Run with ease · Scale without limits · Stay in control
One governed AI platform for your whole business.
Run Project Management, Marketing, Sales & CRM, HR, Finance & Accounting, and
Operations on one platform — every team working from a single source of truth instead of
a dozen disconnected tools. AI agents take on the busywork, while every sensitive or
outbound action pauses for human approval and is fully audit-logged. Bring your own AI
model; your keys stay encrypted.
15-day free trial · No credit card required · All 20+ modules included
Goal
“Summarise last week's pipeline and email the team”
Plan
Project kickoff, phase-by-phase plan
Agent
Runs each step with its tools, skills & powers
Approval
Outbound email pauses for a human ✓
Output
Delivered & logged for audit
Three principles every business is built on
See it, stay on top of it, repeat it. Reports, Reminders and Reproduce are the foundation SMAIVIZ is built on — the 3 Rs behind every module, agent and approval.
RThe first R
Reports
See the whole business in one place — live, not last quarter.
Tableau-style dashboards in every module — set any one as your home view
Sales, finance, inventory, people and operations on a single source of truth — so one action flows across your whole business automatically. No exports, no integrations, no silos.
A deal is wonClosed in your pipeline
→
The order runsCaptured, allocated & shipped
→
Finance postsInvoice & ledger, automatically
→
Leaders see itLive dashboards, in real time
One suite, every function
30+ built-in capabilities across sales & CRM, finance, inventory, manufacturing, HR, marketing and operations — turn on what you need as you grow.
Analytics & AI, built in
Live dashboards, forecasts and anomaly alerts in every module — with AI agents that plan and act on the very same data.
Open & governed
Connectors, an event bus and an open API tie it together — under enterprise roles, approvals and a tamper-evident audit trail.
Full ERP coverage — and everything around it
One system of record across the back office, the front office and the shop floor.
Where you land in that range depends on what you actually use — which modules you switch on, how much customization you need, and your database and AI usage. Start small with a couple of modules and grow into the rest as you need them.
Paying monthly instead runs $20 – $200₹1,500 – ₹15,000 per user / month. Every organization holds a minimum of 3 licences.
Your personal organization is free for life, with limited access. Licences apply to team organizations.
Rolling out across a larger team, or need volume pricing and a guided onboarding? Talk to our sales team →
Limits apply to file storage and other resources. Based on the total number of licences and volume, pricing may increase or decrease with at least 30 days’ notice. Local taxes are charged in addition to the prices shown.
Describe the goal. Your AI agents handle the rest.
From lead to close to invoice to report — coordinated AI agents plan and execute it, every sensitive step gated by you and logged for good. Start free, or talk to our team about rolling it out across your business.
We use cookies — essential ones to run SMAIVIZ, and optional ones for preferences
and anonymous diagnostics. You choose what we may store; nothing optional is set
until you allow it. See our
Cookie Policy.
Cookie preferences
Choose which cookies SMAIVIZ may use. Necessary cookies are always on; everything
else stays off until you allow it. Full details in the
Cookie Policy.
Appearance
Strictly necessaryAlways on
Required for sign-in, security (CSRF protection), remembering your cookie choice, and your appearance & accessibility settings. The service can't run without these, so they can't be switched off.
Functional
Remembers your language and chat-panel state across visits. Stored locally on your device.
Analytics
Anonymous, scrubbed front-end error diagnostics so we can find and fix bugs. No third-party analytics and no profiling.
Marketing
We don't use advertising or third-party tracking cookies today. This stays off unless that ever changes.
Choose a new password
Delete account
Your account will be scheduled for deletion. We keep your data for
90 days so you can sign in again to reactivate. All
sessions and API keys are revoked immediately. After 90 days the
account is permanently removed and audit-log entries are anonymized.
Please review our Terms & Conditions
and Privacy Policy and accept to continue.
We log security events for governance review; you can export or delete your data anytime from Settings.
No recent chats yet.
No plans yet — describe a one-off task in the planner above and the engine will build a plan for it.
No routines yet — a Routine runs Agents on a schedule (or on-demand) and produces an Output.
No outputs yet — Routines produce these when they run.
Loading history…
Section
Frequently asked questions
Do I need to sign in to try SMAIVIZ?
You can browse the public pages — overview, documentation, FAQs, security, terms,
privacy and the blog — without an account. To use the app (chat, projects,
automations and your own AI assistants), you sign in so your work stays private to you.
Do I need to know how to code?
No. You describe what you want in plain English and SMAIVIZ helps build it — whether
that's an automation, an AI assistant, or a report.
What can I do with SMAIVIZ?
Run your business from one place: manage customers and deals, organise your team of
people and AI agents, plan and track work, automate the busywork, and build AI
assistants that do real tasks for you.
Which AI models can I use?
You can choose the AI model that best fits each task, and bring your own model key if
you prefer — so you stay in control of model choice, data, and cost.
Can AI act on its own, or do I stay in control?
You stay in control. Anything sensitive waits for your approval before it happens, and
you decide exactly what each AI agent is allowed to do.
Can I work as a team?
Yes. Invite your teammates and choose what each person can see and do — from
view-only access up to full control.
Is my data private and secure?
Yes. Your data and any keys you add are kept private to your account and encrypted, and
only you and the people you invite can see your workspace. You can also keep your data
in the region you choose.
Can I export or delete my data?
Anytime. Export everything we hold about you in one file from your settings, and delete
your account whenever you like — with a short grace window in case you change your mind.
How much does it cost?
You can start for free and upgrade when you're ready, so you only pay as your needs
grow.
Payment & subscription terms
Version: 2026-06-14 · Last updated: 14 June 2026.
These Payment & Subscription Terms (the “Payment Terms”) govern your purchase
and use of paid plans on SMAIVIZ, operated by Smaiviz Pvt. Ltd.
(“SMAIVIZ”, “we”, “us”). They supplement, and are in
addition to, our Terms of Service and Privacy Policy, which you also accept. By selecting a
plan and clicking I agree, you accept these Payment Terms.
1. Plans, seats & billing cycle
Paid plans are billed per seat, per billing cycle (monthly unless stated
otherwise) in advance. The price shown at checkout for your region applies. We may change
plan pricing or features on a prospective basis with notice; changes do not affect the cycle
you have already paid for.
2. Free trial
Paid plans may start with a free trial of the length shown at checkout
(e.g. 7 days). A valid payment method is required to start the trial. Unless you
cancel before the trial ends, the plan automatically converts to a paid subscription
and we charge your payment method the then-current fee for your selected plan and seats. You
can cancel at any time during the trial from Billing settings to avoid being charged.
3. Automatic renewal & cancellation
Subscriptions renew automatically at the end of each billing cycle until you
cancel. You authorise us (and our payment processors) to store your payment method and charge
it for each renewal. You may cancel renewal at any time from Billing settings; cancellation
takes effect at the end of the current paid cycle, and you retain access until then. We do
not provide pro-rated refunds for partial cycles except where required by law (see §6).
4. Payment processing
Payments are processed by third-party providers — Stripe (for customers
billed in USD) and Razorpay (for customers billed in INR). Your card and
payment details are handled by these processors under their terms and privacy policies; we do
not store full card numbers. You are responsible for keeping a valid payment method on file.
5. Taxes (incl. GST)
Fees are exclusive of taxes unless stated. You are responsible for any applicable sales tax,
VAT, or GST. For Indian customers, 18% GST applies; provide
your GSTIN at checkout to receive a tax invoice. Where we are required to
collect tax, it is added at checkout.
6. Refunds
Except where required by applicable law or expressly stated, fees are non-refundable
and there are no refunds or credits for partial periods, unused seats, or features not used.
If you believe you were charged in error, contact billing support and we will review in good
faith.
7. Failed payments & suspension
If a charge fails, we may retry and notify you. If payment remains unpaid, we may
downgrade, suspend, or restrict access to paid features until the balance is
settled. We are not liable for loss of access arising from a failed payment.
8. Plan changes
You can upgrade, downgrade, or change seat counts from Billing settings. Upgrades may be
charged immediately (prorated by the processor where supported); downgrades take effect at the
next cycle. Enterprise plans are governed by a separate order form or agreement.
9. Changes to these terms
We may update these Payment Terms. Material changes are versioned; when the version changes we
will ask you to review and accept the updated terms before continuing to use paid features.
10. Governing law & contact
These Payment Terms are governed by the laws stated in our Terms of Service. For billing
questions, contact billing@smaiviz.com.
Everything that governs your use of SMAIVIZ, in one place. Pick a
policy from the left, or jump in below.
These policies are published by Smaiviz Private Limited (“SMAIVIZ”),
registered office 7-365, Mahidhara Luxuria, Muthangi, Hyderabad – 502300, Telangana, India.
They should be read together — each cross-references the others where relevant.
Privacy & data
Privacy Policy — what we collect, how we use it, and your rights by region.
Cookie Policy — cookies and similar technologies we use.
A Data Processing Agreement (DPA) is available to business customers on request.
Privacy policy
Version 2026-08-04 · Effective date: 4 August 2026 · Last updated: 4 August 2026.
This Privacy Policy explains how Smaiviz Pvt. Ltd. (“SMAIVIZ”, “we”,
“us”), a company incorporated in India with its registered office at
7-365, Mahidhara Luxuria, Muthangi, Hyderabad – 502300, India, collects, uses, shares, and
protects personal information, and the choices and rights
you have. Where a specific law gives you additional rights, the
region-specific section (§14) controls for residents of that region.
1. Who we are & our role
For individual (B2C) accounts, SMAIVIZ is the controller /
business / Data Fiduciary of the personal data you
provide. For business (B2B) customers, the customer organisation is the controller of its
end-users' data and SMAIVIZ acts as a processor /
service provider / Data Processor on its documented
instructions. Each organisation manages its controller posture (jurisdiction, DSAR
onboarding, data-protection contact, residency) at
Settings → Data & Compliance.
Contact for privacy matters, and our Grievance Officer (India) /
data-protection contact for other regions, is
privacy@smaiviz.com (see §17). Business-customer
end-users should contact their
organisation's administrator first.
2. Key terms
“Personal data” (also “personal information” in the US, and
“personal data” of a “Data Principal” under India's DPDP Act) means
information that identifies or relates to an identifiable individual. Under India's Digital
Personal Data Protection Act 2023 (“DPDP Act”) you are a Data
Principal and we are a Data Fiduciary. Under US state laws you are
a consumer; under UK GDPR you are a data subject.
“Customer Data” means prompts, files, configurations, workflows, tasks,
outputs, and other content submitted to or generated through the Service.
3. Information we collect
Account data: email address, optional display name, password hash (never plaintext), Google subject identifier when OAuth is used.
Session & device data: session identifier hash, IP address, user-agent, and session creation/expiry timestamps.
Credentials you add: third-party API keys you provide, encrypted at rest. We display only the last four characters in the UI.
