This Schedule defines the data and use cases supported by the ordinary Sento Service. It applies to intentional Customer configuration. Incidental unsolicited information typed by an end user into a free-form conversation does not automatically create a Customer breach, but Sento and Customer may need to minimize, restrict or delete it.
1. Supported in the ordinary Service
| Data / use case | Status | Baseline requirements |
|---|---|---|
| Ordinary business contact and account data | Supported | Agreement, Privacy/DPA baseline, least privilege |
| Customer-support and business conversation content | Supported | Customer lawful basis/notices; DPA |
| CRM, order, subscription and service-status data | Supported | Data minimization; access controls |
| Customer documents and knowledge-base content | Supported | Customer rights to provide/use content; DPA |
| Non-sensitive transaction status/metadata without full payment credentials | Supported | Minimize fields; use dedicated payment provider for payment credentials |
| Technical, security and ordinary product-usage data | Supported | Purpose limitation; security/retention controls |
2. Prohibited in the ordinary Service
Customer must not intentionally configure the ordinary Sento Service to collect or process:
- passports, national identity documents, government identifiers or KYC identity-document datasets;
- biometric or genetic data;
- medical records, diagnosis/treatment information or other health data intended for regulated healthcare processing;
- children's or minors' Personal Data as a targeted Sento use case;
- special-category/sensitive Personal Data whose intentional processing requires a specialized legal/security regime not expressly supported by Sento;
- full payment-card credentials, CVV or similar authentication data;
- end-user passwords, private keys, seed phrases or other authentication secrets as Customer Content;
- stolen credentials, malware or exploit payloads except in a separately authorized defensive-security environment; or
- unlawful content/workflows.
3. High-impact automated decisions
The ordinary Sento Service must not be configured as the sole or determinative system for decisions about credit, employment, housing, insurance, healthcare eligibility/treatment, education admission, law enforcement, access to essential services or another legally significant/high-impact eligibility decision.
Sento's ordinary AI support replies, summarization, classification and routing are intended for customer-relations workflows, not for high-impact eligibility decisions.
4. Incidental restricted content
If an end user unexpectedly includes restricted information in a free-form message that Customer did not configure Sento to solicit, Sento and Customer will apply reasonable measures appropriate to the data and applicable law, which may include minimization, access restriction, deletion and incident/compliance review.
Repeated or intentional collection of prohibited data may result in suspension of the affected workflow until the configuration is corrected.
5. Future support
A prohibited category is not converted into a supported category merely by Customer request or consent. If Sento later develops a separately documented product configuration for a regulated category, Sento must update this Schedule and implement the necessary legal, security and product controls before enabling that use.