Legal

Privacy Policy

This policy explains how Pama Technologies handles information when organisations and their authorised users use PamaOS.

Effective August 4, 2026

1. Who we are

PamaOS is a configurable, offline-first business operating system operated by Pama Technologies ("Pama", "we", "us", or "our"). This Privacy Policy applies to PamaOS websites, applications, modules, and related services.

The organisation that creates a PamaOS workspace controls the business records entered by its owners, employees, contractors, and other authorised users. Pama processes that information to provide the service.

2. Information we collect

Depending on how PamaOS is configured, we may process:

  • Account information, including names, email addresses, authentication identifiers, roles, and organisation membership.
  • Business information entered into enabled modules, such as products, sales, orders, customers, inventory, staff, attendance, payroll, expenses, reports, files, and internal notes.
  • Device and offline-workspace information, including local profiles, device identifiers, synchronisation state, and data needed to keep enabled modules available when internet access is unreliable.
  • Usage, diagnostic, and security information, such as browser type, application events, error logs, performance information, IP address, and suspicious-access signals.
  • Integration information, including connected account identifiers, permissions, and authorisation tokens required to provide an integration requested by the organisation.

3. How we use information

We use information to:

  • Provide, secure, maintain, and improve PamaOS.
  • Authenticate users and enforce organisation roles and permissions.
  • Store business records locally and synchronise authorised changes between devices and cloud services.
  • Generate and deliver documents, notifications, invoices, reports, and other actions requested by authorised users.
  • Diagnose failures, prevent abuse, respond to support requests, and comply with applicable legal obligations.

We do not sell personal information or use connected mailbox data for advertising.

4. Google account and Gmail data

When an organisation chooses to connect a Google account, PamaOS asks only for the permissions needed for the enabled feature. For invoice and document delivery, PamaOS may request permission to send email on behalf of the connected account.

PamaOS uses this permission only when an authorised user requests or schedules a message from PamaOS. PamaOS does not use the send-only permission to read, modify, or delete the connected account's inbox. We process the sender address, recipient, message content, attachments, and authorisation credentials necessary to complete the requested send.

PamaOS's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not transferred for advertising, sold to data brokers, or reviewed by people except when necessary for security, legal compliance, or support requested by the user.

An organisation may disconnect Google from PamaOS, and the Google account owner may also revoke access from their Google Account security settings.

5. Offline storage and synchronisation

PamaOS is designed to keep authorised business functions available during network outages. Information may therefore be stored on devices used by the organisation and later synchronised when connectivity returns.

Organisations are responsible for controlling physical access to their devices, removing access for former staff, and using device passwords, encryption, and other available security protections. Removing an account from the cloud may not immediately erase copies stored on an offline device that has not reconnected.

6. How information is shared

We may share information only as necessary with:

  • Service providers that support hosting, authentication, data storage, analytics, communications, customer support, and security.
  • Authorised members of the organisation according to configured roles, modules, locations, and permissions.
  • Authorities or other parties when required by law, needed to protect rights and safety, or involved in a legitimate business transfer.

Service providers may process information only for the services they provide to us and are expected to protect it appropriately.

7. Data retention and deletion

We retain information for as long as needed to provide PamaOS, maintain security and records, resolve disputes, and satisfy legal obligations. Retention may vary by data type, subscription status, organisation settings, and applicable law.

Organisation owners may request account or workspace deletion. Connected integration credentials are removed or revoked when the connection is deleted, subject to limited backup and security-log retention. Local copies may remain on an organisation-controlled device until that device reconnects or its PamaOS data is removed.

8. Security

We use administrative, technical, and organisational safeguards designed to protect information, including access controls and secure handling of integration credentials. No storage or transmission method is completely secure, so we cannot guarantee absolute security.

9. Your choices and rights

Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or receive a copy of their personal information. In most cases, staff and customer record requests should first be directed to the organisation that controls the relevant PamaOS workspace.

Organisation owners may manage users, permissions, enabled modules, connected services, and certain retention controls from PamaOS.

10. International processing and children

PamaOS and its service providers may process information in countries other than the user's country. Where required, we use appropriate safeguards for international transfers.

PamaOS is a business service and is not directed to children. A business that records information about minors must have an appropriate lawful basis and configure access responsibly.

11. Changes to this policy

We may update this policy as PamaOS, our integrations, or legal requirements change. We will publish the revised policy with a new effective date and provide additional notice when a material change requires it.

12. Contact us

Questions, privacy requests, and concerns may be sent to official@pama.page.