Product privacy details

These details supplement the Rama OS Privacy Policy. A customer's own notice, contract, employment notice, recording disclosure, or consent may also apply.

Workforce and applicants

Data: Contact details, applications, documents, wages, schedules, attendance, training, certifications, and related employment records.

Purpose: Recruiting and workforce operations selected by the hospitality business.

Roles and obligations: The hospitality business is normally the controller; Rama acts as its processor. The business remains responsible for employee and applicant notices, lawful instructions, and required retention.

Recipients: Rama hosting and storage providers; payroll or AI providers only when the business configures and invokes those features.

Retention: Customer-configured and subject to employment, payroll, safety, dispute, and legal-hold requirements.

Voice

Data: Caller number, call metadata, transcripts, consent evidence, order context, and audio only when recording is enabled.

Purpose: Voice ordering, call routing, quality, fraud prevention, and safety.

Roles and obligations: The hospitality business normally decides whether and how Voice is used. It must supply any required recording notice and obtain consent before capture.

Recipients: Approved telephony, speech-recognition, speech-generation, AI, hosting, and storage providers.

Retention: Audio, transcripts, and replay artifacts have separate feature-specific schedules. Recording is not represented as universally active.

Vision

Data: Configured camera snapshots, zone or occupancy events, safety events, and derived tracking identifiers when enabled.

Purpose: Operational visibility, safety, occupancy, and other customer-configured uses.

Roles and obligations: The hospitality business normally controls the deployment, camera placement, signage, and legal basis. Rama provides processing tools.

Recipients: Rama hosting and storage providers and an approved model provider only when the configured workflow invokes one.

Retention: Snapshots should be short-lived; event retention is feature- and customer-specific. Vision must not be described as never storing imagery when snapshots can be configured.

Guests, loyalty, marketing, and reservations

Data: Contact details, reservations, visits, notes, preferences, loyalty activity, consent and suppression records, and communications.

Purpose: Reservations, guest service, loyalty, transactional messages, and consented marketing.

Roles and obligations: The hospitality business normally controls the guest relationship. Rama acts on its instructions and separately controls security and service-administration data.

Recipients: Hosting, email, SMS, wallet, and customer-authorized integration providers.

Retention: Customer-directed, with financial, dispute, suppression, and legal exceptions. Marketing consent can be withdrawn independently of transactional service messages.

Commerce, payments, finance, and integrations

Data: Orders, employee attribution, transaction references, invoices, accounting and tax records, fraud signals, and connected-provider identifiers.

Purpose: Order fulfillment, payment processing, billing, accounting, tax, reconciliation, and fraud prevention.

Roles and obligations: The hospitality business controls its commerce and connected accounts. Payment processors and connected platforms may act under their own terms for portions of the transaction.

Recipients: The selected payment processor, POS, accounting platform, and Rama hosting providers.

Retention: Payment, payroll, tax, and accounting evidence can require longer retention. Rama does not intentionally store raw card numbers or security codes.

Documents, uploads, and support evidence

Data: Files, images, audio or video, document metadata, support messages, and evidence submitted for a requested feature.

Purpose: Deliver the requested feature, review an application or record, provide support, or preserve approved operational evidence.

Roles and obligations: Role depends on the feature. Sensitive customer uploads are generally processed for the customer; Rama controls its own support and security records.

Recipients: Private object storage, hosting, and an approved scanner or model provider only when the workflow requires it.

Retention: Feature deletion, subject erasure, age-based expiry, quarantine, orphan reconciliation, and documented legal holds apply by category.

Artificial intelligence

Data: Prompts, the minimum selected operational context, tool results, outputs, usage, and safety metadata.

Purpose: Provide the AI feature requested by the user, including summaries, recommendations, drafting, and approved operational assistance.

Roles and obligations: Rama and the hospitality business have context-dependent roles. AI output is not a substitute for human review and must not be the sole basis for consequential employment, credit, health, or similar decisions.

Recipients: Only an approved provider allowed for the applicable data class. Current configured providers include Anthropic and OpenAI; the live register controls authorization.

Retention: Rama AI sessions and provider-side data follow separately governed schedules and contract settings. A credential alone cannot authorize sensitive egress.