1. Who is responsible
For your own account information, the operator of the SAMT deployment you use is responsible for that processing. For recipient lists, numbers, email addresses and message content you upload and send, you remain responsible for deciding why that data is used and whether you are permitted to use it. SAMT processes that data to provide the Service and carry out your authorised instructions, subject to platform safety controls.
2. Information we process
We process the following categories of data:
- Account data — your name, email address, hashed password, role and account/session status.
- Recipient data — the phone numbers, email addresses and names you add to audiences, lists or campaigns.
- Permission data — consent status, consent source and time where recorded, opt-out/revocation state and durable suppression records used to prevent accidental re-send.
- Message data — campaign content, destination information and delivery results.
- Sender and provider data — configured sender identities, sender-approval status and provider credentials. Provider credentials are encrypted at rest using AES-256-GCM.
- Technical and security data — operational logs, audit events and other data needed to operate, secure and troubleshoot the Service.
3. How we use it
We use this information to:
- Provide the core features — number checks, audience/list management, sending and tracking.
- Authenticate you, manage sessions and secure your account.
- Apply recipient permission, opt-out, sender-identity and platform safety controls.
- Maintain, monitor and improve the reliability and security of the Service.
- Respond to valid legal, security or abuse requirements where applicable.
4. Recipient permission & your responsibility
You are responsible for ensuring you have an appropriate basis to store and contact each recipient and for handling recipient data fairly. SAMT may require explicit permission evidence for protected sends and may retain revocation or suppression state so an address or number is not accidentally contacted again.
A SAMT permission or sender-approval control is a product safety mechanism. It does not itself determine whether your activity complies with the law in every jurisdiction.
5. Sharing
To deliver messages, relevant data such as a destination address or number and message content is shared with the messaging provider used for that send. This may be a provider you connect or, where available, a SAMT-managed messaging service. We do not sell personal data.
We may also use infrastructure and service providers needed to operate the platform. Their processing depends on the deployment and service configuration in use.
6. Storage & security
Data is stored in the systems configured for the SAMT deployment. Technical and organisational controls include encrypted provider credentials, access controls, revocable sessions, audit records, rate limiting and messaging safety ceilings. No system is perfectly secure, but these controls are intended to reduce operational and security risk.
7. Retention
Retention depends on the data type, workspace settings, operational requirements and any applicable legal obligations. Deleting a list or contact does not necessarily remove a separate revocation or suppression record immediately where retaining that limited state is needed to prevent an accidental future re-send.
8. Your choices and requests
Depending on where you are located, you or people whose data you control may have rights concerning personal data. Account-related or privacy requests for SAMT can be sent to support@samt.run. Recipient requests should normally be handled by the organisation that uploaded or used that recipient data.
9. International processing
The countries in which data is processed depend on the infrastructure and messaging providers configured for the deployment and the channels you use. You are responsible for assessing any requirements that apply to your own recipient data and provider choices.
10. Changes & contact
We may update this notice as the Service evolves. Privacy questions about SAMT can be sent to support@samt.run. This notice does not claim jurisdiction-specific compliance or certification beyond the controls it actually describes.
This document is a general template provided for convenience and does not constitute legal advice. Have it reviewed by a qualified lawyer in your jurisdiction before relying on it.