This Privacy Policy explains how Sento processes Personal Data for purposes Sento determines itself, including its website, account administration, billing, sales, support, security, marketing and product operations. It also explains how Sento distinguishes those activities from Customer Personal Data processed only on Customer instructions.
1. Controller / business
Controller / business: [CONTRACTING_ENTITY_NAME]
Entity type: [ENTITY_TYPE]
Jurisdiction of organization: [JURISDICTION_OF_ORGANIZATION]
Registration number: [REGISTRATION_NUMBER]
Tax number, if applicable: [TAX_NUMBER_IF_APPLICABLE]
Registered address: [REGISTERED_ADDRESS]
Privacy/legal contact: [LEGAL_EMAIL]
EU/EEA representative, if Article 27 GDPR requires one: [EU_REPRESENTATIVE_IF_REQUIRED]
UK representative, if Article 27 UK GDPR requires one: [UK_REPRESENTATIVE_IF_REQUIRED]
When Sento processes Customer Personal Data solely on Customer's documented instructions to provide the Service, Customer is the controller/business or upstream processor and Sento acts as processor/service provider or the closest equivalent role. That processing is governed by the Sento International Data Processing Agreement (DPA), not by an independent Sento purpose merely because Sento has technical access to the data.
2. Personal Data categories and sources
Sento may process the following categories for its own purposes:
| Category | Examples | Typical source |
|---|---|---|
| Account and business identity | name, business email, organization, role, account/workspace identifiers | individual, Customer administrator |
| Sales and relationship data | inquiry/demo/connection context, business contact details, meeting or relationship notes | individual, business contact, public/business source where lawful |
| Support and communications | support request, feedback, service correspondence | individual or Customer representative |
| Billing and transaction data | plan, invoice, tax/business information, payment status and provider transaction reference | Customer, payment/billing provider |
| Technical and security data | IP address, device/browser information, authentication/security events, API/service logs, abuse/fraud indicators | Service/browser/infrastructure |
| Product usage data | feature events, capacity/credit usage, performance and reliability measurements | Service/application |
| Website/storage data | cookies, local/session storage and similar identifiers | browser/device, as described in the Cookie Notice |
| Marketing preference data | channel, consent/objection/opt-out status and related compliance record | individual or outreach process |
Customer Personal Data may include messages, documents, CRM records, contact data and other Customer Content supplied under Customer instructions. Sento does not independently define the Customer's purpose for that data.
3. Purposes and legal bases
Sento may process its own-controller/business data to:
- create and administer accounts and provide requested Service access;
- respond to support, demonstration, sales and connection requests;
- bill Customers, administer subscriptions and satisfy accounting/tax/legal obligations;
- authenticate users, protect Sento, prevent fraud/abuse and investigate security events;
- measure reliability, capacity, product usage and website performance;
- improve product functionality using Usage Data and lawfully collected feedback, without treating Customer Content as generalized AI training data;
- send permitted B2B marketing and maintain opt-out/suppression records;
- establish, exercise or defend legal claims and comply with binding legal obligations; and
- manage vendors, corporate transactions and business operations.
Where GDPR/UK GDPR applies, the legal basis depends on the activity and may include performance of or steps toward a contract, compliance with a legal obligation, Sento's or a third party's legitimate interests balanced against individual rights, and consent where consent is required. Sento does not use consent where another basis is required by law, and withdrawal of consent does not affect processing lawfully carried out before withdrawal.
In other jurisdictions, Sento relies on the consent, contractual/business-purpose, legitimate-purpose or other legal ground permitted by the applicable law.
4. Analytics and website measurement
For the international website, Google Analytics 4 may be used when configured. Non-essential analytics is subject to the rules described in the Cookie Notice.
In the EEA, United Kingdom and other jurisdictions requiring prior consent for non-essential terminal-device storage/access, non-essential analytics is not activated until valid consent is recorded. In other jurisdictions, Sento applies the notice, choice, opt-out or other legal basis required by local law.
Advertising signals, cross-context behavioral advertising and marketing pixels are disabled by default in the international baseline unless separately disclosed and lawfully enabled.
Sento does not intentionally include Customer Content, live-chat message text, prompts, AI responses, passwords, full payment-card data or free-form user-entered text in website analytics events. Where behavior-recording technology is enabled, fields/areas that may contain such information must be excluded from capture or masked as appropriate.
5. AI and data use
Sento may use AI to provide enabled functions such as knowledge retrieval, classification, routing, summarization, response generation and Customer-configured actions.
Customer Content, Input and Output are not generalized model training data by default. Customer-specific indexing, embeddings, retrieval, inference and separately agreed Customer-specific adaptation are service processing and do not become generalized training merely because AI technology is involved.
A generalized-training program using Customer data requires a separate express authorization and all independently required legal bases, notices, rights, confidentiality and transfer/provider safeguards.
The Sento AI and Data Use Notice provides additional information.
6. Recipients and service providers
Sento may provide Personal Data, only as necessary for the relevant purpose, to categories such as:
- hosting, database, object-storage and backup providers;
- AI inference/model/embedding providers used for enabled functions;
- communications, authentication and support providers;
- monitoring, security and analytics providers;
- payment, banking, accounting and tax providers;
- professional advisers, auditors, insurers and legal counsel;
- public authorities, regulators and courts where legally required; and
- a successor or transaction counterparty in a financing, merger, acquisition, restructuring or asset sale, subject to appropriate safeguards.
