Skip to content

SMARTBEAM AI PRIVACY NOTICE

Last updated: 02 September 2026

1. About this Privacy Policy

This Privacy Policy explains how SmartBeam AI (“SmartBeam”, “we”, “us” or “our”) collects, uses, discloses, stores and otherwise processes Personal Data in connection with our website at https://smartbeam-ai.com (the “Website”), enquiries, demonstrations, pilots, events, business relationships and the SmartBeam AI products and services (together, the “Services”).

This Privacy Policy applies when SmartBeam AI determines why and how Personal Data is processed and therefore acts as a data fiduciary, controller or equivalent role under Applicable Privacy Law. It does not replace any customer contract or data processing agreement that applies when SmartBeam processes Personal Data solely on a customer’s instructions.

In this Privacy Policy, “Applicable Privacy Law” means any privacy or data-protection law applicable to the relevant processing, including, as and when applicable, the Digital Personal Data Protection Act, 2023 and the rules made under it (the “DPDP Framework”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the EU General Data Protection Regulation (“EU GDPR”), the UK GDPR, and applicable United States state privacy laws.

A reference to “Personal Data” includes personal data, personal information and similar terms under Applicable Privacy Law: information relating to an identified or identifiable individual. Data about industrial equipment that cannot identify an individual is not Personal Data, although we protect customer operational data in accordance with our contracts and security measures.

2. Who this Privacy Policy covers

This Privacy Policy covers individuals who visit the Website; submit an enquiry, request access, request a pilot, schedule a technical discussion or obtain resources; represent or work for customers, prospective customers, suppliers, partners or advisers; use an authorised customer account or interface; attend an event or interact with us; or apply for a role with SmartBeam.

The Website and Services are intended for organisations and adult business users. They are not directed to children.

3. Personal Data we collect

3.1. Data you provide

· Contact and professional data: name, work email address, telephone number, employer, job title, department, business location and professional profile details.

· Enquiry and pilot data: company name, number and type of pumps in a fleet, operational challenges, project requirements, messages, meeting details, technical questions and information submitted when you request access, a pilot, a demonstration, a white paper or a security and compliance pack.

· Technical and operational materials: documents and datasets supplied for discovery, evaluation or a pilot, including P&IDs, pump specifications, equipment identifiers, historian extracts, telemetry, waveform or sensor data, maintenance records and diagnostic context. These materials are ordinarily equipment or business data, but may contain Personal Data such as names, work contact details, usernames, operator identifiers or free-text notes.

· Account and support data: account identifiers, role and access permissions, support requests, correspondence, feedback and training or implementation records, where customer access to the Services is enabled.

· Recruitment data: curriculum vitae, employment and education history, professional qualifications, references and other information supplied in connection with a job application.

· Communications: the content and metadata of emails, calls, meetings and other communications with us. We will give appropriate notice if a call or meeting is recorded.

3.2. Data collected automatically

When you visit or interact with the Website or Services, we and our authorised providers may collect device and usage data, including IP address, browser and device type, operating system, language, referring and exit pages, pages or features viewed, dates and times, approximate location derived from IP address, cookie or similar identifiers, and security and audit logs. The Website presently uses WordPress and HubSpot tools to support website analytics, enquiries and business communications.

3.3. Data from other sources

We may receive Personal Data from your employer or another customer contact, referral partners, event organisers, professional networks, publicly available business sources, service providers, and group companies or business partners. We use such data only for purposes reasonably connected with the source and context in which it was obtained.

Please do not submit health, biometric, financial-account, payment-card, government-identifier or other sensitive or special-category Personal Data unless we specifically request it for a lawful purpose and provide any additional notice required by law.

