Effective date: June 2025
This Privacy Policy explains how Sentsai ("we", "us", "our") collects, uses, stores, and shares personal data when you use our Microsoft 365 licensing audit service.
Sentsai operates in a dual capacity. When you connect your Microsoft 365 tenant and run a scan, your organization is the data controller for the personal data of your employees (Microsoft 365 users), and Sentsai acts as a data processor, processing that data only to provide the contracted service under your documented instructions. The binding terms of that processor relationship are set out in our Data Processing Agreement.
Separately, for data relating to you personally as a platform user (your email address, account activity, and usage of our platform), Sentsai is the data controller and this policy explains how we handle that data.
The distinction matters for your rights and our obligations:
(a) Account data - collected when you authenticate with Microsoft:
(b) Microsoft 365 tenant data - retrieved via the Microsoft Graph API during a scan:
(c) Usage and platform data - logged automatically:
(d) Payment data - processed by Stripe on our behalf. We receive from Stripe a payment confirmation and a link to the receipt Stripe issues for that payment, which we store so you can open it from your billing page. If you choose optional automatic renewal, Stripe stores your payment method and creates a customer record, and we hold only Stripe's reference identifiers for them, together with a record of your renewal consent (when you agreed, from which IP address, and under which Terms version). If you do not choose automatic renewal, each payment is a one-off charge and we hold no customer record or stored payment method at Stripe. In every case we do not store payment card numbers, CVVs, or bank account details, and we never will - the card is held by Stripe, not by us. Turning automatic renewal off, or erasing your account, removes these records as described in this policy; erasure also removes the stored receipt links, so the financial record we are required to retain no longer leads back to you.
We use the data we collect for the following purposes:
We do not sell your data. We do not use your data or your employees' data for any purpose other than producing your report and operating, supporting, and securing the Service, and we never use it to train machine-learning models. Support access is deliberately narrow: our administrative console is read-only and shows account records (such as the administrator contact email and subscription state), billing records, and de-identified report aggregates. It is built so it cannot display the names or email addresses of the people in your directory, nor the text of any finding. Every administrative view of your account is written to the same tamper-evident audit log you can export, including the identity of the person who looked.
We rely on the following legal bases under Article 6 of the UK GDPR / EU GDPR:
PUT /gdpr/retention. You can trigger immediate deletion at any time via DELETE /gdpr/erase. Deletion is permanent and irreversible.We share data with the following sub-processors to deliver the service. We have a Data Processing Agreement or equivalent safeguard in place with each sub-processor.
Email communications. We use Resend to send you two kinds of email. Service (transactional) emails, such as report-ready notices and reminders that your subscription is about to expire, are part of the service and are always sent. Receipts for card payments come from Stripe rather than from us. Marketing emails, such as occasional reminders that it may be time to re-run your audit, are sent on the basis of our legitimate interest in keeping existing customers informed about a service they have used. Every marketing email includes a one-click unsubscribe link; unsubscribing stops all marketing email while leaving service emails unaffected. We never share your data with any third party for that third party's own marketing.
Some of our sub-processors are based in the United States, which is outside the UK and EEA. Transfers of personal data to these sub-processors are covered by one or more of the following safeguards:
You may request details of the specific transfer mechanism applicable to any sub-processor by contacting privacy@sentsai.com.
Under the UK GDPR, EU GDPR, and equivalent data protection laws, you have the following rights regarding your own personal data (account data). For rights relating to your employees' data, see our Data Processing Agreement.
GET /gdpr/exportDELETE /gdpr/erase. For full account deletion: DELETE /account/delete.Rights that affect your whole organization - erasure, consent withdrawal, and changing the retention period - require a Microsoft 365 administrator, because a Sentsai account belongs to the tenant rather than to an individual and those actions apply to everyone in it. Access and data export are available to any signed-in user. To exercise any of these rights, use the self-service API endpoints above or contact privacy@sentsai.com. We will respond within 30 days. We may need to verify your identity before processing certain requests.
To exercise rights on behalf of your employees (as data controller), use the same self-service endpoints with your administrator credentials, or contact us and we will assist.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration, including:
If you discover a security vulnerability, please report it responsibly to security@sentsai.com.
Data breach notification. Despite these measures, if a personal data breach occurs we act in line with applicable data protection law. Where we process data on behalf of a customer (as processor), we notify that customer without undue delay and in any event within 72 hours of becoming aware of the breach, so they can meet their own notification duties (see our Data Processing Agreement, clause 9). Where we act as controller of the affected data (for example, account administrator details), we notify affected individuals and the relevant supervisory authority where required by law, without undue delay. In all cases we maintain an internal record of personal data breaches - their nature, effect, and the remedial action taken - as required by Article 33(5) GDPR.
We use only strictly necessary session cookies to maintain your authenticated session. These cookies are:
We do not use tracking cookies, advertising cookies, or analytics cookies. No cookie consent banner is required under applicable law for strictly necessary functional cookies.
For privacy-related questions or to exercise your rights, contact our Data Protection contact:
Email: privacy@sentsai.com
If you are not satisfied with our response, you have the right to lodge a complaint with your data protection supervisory authority: