SentsaiHome
Legal

Policies & Agreements

Last updated: August 2026. These documents govern your use of Sentsai and our handling of your data. Please read them before using the platform.

Terms of Service
Your rights and obligations as a Sentsai customer, including payment terms, limitations of liability, and acceptable use. Governed by Ontario, Canada law. Acceptance is version-stamped - if the terms change materially, you will be prompted to re-accept before running further scans or initiating payments.
Privacy PolicyGDPR · PIPEDA · CCPA
What personal data we collect (account data, Microsoft 365 tenant data processed on your behalf, usage logs, payment confirmations), why and on what legal basis, how long we retain it, when and how it is deleted, and how to exercise your rights. Covers our dual role as both data controller (for your account data) and data processor (for your Microsoft 365 employee data).
Data Processing AgreementGDPR Art. 28
Required by GDPR Article 28 and incorporated by reference into the Terms of Service - no separate signature needed. Defines Sentsai as data processor and your organization as data controller for Microsoft 365 tenant data. Covers sub-processor disclosures, technical and organizational measures, breach notification obligations (72-hour window), data subject assistance obligations, and deletion/return commitments.
CCPA Service Provider AddendumCCPA / CPRA
Required for California businesses under the CCPA/CPRA. Certifies Sentsai as a Service Provider - we do not sell, share, or use your data for cross-context behavioral advertising or for any purpose other than providing the contracted service. Defines processing restrictions and Sentsai's obligations to your California consumers.
Cookie Policy
Details of the strictly necessary cookies Sentsai sets. We use three cookies: an opaque session identifier (sentsai_session_id, 8-hour TTL backed by a server-side Redis store), a tenant reference (sentsai_tenant_id, 30-day TTL), and a short-lived CSRF token (oauth_state, 10 minutes, set only during the OAuth login flow). All are HttpOnly, Secure, and SameSite=Lax. No tracking cookies. No advertising cookies. No third-party cookies.
Security & TrustTechnical
Audit-ready technical detail: OAuth 2.0 read-only access model, RS256 id_token cryptographic verification, server-side session architecture with Redis, field-level AES-128-CBC encryption with startup self-test, PostgreSQL audit log immutability trigger (SOC 2 CC7.2), GDPR data subject rights endpoints, Stripe webhook signature and BOLA controls, HTTP security headers (CSP, HSTS, Permissions-Policy), and container non-root execution.

Questions, including privacy-specific requests? Contact us at privacy@sentsai.com.