4. Why we process Personal Data

We process Personal Data only for lawful, specified purposes. Depending on the context and Applicable Privacy Law, processing is based on your consent; your voluntary provision of data for a specified purpose; steps requested by you or your organisation in anticipation of, or performance under, a contract; compliance with law; protection of individuals; or another ground permitted by Applicable Privacy Law. Where the EU GDPR or UK GDPR applies, our legal bases may also include our legitimate interests, provided those interests are not overridden by your rights and interests.

More specifically, where the EU GDPR or UK GDPR applies, we ordinarily rely on steps requested before entering into a contract or performance of a contract for enquiries, accounts, pilots and Services; legitimate interests for B2B relationship management, security, fraud prevention, Service improvement and relevant professional communications; consent for non-essential cookies and consent-based marketing; legal obligations for mandatory records and disclosures; and the establishment, exercise or defence of legal claims where necessary. Recruitment processing is based on requested pre-contractual steps, legal obligations and legitimate interests, as applicable.

We process Personal Data to:

· operate, secure, maintain and improve the Website and Services;

· respond to enquiries and requests; assess requirements; provide demonstrations, pilots, diagnostic reports, resources and support; and communicate about projects;

· create and administer authorised accounts, authenticate users, manage access, and provide implementation, training and customer support;

· perform contracts with customers, suppliers and partners, manage business relationships, and maintain commercial and operational records;

· analyse equipment datasets and telemetry to provide pump-health, efficiency, fault-detection and prescriptive insights requested by the relevant customer;

· understand Website and Service performance, troubleshoot problems, develop features, and generate aggregated or de-identified statistics;

· send product updates, technical content, invitations and marketing communications where permitted by law, and record preferences and opt-outs;

· prevent, detect and investigate fraud, misuse, security incidents and violations of our terms or policies;

· comply with legal, regulatory, tax, audit, reporting and law-enforcement requirements; establish, exercise or defend legal claims; and obtain professional advice or insurance; and

· evaluate candidates and administer recruitment.

We do not use Personal Data submitted through the Website or Services to make solely automated decisions about individuals that produce legal or similarly significant effects. SmartBeam’s AI analyses industrial pump and operational data; it is not intended to profile individuals.

5. Consent and choices

Where consent is required, we will request it through a clear affirmative action and provide a notice describing the Personal Data sought and the specific purpose. Consent is not inferred merely because this Privacy Policy is available. You may withdraw consent at any time using the contact details in section 17 or the relevant preference control. Withdrawal will not affect processing already undertaken lawfully, but it may prevent us from providing a feature or response that depends on the withdrawn data.

You may opt out of marketing emails by using the unsubscribe link or contacting us at info@smartbeam-ai.com. Service, security, transactional and relationship communications may still be sent where necessary and lawful.

6. Customer data and SmartBeam AI’s processor role

A customer may provide or make available operational datasets, telemetry, account information or other data in connection with a pilot or deployment (“Customer Data”). Where Customer Data contains Personal Data and SmartBeam processes it solely for the customer’s specified purposes and instructions, the customer is the data fiduciary or controller and SmartBeam acts as its data processor or processor.

In that situation, the customer’s privacy notice and our agreement with that customer govern the processing. Requests concerning such Personal Data should ordinarily be directed to the customer. If we receive a request, we may refer it to the customer and assist the customer as required by contract and law. Any use of Customer Data for model training or improvement is governed by the customer agreement and Applicable Privacy Law. Where Customer Data contains Personal Data, we will not use it for an independent purpose unless the agreement permits that use and a lawful ground applies.

We may create statistical, aggregated or de-identified information from Customer Data where permitted by the customer agreement and law. We take reasonable measures designed to prevent such information from identifying an individual and do not attempt to re-identify it.

7. How we disclose Personal Data

We disclose Personal Data only where reasonably necessary for the purposes described in this Privacy Policy, including to:

· Service providers and processors: cloud hosting, cybersecurity, analytics, customer-relationship management, website hosting, communications, collaboration, support, recruitment and professional-service providers, including providers that support WordPress and HubSpot functionality.

