Copyright © 2026 Valamm.AI
Privacy Policy
This Policy explains how we collect, use, share, retain and protect personal data across our go-to-market, market-acceleration, GCC hosting and entity-setup services, and through our use of third-party platforms including LinkedIn.
Introduction
This Privacy Policy (the "Policy") is an electronic record within the meaning of the Information Technology Act, 2000, and is published and maintained in accordance with applicable data protection laws in India.
The website www.valamm.ai (the "Website") and the services described on it are operated by Valamm.AI Labs Private Limited ("Valamm", "we", "us", "our"), a company incorporated under the Companies Act, 2013, with its office at BHIVE Platinum, HAL Old Airport Road, Kodihalli, Indiranagar, Bengaluru, Karnataka 560008, India.
This Policy explains how we collect, use, share, retain and protect personal data across our go-to-market, market-acceleration, Global Capability Centre (GCC) hosting, and entity-setup services (the "Services"), and through our use of third-party platforms including LinkedIn. By using the Website or Services you confirm you have read and understood this Policy.
Our two roles
Valamm operates in two capacities:
- As a Data Fiduciary — where we determine the purpose and means of processing: Website visitors; prospective clients and business contacts; leads captured through our own forms (including LinkedIn lead-generation forms); job applicants; our personnel; and our vendors and partners.
- As a Data Processor — where we process personal data on the documented instructions of a client (for example, running GTM campaigns, building pipelines, or hosting a Micro-GCC). In this role the client is the Data Fiduciary, and that processing is governed by our separate agreement with the client, not by this Policy (see Section 10).
Definitions
- Consent — a freely given, specific, informed and unambiguous agreement to processing.
- Cookies — a small file placed on your device when you visit or use certain features of the Website, allowing it to remember your actions or preferences for a period of time.
- Data Fiduciary — the person who determines the purpose and means of processing personal data.
- Data Principal / "you" — the individual to whom the personal data relates.
- Data Processor — a person who processes personal data on behalf of a Data Fiduciary.
- Partners — select third parties with whom we have contracts for the purposes described in this Policy.
- Personal Data — any data about an individual who is identifiable by or in relation to such data.
- Processing — any operation on personal data (collection, use, storage, sharing, disclosure, erasure, etc.).
- Service Providers — entities to whom we disclose personal data to process it for a specific purpose under a written contract.
- Sub-processor — a third party we engage to process personal data under written contract.
Personal data we collect
4.1 Information you provide directly
- Contact & enquiry data — name, business email, phone, country, company, role/designation, and message content (via our contact form, info@valamm.ai, or Calendly bookings).
- LinkedIn lead data — where you submit a LinkedIn Lead Generation Form or respond to our LinkedIn campaigns, we receive the details you submit (typically name, business email, job title, company and location).
- Recruitment data — name, contact details, CV/résumé, work and education history, and, later in a hiring process, identity/verification documents.
- Client onboarding data — business contact and scoping information from client representatives.
4.2 Information collected automatically
IP address, device/browser type, operating system, referring/exit URLs, pages viewed, session data, and similar diagnostics — including via Cookies, Google Tag Manager, Google Analytics and advertising pixels (Section 8).
4.3 Information from third-party and public sources
We may obtain limited business contact data from publicly available professional sources, referrals, partners, event organisers, and third-party business-data providers, where relevant to a business relationship. Where we obtain your data this way, this Policy serves as your notice; on request we will tell you the source of the data we hold about you, and you may object to or opt out of this processing at any time (Sections 7 and 9).
LinkedIn data and API usage
We use LinkedIn's platform and Application Programming Interfaces (APIs) — including LinkedIn Lead Generation Forms and LinkedIn advertising and marketing products — to reach relevant business audiences, generate leads, and measure our campaigns.
When you interact with our LinkedIn content, forms or ads, we may receive personal data that you have chosen to submit or that LinkedIn makes available to us in accordance with your settings and LinkedIn's terms (such as your name, professional email, job title, company and location).
In relation to any data obtained through LinkedIn:
- we use it only for the business purposes described in this Policy (primarily responding to your interest and providing information about our Services);
- we process it in accordance with LinkedIn's API Terms of Use, Platform Guidelines and applicable policies;
- we do not sell LinkedIn member data, and we do not use it for any purpose outside the scope permitted by LinkedIn and by you;
- we store it securely and retain it only for as long as necessary (Sections 12 and 13); and
- you may ask us to access or delete the LinkedIn data we hold about you at any time (Section 14).
How we collect personal data
We collect personal data (a) directly from you, (b) automatically when you use the Website, and (c) from the third-party and public sources described in Section 4.3, including LinkedIn.
Purposes and lawful basis
We process personal data to: respond to enquiries, forms and bookings; scope, contract for and deliver the Services; assess job applications; operate, secure and improve the Website and our operations; send business and marketing communications (with opt-out); perform analytics; comply with law and defend legal claims; and prevent fraud and misuse.
