacy matter, including requests to access or delete your data.
When we operate an AI agent for a client, that client is the controller of the end-user conversations and data flowing through the agent, and we act as their processor (service provider) under their instructions and our written agreement. If you interacted with an agent branded as another business, please direct your request to that business; we will support them in responding, and you may also contact us and we will route your request.
2. Data we collect
We collect only what we need for the purposes described in this policy. Depending on how you interact with us, this includes:
- Contact and business data you submit: name, email address, phone number, company, role, and the content of your message when you use our contact form, book a call, or email us.
- Account data: when you create or access a Rambit account, including through Google Sign-In, we process your name, email address, profile picture, and the account identifier provided by the identity provider.
- Usage and device data: pages viewed, referring page, approximate location derived from IP address, browser and device type, and interaction events, collected through our analytics tooling.
- Agent conversation data: when an AI agent we operate handles a conversation, we process the messages exchanged, the channel identifier (such as a WhatsApp phone number or web session), profile name where the platform provides it, timestamps, and any attachments or metadata the end user sends.
- Integration data: when a client connects a third-party system (CRM, calendar, spreadsheet, messaging platform, internal database), we process the records that integration exposes to the agent, limited to what the configured use case requires.
- Billing and contractual data: company details, tax identifiers, invoices, and payment status for clients. We do not store full card numbers; payments are handled by our payment processors.
We do not intentionally collect special-category data (health, biometric, religious, political, sexual-orientation data) and we ask clients not to configure agents to solicit it. If such data reaches us incidentally within a conversation, we process it only as needed to deliver the service and delete it on request.
3. How and why we use data
- To provide the service: build, configure, run, and monitor AI agents; deliver answers, route conversations, and execute the automations a client has set up.
- To respond to enquiries: answer your messages, prepare proposals, and follow up on a commercial conversation you started.
- To maintain and secure the service: debug failures, investigate abuse or fraud, keep audit logs, and protect accounts.
- To improve the service: measure aggregate usage, quality, and agent performance, using aggregated or de-identified data wherever it is sufficient.
- To comply with the law: meet accounting, tax, and regulatory obligations and respond to lawful requests.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use client or end-user conversation data to train our own general-purpose models or the models of our providers.
4. Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (delivering the services you or your employer requested); our legitimate interests (securing the service, understanding aggregate usage, pursuing a commercial conversation you initiated); your consent (non-essential analytics cookies and marketing communications, which you can withdraw at any time); and compliance with a legal obligation.
Where Colombian Law 1581 of 2012 and Decree 1377 of 2013 apply, we process personal data with the prior, express, and informed authorisation of the data subject, and we honour the habeas data rights described below. Our contact channel for the exercise of those rights is contacto@rambit.co.
5. Google user data and Google Sign-In
We offer Google Sign-In (Google OAuth) so you can access a Rambit account without creating a separate password. When you choose it, Google shares with us the scopes you approve on the consent screen — normally your basic profile (name, profile picture, Google account ID) and your email address.
- We use this data only to create and authenticate your account, identify you inside the product, display your profile, and send you service-related messages about your account.
- We request the minimum scopes needed for the feature you are using, and we ask for additional scopes only at the moment a feature requires them, with a clear explanation.
- We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except to the subprocessors listed in this policy that host or secure our infrastructure on our behalf, or where required by law.
- We do not use Google user data to develop, improve, or train generalised or non-personalised AI or machine-learning models.
- You can revoke our access at any time from your Google Account permissions page, and you can ask us to delete the associated account data as described in the deletion section.
Rambit's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Meta platform data (WhatsApp, Messenger, Instagram)
We act as a technology provider that helps businesses connect and operate messaging channels on Meta platforms, including the WhatsApp Business Platform. When a business we serve grants us access, we process platform data strictly to provide that business the messaging and automation features it has asked for.
- Data processed may include end-user phone numbers, WhatsApp or platform profile names, message content and attachments, delivery and read status, message templates, and the business account and phone number identifiers needed to route messages.
- We process this data solely on behalf of, and under the instructions of, the business that owns the messaging account. That business is responsible for having a lawful basis and for giving its end users notice of the automation.
- We do not sell, license, or monetise platform data; we do not use it for advertising or ad targeting; we do not combine it with data from other businesses; and we do not use it to build profiles or datasets unrelated to the service the business receives.
- We keep access tokens and credentials encrypted, limit access to the personnel who need it to operate the service, and revoke access when an engagement ends.
- When a business disconnects its account, or when we no longer need the data to provide the service, we delete or return the platform data as described in the retention section.