Content you create: chats, prompts, agent/routine configurations, files, tasks, and the outputs the Service produces for you.
Audit log: action name, target, IP, user-agent, timestamp, and optional JSON metadata for sensitive actions. We do not write chat or routine contents to the audit log.
Consent records: consent version, acceptance timestamp, and IP — including your cookie-consent receipts (see the Cookie Policy).
Operational metrics: aggregated routine counts, token usage, and durations — not linked to chat contents.
Support communications: messages you send us and our responses.
Sources. We collect this information directly from you, automatically from
your use of the Service (sessions, security logs, diagnostics), and — for B2B accounts —
from the organisation that provisioned your account.
Workforce data. Organizations may use the Service to manage information
relating to workers, including people and AI agents.
Such information is processed solely to provide workforce-management, governance,
accountability, reporting, compliance, and operational functionality requested by the
customer.
Sensitive information. We do not require sensitive data to use the Service.
Input guardrails actively block payment-card and national-ID numbers and
redact emails/phone numbers from prompts. Where an organisation knowingly
processes special categories (children/teen, health, financial/payment, biometric), it must
declare them under Settings → Data & Compliance,
which records the lawful basis and safeguards. We do not use sensitive personal information
to infer characteristics about you.
4. How we use your information
Provide and operate the Service (authentication, sessions, agents, routine execution, delivering outputs).
Secure the Service (rate limiting, intrusion and fraud detection, abuse prevention).
Maintain a governance audit trail for sensitive and outbound actions.
Improve reliability and performance using aggregated, de-identified metrics and (with your consent) scrubbed error diagnostics.
Communicate with you about the Service, security, and support.
Comply with legal obligations and respond to lawful requests.
We do not use your prompts, content, or outputs to train our own models, and we do not sell your personal information.
5. Legal bases & grounds for processing
Where required (UK GDPR and similar), we rely on:
Performance of a contract — to provide the Service you signed up for.
Legitimate interests — security, fraud prevention, and service improvement (balanced against your rights), including:
Governance and accountability controls
Security monitoring and incident response
Audit-trail maintenance and compliance review
Abuse prevention and platform integrity
Consent — for optional cookies/diagnostics and any feature clearly marked as consent-based; you may withdraw consent at any time.
Legal obligation — retention of records as required by law.
Under India's DPDP Act we process personal data on your consent (given
after clear notice and itemised to purpose) or for permitted legitimate uses
(such as a purpose for which you voluntarily provided data, or to comply with law). In the
US, processing is disclosed at or before collection (§14.1) rather than relying on a consent
“legal basis”.
6. Cookies & similar technologies
We use first-party cookies and local storage as described in our
Cookie Policy. Non-essential cookies load only with
your consent; you can change or withdraw your choice any time via
.
7. How we share information
We disclose personal data only to the following categories of recipients, for the purposes shown:
AI model providers (Google Gemini by default; OpenAI, Anthropic, Microsoft Azure OpenAI, Amazon Bedrock, and others you select) — your prompts and outputs are transmitted for inference. When you bring your own key, processing is governed by your agreement with that provider.
Cloud & infrastructure providers (e.g. Google Cloud, AWS, Azure) — to host and run the Service.
Connectors you enable (e.g. email, calendar, Slack, GitHub) — only the data needed for the action you request, after the Approvals gate where applicable.
Professional advisers and authorities — only when required by law and after appropriate review.
A successor in a merger, acquisition, or asset sale, under equivalent protections.
Third-party AI providers may retain, process, or log data according to their own terms,
privacy policies, and operational requirements.
Customers should review the privacy and security commitments of any providers they choose
to use through the Service.
We do not sell personal information, and we do not share it
for cross-context behavioural advertising (as those terms are defined under US state laws).
We do not use third-party advertising networks or advertising cookies.
Operational analytics, monitoring, security, fraud-prevention, and support technologies may
be used to operate, secure, maintain, and improve the Service.
8. AI processing & automated decisions
SMAIVIZ is an AI platform: agents process the prompts and content you give them to plan and
run tasks. Outbound or sensitive actions pause at the Approvals gate for a
human to authorise. We do not make decisions that produce legal or similarly
significant effects based solely on automated processing without meaningful human
involvement, and we do not use your data for profiling for advertising. You can request human
review of any output. AI can produce inaccurate results; do not rely on outputs for legal,
medical, financial, or other professional decisions without independent verification.
8A. AI governance & accountability
SMAIVIZ provides governance controls designed to support responsible deployment of AI
systems. These controls may include:
Human approval workflows
Accountability chains
Agent autonomy controls
Audit logging
Permissions and access controls
Guardrails and policy enforcement
Organizations remain responsible for configuring these controls appropriately for their
use cases. Every AI agent action can be associated with a responsible human through the
accountability framework.
AI-generated outputs may be similar or identical to outputs generated for other users.
SMAIVIZ does not guarantee the uniqueness of AI-generated content.
9. International data transfers
Your data may be processed in regions selected by the deployment operator and the providers
listed in §7, which may be outside your country. Where data leaves your jurisdiction we rely
on appropriate safeguards — for example the EU/UK Standard Contractual
Clauses and the UK International Data Transfer Addendum, Australia's APP 8 reasonable
steps, Singapore PDPA transfer-limitation safeguards, Canadian comparable-protection
measures, and India's DPDP cross-border rules (transfers permitted except to countries the
Government restricts). Business customers can declare a preferred
data-residency region under
Settings → Data & Compliance; this preference is
advisory and actual residency depends on the deployment's infrastructure.
Transfer mechanisms and safeguards may change over time as laws, regulations, regulatory
guidance, and international transfer frameworks evolve.
10. Data retention
Account data: kept until you delete your account, then a 90-day grace window during which you can sign in to reactivate; after that the user row is permanently removed.
Inactive personal-only accounts: if your only workspace is your personal “My Org” and you don't sign in for 30 days, the account is disabled (we email you 3 days beforehand); it can be re-enabled by signing in and confirming, and is permanently deleted after 60 days of inactivity via the same erasure process.
Audit log: 365 days by default (configurable). After deletion the entries are anonymised (user_id set to NULL) but the trail remains for compliance review.
Sessions: revoked on logout, password change, or account deletion; otherwise expire after one week of inactivity.
API keys: until you revoke them, or automatically on account deletion.
Cookie-consent receipts: kept to evidence your choice; the matching user link is removed on account deletion.
Backup retention
Deleted information may remain in encrypted backups for a limited period before being
automatically overwritten or removed according to operational backup-retention schedules.
Backup copies are protected using the same security controls applied to active systems
where reasonably practicable.
11. Security
We use strong, memory-hard password hashing, authenticated encryption for secrets at
rest, CSRF protection, rate limiting, secure cookies, brute-force throttling, and audit
logging. See our
Security Policy for additional information
regarding safeguards, governance controls, and security practices. No security
control is absolute; please use a unique password and protect your devices. We will notify
you and the relevant authorities of a personal-data breach as required by law (§15).
11A. Security documentation & audits
Enterprise customers may request reasonable security documentation describing our security
practices. To protect the Service and other customers, intrusive testing — penetration tests,
vulnerability or load testing, source-code review, or similar — requires our prior written
consent. To report a suspected vulnerability, email
security@smaiviz.com.
12. Children's privacy
The Service is not directed to children. We do not knowingly collect data from children
below the age of digital consent in your jurisdiction. If we become aware that a child
below the applicable minimum age has created an account without required parental or
guardian consent, we will take reasonable steps to remove the account and associated
personal data in accordance with applicable law. In the United States we
follow COPPA (under 13) and do not sell or
share the personal information of consumers we know to be under 16 without opt-in. In
India, processing the data of anyone under 18 requires verifiable consent of
a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or
targeted advertising toward children.
13. Your privacy rights & how to exercise them
Subject to your region (§14), you may have the right to:
Access & portability — export your data any time as machine-readable JSON from Settings → Privacy & Data.
Correct / rectify — update your profile in Settings.
Delete / erase — delete your account from the Account page; a 90-day grace window applies, after which data is permanently purged (credentials, sessions, consents cascade).
Restrict / object — ask us to freeze processing; while restricted your data is kept and stays accessible/exportable/erasable but is not otherwise actively processed (AI generation is blocked).
Withdraw consent — as easily as you gave it (e.g. ), without affecting prior lawful processing.
Human review — of any AI output (§8).
Complain — to your data-protection regulator (§17).
To make a request, use the in-product tools above or contact us (§17). We verify requests
against your account, respond within the statutory window for your region (commonly ~30 days
for UK GDPR / India DPDP, ~45 days for US state laws, extendable as the law allows), and do
not discriminate against you for exercising your rights. You may use an authorised agent
where the law permits. Business-customer end-users: requests are routed
through the controller's DSAR service at
Settings → Data & Compliance; data a controller
holds outside SMAIVIZ remains its responsibility.
14. Region-specific rights
14.1 United States
If you are a US resident, you have rights under the California Consumer Privacy Act as
amended by the CPRA and under comparable laws in states including Virginia, Colorado,
Connecticut, Utah, Texas, Oregon, Montana, and others. These include the rights to
know/access the categories and specific pieces of personal information we
collect, the sources, business purposes, and categories of recipients; to
delete and correct your information; to opt out of
the sale or sharing of personal information and of targeted advertising; to
limit the use of sensitive personal information; to non-discrimination
for exercising rights; and, in several states, to appeal a denied request.
Categories we collect (CCPA): identifiers (email, IP); internet/network activity (session and security logs); user content you provide; and inferences only as needed to operate the Service.
No sale or sharing. We do not sell or share personal information and have not in the preceding 12 months. Because we do not sell or share, there is nothing to opt out of — but you may still record a preference under Preferences → Privacy, and we honour Global Privacy Control (GPC) signals.
Sensitive personal information. We do not use or disclose it for purposes beyond providing the Service.
Authorised agents may submit requests with proof of authorisation; we may still verify your identity.
“Shine the Light” (California Civil Code §1798.83): we do not disclose personal information to third parties for their direct-marketing purposes.
14.2 India (Digital Personal Data Protection Act, 2023)
If you are in India, you are a Data Principal and we are a Data
Fiduciary. We process your personal data based on your consent
(given after clear notice, itemised to purpose, and withdrawable) or a permitted
legitimate use. You have the right to:
Access a summary of the personal data we process and the processing activities and recipients.
Correction, completion, updating, and erasure of your personal data.
Grievance redressal — raise a grievance with our Grievance Officer (§17), who will respond within the period prescribed by law.
Nominate another individual to exercise your rights in the event of death or incapacity.
Withdraw consent at any time, as easily as it was given.
If your grievance is not resolved, you may escalate to the Data Protection Board of
India. Where you may manage consent through a registered Consent
Manager, we will honour valid instructions received through it. Children's data is
handled per §12 (verifiable parental consent for under-18s; no tracking, behavioural
monitoring, or targeted advertising). We will report personal-data breaches to the Board and
affected Data Principals as required.
