Product privacy details
These details supplement the Rama OS Privacy Policy. A customer's own notice, contract, employment notice, recording disclosure, or consent may also apply.
Workforce and applicants
Data: Contact details, applications, documents, wages, schedules, attendance, training, certifications, and related employment records.
Purpose: Recruiting and workforce operations selected by the hospitality business.
Roles and obligations: The hospitality business is normally the controller; Rama acts as its processor. The business remains responsible for employee and applicant notices, lawful instructions, and required retention.
Recipients: Rama hosting and storage providers; payroll or AI providers only when the business configures and invokes those features.
Retention: Customer-configured and subject to employment, payroll, safety, dispute, and legal-hold requirements.
Voice
Data: Caller number, call metadata, transcripts, consent evidence, order context, and audio only when recording is enabled.
Purpose: Voice ordering, call routing, quality, fraud prevention, and safety.
Roles and obligations: The hospitality business normally decides whether and how Voice is used. It must supply any required recording notice and obtain consent before capture.
Recipients: Approved telephony, speech-recognition, speech-generation, AI, hosting, and storage providers.
Retention: Audio, transcripts, and replay artifacts have separate feature-specific schedules. Recording is not represented as universally active.
Vision
Data: Configured camera snapshots, zone or occupancy events, safety events, and derived tracking identifiers when enabled.
Purpose: Operational visibility, safety, occupancy, and other customer-configured uses.
Roles and obligations: The hospitality business normally controls the deployment, camera placement, signage, and legal basis. Rama provides processing tools.
Recipients: Rama hosting and storage providers and an approved model provider only when the configured workflow invokes one.
Retention: Snapshots should be short-lived; event retention is feature- and customer-specific. Vision must not be described as never storing imagery when snapshots can be configured.
Guests, loyalty, marketing, and reservations
Data: Contact details, reservations, visits, notes, preferences, loyalty activity, consent and suppression records, and communications.
Purpose: Reservations, guest service, loyalty, transactional messages, and consented marketing.
Roles and obligations: The hospitality business normally controls the guest relationship. Rama acts on its instructions and separately controls security and service-administration data.
Recipients: Hosting, email, SMS, wallet, and customer-authorized integration providers.
Retention: Customer-directed, with financial, dispute, suppression, and legal exceptions. Marketing consent can be withdrawn independently of transactional service messages.
Commerce, payments, finance, and integrations
Data: Orders, employee attribution, transaction references, invoices, accounting and tax records, fraud signals, and connected-provider identifiers.
Purpose: Order fulfillment, payment processing, billing, accounting, tax, reconciliation, and fraud prevention.
Roles and obligations: The hospitality business controls its commerce and connected accounts. Payment processors and connected platforms may act under their own terms for portions of the transaction.
Recipients: The selected payment processor, POS, accounting platform, and Rama hosting providers.
Retention: Payment, payroll, tax, and accounting evidence can require longer retention. Rama does not intentionally store raw card numbers or security codes.
Documents, uploads, and support evidence
Data: Files, images, audio or video, document metadata, support messages, and evidence submitted for a requested feature.
Purpose: Deliver the requested feature, review an application or record, provide support, or preserve approved operational evidence.
Roles and obligations: Role depends on the feature. Sensitive customer uploads are generally processed for the customer; Rama controls its own support and security records.
Recipients: Private object storage, hosting, and an approved scanner or model provider only when the workflow requires it.
Retention: Feature deletion, subject erasure, age-based expiry, quarantine, orphan reconciliation, and documented legal holds apply by category.
Artificial intelligence
Data: Prompts, the minimum selected operational context, tool results, outputs, usage, and safety metadata.
Purpose: Provide the AI feature requested by the user, including summaries, recommendations, drafting, and approved operational assistance.
Roles and obligations: Rama and the hospitality business have context-dependent roles. AI output is not a substitute for human review and must not be the sole basis for consequential employment, credit, health, or similar decisions.
Recipients: Only an approved provider allowed for the applicable data class. Current configured providers include Anthropic and OpenAI; the live register controls authorization.
Retention: Rama AI sessions and provider-side data follow separately governed schedules and contract settings. A credential alone cannot authorize sensitive egress.