Our processing of Meta platform data is additionally governed by the Meta Platform Terms and the applicable developer and WhatsApp Business policies. End users' use of WhatsApp itself remains subject to WhatsApp's own privacy policy.
7. AI models and automated processing
Our agents use large language models supplied by third-party providers. To generate a response, the relevant conversation content and the context a client has configured are sent to the model provider through their business APIs.
- We use providers whose terms prohibit training their models on data submitted through their business APIs, and we do not opt in to any training or model-improvement programme with client data.
- Agents are designed to assist, not to make decisions with legal or similarly significant effects on a person. Where an automation could affect someone materially — pricing, eligibility, account changes — we configure a human review step with the client.
- Model outputs can be inaccurate or incomplete. We advise clients to disclose that an end user is interacting with an automated assistant and to offer a route to a human.
- You have the right to object to solely automated decision-making and to request human intervention; write to us and we will arrange it with the responsible business.
8. Service providers and international transfers
We share data with a limited set of vendors that help us run the service, each bound by a written agreement with confidentiality and security obligations, and each permitted to use the data only to provide their service to us. Categories include: cloud hosting and databases; AI model providers; messaging platform providers, including Meta for WhatsApp and related channels; identity providers, including Google for sign-in; transactional email delivery; product analytics; and payment and invoicing providers.
Because these providers and our own team operate from several countries, personal data may be transferred outside your country of residence, including to the United States and the European Union. For transfers from the EEA, the UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, together with technical measures such as encryption in transit and at rest. We can provide a current list of subprocessors on request.
10. How long we keep data
- Contact form and enquiry data: up to 24 months from our last exchange, unless a commercial relationship starts.
- Account data: for as long as the account is active, and up to 12 months after closure to handle disputes and legal obligations.
- Agent conversation data: for the period agreed with the client operating the agent, by default no longer than 12 months, after which it is deleted or aggregated.
- Platform access tokens and credentials: until the integration is disconnected or the engagement ends, then revoked and deleted.
- Billing and accounting records: for the period required by tax and commercial law, typically 5 to 10 years.
- Security and audit logs: up to 12 months.
When a retention period ends we delete the data or irreversibly de-identify it. Backups are rotated on a defined cycle, so deleted data may persist in encrypted backups for a short additional period before being overwritten.
11. Your rights
Subject to applicable law, you can ask us to: confirm whether we hold data about you and give you a copy; correct inaccurate or incomplete data; delete data; restrict or object to certain processing; port your data to another provider; withdraw consent you previously gave; and, in Colombia, revoke your authorisation or request deletion where processing does not respect constitutional or legal principles.
Write to contacto@rambit.co and we will respond within the time limits set by the applicable law — within 10 business days for consultations and 15 business days for claims under Colombian rules (each extendable as the law allows), and within one month under the GDPR. We may need to verify your identity before acting. If you are unsatisfied, you may complain to your local data protection authority, and in Colombia to the Superintendencia de Industria y Comercio.
12. How to request data deletion
To delete your data, email contacto@rambit.co from the address associated with your data, with the subject line "Data deletion request", and tell us which data you mean — your Rambit account, a Google Sign-In connection, or a conversation with a specific business's agent. Include the phone number or channel identifier if your request concerns a messaging conversation.
- We acknowledge deletion requests within 5 business days and complete them within 30 days, or sooner where the law requires it.
- For a Rambit account: we delete the account record, profile data, and any identity-provider connection, including data received from Google Sign-In.
- For a conversation with an agent operated for a client: because that client is the controller, we forward your request to them and delete the data from our systems on their instruction, which we will follow up on until it is resolved.
- To cut off future access immediately, you can also revoke Rambit's permission in your Google Account permissions page, or block the business's messaging number in your messaging app.
- We may retain the minimum data needed to comply with legal obligations, resolve disputes, or enforce our agreements, and we will tell you if that applies.
13. Security
We protect data with encryption in transit and at rest, role-based access control with least privilege, secrets management for platform credentials, audit logging, code review, dependency monitoring, and regular backups. Access to production data is limited to the personnel who need it, under confidentiality obligations. No system is perfectly secure; if a breach affects your personal data we will notify you and the competent authority as required by law.
14. Children
Our services are directed at businesses and are not intended for children under 14, or under 16 where local law sets that threshold. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
15. Changes to this policy
We may update this policy as our services or the law change. We will revise the "last updated" date above and, for material changes affecting your rights, notify account holders by email or an in-product notice before the change takes effect. The current version is always published at rambit.co/privacy.
16. Contact
Rambit SAS, NIT 901.442.697-8. Registered address: Carrera 24B, Bogotá 111411, Colombia. Privacy and data protection enquiries: contacto@rambit.co. General enquiries: contacto@rambit.co.