Some recipients act as Sento processors/service providers; others may be independent controllers for their own regulated purposes. Customer Personal Data Subprocessors and applicable categories are described in the Subprocessors and Third-Party Recipients document.
7. International transfers
Where Personal Data is subject to a restricted international transfer, Sento uses the mechanism required by the applicable law and actual transfer facts.
This may include adequacy or comparable recognition, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum to the EU SCCs, ANPD transfer mechanisms for Brazil, or another lawful safeguard applicable to the relevant jurisdiction.
The International Data Transfer Addendum explains the framework. Actual provider identities, processing locations and transfer routes are maintained in the current Subprocessor/deployment records where disclosure is required.
8. Retention
Sento keeps Personal Data only for as long as reasonably necessary for the disclosed purpose, a binding legal/recordkeeping requirement, security/abuse prevention, dispute/claim protection or another lawful basis.
Typical retention logic is:
| Category | Retention logic |
|---|---|
| Account/service data | while the account/relationship is active, plus a limited closure/dispute/legal period where needed |
| Sales/support/business correspondence | while needed to handle the request/relationship and any reasonable follow-up, claim or recordkeeping requirement |
| Billing/tax/accounting records | for the period required by applicable accounting/tax law |
| Technical/security logs | while reasonably necessary for reliability, security, abuse prevention, investigation and legal requirements |
| Website analytics | according to the configured analytics retention and applicable consent/choice rules |
| Marketing preferences | until opt-out/withdrawal and thereafter only as needed for suppression/compliance evidence |
| Customer Personal Data | according to Customer instructions and the DPA, including protected backup overwrite/deletion |
When a purpose and all lawful retention grounds end, Sento deletes or irreversibly anonymizes the Personal Data. Data that is truly anonymous and no longer relates to an identifiable person may be retained for product, security and statistical purposes.
9. Security
Sento applies legal, organizational and technical safeguards appropriate to the processing risk. The public Security and Trust document describes the baseline without claiming an unverified certification, encryption algorithm, audit status or recovery metric.
10. Individual privacy rights
Rights depend on the law applicable to the person and processing. The Sento Regional Privacy Rights Notice describes rights and request procedures for the EU/EEA, UK, applicable US states including California, Canada, Brazil, Australia, New Zealand and Singapore.
Requests may be sent to [LEGAL_EMAIL]. Sento uses proportionate verification and responds within the period required by the applicable law.
If a request concerns Customer Personal Data for which Sento acts only as processor/service provider, Sento may direct the request to the relevant Customer and assist Customer under the DPA.
11. US state privacy disclosures
Where an applicable US state privacy law covers Sento's processing, Sento provides the rights and disclosures required by that law.
Sento does not intentionally sell Personal Data for monetary consideration and does not use Customer Content for targeted advertising. If a particular website/advertising technology is legally classified as sale, sharing or targeted advertising under an applicable state law, Sento treats the processing accordingly and honors the legally required opt-out mechanism and qualifying opt-out preference signals where applicable.
The categories of Personal Data, source categories, business/commercial purposes and recipient categories are described in Sections 2, 3 and 6. Sento does not unlawfully discriminate against a person for exercising an applicable privacy right.
12. Marketing communications
Marketing communications are governed by the Sento International Marketing Communications Notice. Service/support/demo/contract communications are distinguished from marketing. Contacting Sento for support, a demonstration or contracting does not by itself create marketing consent where applicable law requires separate consent.
13. Cookies and similar technologies
The Sento International Cookie and Similar Technologies Notice describes the categories of technologies, international analytics baseline and regional consent/choice rules.
Strictly necessary technologies may operate without a separate opt-in where applicable law permits. Non-essential analytics, functional or marketing technologies are subject to the consent/choice required in the relevant region.
14. Restricted data, children and high-impact uses
Sento is a B2B service and is not directed to children. The ordinary Service is not intended to be configured to collect children's data, government/KYC identity-document datasets, biometric/genetic data, regulated health records or other data categories prohibited by the Supported and Restricted Data Schedule.
The ordinary Service is also not intended to make high-impact eligibility decisions in credit, employment, housing, healthcare, insurance, education admission, law enforcement or comparable contexts.
If Sento learns that a prohibited configuration has been intentionally enabled, it may require the processing to stop and may suspend the affected workflow while the issue is addressed.
15. Data breaches and regulatory cooperation
Sento manages Personal Data breaches under the notification, investigation and cooperation rules applicable to its role and the relevant jurisdiction. When Sento acts as processor for Customer Personal Data, the DPA governs Sento's notice and assistance to Customer.
16. Changes
Sento may update this Policy when law, product or processing changes. A new policy version does not retroactively create a legal basis for processing that required a separate consent or other basis at the time it occurred.
Material changes are communicated in the manner required by applicable law.
17. Contact and complaints
Privacy questions and rights requests may be sent to [LEGAL_EMAIL]. Where applicable law gives a right to complain to a regulator, the relevant authority is identified in the Regional Privacy Rights Notice or by the law applicable to the individual.