Privacy policy.
Last updated: 2026-07-12
1. Who We Are
Senty ('we', 'us', 'our') provides an AI-powered email response platform for business-to-business (B2B) clients. Under the General Data Protection Regulation (GDPR), Senty acts as a data processor on behalf of its clients. Each client company is the data controller responsible for the personal data of their own customers and end-users. Clients must ensure their own privacy notices disclose the use of Senty and AI-assisted email processing.
2. Data We Process
On behalf of our clients, Senty processes the following categories of personal data:
- Email content: sender address, recipient addresses, subject line, message body, and any attachments or HTML content present in emails handled through connected Gmail inboxes.
- Platform user data: name, business email address, phone number (optional), role, and hashed password for Senty platform users (company staff).
- Usage data: token usage per AI draft generation event, associated with company and (anonymised after deletion) platform user identifiers.
- OAuth credentials: Gmail OAuth tokens for connected inboxes, stored encrypted in Senty's database.
3. AI Processing
To generate AI draft email responses, Senty sends email content (sender address, recipient addresses, subject line, and message body) to one or more AI sub-processors, including a primary EU-region cloud AI service and, only as an automatic fallback if the primary service is unavailable, one or more additional AI infrastructure providers. This constitutes a transfer of personal data to a sub-processor. Clients must ensure their own privacy notices inform end-users that email content may be processed by AI systems. The specific named sub-processors, the regions they process data in, and their DPA status are listed in Senty's signed Data Processing Agreement, and are also available to authenticated client administrators via GET /api/legal/sub-processors.
4. Data Security
Senty applies the following technical security measures:
- Encryption at rest (infrastructure layer): the production database runs on infrastructure with full-disk encryption at rest, covering all stored data including email message bodies and AI draft responses.
- Encryption at rest (application layer): Gmail OAuth tokens are additionally encrypted using AES-128-CBC (Fernet) before storage, on top of infrastructure-level disk encryption.
- Password hashing: platform user passwords are hashed with Argon2id (memory-hard, OWASP-recommended settings).
- Encryption in transit: all data is transmitted over HTTPS/TLS.
- Access control: role-based access (USER / ADMIN / SUPERADMIN) with short-lived JWT authentication tokens (30-minute expiry by default).
- Multi-tenancy isolation: all data is scoped to company identifiers; cross-tenant access is prevented at the database query level.
- PII filtering in logs: log output is filtered to redact email addresses before writing to any log stream.
5. Data Retention
Senty retains email thread data in accordance with the following policy:
- Active email threads are retained while the client account is active.
- When a thread is deleted by a platform user, it is soft-deleted (flagged as deleted) and permanently purged after the data retention period (default: 365 days from deletion).
- Token usage records (anonymised after user deletion) are retained for billing and audit purposes.
- Clients may request immediate erasure of their company's data by contacting their Senty account administrator, who can trigger a full data purge.
6. Your Rights (GDPR)
As a data processor, Senty supports clients in fulfilling their obligations to data subjects under GDPR, including:
- Right of access (Art. 15): Senty provides a data export endpoint (GET /api/companies/{id}/data-export) that clients can use to retrieve all stored personal data for their company.
- Right to erasure (Art. 17): Senty provides a data purge endpoint (DELETE /api/companies/{id}/purge) that permanently deletes all company data.
- Right to data portability (Art. 20): exported data is provided in machine-readable JSON format.
- Right to object to AI processing (Art. 21): AI draft generation can be disabled at the company level; email storage continues independently. End-users wishing to exercise their rights should contact the company (data controller) whose email inbox Senty is connected to.
7. Sub-processors
Senty uses sub-processors across the following categories: cloud infrastructure and hosting, Gmail API access and email notifications, AI draft generation (a primary EU-region provider plus automatic fallback providers if the primary is unavailable), and voice transcription of spoken revision instructions (audio and resulting transcript text only). The specific named sub-processors, the regions they operate in, and their Data Processing Agreement status are provided in Senty's signed DPA with each client, and are available in full to authenticated client administrators at GET /api/legal/sub-processors. Clients are notified of sub-processor changes with reasonable advance notice.
8. Contact
For questions about this policy or to exercise data subject rights, contact the company (data controller) whose Senty account is involved, or reach Senty's data protection contact via your client agreement.