GDPR and Data Protection
- Last updated
- Effective
How Senitix handles personal data under the GDPR and UK GDPR: who is responsible for it, where it is stored, how transfers are protected, and how to exercise your rights.
1. About this page
This page explains how Senitix handles personal data under the EU General Data Protection Regulation (GDPR) and the UK GDPR. It is written for customers in the European Economic Area (EEA) and the United Kingdom, and for people in those places whose personal data Senitix handles.
Senitix is provided by Senitix Teknoloji LTD. ŞTİ., a company established in Türkiye. The GDPR and the UK GDPR apply to us when we offer Senitix to people and organizations in the EEA and the UK. Because we are established in Türkiye, Turkish Law No. 6698 on the Protection of Personal Data (KVKK) also applies to all of our processing.
This page is a summary, not a second privacy notice. Our Privacy Policy is the notice for the personal data we control, and our Data Processing Agreement (DPA) is the contract for the personal data we process for customers. If this page and either of those documents differ, the Privacy Policy or the DPA governs. If you are in the United States, see the Privacy Policy’s section on US state privacy rights instead.
2. Who we are and how to reach us
Where Senitix is the controller (see section 3), the controller is Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye, Central Registration System (MERSİS) number 0478-1132-3580-0001.
- Privacy questions and requests about your personal data: privacy@senitix.com
- The DPA, contracts and legal notices: legal@senitix.com
- Reporting a security vulnerability: security@senitix.com
- Account support and billing: support@senitix.com
Senitix has not appointed a data protection officer. Our privacy contact is privacy@senitix.com.
2.1 Representative in the EU and the UK
We have not designated a representative in the EU or UK; you can reach us directly at privacy@senitix.com. If we designate one, we will name it on this page.
3. Controller or processor: who is responsible for your data
Under the GDPR, the controller decides why and how personal data is used, and a processor handles it on the controller’s behalf. Senitix plays both roles, depending on the data.
| Personal data | Senitix’s role | Where the rules are |
|---|---|---|
| Records a customer keeps in Senitix CRM: contacts, leads, accounts, deals, activities, notes and files, and the email and calendar items its users sync | Processor. The customer is the controller. | The customer’s own privacy notice, and our DPA with the customer |
| What users ask Senitix AI about those records, and what it returns | Processor | Our DPA |
| User accounts: name, work email, the phone number used for verification, role, sign-in history and security logs | Controller | Our Privacy Policy |
| Subscription billing and payment records | Controller | Our Privacy Policy |
| Messages you send us through senitix.com, by email or to support | Controller | Our Privacy Policy |
| Visits to the senitix.com website | Controller | Our Privacy Policy and Cookie Policy |
3.1 If your data is in a customer’s CRM
If a company keeps your details in Senitix CRM, for example because you are its customer, supplier or prospect, that company decides what it holds about you and why. Its privacy notice applies, and requests about that data go to it (see section 8.3). We use that data only to provide and secure the service on the customer’s instructions. We do not sell it, use it for advertising or use it to train AI models.
3.2 If your organization is a Senitix customer
Your organization is the controller of the records it keeps in Senitix and chooses the lawful basis for them. The DPA forms part of the Terms of Service, so it applies when your organization accepts them. If you store special categories of personal data, such as health information, you are responsible for having a condition for that processing under Article 9 GDPR.
The product gives your team the tools to act on individuals’ requests. Authorized users can find, correct and delete records, export records as CSV or Excel files, and control who sees which records and fields with roles and field-level security. Deleted records stay in a recycle bin for 90 days by default, and each workspace can set that period anywhere from 30 days to 7 years. They are then permanently deleted.
3.3 Connected Google and Microsoft accounts
A user can connect Gmail and Google Calendar, or Outlook mail and calendar, to sync messages and events into the customer’s workspace. That data is customer data, and we process it as the customer’s processor. Senitix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The Privacy Policy’s Google user data section explains what we access and why.
