← sentilai.com

Privacy Policy

Version 1.1 · Last updated: 10 August 2026 · Terms of Service · Data Processing Agreement · Sub-processors

Who we are

BRIGHTOPS SMART SOLUTIONS SOCIEDAD LIMITADA, trading as Sentilai — CIF B22733836, registered office Calle de les Eres 7, 46726 Almiserà (Valencia), Spain; Registro Mercantil de Valencia, Section 8, Folio V-227228. For anything related to your personal data, contact [email protected].

What this policy covers — and what it doesn't

This policy covers the data for which Sentilai is the controller: this website and its waitlist, account signup, the accounts of tenant admins and developers, support tickets, and billing contacts.

It does not cover your organisation's workload data inside the Sentilai platform — AI request audit records, optional prompt captures, device inventory, MCP inventory. For that data your organisation is the controller and Sentilai is a processor, acting under our Data Processing Agreement. If you are a developer whose employer uses Sentilai, your employer decides what is governed and captured; direct your questions to them first — the DPA describes what we do on their behalf.

What we collect, why, and for how long

Waitlist

If you join the waitlist we store the email address you submit and the time you submitted it — no name, no IP address, no browser fingerprint. Legal basis: your consent (GDPR Art. 6(1)(a)). Kept until we've sent the launch notification and you've had a reasonable chance to act on it, or until you ask us to delete it, whichever comes first.

Account signup

When you start a signup we store the company name, your name, your email address, and — for abuse prevention — the network address the request came from. Nothing else is created until you confirm the address by clicking the link we email you. Legal bases: steps prior to entering a contract (Art. 6(1)(b)) and our legitimate interest in preventing abuse of an open signup form (Art. 6(1)(f)). Unconfirmed signup records are deleted shortly after their two-hour confirmation window lapses; confirmed records are kept for 30 days as the record of how the account came to exist, then deleted.

Accounts

For each tenant admin and developer we store name, email address, organisation membership, and passkey credential references (the public half of a passkey — never biometric data, which stays on your device). Legal basis: performance of the contract (Art. 6(1)(b)). Kept for the life of the customer relationship; when a tenant is offboarded, its account data is deleted within 30 days.

Support tickets

Tickets contain what you write in them, including replies sent by email and attachments. Legal basis: performance of the contract. Closed tickets and their whole history are deleted 24 months after closure; a terminated tenant's tickets are deleted with the tenant.

Billing

Subscriptions are sold by Paddle as Merchant of Record. Paddle is an independent controller for payment data — Sentilai never receives your card details. We hold the billing contact and subscription state. See Paddle's privacy policy.

Security and staff audit

We keep append-only logs of what our own staff access, including a mandatory reason when raw customer content is viewed. Legal basis: legitimate interest in operating the service securely and being able to demonstrate it (Art. 6(1)(f)).

What we deliberately don't do

Who receives your data

The service providers below process controller-scope data on our behalf. The full platform-level list, including what each one sees, is on the sub-processors page.

ProviderPurposeLocation
Hetzner Online GmbHAll hosting and storageGermany / Finland (EU)
Cloudflare, Inc.DNS, DDoS protection, reverse proxy (TLS termination) for all public endpointsGlobal edge; US company
Resend, Inc. (on AWS eu-west-1)Transactional email and inbound support-ticket emailEU infrastructure; US company
Google (Workspace)Our corporate mailboxes — support correspondence you send to us by email lands thereEU data regions; US company
Paddle.com Market LtdMerchant of Record — independent controller for payment dataUK / EU

International transfers

Processing happens in the EU. Some providers above are US companies (Cloudflare, Resend, Google); where their processing involves a transfer outside the EU/EEA, it is covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses, per each vendor's current published mechanism.

Your rights

Under the GDPR you can request access to, correction of, or deletion of your data, restriction of or objection to processing, data portability, and — where processing rests on consent — withdraw that consent at any time. Write to [email protected]; we respond within one month. You can also lodge a complaint with a supervisory authority — ours is the Spanish Agencia Española de Protección de Datos (AEPD, aepd.es), but you may use the authority of your own country.

Changes

When this policy changes materially we update the date above and, for account holders, give notice by email or in the product before the change takes effect.

© 2026 Sentilai · Terms · Refunds · DPA · Sub-processors · [email protected]