1.Who we are
Sentlyx (“Sentlyx”, “we”, “us”) makes software that finds sensitive data in the prompts that employees send to AI apps, such as ChatGPT and Claude. Companies buy Sentlyx to protect their data. Their admins use the Sentlyx console to set policies and to see the results.
This policy applies to our website sentlyx.com, to the Sentlyx console, and to the emails and other contact that we have with you. For questions about this policy, write to contact@sentlyx.com.
2.Our two roles
The law gives us one of two roles, and the role depends on the data.
- Role
- Controller (in India: data fiduciary)
- Data
- Data about visitors to our website, about the admins of our customers as account holders, and about people who contact us. We decide why and how we use this data.
- Document that applies
- This privacy policy
- Role
- Processor (in India: data processor)
- Data
- Data that the Sentlyx service handles for a customer, for example the employees of the customer, their devices and their AI use. The customer decides why and how this data is used.
- Document that applies
- The customer agreement and the data processing agreement (DPA) with that customer
| Role | Data | Document that applies |
|---|---|---|
| Controller (in India: data fiduciary) | Data about visitors to our website, about the admins of our customers as account holders, and about people who contact us. We decide why and how we use this data. | This privacy policy |
| Processor (in India: data processor) | Data that the Sentlyx service handles for a customer, for example the employees of the customer, their devices and their AI use. The customer decides why and how this data is used. | The customer agreement and the data processing agreement (DPA) with that customer |
Clause 3 explains the processor role in short. All other clauses are about the controller role.
3.Data in the Sentlyx service
A customer installs the Sentlyx agent on the computers of its employees. The agent checks what an employee sends to an AI app or an AI website. Depending on the settings of the customer, the service handles this data (“customer data”):
- The name, email address and group of each employee, from the directory of the customer.
- Facts about each device, for example the device name, the hardware identifier and the agent version.
- The AI apps and AI websites that an employee uses, and the time of use.
- The result of each check: the app, the type of sensitive data found, the action (allow, warn, redact or block), a masked sample of the prompt and the reason that the employee typed after a warning.
- The full text of a prompt, only if the customer turns on full-prompt capture. The device encrypts the prompt with a key of the customer before it sends it.
- The audit log of the actions of the admins of the customer.
By default, raw values never leave the laptop. The agent finds sensitive values on the device and replaces them with placeholders before it sends the masked text to the service.
We use customer data only to give the service to the customer, as the customer agreement and the DPA say. We do not sell customer data. We do not use customer data to train models for other customers. The agent does not read the clipboard.
If you are an employee of a Sentlyx customer: your employer controls this data and decides how it is used. Your employer must tell you about the monitoring. To ask about your data or to use your rights, contact your employer. If you contact us, we send your request to your employer.
4.Data that we collect
When you visit our website
Our servers record the IP address, the browser type, the page that you ask for and the time, as all web servers do. Our website has no analytics tools, no advertising tools and no tracking cookies. We host our fonts ourselves, so your browser does not contact a font service.
When you contact us
If you send us an email, we get your name, your email address, your company and what you write to us.
If you use the demo request form, we get your name, your work email address, your company, the number of employees and your message. The form sends these details to our inbox as an email and does not store them anywhere else. To stop spam, the form also sends the time that you took to fill it in, and we count the requests from each IP address. We store a hash of the IP address, not the IP address, and the count expires after 2 hours.
When you sign up or use the console
- Account data: your work email address, your name, your company name, the email domain of your company and your admin roles.
- Sign-in data: the secret of your authenticator app (encrypted), your recovery codes (stored as hashes), the sign-in links that we email to you, and your sessions. If your company uses single sign-on (SSO), we get your name, your email address and your groups from the identity provider of your company.
- Security data: for each sign-in and each session, the IP address, the approximate country and the browser. We use these facts to protect your account, for example to email you after a sign-in from a new browser.
- Region lookup: when you sign in, the console sends the domain of your email address to our login router, to find the region that holds your account. To stop abuse, the router counts the lookups from each IP address. It stores a hash of the IP address, not the IP address.
- Billing data: if you buy Sentlyx, the billing contact, the billing address, the tax number and the payment records. A payment provider handles card details. We do not store full card numbers.
