Privacy Policy
- Last updated
- Effective
How Senitix collects, uses, discloses and protects personal information, where it is processed, and how to use your U.S. state, EU, UK and Turkish privacy rights.
1. Overview
This Privacy Policy explains how Senitix Teknoloji LTD. ŞTİ. (“Senitix,” “we,” “us” or “our”) collects, uses, discloses and protects personal information when you visit senitix.com, sign up for or use the Senitix application (including app.senitix.com and crm.senitix.com), connect another service to it, or contact us. It also explains the choices and rights you have.
Senitix is a service for businesses and other organizations. The people who use it do so on behalf of the organization that holds the subscription, and this policy is written with that in mind.
Key points
- We do not sell or share personal information, and we do not use it for targeted advertising.
- Our website loads Google Analytics only after you consent, and you can change that choice at any time; see section 8.
- The Senitix service is hosted on Amazon Web Services (AWS) in Frankfurt, Germany, with disaster-recovery copies in Ireland. Senitix itself is a company based in Türkiye.
- For the information our customers keep in Senitix, such as the contacts and deals in a CRM workspace, the customer decides how it is used and we process it on the customer’s behalf.
- We do not use your data, or what you give Senitix AI, to train AI models.
- You can ask to access, correct or delete your personal information by writing to privacy@senitix.com.
This policy does not cover websites or services run by others, including services you connect to Senitix. Their own privacy policies apply to them.
2. Who we are
Senitix Teknoloji LTD. ŞTİ. is a limited liability company registered in Türkiye, MERSİS No. 0478-1132-3580-0001. It provides Senitix in every market and decides how the personal information described in this policy is used. Customers in the United States contract with this company.
- Registered address: Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye
- Privacy questions and requests: privacy@senitix.com
- Company details: Company information
3. Our two roles: controller and processor
Senitix handles personal information in two different capacities. Which one applies decides whose rules govern the information and where you should send a request about it.
When we decide how information is used
We are the controller (in the terms of U.S. state privacy laws, the “business”) for the information we collect for our own purposes:
- your Senitix account and profile, and your sign-in and security records;
- billing, payment and invoicing records;
- visits to our website and the messages you send through our contact and sales forms;
- support requests and other correspondence with us; and
- marketing email you have agreed to receive.
This policy describes how we handle that information.
When we act for our customers
Our customers use Senitix to store and work with their own information: for example, the contacts, leads, accounts, deals, emails, calendar events, files and notes in a CRM workspace, the open and click data a customer collects when it turns on tracking for emails it sends, and what its users give Senitix AI. We call this Customer Data. For Customer Data, the customer is the controller (the “business”) and Senitix is its processor (under U.S. state laws, its “service provider” or “processor”). We process Customer Data only to provide the service and as the customer instructs, under our Data Processing Agreement and Terms of Service. We do not sell it, and we do not use it for our own marketing.
If your information is in a Senitix customer’s workspace, for example because you are a contact of a company that uses Senitix, that company’s privacy notice explains how it uses your information, and your request should go to that company. If you send the request to us, we will pass it to the customer when we can identify it, and we will help the customer respond.
4. Notice at collection
This section summarizes, for each category of personal information we collect as a controller, where it comes from, why we use it, to whom we disclose it for a business purpose and how long we keep it. The categories are those used by the California Consumer Privacy Act (CCPA). During the 12 months before this policy took effect, we collected the same categories from the same sources, for the same purposes, and disclosed them to the same categories of recipients, except that our previous website also used Google Analytics and Crisp live chat for visitors who agreed to them (see section 8).