14.3 United Kingdom (UK GDPR & Data Protection Act 2018)
You have the rights of access, rectification, erasure, restriction, portability, and to
object to processing, plus rights relating to automated decision-making (§8). Our legal bases
are in §5. You may lodge a complaint with the Information Commissioner's Office
(ICO).
14.4 Canada (PIPEDA & provincial laws)
You may access your personal information, challenge its accuracy, and withdraw consent
(subject to legal or contractual limits). Quebec residents have additional rights under Law
25. You may complain to the Office of the Privacy Commissioner of Canada (OPC)
or your provincial regulator. We report breaches posing a real risk of significant harm to
the OPC and to you.
14.5 Australia (Privacy Act 1988 & the Australian Privacy Principles)
You may request access to and correction of your personal information, and you may deal with
us anonymously or by pseudonym where lawful and practicable. Cross-border disclosures follow
APP 8. Eligible data breaches are notified under the Notifiable Data Breaches scheme. You may
complain to the Office of the Australian Information Commissioner (OAIC).
14.6 Singapore (Personal Data Protection Act)
You may request access to and correction of your personal data, and withdraw consent. We
collect, use, and disclose personal data only for purposes a reasonable person would consider
appropriate and that we have notified to you. Our data-protection contact (DPO) is in §17,
and you may complain to the Personal Data Protection Commission (PDPC). We
notify notifiable breaches to the PDPC and affected individuals.
14.7 All other regions
If you are outside the regions named above, we still apply the protections in this policy as
our baseline. Where your local data-protection law grants you rights — such as to access,
correct, or delete your data, to object to or restrict processing, to withdraw consent, or to
complain to a supervisory authority — we will honour them. Contact us (§17) and we will
respond in line with applicable law.
Subprocessors
We may engage trusted subprocessors and service providers to assist in delivering the
Service. Such subprocessors may provide infrastructure, hosting, security, analytics,
communications, customer support, or AI processing services.
We require subprocessors to maintain appropriate confidentiality, privacy, and security
obligations. A list of significant subprocessors may be published separately or provided
upon request.
15. Data-breach notification
If a breach of security leads to the unauthorised access, loss, or disclosure of your
personal data, we will assess it and notify the competent authority and affected individuals
where required and within the timelines set by your law — for example without undue delay and
within 72 hours to the ICO (UK), to the Data Protection Board of India and affected
principals, to the OAIC (Australia) and PDPC (Singapore) for notifiable breaches, to the OPC
(Canada) for real-risk-of-significant-harm breaches, and as required by applicable US state
breach-notification laws.
16. Changes to this policy
We may update this policy. Material changes will be announced via an in-app banner and the
“Last updated” date above will change. Continued use after the effective date
indicates acceptance of the updated policy.
17. How to contact us & complain
For privacy questions, requests, grievances, or to exercise your privacy rights, contact:
Business-customer end-users should contact their organization's administrator first
regarding data controlled by that organization.
You also have the right to complain to your applicable regulator, including:
Data Protection Board of India (India)
Information Commissioner's Office (United Kingdom)
Office of the Privacy Commissioner of Canada
Office of the Australian Information Commissioner
Personal Data Protection Commission (Singapore)
California Privacy Protection Agency and applicable State Attorneys General (United States)
Cookie policy
Last updated: 11 June 2026 · Policy version:2026-06-11
This Cookie Policy explains how Smaiviz Pvt. Ltd. (“SMAIVIZ”) uses cookies and
similar technologies, and the choices you have. It supplements our
Privacy Policy.
1. What are cookies & similar technologies
Cookies are small files a site stores in your browser. We also use comparable
local-storage entries on your device. Together we call these
“cookies” in this policy. All of the cookies we use are
first-party (set by SMAIVIZ) — we set no third-party advertising
or tracking cookies, and we do not use cookies to sell or share your information or
for cross-context behavioural advertising.
2. Why and on what basis we use cookies
Strictly necessary cookies are used because the Service cannot run without
them (sign-in, security, and remembering your choice); most laws permit these without
consent. For all other cookies our basis depends on your region:
UK, India, Canada, Australia, Singapore — we ask for your prior consent before setting non-essential cookies (UK PECR/UK GDPR; India DPDP; PIPEDA; the Privacy Act/APPs; the PDPA).
United States — we provide notice and choice; you can opt out of non-essential cookies at any time, and we honour Global Privacy Control (GPC) signals where applicable.
3. How we ask for consent
On your first visit we show a cookie banner with equal-prominence Accept all,
Reject non-essential, and Cookie settings choices. Every non-essential
category is off by default; we never load optional cookies before you
choose, and ignoring the banner stores nothing optional. Your choice is recorded against a
policy version, and if we materially change this policy we will ask again. You can change or
withdraw your choice at any time — as easily as you gave it — via the
link in the footer.
4. Categories we use
Strictly necessary — sign-in, security, remembering your cookie choice, and your appearance & accessibility settings (a user-requested preference we keep so the interface stays usable).
Functional — remembers your language and chat-panel state.
Analytics — anonymous, scrubbed front-end error diagnostics so we can fix bugs. No third-party analytics, no profiling.
Marketing — none today. We set no advertising or third-party tracking cookies; this category stays empty unless that ever changes.
5. The cookies we use
All of the following are first-party (provider: SMAIVIZ).
Name
Type
Category
Purpose
Duration
smaiviz_session
Cookie (HttpOnly)
Necessary
Keeps you signed in.
Session lifetime
smaiviz_csrf
Cookie
Necessary
CSRF protection (double-submit token).
Session lifetime
smaiviz_cookie_consent
Cookie
Necessary
Stores your cookie choices and the policy version they apply to.
12 months
smaiviz_authed
Local storage
Necessary
A sign-in breadcrumb that prevents a page flash on load.
Until sign-out / cleared
smaiviz_prefs
Local storage
Necessary
Your appearance & accessibility settings (theme, contrast, motion, text size) — kept as an essential, user-requested preference.
Until cleared
smaiviz_locale
Local storage
Functional
Your chosen language.
Until cleared
chat-dock-state
Local storage
Functional
Remembers whether the chat panel is minimised, open or maximised.
Until cleared
Saved chats cache
Local storage
Functional
A local copy of your recent chats for faster loads.
Until cleared
Anonymous diagnostics
No cookie — network report
Analytics
Sends scrubbed front-end error reports to our servers; nothing is stored in your browser.
n/a
We record a consent receipt (the categories you chose, the policy version,
a timestamp, and your IP address) so we can demonstrate your choice if asked. See the
Privacy Policy for how we handle that data and your
rights.
6. Do Not Track & Global Privacy Control
Because we set no tracking or advertising cookies, there is no cross-site tracking to switch
off. Where applicable in the United States, we treat a recognised Global Privacy
Control (GPC) browser signal as a valid opt-out of any non-essential processing.
7. Managing your choices
Use
to review or change your consent at any time. You can also block or delete cookies through
your browser settings — though strictly-necessary ones will be re-created as needed for the
Service to work, clearing them will sign you out, and disabling local storage may break some
features.
8. Region-specific notes
United States — we provide this notice and honour GPC; we do not sell or share personal information through cookies.
United Kingdom — non-essential cookies are set only with your prior consent under PECR and UK GDPR.
India — non-essential cookies are set only with your consent under the DPDP Act; you may withdraw it at any time.
Canada, Australia, Singapore — we obtain consent for non-essential cookies and limit use to the purposes described above (PIPEDA; the Privacy Act/APPs; the PDPA).
All other regions — where your local law requires consent for non-essential cookies we ask for it; otherwise we apply the above as our baseline and honour any rights your local law provides.
9. Changes to this policy
If we materially change how we use cookies we will bump the policy version, update the date
above, and ask for your consent again the next time you visit.
Version 1.0 · Effective & last updated: 16 June 2026.
This policy describes how SMAIVIZ retains, recovers, deletes, and disposes of Customer
Data, personal data, and system records. Read it together with the
Privacy Policy and the
Subprocessor policy.
Retention principles
We retain information only as long as reasonably necessary for legitimate business
purposes, contractual obligations, legal requirements, security, and operational
continuity — and no longer, unless the law or a contract requires it.
Retention by data type
Customer account data (name, email, account identifiers, billing/subscription info, communication history) — kept while the account is active and for a reasonable period afterwards as needed for legal, operational, and fraud-prevention purposes.
Customer Content (prompts, files, configurations, outputs) — kept while the account is active.
Audit logs — retained for a defined period for security and compliance, then anonymised or removed.
Backups — included in encrypted backups for a limited period before being overwritten or removed on the backup-rotation schedule.
Account termination
Recovery period. After termination, Customer Content may remain recoverable for up to thirty (30) days.
Deletion. Information is then scheduled for deletion from production systems within ninety (90) days.
Retention exceptions
We may retain information longer where necessary for legal/regulatory compliance, fraud
prevention, dispute resolution, security investigations, or where it persists in backups
pending rotation. Anonymised and aggregated information may be retained indefinitely where
permitted by law.
Version 1.0 · Effective & last updated: 16 June 2026.
A “subprocessor” is a third-party service provider engaged by SMAIVIZ that may
process Customer Data in connection with the Service. We select subprocessors for their
security standards, reliability, legal compliance, and privacy protections, and require
them to maintain appropriate confidentiality and security obligations.
AI service providers
OpenAI — AI model processing & generation. Data: prompts, uploaded content, instructions, metadata, generated outputs.
Anthropic — AI model processing & generation. Data: as above.
Google AI services — AI model processing & generation. Data: as above.
Microsoft Azure OpenAI — enterprise AI model services. Data: as above.
Amazon Web Services (Bedrock) — AI model services. Data: as above.
Processing locations: multiple regions as determined by each provider.
When you bring your own key, your use of that provider is governed by your agreement with it.
Infrastructure & operations
Google Cloud — hosting, storage, and infrastructure.
Payment processors (e.g. Stripe, Razorpay) — billing and payment processing.
Analytics, monitoring, communications, and support providers — to operate, secure, and support the Service.
Changes
We may add or replace subprocessors as the Service evolves. An up-to-date list is available
on request at privacy@smaiviz.com; business
customers may request advance notice under their agreement.
Terms & Conditions
Version 2026-08-04 · Effective date: 4 August 2026 · Last updated: 4 August 2026.
These Terms & Conditions (“Terms”) govern your access to and use of
SMAIVIZ (the “Service”), operated by Smaiviz Pvt. Ltd. (“SMAIVIZ”,
“we”, “us”), a company incorporated in India with its registered
office in Hyderabad, India. Please read them together with our
Privacy Policy and
Cookie Policy.
Definitions
“Service” means the SMAIVIZ platform.
“Account” means a registered user account.
“Organisation” means a legal entity using the Service.
“Workspace” means an environment within the Service.