We rely on your consent and on other lawful bases permitted under applicable data protection laws in India (including data you voluntarily provide for a specified purpose, employment-related purposes, and legal compliance). Some business-contact data used for outreach is provided by clients, obtained from third-party business-data providers, or drawn from publicly available professional sources; we use it on the basis of our legitimate interest in business-to-business marketing, and you may object at any time. Where processing relies on consent, you may withdraw it at any time; withdrawal does not affect prior processing and may mean we can no longer provide a requested service or feature.
Cookies, analytics and advertising
We use Cookies and similar technologies (including Google Tag Manager, Google Analytics, and advertising/retargeting pixels such as the LinkedIn Insight Tag and Google Ads) to operate the Website, measure traffic, and deliver and measure advertising. Strictly necessary Cookies are always active; analytics and advertising Cookies are used with your consent where required. You can manage Cookies through your browser and our Cookie banner / preference tool.
Marketing and your choices
Every marketing message includes an unsubscribe link, and you may opt out of all marketing at any time by emailing privacy@valamm.ai. On request, we will also tell you the source of your data where we hold it and remove you from our outreach lists.
How we share and disclose personal data
We do not sell your personal data. We share it only as below, under contract and appropriate safeguards:
- Service Providers / Sub-processors — hosting, analytics, scheduling (Calendly), email/CRM, cloud infrastructure, DevOps, HR/payroll, legal/CFO and marketing/design partners, and advertising platforms (LinkedIn, Google) for lead generation and ad delivery/measurement.
- Partners — only where relevant to a Service you engage, under confidentiality.
- Clients — where we act as a Data Processor, per their instructions and our agreement.
- Legal / regulatory — where reasonably necessary to comply with law, court orders or lawful government requests, to enforce our terms, protect rights and safety, or prevent or investigate fraud or offences.
- Business transfers — in a merger, acquisition or restructuring, subject to this Policy.
We may also disclose aggregated or de-identified information that does not identify anyone.
Personal data we process on behalf of clients
When delivering GTM, market-acceleration, customer-acquisition and Micro-GCC/hosting Services, we may process personal data as a Data Processor on behalf of a client. In this role we: process only on the client's documented instructions and for the agreed purposes; require the client to confirm it has the lawful basis and rights for the data it provides; apply appropriate security and impose equivalent terms on sub-processors; assist the client with data-principal requests and breach obligations; and delete or return the data at the end of the engagement.
Automated processing and profiling
We may use analytics, CRM scoring and AI-assisted tools to organise, prioritise or rank business leads and, in recruitment, to help screen applications. These tools support human decision-making; we do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. You may contact us to ask about, or object to, this processing.
Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, to maintain business relationships, and to meet legal, tax and regulatory requirements, after which it is deleted or anonymised. Indicative periods:
| Enquiry / lead data | 24 months after last contact |
| Unsuccessful candidate data | 12 months |
| Contractual and financial records | Up to 8 years, as required by applicable law |
Your rights
Subject to applicable law and verification of your identity, you may:
- Access a summary of the personal data we hold about you and our processing of it;
- Request correction, completion or updating;
- Request erasure where the data is no longer needed or where you withdraw consent (unless retention is legally required);
- Withdraw consent;
- Nominate another individual to exercise your rights; and
- Raise a grievance.
HOW TO EXERCISE YOUR RIGHTS
To exercise any right, contact our Grievance Officer (Section 18). We will respond within 30 days.
Security, Force Majeure and breach notification
We implement reasonable technical, organisational and physical security measures (access controls, encryption where appropriate, and vendor safeguards) and review them periodically. However, no method of internet transmission or electronic storage is fully secure, and we do not guarantee absolute security. You are responsible for safeguarding any credentials we issue to you.
We are not liable for any loss or unauthorised access arising from events beyond our reasonable control, including fire, flood, acts of God, civil disturbance, war, government action, power or network failure, hacking, malware, unauthorised access or system failure not attributable to our failure to take reasonable measures.
In the event of a personal-data breach, we will notify affected individuals and the relevant authority within the timelines required by law.
Children's data
The Website and Services are intended for business users and are not directed at children. We do not knowingly process the personal data of children (individuals under 18) without verifiable parental or guardian consent, and we do not track or target children. If you believe we hold such data, please contact us for prompt deletion.
Third-party websites and links
The Website may link to third-party websites, tools or advertisements (including clients' and partners' sites). We are not responsible for their privacy practices or content; access is at your own risk, and you should review their policies. A link or advertisement is not an endorsement.
Grievance Officer / Data Protection contact
Valamm Grievance Officer
Valamm.AI Labs Private Limited
Email: privacy@valamm.ai
Address: BHIVE Platinum, HAL Old Airport Road, Kodihalli, Indiranagar, Bengaluru, Karnataka 560008, India
Phone: +91 9187968350
We are committed to answer your questions within the reasonable time limit. Any delay in the resolution time shall be proactively communicated to you. If you suspect any misuse or loss or unauthorized access to your Personal Information please let us know immediately.
Changes to this Policy
We may revise this Policy from time to time. Material changes will be posted on the Website with a revised "Last updated" date and, where appropriate, notified by email. Continued use of the Website or Services after changes take effect constitutes acceptance.
Governing law and jurisdiction
This Policy is governed by the laws of India. The courts at Bengaluru, Karnataka, India shall have exclusive jurisdiction over any disputes arising out of or in connection with this Policy.