4. What we use personal data for, and our lawful bases
This table summarizes the purposes for which Senitix is the controller and the lawful basis for each under Article 6(1) of the GDPR and the UK GDPR. The categories of personal data, their sources, who receives them and how long we keep them are set out in the Privacy Policy’s notice at collection.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account and providing the service, including support | Contract (Art. 6(1)(b)). If your organization holds the subscription and invited you, our legitimate interest in providing the service it bought (Art. 6(1)(f)). |
| Billing and collecting subscription fees | Contract (Art. 6(1)(b)) |
| Keeping invoices and accounting records, and responding to lawful requests from authorities | Legitimate interests (Art. 6(1)(f)) in complying with the accounting and tax record-keeping law that applies to us in Türkiye; legal obligation (Art. 6(1)(c)) where EU or UK law separately requires it, for example in responding to a lawful request from an EU or UK authority |
| Securing accounts and the platform: sign-in protection, verification codes, checking where sign-ins come from, preventing fraud and abuse, screening sign-ups against sanctions lists, and keeping audit logs | Legitimate interests (Art. 6(1)(f)) in keeping customers, users and the service secure, and in not providing the service to sanctioned parties; legal obligation (Art. 6(1)(c)) where EU or UK sanctions law applies to us directly |
| Service messages: security alerts, billing notices and changes to our terms | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Answering questions you send through senitix.com or by email | Legitimate interests (Art. 6(1)(f)) in replying, or steps you ask us to take before entering into a contract (Art. 6(1)(b)) |
| Analytics cookies on our website (Google Analytics) | Consent (Art. 6(1)(a)), which you can withdraw at any time in “Cookie settings”; strictly necessary cookies, including the one that records your choice, rely on our legitimate interest (Art. 6(1)(f)) in operating the website |
| Product news and marketing email | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Establishing, exercising or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
You can object at any time to processing based on legitimate interests (see section 7). To create an account you need to give us your name and work email, and billing details for a paid subscription; without them we cannot provide the service. Everything else is optional.
We do not sell personal information and do not use it for targeted advertising. Until you consent, the www.senitix.com website sets no analytics cookie and loads no analytics script; Cloudflare, which protects the site, may set a strictly necessary bot-management cookie. If you accept the Analytics category in our cookie banner, we load Google Analytics on the lawful basis of your consent, which you can withdraw at any time in “Cookie settings”; withdrawing it stops analytics and deletes the Google Analytics cookies. The Senitix app uses cookies and your browser’s storage only to keep you signed in, protect your account, keep the service working and remember your language, settings and unsaved work. The Cookie Policy lists each one.
5. Where data is stored and how transfers are protected
5.1 Hosting in the EU
The Senitix application, its databases, file storage and backups run on Amazon Web Services in Frankfurt, Germany (eu-central-1), with disaster recovery in Ireland (eu-west-1). The models behind Senitix AI run on Amazon Bedrock in the EU, and error monitoring uses Sentry’s EU region.
5.2 Why data still crosses borders
Hosting in the EU does not mean data never leaves it. Senitix is established in Türkiye, and our staff operate, secure and support the service from there, so data can be accessed from Türkiye when that work requires it. Some of our service providers are based in the United States, and Cloudflare handles traffic at the location nearest to each visitor. Neither the European Commission nor the United Kingdom has recognized Türkiye as providing an adequate level of data protection.
| Where | What happens there | Safeguard |
|---|---|---|
| European Union: Frankfurt, Germany, with disaster recovery in Ireland | The Senitix application, databases, file storage and backups (Amazon Web Services); Senitix AI model processing (Amazon Bedrock); error monitoring (Sentry, EU region) | The data stays in the EEA. |
| Türkiye | Senitix staff operate, secure and support the service and can access data remotely when that work requires it. Subscription payments are processed by iyzico (iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.). | Customer data: the Standard Contractual Clauses in the DPA. Data you give us directly: the GDPR and UK GDPR apply to us (section 5.3). |
| United States | Transactional email (Twilio SendGrid), SMS verification codes (Twilio), sign-in location lookups (IPinfo), our company mailboxes (Google Workspace), and, for visitors outside the EEA, UK and Türkiye who accept analytics, website analytics (Google LLC) | Standard Contractual Clauses in each provider’s data processing terms; Google LLC is also certified under the EU-U.S. Data Privacy Framework |
| Website analytics you consent to | Google Analytics, provided by Google Ireland Limited for visitors in the EEA, the UK and Türkiye, only if you accept the Analytics category in our cookie banner | You choose whether this processing happens at all; see our Cookie Policy |
| Cloudflare’s global network | Content delivery, firewall and DDoS protection, handled at the Cloudflare location nearest to each visitor | Standard Contractual Clauses in Cloudflare’s data processing terms |
| Services a user chooses to connect | Gmail and Google Calendar (Google) or Outlook mail and calendar (Microsoft) when a user connects them, and signing in with a third-party account if a user chooses to | The customer or user directs the connection; the provider’s own terms govern the account held with it |
5.3 The safeguards we use
- Customer data accessed from Türkiye. The DPA incorporates the Standard Contractual Clauses (SCCs) adopted by the European Commission in Implementing Decision (EU) 2021/914, using Module 2 where the customer is a controller and Module 3 where the customer is itself a processor, and, for data covered by UK law, the International Data Transfer Addendum issued by the UK Information Commissioner.