| Category | What it includes | Where it comes from | Why we use it | Disclosed for a business purpose to | How long we keep it |
|---|---|---|---|---|---|
| Identifiers | Name, email address, phone number, account and workspace IDs, IP address, session identifiers | You; your organization, when it invites you; a sign-in provider you choose; your device | Create and secure accounts, provide the service, communicate with you, answer inquiries, bill, prevent fraud and abuse, comply with law | Hosting and network providers; email and SMS delivery providers; security and error-monitoring providers; our payment processor; your organization’s administrators; professional advisers; authorities where the law requires | While your account exists; unverified sign-ups are deleted after 30 days (see section 13) |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Billing name and address, billing contact, a tax number where invoicing requires one, payment card details | You; our payment processor | Take payments, issue invoices, keep accounting and tax records, prevent fraud | Our payment processor (card details go only to it); hosting providers; accountants and auditors; tax authorities where the law requires | Invoices and billing records: 10 years. We do not store full card numbers. |
| Commercial information | Plan, number of users, subscription and payment history, invoices; in a sales inquiry, the plan you are interested in, company size and number of CRM users | You; our records of your purchases | Provide and bill the service, answer sales inquiries, comply with tax law | Our payment processor; hosting providers; our email provider; professional advisers | Billing records: 10 years; inquiries: as described in section 13 |
| Internet or other electronic network activity | Website request logs (IP address, browser, page, time); sign-in history; actions recorded in your account’s audit log; error reports; delivery, and where tracking is enabled, opens and clicks of emails we send; and, only if you accept analytics on our website, the pages you view, the site or search engine you arrived from, your device, browser and language, your approximate city-level location (derived by Google from your IP address, which it does not log or store), and whether you submitted our contact or sales form or clicked to start a free trial or sign up | Your browser and device; our systems; our email delivery provider; Google Analytics, if you accept analytics | Deliver and protect the website and service, detect abuse, fix errors, keep audit trails, understand how features are used; site analytics, to understand how visitors use our website, only if you consent | Hosting and network providers; our error-monitoring and email delivery providers; your organization’s administrators (audit log); Google, as our service provider for analytics | Server and application logs: generally 30 days; sign-in attempts: 30 days; audit logs: 7 years; analytics data: 14 months in Google Analytics; your consent choice: 180 days |
| Geolocation data (approximate only) | Country, region and city inferred from the IP address used to sign in; the country you choose at sign-up | Your IP address, through our IP-lookup provider; you | Detect unusual sign-ins; set up your account for your country | Our IP-lookup provider; hosting providers | With the sign-in, session or account record it belongs to |
| Professional or employment-related information | Company name, job title, industry, company size | You; your organization | Set up your account, answer sales inquiries, make our communication relevant to you | Hosting providers; our email provider | While your account exists; inquiries: as described in section 13 |
| Communications and content you provide | Messages you send through our forms or by email, support conversations and attachments, feedback; a profile photo if you add one | You | Answer you, provide support, show your profile to your team, improve our service and help content, keep a record of our dealings | Our email provider; our email delivery provider; hosting providers | As long as needed to handle the matter and follow up (section 13) |
| Sensitive personal information | Account log-in credentials (email address and password, stored only as a one-way hash); your card number and security code when you pay by card | You | Authenticate you, secure your account, take payments; never to infer characteristics about you | Our payment processor (card details only); hosting providers | Password hash: while your account exists; card details: not stored by us |
We do not sell or share personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising or use it for targeted advertising. Our current website uses Google Analytics only after a visitor consents in the cookie banner described in section 8, and only as our service provider under a contract that limits Google to providing analytics to us, with Google Signals and ads personalization off; we do not consider this a sale or share of personal information. Our previous website, which senitix.com has replaced, used Google Analytics and a live-chat tool for visitors who agreed to them in a cookie banner; we are confirming how those tools were configured during the 12 months before this policy took effect and will correct this statement if that review finds that their use should be treated as a “sale” or “share” of personal information under the CCPA for that period. We do not knowingly sell or share the personal information of anyone under 16.
We do not collect precise geolocation, biometric information or characteristics of protected classifications, and we do not draw inferences from your information to build a profile about you. Your rights are explained in section 16 for U.S. states and section 17 for the EU, the UK and Türkiye.
5. Information we collect
Information you give us
- Account details. When you sign up: your name, email address, password and country, and, if you choose to give them, your phone number, language, time zone, industry and company size. If someone invites you to a workspace, that person gives us your name and email address.
- Profile details. Anything you add to your profile, such as a job title or a photo.