“User” means any individual accessing the Service.
“Customer Data” means data submitted by users.
“AI Agent” means an automated software agent configured within the Service.
1. Acceptance of these Terms
By creating an account or using the Service, you agree to be bound by these Terms. If you
do not agree, do not register or use the Service. If you use the Service on behalf of an
organisation, you represent that you have authority to bind that organisation, and
“you” refers to that organisation. For business customers, any signed order
form or master agreement and our Data Processing Addendum take precedence over these Terms
to the extent of a conflict.
2. Eligibility
You must be able to form a legally binding contract to use the Service. The Service is
intended for business and professional use and is not directed to children.
Where you are below the age of majority or the age of digital consent in your jurisdiction,
you may use the Service only with the involvement and consent of a parent or legal guardian
to the extent permitted by law. How we handle children's data (including COPPA and the
verifiable parental-consent rules of India's DPDP Act) is described in the
Privacy Policy. If you believe a minor is using
the Service without proper consent, contact
privacy@smaiviz.com.
3. Accounts & security
You are responsible for all activity under your account and for keeping your password and API keys confidential.
Provide accurate registration information and keep it current.
Notify us promptly of any unauthorised access or security incident.
We may suspend or terminate accounts that violate these Terms, abuse the Service, or pose security or legal risk.
4. The Service
SMAIVIZ is a platform for building and running AI agents, workflows, and routines, with
governance, approvals, and an audit trail. We may add, change, or discontinue features. We
will give reasonable notice of materially adverse changes where practical.
The Service includes governance mechanisms such as approvals, accountability chains, audit
logs, autonomy controls, and human-oversight features designed to support the responsible
deployment of AI systems.
Beta features
We may provide features designated as alpha, beta, preview, early access, or experimental.
Such features may be modified, suspended, or withdrawn at any time and are provided without
any service-level commitment or warranty.
Service limits
The Service may impose limits on usage, storage, API calls, workflow executions, agent
runs, file uploads, and similar resources. Exceeding these limits may result in throttling,
additional charges, suspension, or upgrade requirements.
5. Your content
“Your Content” means the inputs you submit (prompts, files, configurations) and
the outputs generated for you. As between you and us, you own Your Content,
subject to the terms of any model or third-party provider you use. You grant us a limited,
worldwide, non-exclusive licence to host, process, and transmit Your Content solely to
operate, secure, and support the Service. We do not use Your Content to train our
own models, and we do not sell it. You are responsible for Your Content and for
having the rights and permissions needed to submit it. Except for Your Content, no
ownership rights in the Service, models, prompts, workflows, templates, or platform
materials are transferred to you.
6. Acceptable use
You agree not to use the Service to:
Violate any law or regulation, or infringe any third party's rights (including IP, privacy, and publicity rights).
Generate or distribute unlawful, harmful, infringing, defamatory, deceptive, or harassing content, malware, or spam.
Attempt to identify individuals from, or build profiles for, unlawful surveillance or discrimination.
Reverse engineer, decompile, or extract source code beyond rights expressly granted, or circumvent security or usage limits.
Interfere with or disrupt the integrity, security, or performance of the Service.
Copy, replicate, or commercially exploit substantial parts of the Service in order to create a competing product, or resell the Service, without our prior written agreement.
Access, scrape, harvest, index, or download the Service or its content by automated means (including bots, crawlers, scrapers, or headless browsers), other than a search engine that honours our robots.txt; or cache, store, or redistribute our content beyond ordinary personal use.
Copy, mirror, frame, or clone the Service's pages, design, layout, text, code, or other content, in whole or in part; or remove, alter, or obscure any proprietary notice or embedded identifier.
You must also comply with the acceptable-use and safety policies of any model or
infrastructure provider you use through the Service.
Your compliance responsibilities
You are responsible for ensuring that your use of the Service complies with applicable
laws, including employment, privacy, tax, export, consumer-protection, and AI-related
regulations.
7. AI outputs
The Service orchestrates third-party AI models. AI output may be inaccurate, incomplete,
biased, or unsuitable for your purpose, and similar prompts can produce different results.
You are responsible for reviewing and validating any output before relying on it,
and you must not rely on it for legal, medical, financial, safety-critical, or other
professional decisions without independent verification. The Service provides assistive
output; a human remains responsible for decisions and for actions taken through approvals.
AI outputs may be substantially similar to content generated for other users, and SMAIVIZ
does not guarantee the uniqueness of generated output.
8. Third-party services & your API keys
Your use of model and cloud providers (e.g. Google Gemini, OpenAI, Anthropic, AWS, Google
Cloud, Microsoft Azure) and of connectors you enable is subject to those providers' own
terms. When you bring your own API key, your use of that provider is governed by your
agreement with it; you authorise us to transmit your prompts and outputs to it to provide
the Service. We do not control third-party providers and are not responsible for their
availability, output, or acts.
9. Intellectual property & feedback
We and our licensors retain all rights in the platform, including its software, design,
and documentation. Except for the rights expressly granted, no licence is implied. If you
send us feedback or suggestions, you grant us a perpetual, irrevocable, royalty-free
licence to use them without restriction.
Open-source software
Certain components may include open-source software governed by their respective licences.
Nothing in these Terms overrides those licences.
10. Fees, billing & taxes
Paid plans are billed in advance through our billing provider; usage beyond plan limits may
be billed separately. Fees are exclusive of taxes, which are your responsibility. Unless
required by law or stated otherwise, fees are non-refundable. We may change pricing with
reasonable advance notice effective from your next billing period.
10a. Free trials, expiry & non-payment
Your personal “My Org” workspace is provided free of charge and is not subject to
these trial or payment rules. Every additional organisation you create
starts with a 15-day free trial from the date it is created. If a paid
subscription is not in place when the trial ends, that organisation is
disabled.
When a paid subscription lapses (non-payment, expiry or cancellation), we provide a
3-day grace period during which the organisation stays usable. During the
trial and the grace period the organisation is visibly flagged in the app. After the grace
period ends the organisation is disabled.
While an organisation is disabled, its members cannot access its modules or data (including
by direct link). The organisation's owner and admins retain access to Plans, Billing
and Payments (and organisation settings) so they can renew; paying re-enables the
organisation. Billing and Plans are visible only to an organisation's owner and admins. No
data is deleted merely because an organisation is disabled; standard retention and deletion
rules (see the Privacy Policy) continue to apply.
11. Privacy & data protection
Our handling of personal data is described in the
Privacy Policy. For business customers where we
act as a processor, a Data Processing Addendum is available on request and, once entered
into, forms part of these Terms and governs that processing.
Confidentiality
Each party agrees to protect confidential information received from the other party and to
use it only for purposes related to the Service.
12. Service availability & support
We aim for high availability but do not guarantee uninterrupted or error-free service.
Maintenance and incidents are surfaced via the in-app status indicator; scheduled
maintenance is announced in advance where reasonably practical.
13. Suspension & termination
You may stop using the Service and delete your account at any time from
Settings → Account; a 90-day grace and deletion
process applies as described in the Privacy Policy. We may suspend or terminate access for
breach of these Terms, suspected unlawful or harmful use, or to protect the Service or other
users, with notice where reasonable. Sections intended to survive termination (including
§§5, 7, 9, 14–18, 20, the Confidentiality clause, and the Definitions) continue to apply.
Inactive accounts. To keep the Service secure and free of dormant data, an
account whose only workspace is its personal “My Org” (i.e. you belong to no
other organisation) and that has not signed in for 30 days will be
disabled. We email you a reminder 3 days beforehand. A
disabled account can be re-enabled simply by signing in and confirming, up until it is
permanently deleted after 60 days of inactivity. Deletion follows the same
grace-and-erasure process described in the Privacy Policy.
14. Disclaimers
Except as expressly stated and to the extent permitted by law, the Service is provided
“as is” and “as available” without warranties of any kind, express
or implied, including merchantability, fitness for a particular purpose, accuracy, and
non-infringement. Nothing in these Terms excludes or limits any warranty, guarantee,
or liability that cannot be excluded or limited under the law that applies to you —
including statutory consumer guarantees in jurisdictions such as the UK, Australia, India,
Canada, and Singapore.
15. Limitation of liability
To the maximum extent permitted by law, SMAIVIZ and its affiliates will not be liable for
any indirect, incidental, special, consequential, or punitive damages, or any loss of
profits, revenue, data, or goodwill, arising from or related to the Service. To the maximum
extent permitted by law, our total aggregate liability arising out of or related to the
Service will not exceed the greater of the amounts you paid us for the Service in the 12
months before the event giving rise to the claim, or USD 100. These limits do not apply to
liability that cannot be limited by law (such as for death or personal injury caused by
negligence, fraud, or wilful misconduct), and nothing here affects your non-excludable
statutory rights as a consumer.
16. Indemnification
You will indemnify and hold harmless SMAIVIZ and its affiliates from third-party claims,
losses, and reasonable costs arising out of Your Content, your use of the Service, or your
breach of these Terms — except to the extent caused by our own breach or unlawful conduct.
17. Export controls & sanctions
You represent that you are not located in, and will not use the Service in or for the
benefit of, any country or party subject to applicable trade sanctions or export-control
restrictions, and that you will comply with applicable export-control and sanctions laws.
18. Governing law & disputes
These Terms are governed by the laws of India, without regard to conflict-of-laws rules, and
the courts at Hyderabad, Telangana, India have jurisdiction over disputes. This does not
deprive you of the protection of mandatory consumer-protection laws of
your country of residence, or of your right to bring a complaint before, or seek remedies
from, a competent regulator or court where the law gives you that right.
19. Changes to these Terms
We may update these Terms. Material changes will be communicated via in-app banner or
email, and the “Last updated” date above will change. Continued use after the
changes take effect constitutes acceptance; if you do not agree, stop using the Service.
20. General
Entire agreement. These Terms, with the Privacy and Cookie Policies and any order form or DPA, are the entire agreement between you and us about the Service.
Severability. If any provision is unenforceable, the rest remains in effect.
No waiver. Failing to enforce a provision is not a waiver of it.
Assignment. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets.
Force majeure. Neither party is liable for delays or failures caused by events beyond its reasonable control.
Notices. We may give notice via the Service or by email; notices to us go to the address in §21.
No third-party beneficiaries except as expressly stated.
21. Contact
Questions about these Terms can go to
terms@smaiviz.com (or, for organisation accounts,
your workspace administrator). Privacy questions go to
privacy@smaiviz.com.
Version 1.0 · Effective & last updated: 16 June 2026.
This Acceptable Use Policy (“AUP”) governs use of all SMAIVIZ products, APIs,
AI systems, agents, automations, and related services, and forms part of the
Terms. You remain solely responsible for the content,
prompts, workflows, automations, and outputs in your account. Violations may result in
suspension, termination, credit forfeiture, legal action, or reporting to authorities.