5.How we use the data
We use the data from clause 4 for these purposes only:
- Purpose
- Create and run your account, and give the service
- Data
- Account data, sign-in data, region lookup
- Legal basis (EEA and UK)
- Contract
- Purpose
- Protect accounts and the service, and find and stop abuse
- Data
- Sign-in data, security data, server logs
- Legal basis (EEA and UK)
- Legitimate interests (security)
- Purpose
- Send service emails, such as sign-in links, security alerts and notices about the service
- Data
- Account data
- Legal basis (EEA and UK)
- Contract; legitimate interests
- Purpose
- Answer your questions and requests
- Data
- Contact data
- Legal basis (EEA and UK)
- Legitimate interests; contract
- Purpose
- Bill customers and keep business records
- Data
- Billing data, account data
- Legal basis (EEA and UK)
- Contract; legal obligation
- Purpose
- Obey the law, and set up, use or defend legal claims
- Data
- Any data that the matter needs
- Legal basis (EEA and UK)
- Legal obligation; legitimate interests
| Purpose | Data | Legal basis (EEA and UK) |
|---|---|---|
| Create and run your account, and give the service | Account data, sign-in data, region lookup | Contract |
| Protect accounts and the service, and find and stop abuse | Sign-in data, security data, server logs | Legitimate interests (security) |
| Send service emails, such as sign-in links, security alerts and notices about the service | Account data | Contract; legitimate interests |
| Answer your questions and requests | Contact data | Legitimate interests; contract |
| Bill customers and keep business records | Billing data, account data | Contract; legal obligation |
| Obey the law, and set up, use or defend legal claims | Any data that the matter needs | Legal obligation; legitimate interests |
We do not sell your personal data. We do not use it for advertising. We do not make decisions about you with legal or similar effects by automated means alone. Clause 12 gives the basis under the law of India.
8.Where we store data
Each customer selects one home region when it signs up. The account and the customer data of that customer stay in that region. Today, the only region is India: the data is in the AWS Mumbai region (ap-south-1), and the backups are in the AWS Hyderabad region (ap-south-2). We will add regions in Europe and the Americas.
Some data leaves the home region. The login router keeps the email domain and the region of each customer, so that it can send you to the correct region. Our own email is in Google Workspace, which can store data in other countries.
If you are outside India, your data goes to India when you use our website or console. Clause 13 explains how we protect data that we send out of the EEA or the UK.
9.How long we keep data
We keep personal data only for as long as we need it for the purposes in clause 5:
- Data
- Server logs of the website and the console
- How long
- Up to 30 days
- Data
- Sign-in links
- How long
- Deleted 1 day after we send them
- Data
- Sessions
- How long
- A session ends after 30 minutes with no activity or after 12 hours (your company can change these times). We delete it soon after it ends.
- Data
- The hashed IP counters of the login router
- How long
- They expire after 20 minutes, and the database then deletes them
- Data
- The hashed IP counters of the demo request form
- How long
- They expire after 2 hours, and the database then deletes them
- Data
- Account data and security data
- How long
- As long as the account exists. After the account closes, we delete the data or make it anonymous, except data that we must keep by law.
- Data
- Emails with you, and demo requests
- How long
- As long as we need them to answer you and to keep a record of our business
- Data
- Billing data
- How long
- As long as tax and accounting laws make us keep it
| Data | How long |
|---|---|
| Server logs of the website and the console | Up to 30 days |
| Sign-in links | Deleted 1 day after we send them |
| Sessions | A session ends after 30 minutes with no activity or after 12 hours (your company can change these times). We delete it soon after it ends. |
| The hashed IP counters of the login router | They expire after 20 minutes, and the database then deletes them |
| The hashed IP counters of the demo request form | They expire after 2 hours, and the database then deletes them |
| Account data and security data | As long as the account exists. After the account closes, we delete the data or make it anonymous, except data that we must keep by law. |
| Emails with you, and demo requests | As long as we need them to answer you and to keep a record of our business |
| Billing data | As long as tax and accounting laws make us keep it |
The customer sets the retention of customer data, for example 30 days for prompt text and 1 year for events. When the customer agreement ends, we delete the customer data as the DPA says.
