Privacy Policy
Version 1.1 · Last updated: 10 August 2026 · Terms of Service · Data Processing Agreement · Sub-processors
Who we are
BRIGHTOPS SMART SOLUTIONS SOCIEDAD LIMITADA, trading as Sentilai — CIF B22733836, registered office Calle de les Eres 7, 46726 Almiserà (Valencia), Spain; Registro Mercantil de Valencia, Section 8, Folio V-227228. For anything related to your personal data, contact [email protected].
What this policy covers — and what it doesn't
This policy covers the data for which Sentilai is the controller: this website and its waitlist, account signup, the accounts of tenant admins and developers, support tickets, and billing contacts.
It does not cover your organisation's workload data inside the Sentilai platform — AI request audit records, optional prompt captures, device inventory, MCP inventory. For that data your organisation is the controller and Sentilai is a processor, acting under our Data Processing Agreement. If you are a developer whose employer uses Sentilai, your employer decides what is governed and captured; direct your questions to them first — the DPA describes what we do on their behalf.
What we collect, why, and for how long
Waitlist
If you join the waitlist we store the email address you submit and the time you submitted it — no name, no IP address, no browser fingerprint. Legal basis: your consent (GDPR Art. 6(1)(a)). Kept until we've sent the launch notification and you've had a reasonable chance to act on it, or until you ask us to delete it, whichever comes first.
Account signup
When you start a signup we store the company name, your name, your email address, and — for abuse prevention — the network address the request came from. Nothing else is created until you confirm the address by clicking the link we email you. Legal bases: steps prior to entering a contract (Art. 6(1)(b)) and our legitimate interest in preventing abuse of an open signup form (Art. 6(1)(f)). Unconfirmed signup records are deleted shortly after their two-hour confirmation window lapses; confirmed records are kept for 30 days as the record of how the account came to exist, then deleted.
Accounts
For each tenant admin and developer we store name, email address, organisation membership, and passkey credential references (the public half of a passkey — never biometric data, which stays on your device). Legal basis: performance of the contract (Art. 6(1)(b)). Kept for the life of the customer relationship; when a tenant is offboarded, its account data is deleted within 30 days.
Support tickets
Tickets contain what you write in them, including replies sent by email and attachments. Legal basis: performance of the contract. Closed tickets and their whole history are deleted 24 months after closure; a terminated tenant's tickets are deleted with the tenant.
Billing
Subscriptions are sold by Paddle as Merchant of Record. Paddle is an independent controller for payment data — Sentilai never receives your card details. We hold the billing contact and subscription state. See Paddle's privacy policy.
Security and staff audit
We keep append-only logs of what our own staff access, including a mandatory reason when raw customer content is viewed. Legal basis: legitimate interest in operating the service securely and being able to demonstrate it (Art. 6(1)(f)).
What we deliberately don't do
- No analytics, no tracking, no advertising pixels — on this website or in the product.
- No cookies on this website. After you join the waitlist, your browser's local storage remembers that you signed up; that value never leaves your device. The product's console uses strictly necessary session state only.
- No sale of personal data, no advertising use. Ever.
Who receives your data
The service providers below process controller-scope data on our behalf. The full platform-level list, including what each one sees, is on the sub-processors page.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | All hosting and storage | Germany / Finland (EU) |
| Cloudflare, Inc. | DNS, DDoS protection, reverse proxy (TLS termination) for all public endpoints | Global edge; US company |
| Resend, Inc. (on AWS eu-west-1) | Transactional email and inbound support-ticket email | EU infrastructure; US company |
| Google (Workspace) | Our corporate mailboxes — support correspondence you send to us by email lands there | EU data regions; US company |
| Paddle.com Market Ltd | Merchant of Record — independent controller for payment data | UK / EU |
International transfers
Processing happens in the EU. Some providers above are US companies (Cloudflare, Resend, Google); where their processing involves a transfer outside the EU/EEA, it is covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses, per each vendor's current published mechanism.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your data, restriction of or objection to processing, data portability, and — where processing rests on consent — withdraw that consent at any time. Write to [email protected]; we respond within one month. You can also lodge a complaint with a supervisory authority — ours is the Spanish Agencia Española de Protección de Datos (AEPD, aepd.es), but you may use the authority of your own country.
Changes
When this policy changes materially we update the date above and, for account holders, give notice by email or in the product before the change takes effect.
© 2026 Sentilai · Terms · Refunds · DPA · Sub-processors · [email protected]