You must not use the Service to
Break the law — facilitate crime, fraud, money laundering, or violate sanctions/export-control laws.
Deceive — impersonate people or organisations, forge documents, phish, or run scams or social-engineering.
Attack systems — create or distribute malware/ransomware/spyware, gain unauthorised access, steal credentials, bypass security, or run denial-of-service attacks. (Authorised, lawful defensive security is permitted.)
Generate harmful content — threats, harassment, hateful or discriminatory content, violent-extremist or terrorist material, or unlawful exploitation/abuse material.
Misuse synthetic media — deceptive deepfakes, unauthorised impersonation, or non-consensual synthetic content. (Clearly-disclosed lawful parody, satire, artistic, or educational use may be permitted.)
Infringe IP or privacy — violate copyrights/trademarks/trade secrets or proprietary notices; unlawfully collect, disclose, or surveil personal data.
Run prohibited high-risk use cases — life-critical, emergency, military, weapons, classified, regulated healthcare diagnosis, regulated financial advice, nuclear, or aviation-safety systems, unless expressly authorised in a written Enterprise Agreement.
Abuse the AI/platform — extract model parameters, reverse-engineer systems, circumvent safeguards, or build competing models through unauthorised extraction.
Abuse resources or payments — overload infrastructure, evade usage limits, use stolen payment methods, or commit chargeback/refund/credit fraud.
Resell without authorisation — resell, sublicense, or operate a service bureau on the Service without our prior written agreement.
Automation & agents
You remain responsible for everything your AI agents, automated workflows, scheduled
actions, and integrations do. Delegating an action to an agent does not remove your
responsibility for it.
Enforcement & reporting
We may warn, remove content, restrict, suspend, terminate, forfeit credits, report to
authorities, or take legal action — and may act immediately where needed to protect users,
systems, or rights. Report suspected violations to
support@smaiviz.com.
Email Acceptable Use Policy
Effective date: 16 June 2026 · Last updated: 16 June 2026.
This Email Acceptable Use Policy (“Email Policy”) governs your access to and use of
the email-related services provided by Smaiviz Pvt. Ltd. (“SMAIVIZ”, “we”,
“us”, or “our”), including transactional email, marketing email, SMTP
relay services, email APIs, inbound email processing, email forwarding, mailing lists, and any
other email functionality made available through the SMAIVIZ platform (collectively, the
“Email Services”).
This Email Policy forms part of our Terms & Conditions
and should be read together with our Privacy Policy,
Cookie Policy, Data Processing Addendum (where
applicable), and any Order Form or Master Service Agreement entered into between you and SMAIVIZ.
By using the Email Services, you agree to comply with this Email Policy. Failure to comply may
result in suspension or termination of your access to the Email Services or your SMAIVIZ account.
Definitions
“Email Services” means any email-related functionality provided by SMAIVIZ, including SMTP services, APIs, transactional email delivery, inbound email processing, forwarding, mailing lists, and related services.
“Sender” means any customer, organisation, or user who sends email using the Email Services.
“Recipient” means any person or entity receiving email sent through the Email Services.
“Marketing Email” means any email primarily intended to advertise, promote, or market products, services, events, or commercial activities.
“Transactional Email” means an email sent to facilitate an agreed transaction or relationship, including account verification, password resets, invoices, receipts, billing notices, security alerts, and service notifications.
“Bulk Email” means substantially identical email messages sent to multiple recipients during a single campaign or over a short period.
“Mailing List” means a list of recipients maintained by a Sender for distributing newsletters, announcements, promotional communications, or other recurring email campaigns.
“Spam” means unsolicited, deceptive, unwanted, or unlawful electronic mail, regardless of volume or method of transmission.
“Domain Authentication” means recognised email authentication technologies including SPF, DKIM, DMARC, BIMI, or any successor industry standards.
“Suppression List” means a list of email addresses that must not receive future communications because of unsubscribe requests, hard bounces, complaints, legal requirements, or other suppression events.
1. Acceptance of this Email Policy
By enabling, accessing, configuring, or using the Email Services, you agree to comply with this Email Policy.
If you use the Email Services on behalf of an organisation, you represent that you have authority to bind that organisation to this Email Policy.
Business customers operating under a separately negotiated agreement remain subject to this Email Policy unless expressly stated otherwise in that agreement.
2. Scope
This Email Policy applies to all email activity conducted through the Email Services, including but not limited to:
Transactional emails.
Marketing emails.
Newsletters.
Customer notifications.
Billing communications.
Authentication emails.
Support communications.
SMTP relay.
Email APIs.
Inbound email processing.
Mailing lists.
Automated workflow emails.
AI-generated email communications.
Any future email functionality provided by SMAIVIZ.
This Email Policy applies regardless of whether emails are sent using SMAIVIZ-managed domains or customer-owned domains connected to the Service.
3. Permitted Use
The Email Services may only be used for lawful business, organisational, educational, governmental, or other legitimate purposes.
Examples of permitted use include:
Account verification.
Password recovery.
Security notifications.
Billing communications.
Order confirmations.
Product updates.
Customer support.
Subscription notifications.
Event registrations.
Marketing communications sent with appropriate consent.
Internal organisational communications.
AI-generated communications reviewed by appropriate human oversight where required.
You remain solely responsible for all email content transmitted using the Email Services.
4. Sender Responsibilities
You are responsible for:
ensuring you have all necessary rights, permissions, and legal bases to send emails to recipients;
maintaining accurate sender information;
protecting SMTP credentials, API keys, and authentication tokens;
ensuring recipient lists are obtained lawfully;
honouring unsubscribe requests without unreasonable delay;
complying with applicable anti-spam, privacy, consumer-protection, telecommunications, and electronic communications laws;
ensuring automated email systems remain properly monitored;
promptly responding to abuse complaints relating to your email activity; and
ensuring AI-generated emails are reviewed where appropriate before being relied upon or distributed.
You are responsible for all email activity occurring under your account, including activity performed by employees, contractors, agents, administrators, API integrations, or third-party applications authorised by you.
5. Prohibited Use
You must not use the Email Services to:
send spam or unsolicited commercial email;
send email without obtaining any legally required consent;
purchase, rent, scrape, harvest, or otherwise acquire recipient lists through unlawful or deceptive means;
impersonate another person, organisation, or domain;
forge email headers or routing information;
falsify sender identity;
conceal the origin of email messages through deceptive practices;
distribute malware, ransomware, spyware, viruses, trojans, or other malicious software;
conduct phishing, credential harvesting, business email compromise, or social engineering attacks;
distribute unlawful, fraudulent, misleading, defamatory, obscene, hateful, or threatening content;
send email intended to harass, intimidate, stalk, or abuse individuals or organisations;
interfere with the normal operation of internet infrastructure or mail systems;
intentionally generate excessive bounce rates or complaint rates;
attempt to circumvent rate limits, account restrictions, reputation systems, or security controls;
use compromised accounts or stolen credentials;
transmit content that infringes intellectual property rights or privacy rights;
use the Email Services in violation of applicable export-control, sanctions, or trade laws; or
engage in any activity that could reasonably damage the reputation, deliverability, or integrity of the Email Services or other customers using the platform.
Where we reasonably believe your email activity presents a risk to recipients, internet service providers, domain reputation, or the Email Services, we may suspend or restrict your access immediately.
6. Spam, Bulk Email & Mailing Lists
The Email Services may be used to send bulk email only where recipients have provided any consent or permission required by applicable law or where another lawful basis exists for sending such communications.
You must ensure that:
recipient lists are obtained lawfully and maintained accurately;
recipients have a clear and reasonable method to unsubscribe from marketing communications;
unsubscribe requests are processed without unreasonable delay;
suppression lists are maintained and honoured;
email campaigns accurately identify the sender;
subject lines are truthful and not deceptive;
email content accurately reflects the purpose of the communication; and
mailing lists are regularly maintained to remove invalid, inactive, or unsubscribed recipients.
You must not:
send unsolicited commercial email (“spam”);
send email to purchased, rented, scraped, harvested, or otherwise unlawfully obtained mailing lists;
repeatedly email recipients who have opted out;
use open relays or compromised mail servers;
artificially inflate recipient lists;
conceal unsubscribe mechanisms;
repeatedly resend messages that have permanently failed delivery;
use misleading subject lines intended to deceive recipients into opening messages; or
send bulk email intended primarily to generate complaints, excessive traffic, or disruption.
Repeated spam complaints, excessive hard bounces, blacklist listings, or abuse reports may result in immediate suspension of the Email Services.
7. Marketing Communications
Marketing communications must comply with all applicable electronic communications, consumer-protection, privacy, advertising, and anti-spam laws in every jurisdiction where recipients are located.
Marketing emails should:
clearly identify the sender;
accurately identify promotional content;
include a valid reply address where appropriate;
contain a functional unsubscribe mechanism;
identify sponsored or promotional content where required by law;
Where consent is required by applicable law, you are solely responsible for obtaining, recording, maintaining, and demonstrating such consent.
SMAIVIZ does not verify whether your recipients have provided valid consent and assumes no responsibility for your compliance with applicable marketing laws.
8. Email Authentication & Domain Security
To improve deliverability, reduce abuse, and protect recipients, customers are encouraged to implement recognised email authentication standards for domains used with the Email Services.
These standards may include:
Sender Policy Framework (SPF);
DomainKeys Identified Mail (DKIM);
Domain-based Message Authentication, Reporting and Conformance (DMARC);
Brand Indicators for Message Identification (BIMI); and
any successor authentication standards adopted by the email industry.
Where customer-owned domains are connected to the Email Services, you remain responsible for:
maintaining DNS records;
protecting domain ownership;
renewing domain registrations;
securing domain administration credentials;
preventing domain hijacking; and
maintaining appropriate authentication records.
Failure to properly authenticate sending domains may reduce email deliverability or result in temporary restrictions intended to protect the reputation of the Email Services.
9. Sending Limits & Fair Usage
To maintain reliable service for all customers, the Email Services may be subject to operational limits, including limits relating to:
emails sent per minute;
emails sent per hour;
emails sent per day;
recipient limits;
SMTP connections;
API requests;
attachment sizes;
message sizes;
inbound email processing;
storage capacity; and
other technical limitations.
These limits may vary depending on your subscription plan, account history, sender reputation, domain reputation, infrastructure capacity, regulatory requirements, or security considerations.
We may temporarily throttle, delay, reject, queue, or suspend email transmissions where necessary to:
maintain platform stability;
protect recipient mail systems;
reduce abuse;
comply with legal obligations;
preserve sending reputation; or
investigate suspected misuse.
Attempting to circumvent usage limits through multiple accounts, rotating credentials, automated account creation, proxy services, or other techniques is prohibited.