- Data you give us directly. When you sign up, write to us or visit our website, you provide your data to Senitix in Türkiye. The GDPR and the UK GDPR apply to our handling of that data directly, as this page and the Privacy Policy describe.
- Onward transfers to our providers. When a sub-processor outside the EEA and the UK handles personal data for us, we rely on the SCCs in that provider’s data processing terms.
- Turkish law. Because we are established in Türkiye, transfers we make from Türkiye to other countries must also meet Article 9 of the KVKK.
You can ask for a copy of the safeguards that apply to your data at privacy@senitix.com; we may remove commercially sensitive terms from the copy. A customer assessing a transfer can ask us for the information its assessment needs.
6. The Data Processing Agreement and our sub-processors
The Data Processing Agreement contains the terms that Article 28 GDPR requires between a customer and its processor. Under it, we:
- process customer personal data only on the customer’s documented instructions;
- make sure the people who handle it are bound by confidentiality;
- protect it with appropriate technical and organizational measures;
- engage sub-processors only under written terms that give the same protection;
- help the customer respond to individuals’ requests and meet its security, breach-notification and impact-assessment obligations;
- delete or return the data when the service ends; and
- make available the information needed to show that we meet these obligations, and allow for audits.
The DPA is part of the Terms of Service, so it applies when a customer accepts them. If your organization needs a signed copy, write to legal@senitix.com.
The Sub-processors page lists the providers that process personal data for us, the service each one provides and where it processes the data. We give customers notice before we add or replace a sub-processor, and a customer can object as the DPA sets out.
7. Your rights under the GDPR and the UK GDPR
If the GDPR or the UK GDPR applies to your personal data, you have the rights below. Each one has conditions and exceptions set out in the law. If one of them means we cannot do what you ask, we tell you why.
- Access (Art. 15): confirmation of whether we process your data, a copy of it, and information about how we use it.
- Rectification (Art. 16): correction of inaccurate data and completion of incomplete data.
- Erasure (Art. 17): deletion, for example when we no longer need the data, or when you withdraw consent and no other lawful basis applies.
- Restriction (Art. 18): limiting how we use your data while a question about its accuracy or an objection is resolved, or when you need it kept for a legal claim.
- Portability (Art. 20): your data in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of your consent or a contract.
- Objection (Art. 21): to processing based on legitimate interests, and, at any time and without giving a reason, to direct marketing.
- Withdrawing consent (Art. 7(3)): at any time, without affecting processing that took place before you withdrew it.
- Automated decisions (Art. 22): not to be subject to a decision based solely on automated processing that has legal or similarly significant effects on you, subject to the exceptions in the law.
- Complaint (Art. 77): to a supervisory authority (see section 9).
The Privacy Policy sets out how these rights apply to the data we control.
8. How to make a request
- By email: write to privacy@senitix.com. If you write from the email address on your Senitix account, we can usually confirm who you are without asking for more.
- In the app: signed-in users can export their data and change their marketing preferences under Settings › Privacy.
- Marketing email: use the unsubscribe link in any message.
Tell us which right you want to use and, if your data is in a customer’s CRM, which company holds it.
8.1 Verification and people acting for you
We ask only for the information we need to confirm your identity, and we use it only for that purpose. Someone else can make a request on your behalf, for example a lawyer or a not-for-profit body under Article 80 GDPR, if they show that they are authorized; we may confirm the request with you directly.
8.2 Timing and cost
We respond within one month of receiving your request. If a request is complex, or we receive many, we can extend that period by up to two further months; if we do, we tell you within the first month and explain why. Erasure requests are completed within 30 days. Requests are free. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline it, and we explain why.
8.3 Requests about data in a customer’s CRM
If a customer holds your data in Senitix CRM, that customer is the controller and decides how to respond, so please contact it directly. If you write to us instead, we pass your request to the customer where we can identify it and help it respond. We do not answer the request ourselves unless the customer instructs us to.
