legal // privacy
Privacy Policy
How smAiT Inc. collects, uses, and protects personal information — on this site, in the workplaces where our robots operate, and across smAiT OS.
Last updated: 9 September 2026
Draft for review
This is a working draft published as a placeholder. It has not been reviewed by legal counsel and is not yet in force. It describes our current intended practices in good faith; where it is incomplete, the safest assumption is that we collect less than this document allows for, not more. Questions or corrections: security@smait.ai.
01 — Who we are and what this covers
smAiT Inc.(“smAiT”, “we”, “us”) is a company headquartered at 3530 Bassett Street, Santa Clara, CA 95054, United States. We build the robotics workforce platform and operate robotic workforces on behalf of the organizations that hire them.
This policy covers:
- this website, smait.ai, and the material published on it;
- enquiries, pilot discussions, partner and manufacturer onboarding, and recruiting;
- information about people that reaches us through the robotic workforces we deploy and operate, as described in section 04.
It does not cover:
- the client portal at dashboard.smait.ai, which is governed by the agreement between smAiT and the customer that holds the account;
- third-party sites we link to, including our partners' and manufacturers' own sites, each of which has its own policy.
02 — The short version
We would rather you did not have to read fourteen sections to learn the important parts, so:
- This website currently runs no analytics and no advertising trackers. At the time of writing it sets no cookies of its own. The only thing stored on your device is a record of your cookie choice, so we do not have to ask again.
- The contact form does not send us data. It opens your own email program with a message prepared for you. Nothing is transmitted until you press send, and what arrives is ordinary email.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- Where our robots operate, our customer is normally in charge of the data and we act on their instructions. Section 04 explains what that means and who to ask about it.
- You can ask us what we hold about you, and ask us to delete it, at security@smait.ai.
03 — Information we collect
Information you give us
When you contact us about a pilot, a partnership, or a role, you choose what to tell us. That typically includes your name, your organization, your email address, and whatever you write in your message — which may include details of the work you are considering automating. If you apply for a role, it includes your CV and anything else you send in support of your application.
Our contact form composes this message in your own email client rather than submitting it to a server we control. We receive it the same way we receive any other email, and it is stored in our business email systems.
Information we collect automatically
Like any website, smait.ai is served over the internet, so our hosting provider processes technical information needed to deliver each page and to keep the service available and secure. This includes your IP address, the page requested, the time of the request, and your browser's user-agent string. These server logs are generated by the infrastructure rather than by tracking code, and we use them for security, debugging, and abuse prevention.
If you consent to analytics cookies, we will also collect information about how the site is used — which pages are visited and how people move between them. We do not currently operate analytics; if that changes, we will only do so for visitors who have agreed, and we will update this policy first.
Information from others
We may receive your details from your employer or colleagues when they involve you in a pilot, an integration, or a procurement process, and from partners, manufacturers, and investors who introduce us. We may also look at public professional sources, such as a company website or a public professional profile, when we are researching a prospective customer, partner, or candidate.
What we do not ask for
We do not ask visitors to this site for payment details, government identifiers, or special categories of data such as health information. Please do not send them to us in an enquiry.
04 — Data from robots and deployments
This is the section most privacy policies do not need, and it is the one that matters most for what we do. Robots work in real buildings around real people. To move safely they must sense their surroundings, and those surroundings contain human beings.
Who is responsible for what
When we deploy and operate a robotic workforce at a customer's site, the customer decides what the robots are there to do and what happens to the operational data that results. In data protection terms, the customer is normally the controller and smAiT acts as a processor on their instructions, under a written agreement.
In practice this means: if you are an employee, resident, patient, guest, or visitor at a site where our robots work and you want to know what is recorded about you, the organization that runs that site is the right first point of contact. They hold the notices, the retention decisions, and the record of what the deployment is for. If you contact us instead, we will help you reach them, but we generally cannot make decisions about their data on your behalf.
What the robots and the platform collect
- Sensor data — camera, depth, and other sensor input used for navigation, obstacle avoidance, and task execution. In an occupied building this will include images of people.
- Operational and telemetry data — where a robot is, what task it is running, its battery and health state, faults, and the outcome of the work. This is what makes a fleet reportable, and it is the core of what smAiT OS is for.
- Interaction data — where a robot is deployed to greet, guide, or assist people, the exchange itself may be processed so the robot can respond.
- Oversight records — a human stays in the loop for the fleets we run. When a person reviews or intervenes, that action is logged, which is what makes oversight auditable rather than decorative.
How we approach it
Sensor data is used to operate the robots safely and to deliver the service the customer has asked for. We aim to keep raw sensor data for no longer than operating, debugging, and safety investigation require, and to work from aggregated or de-identified operational data wherever that will do the job.