10. Prohibited Content
You must not use the Email Services to distribute, promote, facilitate, or encourage content that:
violates applicable laws or regulations;
infringes intellectual property rights;
violates privacy or publicity rights;
promotes violence, terrorism, organised crime, or unlawful activities;
contains child sexual abuse material or exploits minors;
promotes human trafficking or exploitation;
facilitates identity theft, fraud, phishing, or financial scams;
distributes malware or malicious software;
promotes illegal drugs or unlawful controlled substances;
promotes unlawful gambling activities;
contains obscene, hateful, discriminatory, or threatening material prohibited by applicable law;
unlawfully collects personal information;
intentionally spreads misinformation where prohibited by law; or
otherwise presents a material risk to recipients, internet service providers, or the Email Services.
The Email Services must not be used to transmit content intended to bypass security controls, deceive recipients, evade spam filters, or facilitate unlawful activities.
Where email content is generated using AI systems available through the SMAIVIZ platform, you remain solely responsible for reviewing such content before transmission. AI-generated content does not relieve you of your legal or contractual responsibilities regarding accuracy, legality, or recipient rights.
11. Security Requirements
You are responsible for maintaining the security of your account and all credentials used to access the Email Services.
You must:
protect SMTP usernames, passwords, API keys, OAuth credentials, and authentication tokens;
restrict access to authorised personnel only;
implement appropriate administrative, technical, and organisational security measures;
maintain secure systems used to send or receive email;
promptly rotate credentials that are suspected to have been compromised;
implement reasonable safeguards against unauthorised access to recipient data;
notify us promptly of any suspected compromise, abuse, or security incident involving the Email Services; and
cooperate with any reasonable investigation relating to security incidents affecting the Email Services.
You must not knowingly permit unauthorised persons to access your email infrastructure through your SMAIVIZ account.
Where we reasonably believe your account has been compromised, we may temporarily suspend email functionality, require credential rotation, restrict API access, or take other reasonable security measures to protect the Email Services and other users.
12. Third-Party Email Providers & Integrations
The Email Services may integrate with third-party providers including email gateways, SMTP providers, DNS providers, cloud infrastructure providers, analytics platforms, CRM systems, customer-support platforms, workflow automation services, and similar technologies.
Your use of such third-party services remains subject to their respective terms, privacy policies, and acceptable use policies.
Where you connect your own third-party email provider, SMTP server, API credentials, or domain, you authorise SMAIVIZ to use those credentials solely for providing the Email Services.
SMAIVIZ does not control third-party providers and is not responsible for:
service interruptions;
delivery delays;
rejected messages;
spam filtering decisions;
domain reputation;
third-party outages;
DNS failures;
security incidents occurring within third-party systems; or
any loss arising from your relationship with a third-party provider.
You remain responsible for ensuring that any third-party integrations used with the Email Services comply with applicable laws and this Email Policy.
13. Monitoring & Enforcement
To protect the integrity, security, reliability, and reputation of the Email Services, SMAIVIZ may monitor operational information relating to email activity.
Such monitoring may include information relating to:
sending volumes;
delivery rates;
bounce rates;
complaint rates;
authentication status;
abuse reports;
spam indicators;
infrastructure performance;
system security; and
compliance with this Email Policy.
We do not routinely review the content of email communications except where reasonably necessary to:
investigate abuse;
respond to legal obligations;
enforce this Email Policy;
protect the security of the Email Services;
prevent fraud;
investigate technical failures;
respond to customer support requests authorised by you; or
comply with applicable law.
Where reasonably necessary, we may request additional information regarding your email practices, recipient consent, mailing lists, authentication configuration, or compliance procedures.
Failure to cooperate with reasonable compliance requests may result in restrictions on the Email Services.
14. Suspension & Termination
We may suspend, restrict, throttle, or terminate your access to the Email Services immediately where we reasonably believe that:
this Email Policy has been violated;
applicable law requires such action;
your email activity presents a material risk to recipients or internet infrastructure;
your account has been compromised;
excessive abuse complaints have been received;
spam complaints exceed acceptable industry thresholds;
bounce rates indicate poor mailing practices;
your sending activity materially damages the reputation of the Email Services;
fraudulent or unlawful activity is suspected; or
continued operation may adversely affect other customers or third-party providers.
Where reasonably practicable, we will provide notice before suspension.
Immediate suspension may occur without prior notice where necessary to:
prevent ongoing abuse;
comply with legal obligations;
protect recipients;
protect the Email Services;
prevent security incidents; or
preserve system integrity.
Suspension of the Email Services does not automatically terminate your SMAIVIZ account unless separately notified.
Termination of your SMAIVIZ account may result in termination of access to the Email Services.
15. Compliance with Laws
You are solely responsible for ensuring that your use of the Email Services complies with all applicable laws and regulations, including those relating to:
electronic communications;
anti-spam requirements;
privacy and data protection;
consumer protection;
advertising;
telecommunications;
cybersecurity;
export controls;
sanctions;
intellectual property;
record retention; and
any other laws applicable to your business or recipients.
Depending on the jurisdictions involved, these laws may include, without limitation:
the Information Technology Act, 2000 (India);
the Digital Personal Data Protection Act, 2023 (India);
the CAN-SPAM Act (United States);
the General Data Protection Regulation (European Union);
the UK GDPR;
Canada’s Anti-Spam Legislation (CASL);
Australia’s Spam Act 2003;
Singapore’s Personal Data Protection Act (PDPA); and
other applicable national, state, provincial, or local laws.
Nothing in this Email Policy constitutes legal advice or guarantees that your use of the Email Services complies with applicable laws.
16. Reporting Abuse
If you become aware of any misuse of the Email Services, including spam, phishing, malware distribution, fraudulent activity, domain abuse, account compromise, or any other violation of this Email Policy, you should notify SMAIVIZ without unreasonable delay.
Reports should include, where reasonably available:
relevant email headers;
sender information;
recipient information;
timestamps;
supporting evidence; and
any other information reasonably necessary to investigate the matter.
SMAIVIZ may investigate reported abuse and take appropriate action, including restricting or terminating accounts, notifying affected parties, cooperating with law enforcement authorities, or implementing technical measures to protect the Email Services.
Submitting knowingly false or malicious abuse reports may itself constitute a violation of this Email Policy.
17. Changes to this Email Policy
We may update this Email Policy from time to time to reflect changes in applicable laws, industry standards, security requirements, technology, or the Email Services.
Where we make material changes, we will provide reasonable notice through one or more of the following methods:
email notification;
an in-app notification;
a notice on our website; or
another communication method reasonably designed to inform affected customers.
The “Last updated” date at the beginning of this Email Policy will indicate the date of the most recent revision.
Your continued use of the Email Services after the revised Email Policy becomes effective constitutes your acceptance of the updated Email Policy. If you do not agree with the revised Email Policy, you must discontinue use of the Email Services.
18. General
Entire agreement. This Email Policy forms part of the SMAIVIZ Terms & Conditions and should be read together with the Privacy Policy, Cookie Policy, Data Processing Addendum (where applicable), and any applicable Order Form or Master Service Agreement. In the event of any conflict, the applicable Order Form or Master Service Agreement shall prevail to the extent of the conflict.
Relationship to the Terms & Conditions. Unless expressly stated otherwise in this Email Policy, all provisions of the SMAIVIZ Terms & Conditions continue to apply to your use of the Email Services, including provisions relating to intellectual property, disclaimers, limitation of liability, indemnification, governing law, dispute resolution, export controls, confidentiality, and termination.
Severability. If any provision of this Email Policy is found to be invalid, illegal, or unenforceable under applicable law, the remaining provisions will continue in full force and effect.
No waiver. Our failure to enforce any provision of this Email Policy shall not constitute a waiver of that provision or of any other rights available to us.
Assignment. You may not assign or transfer your rights or obligations under this Email Policy without our prior written consent. We may assign this Email Policy in connection with a merger, acquisition, corporate restructuring, or sale of assets.
Force majeure. Neither party shall be liable for any delay or failure to perform obligations arising from events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, labour disputes, internet outages, failures of third-party providers, governmental actions, or other force majeure events.
Notices. We may provide notices relating to the Email Services through the Service, by email, or by any other reasonable communication method. Notices to SMAIVIZ should be sent using the contact information provided below.
No third-party beneficiaries. Except where expressly stated, this Email Policy does not create any rights in favour of any third party.
19. Contact
Questions regarding this Email Policy, reports of suspected abuse, or compliance enquiries may be directed to:
Version 1.0 · Effective & last updated: 16 June 2026.
This policy governs subscriptions, prepaid AI credits, renewals, cancellations, refunds,
and chargebacks. It forms part of the Terms. By
purchasing or using the Service, you agree to it.
Prepaid AI credits
Prepaid model. AI usage runs on prepaid credits — you buy credits in advance and consume them through usage. No plan includes a monthly credit allowance.
Free starter credits. Each account receives a one-time grant of 5,000 free credits to try the Service; once used, you top up to continue.
Top-ups. You purchase additional credits in packs. Credits are not currency, have no cash value, and are not redeemable for cash or transferable.
Subscriptions
Paid plans (monthly, annual, or enterprise) are billed in advance and unlock features and
limits — separately from the prepaid credits that power AI usage. You can disable
auto-renewal at any time before the next renewal date; cancellation stops future charges
but does not end the current paid term, which runs to its end.
Refund eligibility
Except as stated here or required by law, purchases are final.
Consumed credits (used to generate outputs) are not refundable. Where only part of a purchase has been used, only the unused portion may be considered, at our discretion.
Generally non-refundable: consumed or expired credits, completed AI processing, generated outputs, and professional/consulting/support services already provided.
Duplicate or unauthorised charges and billing errors (reported within 30 days) are reviewed and adjusted where verified.
Cancellation, chargebacks & outages
You may cancel at any time; access may continue through the paid term. Please contact us
before initiating a chargeback — fraudulent chargebacks may lead to suspension or legal
action. Service availability is governed by any applicable Service Level Agreement; where
it applies, service credits are the sole remedy for qualifying downtime (no automatic cash
refunds). Nothing here limits non-waivable consumer-protection rights.
Requests
Submit refund requests with your account and transaction details to
support@smaiviz.com.
Copyright & DMCA Policy
Version 1.0 · Effective & last updated: 16 June 2026.
SMAIVIZ respects intellectual property rights and expects users to do the same. You may
only upload or process content you own or are authorised to use. This policy sets out how
to report infringement and how we respond.
Reporting infringement
Copyright owners (or their authorised agents) may send a notice including: identification
of the work and the allegedly infringing material; its location; your contact details; a
good-faith statement that the use is unauthorised; a statement under penalty of perjury
that the notice is accurate and you are authorised to act; and your physical or electronic
signature.
On a valid notice we may investigate, request more information, remove or disable access to
content, or restrict accounts. A user who believes content was removed in error may submit
a counter-notification (identifying the material and its prior location, a statement under
penalty of perjury that removal was a mistake, contact details, consent to jurisdiction
where required, and a signature). We may restore content where appropriate.