· Your organisation and authorised users: where you act for a customer, prospective customer, supplier or partner, we may share relevant account, project and communication information with authorised representatives of that organisation.

· Professional advisers and insurers: lawyers, accountants, auditors, consultants, insurers and financial advisers subject to appropriate duties of confidentiality.

· Authorities and other parties for legal reasons: courts, regulators, law-enforcement bodies and other persons where disclosure is required by law or reasonably necessary to protect rights, safety, property, security, prevent wrongdoing or pursue a legal claim.

· Corporate transactions: actual or prospective investors, lenders, acquirers, sellers and advisers in connection with financing, restructuring, merger, acquisition or transfer of all or part of our business, subject to appropriate safeguards.

We require service providers that process Personal Data for us to use it only for authorised purposes, protect it appropriately, and comply with applicable contractual and legal obligations. We do not sell Personal Data for money. Where a disclosure for advertising or analytics is treated as a “sale”, “sharing” or targeted advertising under Applicable Privacy Law, we will provide any notice and opt-out mechanism required by that law.

8. International processing and transfers

SmartBeam and its service providers may process Personal Data in India and in other countries where they operate. Those countries may have different data-protection laws. We will comply with restrictions

notified under the DPDP Framework and any more protective sectoral law. Where the EU GDPR or UK GDPR applies to a transfer outside the relevant jurisdiction, we will use an approved transfer mechanism where required, such as an adequacy decision or standard contractual clauses, together with supplementary measures where appropriate. You may contact us for information about the applicable safeguards.

9. Retention and deletion

We retain Personal Data only for as long as reasonably necessary for the relevant purpose, including to provide the Services, maintain business and security records, comply with law, resolve disputes and enforce agreements. Retention is determined by the nature and sensitivity of the data, the purpose of processing, the relationship with the relevant organisation, risk, limitation periods and mandatory record-keeping requirements.

· Enquiry and business-contact data: for the duration of the enquiry or relationship and a reasonable follow-up period, ordinarily not more than 24 months after the last meaningful interaction unless a longer period is justified or consent remains valid.

· Customer account, contract and project records: for the contract term and ordinarily up to 8 years thereafter, or longer if required for tax, regulatory, audit, warranty, dispute or legal-claim purposes.

· Pilot datasets and Customer Data: for the period stated in the customer agreement or pilot terms and then deleted or returned, subject to backups, legal holds and mandatory retention.

· Security and access logs: for the period reasonably necessary for security, investigation and compliance, subject to any mandatory minimum retention.

· Recruitment data: for the recruitment process and a reasonable period thereafter, ordinarily up to 12 months unless a longer period is required by law or agreed for future opportunities.

When retention is no longer necessary and no lawful exception applies, we delete, anonymise or securely isolate the Personal Data. Residual copies in backups are protected and deleted in accordance with backup cycles.

10. Cookies and similar technologies

The Website uses cookies and similar technologies. Strictly necessary technologies support core operation, security and user-requested functions. Analytics and marketing technologies help us understand Website use, assess campaigns, manage enquiries and improve communications. These may be provided by third parties, including HubSpot.

Where required by law, non-essential cookies or similar technologies will be used only after consent, and you may accept, reject or manage them through the cookie banner or preference centre. You may also adjust browser settings, although blocking necessary technologies may affect functionality. A cookie notice or preference centre should identify the cookies in use, their providers, purposes and durations. Browser-based “Do Not Track” signals are not universally standardised; we respond to legally recognised opt-out preference signals where required.

11. Security and incident response

We use reasonable and appropriate technical and organisational measures designed to protect Personal Data against unauthorised or accidental access, acquisition, use, alteration, disclosure, destruction or loss of availability. Measures may include access controls, authentication, encryption in transit, secure configuration, logging and monitoring, backups, vulnerability and incident management, vendor controls, confidentiality obligations and periodic review.