- Billing details. Your organization’s billing name, address and contact, a tax number where invoicing requires one, and payment card details. Card details are collected for our payment processor, iyzico, and passed to it; we do not store full card numbers or security codes.
- Inquiries. What you enter in our contact or sales forms: your name, work email, phone number, company, job title, company size, number of CRM users, country, the plan you are interested in, the topic and your message. With it we record the acknowledgment you ticked and, if you chose it, your marketing opt-in, in the words shown to you, with the date, page and language.
- Support and correspondence. Messages you send to support@senitix.com or any of our other addresses, and their attachments.
- Marketing preferences. Whether you agreed to receive marketing email, and any later opt-out.
Information collected automatically
- Website visits. When you load a page on www.senitix.com, the providers that host and protect the website receive your IP address, browser and device type, the page you asked for, the referring page and the time. Until you consent, the website sets no cookie and runs no analytics or advertising code; if you accept analytics, Google Analytics also receives this information, as section 8 describes.
- Use of the service. When and how you sign in, the IP address you use and the approximate location (country, region and city) derived from it, your device and browser, and a record of actions taken in your account (the audit log).
- Error reports. When something fails, technical details such as the request involved, your browser, your IP address and an account identifier.
- Emails we send. Our email delivery provider records whether each email was delivered and, where tracking is enabled, whether it was opened or a link in it was clicked.
- Cookies and browser storage in the application. See section 8.
Information from others
- Your organization. Administrators of your workspace can add or change your name, email address, role and permissions.
- Sign-in providers. If you sign in with a Google, Microsoft or GitHub account (where offered) or through your organization’s single sign-on, that provider sends us your name, email address and an account identifier.
- Services you connect. If you connect a mailbox or calendar, we receive the information described in section 10 for Google and section 11 for Microsoft and other mailboxes.
- Our payment processor. The result of each payment and a reference to the card saved with iyzico, never the full card number.
- Our IP-lookup provider. The approximate location of an IP address.
- Public sanctions lists. We compare the names of people who register or sign in with sanctions lists published by governments, such as the list kept by the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) and the European Union’s consolidated list.
6. How we use personal information
- Provide the service. Create and run accounts and workspaces, authenticate users, sync the services you connect, run Senitix AI when you ask it to, import and export data, and deliver the features of your plan.
- Bill and collect payment. Charge subscriptions in advance, prorate upgrades, retry failed payments, issue invoices and receipts, apply taxes and keep accounting records.
- Communicate with you. Send service messages such as email verification, password resets, security alerts, billing notices and notice of changes to the service or our terms, and answer your inquiries and support requests.
- Keep Senitix secure. Verify sign-ins, provide multi-factor authentication, flag sign-ins from unusual locations, limit repeated failed attempts, block automated abuse, check new passwords against known breached passwords, keep audit logs, monitor errors and maintain backups.
- Comply with the law. Screen names against government sanctions lists at registration and sign-in, keep tax and accounting records, respond to lawful requests and handle privacy requests.
- Improve Senitix. Use service logs and error reports to fix problems, see which features are used and plan improvements.
- Market our products. Send product news and marketing email to people who have agreed to receive it.
- Protect our rights. Enforce our Terms of Service, and establish, exercise or defend legal claims.
Where we use de-identified or aggregated information, such as how often a feature is used across all workspaces, we keep it in that form and do not attempt to re-identify anyone. We will not use personal information for a purpose materially different from those described here without telling you first and, where the law requires, asking for your consent.
Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects, with one exception: if the name used to register or sign in exactly matches a name on a government sanctions list, the registration or sign-in is stopped automatically. If this happens to you and you believe it is a mistake, write to privacy@senitix.com and a person will review it.
7. How we disclose personal information
We do not sell or share it
We do not sell personal information or share it for cross-context behavioral advertising. We do not place advertising networks on our website or in the application, and we do not disclose personal information to third parties for their own direct marketing. We disclose it only as described below.
