← Back
Matimo™ Suite of Products Matimo™ Suite of Products

Privacy Notice

Version 2.2 · Last updated: 15 August 2026

Who this notice is about

This notice explains how ROAIQ™ Technologies Private Limited ("ROAIQ™", "Matimo™", "we", "us"), the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), processes personal data of account holders, tenant members, and other individuals ("you", "Data Principal") in connection with the Matimo™ Suite of Products platform. Where relevant, we also describe rights available to users in the EU/UK (GDPR) and California (CCPA/CPRA), see §16.

1. Scope

This notice covers the Matimo™ Suite of Products web application, API, and related services. It does not cover third-party websites or services you access through integrations you configure, see §9.

2. Personal Data We Process

Depending on the features you use, we process:

  • Account & identity data, name, email, tenant, role, authentication metadata.
  • Session data, login events and access/refresh token records used to keep you signed in.
  • Agent & workflow data, prompts, workflow configurations, execution state and results, and any documents you upload to a knowledge base.
  • Usage & billing data, tokens consumed, compute time, execution counts, and credit/subscription usage.
  • Integration data, OAuth connection metadata and encrypted access tokens for any third-party service you connect.
  • Operational & security logs, audit entries and API/system events used to secure and support the Platform.

Some of this data may include personal data of third parties that you or your agents process in the course of using the Platform (for example, contacts in a connected CRM). If you submit such data, you are responsible for having a lawful basis to do so.

3. Purposes & Legal Basis

We process personal data for the following specified purposes:

  • To authenticate you and secure your session.
  • To provide the Platform, running the agents and workflows your tenant configures.
  • To support approvals, auditability, and incident investigation.
  • To meter usage and generate billing/credit records.
  • To operate, secure, debug, and improve the Platform's reliability.
  • To comply with our legal obligations and respond to lawful requests from authorities.

We process personal data on the basis of your consent (for example, when you register an account or connect an integration) and, where applicable, on the basis of legitimate uses recognised under Section 7 of the DPDP Act, such as processing you have voluntarily provided data for a specified purpose and have not indicated you do not consent to. You may withdraw consent at any time as described in §11; withdrawal does not affect processing already carried out, or our ability to retain data as required by law.

4. How We Store & Protect Data

  • Matimo™ Suite of Products runs on AWS infrastructure (ECS, RDS PostgreSQL, ElastiCache Redis, Secrets Manager).
  • All traffic to the Platform is encrypted in transit using TLS 1.2/1.3, with HTTP connections redirected to HTTPS and HSTS enforced.
  • Sensitive credentials you provide, including OAuth tokens and any LLM provider API keys, are encrypted at the application layer (AES-256) before being stored.
  • Infrastructure secrets are stored in AWS Secrets Manager, not in application code.
  • Authentication uses signed JWT access/refresh tokens.
  • We are continuing to expand encryption-at-rest coverage across our underlying data stores as part of ongoing infrastructure hardening; see our Security overview for current status.

5. Data Retention

We retain account and operational data for as long as your account is active, plus a default retention period of 90 days after deletion for operational data and 365 days for audit logs (both configurable per tenant by your administrator, and subject to any longer period required by law). If you exercise your right to erasure (§11), we apply a short grace period (default 30 days) before permanent deletion, primarily to prevent accidental loss and to allow you to change your mind.

6. Tenant Data Isolation

Matimo™ Suite of Products is multi-tenant. Access to your organisation's data is scoped by tenant at the application and data-access layer, reinforced by PostgreSQL Row-Level Security policies on the underlying database as a defence-in-depth measure.

7. Cross-Border Data Transfer

Our infrastructure is currently hosted on AWS in the United States (region: us-east-1). This means your data is transferred to and stored outside India. The DPDP Act permits transfer of personal data outside India except to countries the Central Government specifically restricts by notification; no such restriction currently applies to our hosting location. We do not currently offer a data-residency guarantee limiting storage to a specific country, contact privacy@matimo.ai if this is a requirement for your organisation.

8. Automated Processing

Agents you configure may produce outputs, summaries, or classifications based on the data you provide, using large language models. We do not use these outputs to make automated decisions with legal or similarly significant effects on individuals; if you build an agent or workflow that does, you are responsible for ensuring appropriate human review and compliance with applicable law.

9. Sharing With Third Parties

We share personal data with the following categories of service providers, only as needed to operate the Platform, and we do not sell personal data:

  • Cloud infrastructure, Amazon Web Services (hosting, storage).
  • LLM providers, OpenAI, Anthropic, Google, AWS Bedrock, or a self-hosted/Ollama model, depending on which provider you or your tenant administrator configure for a given agent.
  • Email delivery, Resend, for transactional account and notification email.
  • Payments, our payment processor, who acts as Merchant of Record for paid subscriptions and credit purchases (see our Refund Policy).
  • Integrations you connect, third-party services you choose to connect (for example Slack, Gmail, GitHub, Notion, HubSpot, or Microsoft), which receive only the data your agents send them when you use that integration.
  • Composio, where you or your tenant administrator enables a Composio-mediated connector (for example Jira, Asana, Linear, Google Calendar, Google Drive, Outlook, OneDrive, SharePoint, or Microsoft Teams), Composio (composio.dev) acts as a data processor/subprocessor for the data your agents send through that connector, using the Composio account and API key you configure. Composio is not affiliated with us; see §9 of our Terms of Use for the allocation of responsibility for your Composio account.