10.Security
We protect personal data with technical and organizational measures. These include:
- Encryption of all data in transit (TLS) and at rest, with keys in a key management service.
- Separate data for each customer in the database, enforced by the database.
- A second factor for each admin sign-in (an authenticator app or single sign-on), timeouts for sessions, and an email after a sign-in from a new browser.
- Mutual TLS with a certificate for each device between the agent and the service.
- An audit log of each admin action, that admins cannot change.
- Access for our staff only when the work needs it.
No system is fully secure. If a breach of personal data occurs, we tell the affected customers, the authorities and the affected people, as the law tells us to.
11.Your rights
Depending on where you live, you can have these rights about your personal data:
- Get a copy of your data, and information about how we use it.
- Correct data that is wrong or not complete.
- Delete your data.
- Object to some uses of your data, or limit them.
- Get your data in a format that a machine can read, and move it to another company.
- Withdraw your consent at any time, when we use your data with your consent.
- Make a complaint to us and to the data protection authority.
To use a right, write to contact@sentlyx.com. We can ask you to prove who you are before we act. We answer within the time that the law gives, and we do not charge for a normal request. If your request is about customer data, we send it to the customer (clause 3).
12.India
This clause applies under the Digital Personal Data Protection Act, 2023 and its rules, and under the Information Technology Act, 2000 and its rules.
- Our role: for the data in clause 4, we are the data fiduciary. For customer data, we are a data processor for the customer, and the customer is the data fiduciary.
- Basis: we use your data with your consent, or for a legitimate use that the Act permits, for example when you give us your data for a purpose and do not object to its use for that purpose, or to obey the law.
- Your rights: you can ask for a summary of your data and of how we use it, and for the names of the parties that we share it with. You can ask us to correct, complete, update or erase your data. You can withdraw your consent, as easily as you gave it. You can nominate another person to use your rights if you die or cannot act.
- Grievance Officer: to make a complaint, write to our Grievance Officer at contact@sentlyx.com. We answer within 30 days.
- The Data Protection Board of India: if we do not resolve your complaint, you can complain to the Data Protection Board of India.
13.EEA and UK
This clause applies if you are in the European Economic Area (EEA) or the United Kingdom, under the General Data Protection Regulation (GDPR) and the UK GDPR.
- Legal basis: clause 5 gives the legal basis for each purpose. When the basis is our legitimate interests, you can object, and we stop unless we have strong reasons to continue.
- Your rights: you have the rights in clause 11: access, correction, erasure, restriction, portability and objection, and the right to withdraw consent.
- Transfers: when we send personal data out of the EEA or the UK, for example to India, we use the Standard Contractual Clauses of the European Commission and the UK addendum to them, or another safeguard that the law permits. To get a copy, write to contact@sentlyx.com.
- Complaints: you can complain to the data protection authority of the country where you live or work, or where you think that a breach occurred. In the UK, this is the Information Commissioner’s Office (ICO). Please contact us first, so that we can try to help.
14.United States
This clause applies to residents of US states with consumer privacy laws, for example the California Consumer Privacy Act as amended by the California Privacy Rights Act.
- What we collect: in the last 12 months, we collected these categories of personal information: identifiers (name, email address, IP address), internet activity (server logs, sign-in and session records), professional information (company and role) and commercial information (billing records). Clause 4 gives the sources and clause 5 gives the purposes.
- No sale or sharing: we do not sell personal information, and we do not share it for cross-context behavioral advertising. We did not do this in the last 12 months. We use sensitive personal information, such as account sign-in data, only to give the service and to protect it.
- Your rights: you can ask to know what personal information we collect, use and disclose, and ask us to delete or correct it. An authorized agent can make a request for you. We check your identity before we act. We do not treat you differently because you use a right.
- How to ask: write to contact@sentlyx.com.
15.Children
Sentlyx is a service for companies. It is not for children, and we do not knowingly collect personal data from people under 18. If you think that a child gave us personal data, write to us, and we delete it.
16.Changes to this policy
We can change this policy. The date at the top shows the last change. If a change is important, we tell the admins of our customers by email or in the console before the change starts.
17.Contact us
For all questions and requests about privacy, write to contact@sentlyx.com.