Repeat infringers, trademarks & trade secrets
We may suspend or terminate accounts associated with repeated violations, and we accept
trademark and trade-secret complaints with supporting detail. Knowingly false reports may
be rejected and may lead to account action or legal remedies.
AI-generated content
AI outputs may be influenced by prompts and training methods. We do not guarantee that
generated outputs are unique or free of third-party claims; you remain responsible for
evaluating IP risk in your use of outputs.
AI Output & Automation Disclaimer
Version 1.0 · Effective & last updated: 16 June 2026.
This Disclaimer governs use of our AI services, agents, automations, and APIs, and forms
part of the Terms. Using the Service, you accept the
risks described here.
AI is probabilistic
AI systems may generate unexpected, inaccurate, incomplete, contradictory, outdated, or
fabricated information (“hallucinations”), and may misinterpret instructions.
These are inherent limitations of current AI. We do not warrant that
outputs are accurate, complete, current, error-free, reliable, or fit for your purpose.
Your responsibility
You are responsible for evaluating, validating, and verifying outputs before relying on
them, and for the business, operational, hiring, and other decisions you make based on
them. Do not rely on AI outputs alone.
Not professional advice
AI outputs do not constitute legal, medical, financial, investment, accounting,
engineering, tax, or other professional advice. Consult qualified professionals where
appropriate, and keep meaningful human oversight for important, legal,
health, financial, employment, and compliance decisions.
Automation, agents & generated code
Automations and AI agents may take incorrect actions, act on incomplete information, or
produce unintended outcomes; you are responsible for monitoring and supervising them, and
for all actions performed by agents you configure or operate. AI-generated code may contain
bugs, security vulnerabilities, or infringing material — review, test, and secure it before
deployment.
Third-party AI providers & regulated uses
Outputs may be affected by third-party providers (OpenAI, Anthropic, Google, Azure OpenAI,
AWS Bedrock, and others) updating or changing their models or services. Unless expressly
agreed in an Enterprise Agreement, the Service is not intended for regulated healthcare,
life-critical, military, weapons, aviation-safety, or classified uses. To the maximum
extent permitted by law, SMAIVIZ is not liable for losses arising from outputs,
hallucinations, automation failures, agent actions, or reliance on generated content.
Responsible AI
Version 1.0 · Effective & last updated: 16 June 2026.
We are committed to designing, deploying, and operating AI in a way that promotes trust,
safety, fairness, accountability, transparency, privacy, security, and lawful use. AI
creates real opportunities alongside risks that must be managed responsibly.
Core principles
Human oversight. Important decisions should stay subject to human judgment; AI assists, it doesn't replace responsible decision-making. Sensitive actions pause at the Approvals gate.
Fairness & non-discrimination. We work to evaluate and reduce unfair bias, though it cannot always be eliminated — review outputs before important decisions.
Transparency. We communicate AI capabilities and limitations, including that outputs may be inaccurate, may hallucinate, and may need verification.
Accountability. We maintain internal responsibility for AI governance, risk, and security controls; every agent action can be traced to a responsible human through the accountability framework.
Privacy & security. We protect data per the Privacy Policy and our security practices, and we do not train our own models on your content.
Reliability & compliance. We monitor AI systems and work to meet applicable legal and regulatory requirements.
Our internal AI governance program (system inventory, risk classification, provider
review, and human-oversight controls) underpins these commitments. Customers remain
responsible for their own use of AI outputs and decisions based on them.
Security & trust
Last updated: 16 June 2026.
Security is foundational to a platform that runs autonomous AI agents on your
behalf. This page summarises how we protect your account, your data, and the actions
taken in your workspace. For how we handle personal data, see our
Privacy Policy and
Cookie Policy.
AI governance & human oversight
SMAIVIZ includes governance controls designed for the responsible deployment and
operation of AI systems. These controls include:
Human approval workflows
Accountability chains
Agent autonomy controls
Audit logging
Permission boundaries
Role-based access controls
Organizations remain responsible for determining appropriate approval requirements,
governance policies, and autonomy settings for their agents.
Account & access
Modern password protection. Passwords are stored using a memory-hard, salted hashing algorithm — never in plain text — and are re-hardened as our parameters evolve.
Single sign-on. Optional Google sign-in (OpenID Connect) lets your team use existing, centrally-managed identities.
Secure sessions. Sign-in uses server-side sessions with hardened, same-site cookies; sessions can be revoked and expire automatically.
Role-based access & approvals. Each workspace has role-based access so people only see what they should, and sensitive agent actions can require explicit human approval.
Encryption
In transit. All traffic is served over HTTPS/TLS.
At rest. Sensitive secrets such as your provider API keys are encrypted with authenticated encryption before storage, held in plain text only for the moment a request needs them, and never written to logs.
Minimal exposure. Once saved, secrets are never returned to the browser — the interface shows only the last few characters so you can recognise a key without revealing it.
Application integrity
Database access is fully parameterised through an ORM, and user-supplied content is escaped before display — guarding against injection and cross-site scripting.
State-changing requests are protected against cross-site request forgery.
Authentication is rate-limited to slow brute-force and credential-stuffing attempts.
An append-only audit trail records security-relevant events, with retention and routine pruning.
We do not include third-party advertising networks in the product experience. Operational analytics, monitoring, security, support, and performance-improvement tooling may be used to operate, secure, maintain, and improve the Service.
Vulnerability management
We monitor security advisories affecting our infrastructure, software components, and
technology stack. Security updates are evaluated and applied according to risk,
severity, and operational impact. Critical vulnerabilities receive priority review and
remediation.
Abuse & bot defence
We apply layered defences at the network edge and the application boundary —
including a web application firewall, optional CAPTCHA, and adaptive rate limits — to
keep automated abuse away from your workspace. Suspicious activity is surfaced to
operators for review.
Monitoring & response
Security-relevant events are logged centrally and monitored, with automated alerts on
anomalous patterns so our team can respond quickly. We maintain operational runbooks
for incident handling.
Your data & AI
You own your content. Your prompts, files, and outputs are yours; we process them only to operate the Service.
No training on your content. We do not use your content to train our own models, and we do not sell it — see our Terms.
Bring your own keys. When you connect a model or cloud provider, your use of that provider is governed by your agreement with it.
Model providers
When AI models are used through the Service, prompts, files, and outputs may be
transmitted to the selected model provider to generate responses. Each provider
processes data according to its own terms, privacy commitments, and security practices.
Customers are responsible for reviewing the terms and policies of any third-party
providers they choose to use.
AI agent security
AI agents operate within permissions, guardrails, limitations, and autonomy levels
configured by the customer. Actions may be restricted, approved, audited, delayed, or
blocked based on organizational policies and governance requirements.
Every agent action can be traced through the accountability framework to a responsible
human. Organizations are responsible for reviewing agent configurations and ensuring
that autonomy settings are appropriate for their intended use cases.
Infrastructure
SMAIVIZ runs on Google Cloud, using managed, regularly-patched services. We restrict
production access on a need-to-know basis and keep configuration secrets separate from
application code.
Backup & recovery
Critical platform data is backed up regularly. Backups are encrypted and retained
according to operational requirements. Recovery procedures are periodically tested to
support restoration in the event of operational incidents, service disruption, or data
loss.
Personnel access
Access to production systems and customer data is restricted to authorized personnel
with a legitimate business need. Access permissions are reviewed periodically and
removed when no longer required. Administrative actions are logged and monitored.
Data residency
Customers may specify a preferred data residency region where supported. Actual storage
and processing locations depend on the deployment infrastructure, service configuration,
and applicable legal requirements.
Authentication roadmap
We continue to enhance account-security capabilities and identity-management features as
the platform evolves. Security features may be expanded over time to include additional
authentication, authorization, monitoring, and access-control capabilities.
Compliance & roadmap
We align our controls with widely-recognised security practices and are progressively
maturing toward formal third-party assessment as we move to general availability. If you
have specific compliance requirements, contact
sales@smaiviz.com.
Please do not publicly disclose vulnerabilities until we have had a reasonable
opportunity to investigate and remediate the issue.
Responsible disclosure
If you believe you've found a security vulnerability, please email
security@smaiviz.com with the details and
steps to reproduce. We welcome good-faith research: we will acknowledge your report and
will not pursue or support legal action against researchers who act in good faith, avoid
privacy violations and service disruption, and give us reasonable time to remediate
before any public disclosure.
Information Security
Version 1.0 · Effective & last updated: 16 June 2026.
This summarises the security principles and controls we use to protect Customer Data,
systems, and infrastructure. For the customer-facing overview see also
Security & trust.
Objectives
Our security program supports confidentiality, integrity, availability, accountability,
resilience, and regulatory compliance, and is reviewed and updated periodically.
Controls
Access control. Least-privilege, need-to-know access; uniquely-assigned accounts; periodic review; prompt revocation when no longer required.
Encryption. Data encrypted in transit (HTTPS/TLS) and sensitive secrets encrypted at rest with authenticated encryption.
Monitoring & logging. Centralised logging of security-relevant events with alerting on anomalies.
Vulnerability management. We monitor advisories and apply updates by risk and severity.
Resilience. Encrypted, monitored, periodically-tested backups and multi-region cloud infrastructure for continuity and recovery.
Shared responsibility
You remain responsible for protecting your credentials, securing your endpoints, and
managing user access within your organisation. No control is absolute.
Incident Response
Version 1.0 · Effective & last updated: 16 June 2026.
We maintain a framework to identify, assess, contain, investigate, remediate, and
communicate security incidents affecting our systems or your data.
What counts as an incident
An actual or suspected event that may affect the confidentiality, integrity, availability,
or security of systems or data — for example unauthorised access, credential compromise,
malware/ransomware, data exposure, denial-of-service, or insider threats.
How we respond
Detect & classify incidents by severity.
Contain & investigate with a designated response team (coordination, investigation, remediation, communications, legal review).
Remediate & recover services and preserve evidence.
Notify. Where required by law or contract, we notify affected customers and authorities within a commercially reasonable period, and cooperate on investigation and mitigation.
Improve. We review incidents to strengthen future security.
See the Privacy Policy (data-breach notification)
for how we handle personal-data breaches.
Vulnerability Disclosure Policy
Version 1.0 · Effective & last updated: 16 June 2026.
We welcome good-faith security research that helps us protect customers. This policy
explains how to report a vulnerability and what's in and out of scope.
Scope
www.smaiviz.com and SMAIVIZ web applications, APIs, AI services, cloud services, and hosted
infrastructure we own and operate.
Out of scope
Denial-of-service / DDoS, ransomware or malware deployment, social engineering or phishing
of our people, physical security testing, credential theft, account-takeover attempts,
spam, and any destruction, alteration, or unauthorised access of customer data.
Good-faith research
Avoid privacy violations and service disruption, don't access more data than necessary,
don't modify customer information, and don't maintain persistent access.