We may also disclose personal data where required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets (with notice to you where required by law).

9A. Google User Data (Limited Use Disclosure)

Where you connect a Google account (for example Gmail) to the Platform, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide or improve the specific, user-facing features you invoke through your connected Google account, for example, letting an agent read, search, or send email on your behalf when you configure it to do so. We do not use Google user data to improve the Platform generally, and the "improve the Platform's reliability" purpose in §3 does not extend to Google user data.
  • We do not use Google user data to serve advertisements of any kind.
  • We do not use Google user data to train or improve generalised, non-personalised AI/ML models. Where an LLM provider processes Google user data as part of executing an agent action you configured (see §9), that data is used only to generate the response to your request and is not used by us or, per our provider agreements, by the LLM provider to train their models.
  • We do not sell Google user data, and do not transfer it to third parties except: (a) as necessary to provide or improve the user-facing features you requested (for example passing message content to the LLM provider you configured, solely to generate that response), (b) to comply with applicable law or a valid legal request, or (c) as part of a merger, acquisition, or asset sale, with the acquiring entity bound to these same restrictions.
  • We do not allow humans to read Google user data, except: with your explicit consent for a specific case (for example, support troubleshooting you request), where necessary for security purposes (such as investigating abuse or a security incident), to comply with applicable law, or where the data has been aggregated and anonymised.

10. Cookies & Tracking Technologies

Authentication is handled using browser local storage rather than cookies.

Our public marketing pages (the pages you can reach without signing in, such as this one) use Google Analytics 4, a third-party analytics service that sets cookies to measure site traffic and usage. We use Google's Consent Mode: analytics cookies are set to "denied" by default for every visitor, and are only enabled if you accept them via the cookie banner shown on your first visit. You can decline, and can withdraw your consent at any time by clearing your browser's local storage for this site (which resets the banner) and choosing "Decline". We do not use advertising cookies or advertising trackers. This tracking does not run once you are signed in to the Platform (your tenant workspace, agent chat, Studio canvas, and other authenticated pages) or on any non-production hostname such as demo.matimo.ai.

11. Your Rights as a Data Principal

Subject to applicable law, you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct or complete inaccurate or incomplete personal data.
  • Erase personal data we no longer need for the purpose it was collected, or that you withdraw consent for (subject to our right/obligation to retain certain data, for example for billing or legal-compliance records).
  • Withdraw consent at any time, as easily as you gave it.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Grievance redressal, raise a complaint with us first (§15), and escalate to the Data Protection Board of India if unresolved.

12. How to Exercise Your Rights

You can request data export and account/data erasure directly from your account under Settings, or by emailing privacy@matimo.ai with your account email and the request. We aim to acknowledge requests within 7 days and resolve them within 30 days, or sooner where required by law.

13. Data Breach Notification

In the event of a personal data breach affecting your personal data, we will notify affected users and the Data Protection Board of India (or other applicable authority) without undue delay, as required by the DPDP Act and other applicable law.

14. Children's Privacy

The Platform is intended for business and professional use and is not directed at children. We do not knowingly collect personal data from individuals under 18. If you believe a child has provided us personal data, contact privacy@matimo.ai and we will delete it.

15. Data Fiduciary Contact / Grievance Officer

ROAIQ™ Technologies Private Limited is the Data Fiduciary responsible for personal data processed through the Platform.

Privacy queries & Data Principal requests
privacy@matimo.ai
Grievance Officer (IT Rules, 2021)
Sajesh, Founder & CEO, sajesh@matimo.ai
Registered office
ROAIQ™ Technologies Private Limited, Isha Misty Green, Whitefield, Bangalore, Karnataka 560067, India

16. International Users (GDPR / CCPA)

If you are in the European Economic Area, the UK, or Switzerland, you have equivalent rights under the GDPR/UK GDPR (access, rectification, erasure, restriction, portability, and objection), and the right to lodge a complaint with your local supervisory authority. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information, we do not sell or share personal information as defined by the CCPA/CPRA. Contact privacy@matimo.ai to exercise any of these rights; we will honour the request under whichever framework applies to you.

Honouring these rights is separate from formal certification. ROAIQ™ is not itself SOC 2, HIPAA, or GDPR certified, and no such certification is claimed, see our Compliance page for our full compliance posture.

17. What We Recommend You Avoid Uploading

  • Data your organisation has not authorised you to process outside your own systems.
  • Unredacted secrets, production credentials, or access keys in prompts.
  • Highly sensitive personal data (for example health records) unless your tenant's compliance settings and your own policies are configured to handle that category appropriately.

18. Changes to This Notice

We may update this notice from time to time. If a change is material, we will notify you by email or in-app notice before it takes effect, and update the "Last updated" date above.

19. Contact

For privacy questions, requests, or concerns, contact privacy@matimo.ai.