Privacy Policy
Last updated: November 7, 2025
DataKarma, Inc. ("Event Karma," "we," "us," or "our") operates the Event Karma platform at datakarma.ai and related services. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our event marketing analytics platform.
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other privacy regulations.
Contact Information
Company: DataKarma, Inc.
Address: 440 Strafer St, Cincinnati, OH 45226
Email: support@datakarma.ai
Website: datakarma.ai
Quick Navigation
- 1. Information We Collect
- 2. How We Use Your Information
- 3. Legal Basis for Processing (GDPR)
- 4. Data Sharing and Disclosure
- 5. Third-Party Integrations
- 6. Data Retention
- 7. Your Privacy Rights
- 8. California Privacy Rights (CCPA)
- 9. Data Security
- 10. International Data Transfers
- 11. Cookies and Tracking
- 12. Children's Privacy
- 13. Changes to This Policy
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, company name, job title, phone number
- Authentication Data: Username, password (encrypted), security questions
- Payment Information: Billing address, payment method details (processed by third-party payment processors)
- Communications: Messages, feedback, and support inquiries you send to us
1.2 Information We Collect Automatically
- Usage Data: Pages visited, features used, time spent, click patterns
- Device Information: IP address, browser type, operating system, device identifiers
- Log Data: Access times, error logs, performance data
- Cookies and Similar Technologies: Session IDs, preferences, analytics data
1.3 Information From Third Parties
- CRM Data: Campaign data, contact information, opportunity data from Salesforce, HubSpot, or Marketo
- Event Platforms: Attendee data, registration information from Cvent, Splash, or similar platforms
- Survey Responses: Feedback collected through our branded survey tools
- Sales Team Data: Event feedback and ratings provided by sales representatives
- Partner Data: Feedback from partner organizations and co-marketing participants
2. How We Use Your Information
Service Delivery
- Calculate Success Scores for your events
- Generate AI-powered recommendations using Claude AI
- Create executive reports and performance analytics
- Sync data with your CRM and marketing automation platforms
- Provide predictive event success forecasting
Communication
- Send transactional emails (password resets, account notifications)
- Provide customer support and respond to inquiries
- Send product updates and feature announcements (with opt-out option)
- Request feedback and conduct user research
Improvement and Analytics
- Improve AI models and recommendation algorithms
- Analyze platform usage to enhance features
- Conduct product research and development
- Generate aggregated, anonymized benchmarks and insights
Legal and Security
- Comply with legal obligations and regulatory requirements
- Protect against fraud, security threats, and abuse
- Enforce our Terms of Service
- Defend legal claims and protect our rights
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), UK, and Switzerland, we process your personal data based on the following legal grounds:
Contractual Necessity
Processing necessary to provide our services under our Terms of Service
Legitimate Interests
Improving our services, preventing fraud, and maintaining security
Consent
Marketing communications, cookies, and optional features (you may withdraw consent at any time)
Legal Obligations
Compliance with applicable laws and regulations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your data in the following circumstances:
- Service Providers: Cloud hosting (AWS, GCP), analytics (Posthog), AI services (Anthropic Claude), payment processing (Stripe)
- Business Partners: With your consent, we may share data with CRM platforms (Salesforce, HubSpot, Marketo) and event platforms you've integrated
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)
- Protection of Rights: To protect our rights, property, or safety, or that of our users
5. Third-Party Integrations
Event Karma integrates with the following third-party services. Each integration is governed by that service's privacy policy:
CRM Platforms
- • Salesforce
- • HubSpot
- • Marketo
Event Platforms
- • Cvent
- • Splash
- • Custom event platforms
AI Services
- • Anthropic Claude (report generation, predictions)
Communication
- • Slack
- • Email service providers
You control which integrations are enabled in your account settings. Disabling an integration will stop data sharing with that service.
6. Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy:
- Active Accounts: Data retained while your account is active
- After Account Closure: 90 days for operational purposes, then deleted unless we have a legal obligation to retain it
- Backup Systems: Data may remain in backups for up to 90 additional days
- Aggregated Data: Anonymized, aggregated data may be retained indefinitely for analytics and benchmarking
- Legal Obligations: Data retained as required by law (e.g., financial records for 7 years)
You can request deletion of your account and data at any time by contacting support@datakarma.ai.
7. Your Privacy Rights
Depending on your location, you may have the following rights:
Right to Access
Request a copy of the personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data (subject to legal exceptions)
Right to Restriction
Request limitation of how we process your data
Right to Data Portability
Receive your data in a machine-readable format
Right to Object
Object to processing based on legitimate interests or for marketing purposes
Right to Withdraw Consent
Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, contact us at support@datakarma.ai. We will respond within 30 days (or as required by applicable law).
8. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Your CCPA Rights
- Right to Know: Request disclosure of personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt-out of the "sale" of personal information (we do not sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
Categories of Personal Information
We collect the following categories of personal information:
- Identifiers (name, email, IP address)
- Commercial information (purchase history, account interactions)
- Internet activity (usage data, browsing behavior)
- Professional information (company, job title)
- Inferences (preferences, predictions about behavior)
To submit a CCPA request, email support@datakarma.ai with "CCPA Request" in the subject line.
9. Data Security
We implement industry-standard security measures to protect your personal information:
Technical Safeguards
- • TLS/SSL encryption in transit
- • AES-256 encryption at rest
- • Secure authentication (OAuth 2.0)
- • Regular security audits
Organizational Measures
- • Access controls and authentication
- • Employee training on data protection
- • Confidentiality agreements
- • Incident response procedures
Infrastructure Security
- • SOC 2 compliant cloud providers
- • Regular vulnerability scanning
- • Automated backups
- • Disaster recovery plans
Monitoring
- • 24/7 security monitoring
- • Intrusion detection systems
- • Audit logging
- • Breach notification procedures
While we strive to protect your data, no method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.
QR Code Security
QR codes generated by Event Karma contain short-lived, non-PII tokens. Email addresses are not embedded in QR codes. Tokens expire within minutes and cannot be used to identify individuals without server-side verification.
10. International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have different data protection laws than your country.
For transfers from the EEA, UK, and Switzerland, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Supplier certifications (e.g., EU-U.S. Data Privacy Framework when applicable)
Contact us at support@datakarma.ai for more information about our data transfer mechanisms.
12. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at support@datakarma.ai, and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice in the application
Your continued use of our services after the effective date constitutes acceptance of the updated policy.
Questions or Concerns?
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Email: support@datakarma.ai
Mail: DataKarma, Inc., 440 Strafer St, Cincinnati, OH 45226
We aim to respond to all inquiries within 30 days.