Service providers
Companies that provide services to us receive personal information only to perform those services, under contracts that limit what they may do with it. The main ones are:
| Provider | What it does for us | Where it processes data |
|---|---|---|
| Amazon Web Services (AWS) | Servers, databases, file storage, backups and encryption keys for the Senitix service; Amazon Bedrock for Senitix AI | Germany (Frankfurt), with disaster-recovery copies in Ireland; Senitix AI requests in AWS Regions in the European Union |
| Cloudflare | Domain name service, content delivery, firewall, and protection against bots and denial-of-service attacks | Cloudflare’s global network, at the location nearest to you |
| Google (Google Analytics) | Website analytics, only if you accept analytics on our website (section 8) | Google Ireland Limited for EEA, UK and Türkiye visitors; Google LLC (United States) for other visitors |
| Twilio SendGrid | Delivering the emails the service sends, and receiving emails that users forward to their workspace | United States |
| Twilio | Sending SMS verification codes | United States |
| iyzico (iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.) | Processing payments and storing saved cards | Türkiye |
| Sentry | Error monitoring | European Union (Germany) |
| Google Workspace | Our company email, including the addresses you write to | United States and other Google locations |
| IPinfo | Looking up the approximate location of sign-in IP addresses | United States |
The complete and current list, including providers used only for a particular feature, is on our Sub-processors page.
Your organization
If you use Senitix through your organization’s workspace, its administrators can see and manage your user account, your activity in the workspace and the content you create there, and they can ask us to export or delete it.
Services you connect and sign-in providers
When you connect Google, Microsoft or another service to Senitix, or sign in through an identity provider, information passes between Senitix and that service as you direct. The provider’s own terms and privacy policy govern what it does with the information it holds.
Professional advisers
Our lawyers, accountants, auditors and insurers, who are bound by duties of confidentiality, when we need their advice or services.
Legal requirements and protection
Courts, regulators, law enforcement and other public authorities when we believe in good faith that the law requires it, and others when it is necessary to protect the rights, property or safety of Senitix, our customers or the public, including to prevent fraud and abuse. If a request concerns Customer Data, we refer the requester to the customer where the law allows.
Business transfers
A buyer, investor or successor if Senitix is involved in a merger, acquisition, financing or sale of assets, subject to the commitments in this policy. We will tell you before your personal information becomes subject to a different privacy policy.
With your consent
Anyone else, when you ask us to or agree to it.
8. Cookies, tracking and browser signals
Our website
Until you accept analytics, www.senitix.com sets no analytics, advertising, social media or chat cookie and loads no analytics script; its fonts are served from our own servers. On your first visit, a banner lets you choose “Accept all” or “Reject all,” shown with equal prominence, or open “Cookie settings” to turn the Analytics category on or off separately from Strictly necessary, which is always on. Your choice is stored in a first-party cookie, sx_consent (holding no personal data), for 180 days, and a “Cookie settings” link in the footer of every page lets you change it at any time; withdrawing consent stops analytics and deletes the Google Analytics cookies described below. See Global Privacy Control below for how we treat that browser signal.
If you accept analytics, we load Google Analytics 4 (measurement ID G-JQ32B8VWLV) using Google Consent Mode v2, under which every signal defaults to denied and only the analytics_storage signal becomes granted; the signals used for advertising (ad_storage, ad_user_data, ad_personalization) stay denied whatever you choose, because we do not use Google Analytics for advertising, and Google Signals and ads personalization are off in our account. Google Analytics then sets _ga and _ga_JQ32B8VWLV, each kept for 2 years, and measures the pages you view, the site or search engine you arrived from, your device, browser and language, your approximate city-level location (derived by Google from your IP address, which it does not log or store), and two events: submitting our contact or sales form and clicking to start a free trial or sign up on app.senitix.com. We keep this data in Google Analytics for 14 months. Google Analytics is provided by Google Ireland Limited for visitors in the EEA, the UK and Türkiye, and by Google LLC in the United States for other visitors, and Google processes it as our service provider under its own data processing terms; see section 12 for how transfers to the United States are protected. Using Google Analytics with your consent is not a sale or sharing of personal information.