We do not deploy facial recognition or biometric identification as part of our standard service, and we do not use robots to monitor the productivity of individual workers. Where a customer asks for something beyond the standard deployment, it is agreed in writing, it remains their decision as controller, and it is their responsibility to have a lawful basis and to inform the people affected — including, where the law requires it, workforce or works-council consultation before anything is switched on.
Where we use operational data to improve smAiT OS, our aim is to work with aggregated or de-identified data, and any use beyond operating the customer's own deployment is governed by the customer agreement rather than assumed.
05 — How and why we use information
We use personal information to:
- respond to your enquiry and have the conversation you started, including scoping and running pilots;
- provide, operate, monitor, support, and improve our platform and the workforces we run;
- keep the site, the platform, and our deployments safe — preventing, detecting, and investigating abuse, security incidents, and safety events;
- assess candidates and run our recruiting process;
- manage our relationships with customers, partners, manufacturers, and suppliers;
- send you information about smAiT that you have asked for, or that is closely related to a discussion already underway, and which you can stop at any time;
- meet our legal, regulatory, safety, tax, and accounting obligations, and establish or defend legal claims.
If you are in a jurisdiction that requires a legal basis for each purpose, we rely on: performance of a contract, or steps taken at your request before entering one; our legitimate interests in running, securing, and growing a business, balanced against your rights; your consent, where we ask for it, such as for non-essential cookies; and compliance with legal obligations. Where we rely on consent you may withdraw it at any time, and doing so does not affect anything we did before you withdrew it.
We do not use automated decision-making that produces legal or similarly significant effects about you.
08 — How long we keep it
We keep information for as long as we need it for the purpose we collected it, and then delete it or de-identify it. In practice that means: enquiries and the correspondence around them for as long as the relationship is live and a reasonable period after; candidate information for the length of the process and a limited period afterwards, unless you ask us to keep it on file or to remove it sooner; records we are legally required to retain, such as tax and accounting records, for the period the law sets.
Retention of deployment and sensor data is set by the customer as controller, in the agreement covering their deployment.
09 — How we protect it
We treat security and data governance as first principles rather than features added afterwards. That includes access control on the systems that hold personal information, encryption of data in transit, monitoring, and limiting access to the people who need it for their work.
No system is perfectly secure, and we will not pretend otherwise. If you believe you have found a vulnerability, please report it to security@smait.ai. We respond to every disclosure. If a breach ever affects your personal information, we will notify you and the relevant authorities as the law requires.
10 — Your rights and choices
Depending on where you live, you may have some or all of the following rights: to know what we hold and to get a copy of it; to have it corrected; to have it deleted; to receive it in a portable form; to object to or restrict how we use it; to withdraw consent; and to opt out of marketing.
If you are a California resident, you have the right to know, delete, correct, and to opt out of sale or sharing — although, as set out above, we do not sell or share personal information. You may also designate an authorised agent to act for you. We will not discriminate against you for exercising any of these rights.
To exercise any of them, write to security@smait.ai. We may need to verify who you are before we act, which usually means confirming you control the email address the request relates to. We will respond within the time the applicable law allows, and we will tell you if we need longer and why.
If you are unhappy with our response, you may complain to your data protection authority. We would rather you came to us first so we can put it right.
For information held on a customer's behalf from a robot deployment, please see section 04 — the organization running that site is normally the right place to start, and we will forward your request to them.
11 — International transfers
smAiT is based in the United States and our systems and service providers are located primarily in the United States. If you contact us from outside it, your information will be transferred to and processed in the United States, where data protection law differs from that in your own country.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we do so using an approved transfer mechanism — in most cases the European Commission's Standard Contractual Clauses and the UK Addendum — together with additional safeguards where they are needed. You can ask us for details of the mechanism that applies to you.
12 — Children
Our services are intended for businesses and for adults. This site is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, contact security@smait.ai and we will investigate and delete it.
Where our robots operate in settings that include children, such as an education or care environment, the customer is responsible as controller for the additional protections and consents that setting requires, and we support them in applying them.
13 — Changes to this policy
Our business is young and changing quickly, so this policy will change with it. When we make a material change we will update the date at the top of this page and, where the change significantly affects you, tell you directly or place a notice on the site. If a change means we need your consent, we will ask for it rather than assume it.
14 — How to contact us
Privacy questions, requests, and complaints, and security reports: security@smait.ai. Anything else: info@smait.ai.
Questions about
your data
If something here is unclear, or you want to know what a deployment would mean for the people in your building, ask us before you commit to anything.