Terms of Service →
Your rights and obligations as a Sentsai customer, including payment terms, limitations of liability, and acceptable use. Governed by Ontario, Canada law. Acceptance is version-stamped - if the terms change materially, you will be prompted to re-accept before running further scans or initiating payments.
Privacy Policy →GDPR · PIPEDA · CCPA
What personal data we collect (account data, Microsoft 365 tenant data processed on your behalf, usage logs, payment confirmations), why and on what legal basis, how long we retain it, when and how it is deleted, and how to exercise your rights. Covers our dual role as both data controller (for your account data) and data processor (for your Microsoft 365 employee data).
Data Processing Agreement →GDPR Art. 28
Required by GDPR Article 28 and incorporated by reference into the Terms of Service - no separate signature needed. Defines Sentsai as data processor and your organization as data controller for Microsoft 365 tenant data. Covers sub-processor disclosures, technical and organizational measures, breach notification obligations (72-hour window), data subject assistance obligations, and deletion/return commitments.
Cookie Policy →
Details of the strictly necessary cookies Sentsai sets. We use three cookies: an opaque session identifier (sentsai_session_id, 8-hour TTL backed by a server-side Redis store), a tenant reference (sentsai_tenant_id, 30-day TTL), and a short-lived CSRF token (oauth_state, 10 minutes, set only during the OAuth login flow). All are HttpOnly, Secure, and SameSite=Lax. No tracking cookies. No advertising cookies. No third-party cookies.
Security & Trust →Technical
Audit-ready technical detail: OAuth 2.0 read-only access model, RS256 id_token cryptographic verification, server-side session architecture with Redis, field-level AES-128-CBC encryption with startup self-test, PostgreSQL audit log immutability trigger (SOC 2 CC7.2), GDPR data subject rights endpoints, Stripe webhook signature and BOLA controls, HTTP security headers (CSP, HSTS, Permissions-Policy), and container non-root execution.