9. Complaints
To us. You can complain to us about how we handle your personal data at privacy@senitix.com. We acknowledge a complaint within 30 days of receiving it, look into it, and tell you the outcome.
In the EU and the EEA. You can complain to the supervisory authority in the country where you live or work, or where you believe the infringement took place. The European Data Protection Board lists the authorities at edpb.europa.eu.
In the United Kingdom. You can complain to the Information Commissioner’s Office at ico.org.uk. The ICO generally expects you to raise the complaint with us first.
In Türkiye. Because Senitix is established in Türkiye, you can also complain to the Personal Data Protection Board through the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), Nasuh Akar Mah. 1407. Sok. No:4, 06520 Çankaya, Ankara, kvkk.gov.tr. Turkish law requires you to apply to us first; you can then complain if we reject your application, our answer is inadequate, or we do not answer in time.
10. How long we keep personal data
We keep personal data for as long as the purpose we collected it for requires, or longer where the law requires it. The Data Retention Policy has the full schedule. The periods people ask about most are these:
- After a subscription ends or a workspace is closed: the workspace stays available read-only for 30 days so the customer can export its data. The data is then deleted as the Data Retention Policy describes.
- Deleted records: kept in the recycle bin for 90 days by default (a workspace can choose anywhere from 30 days to 7 years), then permanently deleted. Deleted files stay in the file trash for 90 days.
- Synced email: purged after 365 days.
- Senitix AI conversations: deleted after 180 days without activity.
- Sign-in attempts and expired sessions: 30 days. Data export files: 30 days.
- Audit logs: 7 years.
- Invoices and contracts: 10 years. When an erasure request reaches one of these records, the personal data in it is anonymized and the record is kept.
- Backups: daily backups are kept for 35 days and monthly backups for 365 days, then overwritten. Deleted data leaves the backups on that cycle.
11. How we protect personal data
Our security page and the DPA describe our security measures in more detail. In summary:
- encryption in transit with TLS 1.2 or higher (TLS 1.3 preferred), and HTTP Strict Transport Security (HSTS) on our websites;
- encryption at rest, plus field-level AES-256-GCM encryption with per-workspace keys for designated sensitive fields;
- multi-factor authentication with an authenticator app, or by SMS where it is enabled;
- role-based access control, with each customer’s workspace kept separate in the application;
- audit logs of security events and administrative changes;
- daily and monthly backups stored in the EU, in Frankfurt with copies in Ireland; and
- traffic filtering and DDoS protection through Cloudflare.
Senitix does not hold SOC 2 or ISO/IEC 27001 certification today; we are preparing for a SOC 2 Type II audit. Customer-managed encryption keys (BYOK), data loss prevention and field masking are not available today.
If a personal data breach affects data we process for a customer, we notify that customer without undue delay, as the DPA sets out. Where we are the controller, we notify the competent supervisory authorities within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people, and we tell affected individuals directly when the risk to them is high. To report a suspected vulnerability, write to security@senitix.com.
12. Senitix AI and the EU AI Act
On paid plans, Senitix AI writes a daily digest, answers questions from the records a user can already see, drafts and rewrites email, summarizes threads and suggests a next action. Nothing is sent or changed until the user confirms.
When a user works with Senitix AI, the user’s request and the records it needs are processed by models running on Amazon Bedrock in the EU. We handle this data as the customer’s processor under the DPA. Customer data is not used to train AI models. Senitix AI conversations are deleted after 180 days without activity.
Senitix AI does not make decisions about people that have legal or similarly significant effects: what it produces is a proposal that a person accepts, edits or discards. Lead and deal scoring in Senitix CRM is separate from Senitix AI and follows rules the customer sets.
12.1 Transparency under the EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) sets transparency rules for AI systems that interact with people or generate content (Article 50). In Senitix, AI features carry the Senitix AI name, so users know when they are working with an AI system, and what Senitix AI produces is shown to the user as a draft, summary or suggestion before anything is sent or changed.
Senitix AI is not designed for uses that the AI Act prohibits or classifies as high-risk, such as screening job applicants, evaluating employees or assessing creditworthiness, and it should not be used for them. A customer that uses AI-assisted content in its own communications remains responsible for any disclosure the law requires of it. The Terms of Service govern how Senitix AI may be used.
13. Changes to this page
We update this page when our practices or the law change, and the date at the top shows when it last changed. Changes to the Privacy Policy and the DPA are notified as those documents describe. Questions about this page go to privacy@senitix.com.