How to report
Email security@smaiviz.com (subject: “Security
Vulnerability Report”) with a description, affected systems/URLs, reproduction steps,
a proof of concept where appropriate, a severity assessment, and your contact details.
Safe harbour
If you act in good faith, follow this policy, avoid prohibited activities, report promptly,
and don't exploit a vulnerability beyond what's needed to demonstrate it, we will not pursue
or support legal action against you and will work with you on remediation.
Why SMAIVIZ
Three habits keep a business alive. Most software helps with none of them.
Strip any business down — a workshop, a clinic, a distributor, a software team — and the
same three habits decide whether it thrives: you can see the whole picture, you never drop
the ball, and the thing that worked once happens again reliably. Every business already
does all three. Usually by hand. Usually at the cost of somebody's evening.
See the whole business in one place. Live, not last quarter.
Dashboards in every area
Build the view you need — pick the measure, the grouping and the filter — save it, share it, and pin any one of them as the screen you land on each morning.
The numbers that decide things
Pipeline and forecast, profit & loss, balance sheet, cash flow and multi-currency treasury, stock value, delivery performance and margin — read from the records, not from a monthly submission.
People, projects and marketing too
Headcount, capacity and cost; project health and risk; campaign attribution that reaches the invoice rather than stopping at the click.
One source of truth
Every board reads the same operational data under the same access rules — so two teams cannot arrive at a meeting with two versions of the same number.
The second R — Reminders
Never drop the ball. The system tells the right person — or the right assistant — what needs them now.
Work that chases itself
Due dates, recurring tasks, sales cadences and escalations that run on their own timers instead of depending on who had a quiet afternoon.
Nudges before problems
Period-close reminders, reorder suggestions, expiring batches, calibration due, certificates lapsing — raised while there is still something to do about them.
Joiners, movers and leavers
The workflows that quietly go wrong in every growing company, run as workflows: tasks raised across teams, and a record that each was done.
A human gate on anything sensitive
Approvals sit where money moves and where messages leave the building. Nothing sends unseen, and every step is routed, timed and logged.
The third R — Reproduce
Turn the process that worked once into a routine that runs itself.
A real automation engine
Multi-step workflows with retries, resumption and parallel branches — not a single trigger firing a single action and hoping.
AI assistants on a schedule
Assistants that plan a goal, execute each step with the tools and know-how you gave them, and hand the result back for approval.
Reusable templates
Project blueprints, phase and checklist templates, risk registers and dashboard templates — so the tenth time starts where the ninth ended.
Connectors and an event bus
One thing happening makes the next thing happen, across the whole business, without a nightly sync or a person in the middle.
Why they only work together
SeparatelyA reporting tool shows you a number it was handed. If the handoff was late or wrong, so is the number.
TogetherThe report reads the record that the work created, so it is right by construction and current by default.
SeparatelyA reminder tool nags about a task it can't see the state of.
TogetherThe reminder knows the invoice is unpaid, the stock is short and the job is at risk — because those are the same system.
SeparatelyAn automation tool moves data between products and breaks when one of them changes.
TogetherThere is nothing to move. The modules share the data and react to each other's events.
What actually makes this different
One platform, not a suite of separate products
Finance, sales, stock, warehouse, production, projects, people, service and marketing on one record set. A deal closing moves the order, the stock and the ledger without anyone re-typing it.
AI with a hand on the brake
Assistants take the repetitive half of the work. Anything sensitive or outbound stops for a human, and the safety rules an assistant runs under are set by the server — never by whatever text arrives with a request.
Bring your own AI provider
Use your own key. It is stored encrypted and scoped to your account rather than pooled with anyone else's.
Strict data isolation
Every record belongs to an organisation, and access is checked against membership on every request. Someone outside it doesn't get "denied" — they get "not found", because existence itself shouldn't leak.
An audit trail you didn't configure
Who, when, which record, and what the value was before — kept as a matter of course, for people and assistants alike.
Switch on what you need
Start with one or two areas and grow into the rest. The capabilities most businesses reach for later are already here, switched off.
See it, don't drop it, do it again.
Start free with your own workspace. Bring one week of real work across and judge it on that.
Most companies don't have a software problem. They have a seams problem — a tool for sales,
another for the books, a third for stock, and a person whose real job is carrying
information between them. One action should flow across the whole business on its own. Here
it does, because there is nothing to carry it between.
15-day free trial · No credit card required · Everything below is included
One action, all the way through
No exports, no nightly sync, no integration bill — each step is an event the next step reacts to.
1
A deal is won
Closed in the pipeline by the person who closed it. Nobody emails operations a spreadsheet.
2
The order runs
Captured, priced from the customer's own price book, credit-checked, and allocated against stock that actually exists.
3
Goods move
Picked, packed and shipped. The stock ledger moves once, from a single writer, so quantity and valuation never disagree.
4
Finance posts
The invoice drafts from what actually shipped, at the accounts and tax treatment the item resolves to — not from what someone remembered.
5
Leaders see it
Revenue, margin, receivables and cash update while the day is still happening, and every figure drills to the record behind it.
Full coverage — the back office, the front office and the shop floor
Turn on what you need today; the rest is already here, switched off.
Finance & accounting
Double-entry ledger, receivables and payables, invoicing and bills, payments, tax handling, multi-country treasury, subscriptions and recurring billing, and multi-company consolidation.
Supply chain & inventory
The stock ledger of record, warehouse execution, procurement, order management, product information, and a supplier network with portals and scorecards.
Manufacturing
Work orders and routing, light material planning, bill-of-materials costing with change control, finite-capacity scheduling, shop-floor execution and an effectiveness cockpit.
Quality
Inspection plans, non-conformance and corrective actions, statistical process control, certificates, calibration registers and audits.
Assets & field service
Asset register, preventive and corrective maintenance, tool custody, service tickets, dispatch and response-target tracking.
Sales, CRM & commerce
Accounts and contacts, configurable pipelines, deals and quotes, territories and forecasting, retail point of sale, an online storefront and a customer data platform.
People
Directory and org chart, hiring and onboarding, leave and attendance, payroll and expenses, performance and learning, health & safety and people analytics.
Projects, work & content
Portfolios, projects, tasks and sprints, risks and issues, schedules and specifications, plus files, a knowledge base and forms.
Marketing, analytics & automation
Campaigns across content, social, email and advertising; an executive cockpit and self-service dashboards; workflow automation and threshold alerts.
What holds it together
One record, many views
A customer is one record whether you are quoting them, shipping to them, invoicing them or answering their ticket. So is an item, a person and a job.
An internal event bus
Modules publish what happened and others react. That is why a goods receipt posts to the ledger and a confirmed order reaches the warehouse without an integration.
Analytics on the live data
Dashboards read the operational records directly, under the same access rules and field masking — no second copy of everything, no lag, no numbers that don't match the source.
Open at the edges
An open API, webhooks and connectors, so the systems you are keeping participate instead of being ripped out.
Configurable, not custom
Your chart of accounts, your pipeline stages, your record fields, your numbering and your wording — including renaming modules so the navigation speaks your language.
A migration path, not a big bang
One staged pipeline: field mapping, a dry run with per-row errors, re-runs that update rather than duplicate, and a reconciliation against your old system's control totals as the sign-off gate.
Governed by default
Nothing crosses an organisation boundary
Every row is scoped, and every request is checked against membership. It is enforced in the layer all traffic passes through, not left to a setting someone can misconfigure.
Roles, and finer than roles
Viewer, editor and admin, plus access grants, field-level policies and a permission matrix — with single sign-on, automated provisioning and scheduled access reviews.
AI that acts inside the rules
Assistants work through defined capabilities with policy attached, sensitive and outbound actions pause for a human, and everything they do is logged the way a person's actions are.
Fewer seams. Fewer surprises.
Start free, put one connected flow on it — a deal through to its invoice — and see how much of your day was really just carrying information.
One platform, one bill, priced by the people who use it.
No per-module product to buy, no integration line item, and no separate contract for the
capability you need next quarter. You pay per person, per month — and where you land
depends on what you actually switch on.
15-day free trial · No credit card required · All capabilities available during the trial
What moves you inside that range
A five-column tier table answers "what will this cost us?" with homework. Here is the honest short version.
Which capabilities you switch on
A team running sales and finance sits near the bottom of the range. A business running manufacturing, warehouse execution, quality and multi-company consolidation sits nearer the top.
How much configuration you need
Standard setup is included and self-serve. Deep configuration, bespoke workflows and a guided rollout are where a conversation is worth having.
Your data and AI usage
Storage and AI consumption scale with how hard you use them. You can also bring your own AI provider key, in which case that usage is billed by your provider, not by us.
How many people
Volume matters. If you are rolling out across a larger team, talk to us before you buy — that is exactly the case the range's lower end is designed to reach.
The details worth knowing up front
Monthly costs more than annual
Paying monthly instead runs $20 – $200₹1,500 – ₹15,000 per user / month. Annual billing is the cheaper commitment, and you can start monthly and move.
A minimum of three licences
Every team organisation holds at least three. Below that, the personal workspace is the right home.
Your personal workspace is free for life
With limited access, and no card. Licences apply to team organisations, where the shared data and the governance actually matter.
Seats you can move
A licence is a seat someone holds, not a person you are stuck with. When someone leaves the organisation their seat is released and the next joiner claims it.
Taxes and limits
Local taxes are charged in addition to the prices shown, and limits apply to file storage and other resources.
Notice before a change
Based on total licences and volume, pricing may increase or decrease — with at least 30 days' notice, never a surprise on an invoice.
What's included at every price
The governance, not just the features
Role-based access, field-level policies, approval gates on sensitive and outbound actions, and an audit trail — not an enterprise add-on.
Your data, portable
Scoped to your organisation and exportable. Bring your own AI provider key if you prefer; it stays encrypted and scoped to your account.
A migration you can rehearse
A staged pipeline with a dry run, per-row errors and a reconciliation against your old system's control totals — run it as many times as you need before you commit.
Questions before you buy
Why a range and not a price list?
Because the honest answer depends on what you switch on. Quoting one number would mean
either overcharging a small team or underselling what a larger rollout needs. Tell us
what you run and we will give you the exact figure.
Do we pay more to add a capability later?
You move within the range rather than buying a new product. Nothing has to be
re-implemented and no data has to be migrated — it was already there, switched off.
What happens at the end of the trial?
Nothing is charged automatically without a card. Your data stays yours, and you choose
whether to license the organisation or move to a personal workspace.
Which currency will we be billed in?
The one shown on this page — rupees in India, dollars elsewhere. It is resolved the same
way at checkout, so you are never quoted in one currency and charged in another.
Can we get help with the rollout?
Yes. Volume pricing and guided onboarding are exactly what the sales conversation is
for — sales@smaiviz.com.
Try it before you talk to anyone.
Fifteen days, no card, every capability available. Bring one real week of work across and judge it on that.