No system is completely secure. You are responsible for protecting credentials assigned to you and for notifying us promptly of suspected unauthorised access. If a Personal Data breach occurs, we will investigate, contain and remediate it, maintain required records, and notify affected individuals and authorities where and within the periods required by Applicable Privacy Law.

12. Your privacy rights

12.1. Rights under the DPDP Framework

To the extent the DPDP Framework applies and the relevant provisions are in force, you may have the right to:

· obtain a summary of your Personal Data being processed and the processing activities, and information about the persons with whom it has been shared, subject to lawful exceptions;

· correct inaccurate or misleading Personal Data, complete incomplete Personal Data and update Personal Data;

· request erasure of Personal Data that is no longer necessary, subject to retention required for the specified purpose or by law;

· withdraw consent with comparable ease to the manner in which it was given;

· raise a grievance and, after using our grievance process, complain to the Data Protection Board of India in the manner prescribed; and

· nominate another individual to exercise your rights in the event of your death or incapacity.

12.2. Rights in the EEA and United Kingdom

Where the EU GDPR or UK GDPR applies, you may also have rights to access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests, withdrawal of consent, and complaint to your local supervisory authority. These rights are subject to statutory conditions and exceptions.

12.3. Rights under applicable United States state laws

Where an applicable United States state privacy law covers our processing, you may have rights to know or access, correct, delete and obtain a portable copy of Personal Data, and to opt out of certain sale, targeted-advertising or profiling activities. You may also have a right to appeal a refusal and to use an authorised agent. We will not discriminate against you for exercising a privacy right.

12.4. How to exercise a right

Send a request to [insert dedicated email address] with the subject “Privacy Request” and describe the right you wish to exercise. We may request information reasonably necessary to verify your identity and authority and to locate the relevant data. We will respond within the period required by Applicable Privacy Law. If we cannot fulfil a request, we will explain the reason where the law requires. You may first need to contact your employer or the relevant SmartBeam customer where we process the data only on that customer’s behalf.

13. Your responsibilities

Please provide accurate information, use the Website and Services lawfully, keep account credentials confidential, and do not provide another individual’s Personal Data unless you are authorised to do so and have given any required notice. Under the DPDP Framework, Data Principals must not impersonate another person, suppress material information when providing identification for an official document or service, make false or frivolous grievances or complaints, or furnish false particulars while exercising rights.

14. Children

The Website and Services are not directed to individuals under 18 years of age, and we do not knowingly seek or collect their Personal Data. If you believe a child has provided Personal Data to us, contact us so that we can take appropriate action. If we intentionally process a child’s Personal Data in India, we will obtain verifiable consent from the parent or lawful guardian and comply with restrictions on tracking, behavioural monitoring and targeted advertising, unless a lawful exemption applies.

15. Third-party websites and services

The Website may link to third-party websites, platforms or resources. Their privacy practices are governed by their own notices, not this Privacy Policy. We encourage you to review those notices before providing Personal Data. We are not responsible for a third party’s independent processing.

16. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, the Website, the Services or our practices. We will publish the revised version with an updated date and provide any additional notice or obtain fresh consent where required. Material changes will not be applied retrospectively in a manner that unlawfully reduces your rights.

17. Contact and grievance redressal

Data fiduciary/controller: SmartBeam AI

Registered office: 211, Wadala Udyog Bhavan, MMGS Road, Wadala, Mumbai, Maharashtra 400031, India

General privacy email: info@smartbeam-ai.com

Grievance Officer / person responsible for privacy queries: Shreebhooshan B. – Chief Operating Officer, SmartBeam AI

We will acknowledge and address grievances within the period required by Applicable Privacy Law. If you are not satisfied with our response and the DPDP Framework applies, you may use the prescribed mechanism to approach the Data Protection Board of India after first giving us a reasonable opportunity to resolve the grievance. If the EU GDPR or UK GDPR applies, you may also complain to the competent supervisory authority.