Privacy Policy
Last updated: September 3, 2026
This Privacy Policy explains how Rameau SpA ("Rameau", "we", "us", or "our"), based in Santiago, Chile, collects, uses, stores, and shares information when you use the Rameau website, application/dashboard, and API (together, the "Service").
1. Who We Are
Rameau SpA is the data controller responsible for the personal data
described in this Policy, in connection with your account and organization
data. For questions about this Policy, contact us at [email protected].
Where you upload Documents containing personal data of third parties (for example, personal data about your customers, employees, or vendors contained in invoices or forms), you (the Customer) act as the data controller for that data, and Rameau acts as a data processor acting on your instructions. Any specific processing terms for that relationship should be set out in a separate Data Processing Agreement.
2. Scope
This Policy applies to information collected through:
- The website (
https://rameau.co); - The application/dashboard (
https://app.rameau.co); and - The API (
https://api.rameau.co).
3. Information We Collect
3.1 Account and Organization Data
When you register and use the Service, we collect:
- Email address;
- Full name;
- Password (stored as a salted hash, never in plain text);
- Organization name; and
- Role and permission assignments within your Organization.
3.2 Customer Content
- Documents you upload (PDF, images, Excel, CSV, TSV, TXT files) and associated metadata (upload date, page count, corpus/organization association).
- Extracted data โ the canonical schema and structured records generated from your Documents, along with any corrections or edits you make during human review.
3.3 Billing Information
Subscription plan, seat count, billing status, and payment details necessary to process your subscription (processed via Paddle, our authorised reseller and payment provider; we do not store full card numbers ourselves).
3.4 Usage and Technical Data
Information generated through your use of the Service, such as log data, device/browser information, and API usage, to the extent collected by our infrastructure for security, debugging, and service operation.
4. How We Use Information
We use the information described above to:
- Create and manage your account and Organization;
- Provide the core Service โ schema negotiation, extraction, storage, and export of your data;
- Send transactional communications, including email verification, password reset, and service notices (via ZeptoMail);
- Process billing and manage your subscription;
- Enforce role- and permission-based access controls within your Organization;
- Maintain the security, integrity, and availability of the Service; and
- Comply with legal obligations.
We do not sell your personal data or Customer Content.
5. How We Share Information
We share information with the following categories of third-party service providers, solely as necessary to operate the Service:
| Category | Provider(s) | Purpose |
|---|---|---|
| AI / LLM processing | OpenAI, Azure OpenAI, Mistral, and (where configured) a self-hosted/local Ollama instance | Schema inference, data extraction, OCR |
| Object storage | Linode (S3-compatible storage) | Encrypted storage of uploaded Documents |
| Application database | PostgreSQL (hosted infrastructure) | Storage of application and extracted data |
| Transactional email | ZeptoMail | Account verification, password reset, notices |
| Payments | Paddle | Payment processing and merchant of record for subscriptions and credits |
Document content is transmitted to the AI providers listed above to perform the processing you request. We do not otherwise share Customer Content with third parties except:
- With your Organization's Members, according to their assigned roles and permissions;
- As required by law, regulation, legal process, or governmental request;
- In connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections; or
- With your consent.
6. Data Storage and Security
- Uploaded Documents are stored encrypted at rest in S3-compatible object storage (Linode).
- Application and account data is stored in PostgreSQL.
- Access to Documents, Corpora, templates, and extracted data is governed by role- and permission-based access controls within each Organization.
- Passwords are stored hashed, not in plain text.
No method of storage or transmission is completely secure; we work to protect your information but cannot guarantee absolute security.
7. Data Retention
- Account and Organization data is retained for as long as your account is active, and for a reasonable period afterward to comply with legal, accounting, or dispute-resolution obligations.
- Customer Content (Documents and extracted data) is retained for as long as it remains in your Organization, and for a limited period following account cancellation or termination to allow export, after which it may be deleted, consistent with Section 13 of the Terms of Service.
- You may request deletion of your account and associated data, subject to
legal retention requirements, by contacting
[email protected].
8. International Data Transfers
Because Rameau uses AI providers and infrastructure that may process data outside Chile, your information โ including Customer Content โ may be transferred to and processed in other countries, including the United States and other jurisdictions where our subprocessors operate. Where required by applicable law, we take steps intended to ensure such transfers are subject to appropriate safeguards.
9. Your Rights and Choices
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you;
- Correct inaccurate personal data;
- Request deletion of your personal data;
- Object to or restrict certain processing; and
- Request a copy of your data in a portable format.
To exercise these rights, contact us at [email protected]. For personal
data contained within Customer Content you have uploaded (i.e., where you
are the controller), please use the Service's editing/correction tools, or
contact your Organization administrator.
10. Children's Privacy
The Service is intended for business and professional use and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email. The "Last updated" date at the top of this Policy indicates when it was last revised.
12. Contact Us
- Administrative / privacy inquiries:
[email protected] - Sales inquiries:
[email protected] - Website:
https://rameau.co
Rameau SpA โ Santiago, Chile.