Effective date: June 2025
This Addendum applies when you are a business subject to the California Consumer Privacy Act (as amended by the California Privacy Rights Act - "CCPA/CPRA"), or when you process personal information of California residents using the Sentsai service. It is incorporated by reference into the Sentsai Terms of Service and Data Processing Agreement.
Terms used but not defined here have the meanings given in the CCPA/CPRA.
Sentsai, as Service Provider, shall:
Sentsai processes Personal Information solely for the following Business Purposes:
Sentsai certifies that it understands these restrictions and will comply with them.
The Personal Information processed includes the following CCPA/CPRA categories:
No sensitive personal information (as defined in Cal. Civ. Code § 1798.121) is collected or processed by Sentsai.
The Business is responsible for receiving and responding to consumer (employee) rights requests under the CCPA/CPRA. Sentsai will assist the Business to the extent technically feasible:
GET /gdpr/export) containing all Personal Information held for the Business;DELETE /gdpr/erase) to remove all Personal Information;If a consumer submits a rights request directly to Sentsai, Sentsai will forward it to the Business within 5 business days.
Sentsai uses the following sub-processors that may process Personal Information. Each is engaged under a written contract that imposes equivalent privacy obligations:
Sentsai retains Personal Information for the retention period configured by the Business - 90 days by default, configurable between 30 and 365 days - after which it is automatically deleted. On termination of the agreement, or on request, all Personal Information is deleted within 30 days. One exception, disclosed for accuracy: entries in our immutable audit trail are retained as a record that an action occurred. Their IP address and user-agent fields are erased, leaving an action name, a timestamp and internal identifiers that do not identify a person.
Sentsai implements reasonable security measures including: encryption in transit for internet-facing traffic (TLS 1.2+), field-level encryption at rest, tenant-level data isolation, access logging, and retention-based automatic deletion. In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information, Sentsai shall notify the Business without undue delay.
To the extent there is any conflict between this Addendum and the Terms of Service or DPA with respect to CCPA/CPRA obligations, this Addendum shall control solely with respect to such CCPA/CPRA obligations.
Contact us at privacy@sentsai.com. If you require a signed copy of this Addendum for your procurement process, please contact us and we will provide one.