Cloudflare, which protects the website for us, may also set a strictly necessary security cookie (__cf_bm) that helps it tell people apart from automated bots. Videos on some pages load only when you press play. At that point the video provider, YouTube (through its privacy-enhanced youtube-nocookie.com domain) or Vimeo, receives your IP address and may set its own cookies under its own privacy policy. People who sign in to edit the website receive WordPress’s standard sign-in cookies; visitors do not. Our Cookie Policy lists every cookie, what it does and how long it lasts.
Before this policy took effect, our previous website used Google Analytics and Crisp live chat for visitors who agreed to them in a cookie banner. That website has been replaced. The current website uses Google Analytics again, in the consent-gated way described above; Crisp live chat does not run on it.
The Senitix application
The application uses a small number of cookies and browser storage entries that it needs to work or that remember choices you make: a session cookie that keeps you signed in, an XSRF-TOKEN cookie that protects your account against cross-site request forgery, and local storage that keeps your sign-in active and remembers your language, interface settings and unsaved drafts. None of them is used for advertising or to follow you across other websites, so we do not show a cookie banner. If we ever add cookies that are not needed for the service, we will update our Cookie Policy first and ask for your consent where the law requires. The Cookie Policy lists each cookie, what it does and how long it lasts.
Do Not Track
Some browsers can send a “Do Not Track” signal. Our website and the application do not track you over time or across other websites, so they work the same way whether or not your browser sends one. We do not allow third parties to collect personal information about your online activities over time and across different websites through our website or the application, except the video providers described above once you press play.
Global Privacy Control
We honor opt-out preference signals, such as Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for the browser that sends them; we do neither, so nothing changes on that score. GPC does control one thing: on our website, we treat it as a request to keep the Analytics category off, the same as choosing “Reject all” in the cookie banner, unless you later turn analytics on yourself in “Cookie settings.”
9. Senitix AI
Senitix AI is a set of features in the application, available on paid plans, that prepares work for a person to review: a daily digest, answers to questions about records the user can already see, email drafts and rewrites, summaries of email threads and suggested next steps. When you use Senitix AI, you are working with an AI system. Its output can be wrong, so check it before you rely on it.
What it processes
Your instruction or question; the parts of records you have permission to see that are needed to answer it; and any email or text you ask it to work on. Most of this is Customer Data, which we process for the customer as described in section 3. We also count each user’s AI requests to apply the daily limits of the customer’s plan.
Where it runs
Senitix AI uses models provided through Amazon Bedrock, with AWS’s European Union inference profiles, so requests and responses are processed in AWS Regions in the European Union. We do not send them directly to any model developer. By default, Senitix masks common identifiers, such as email addresses, phone numbers, national ID numbers, IBANs, payment card numbers and IP addresses, before text is sent to a model. If a customer uses Senitix AI’s web search, the search query Senitix AI writes for that request is sent to our web search provider.
No training on your data
We do not use Customer Data, prompts or Senitix AI outputs to train or improve AI models. AWS’s published commitments for Amazon Bedrock state that it does not use prompts and responses to train models and does not distribute them to third parties.
People stay in control
Senitix AI suggests; it does not decide. By default it asks the user to confirm before it creates or changes a record, and sending or replying to an email or deleting anything always requires the user’s confirmation. We do not use Senitix AI to make decisions about people that have legal or similarly significant effects.
How long it is kept
Senitix AI conversations are deleted automatically after 180 days without activity. Records a user creates or updates with Senitix AI’s help are kept like any other Customer Data.
10. Google user data and Limited Use
This section explains how Senitix accesses, uses, stores and shares information from Google when a user connects a Google account to Senitix, for example to see Gmail messages next to CRM records or to keep Google Calendar in sync. Senitix accesses only the Google account the user connects, only after the user authorizes it on Google’s consent screen, and only to provide features the user can see in Senitix.
The data we access and why
- Gmail (
gmail.modify). We read your messages, threads, attachments and labels so they appear next to the related CRM records; send, reply to and forward messages when you do so in Senitix; and apply the changes you make in Senitix, such as marking a message as read or archiving it. This permission does not allow permanent deletion of your messages. - Google Calendar (
calendar.eventsandcalendar.calendarlist.readonly). We read the list of your calendars so you can choose which one to sync, read your events to show your meetings and availability in Senitix, and create, update and delete the events you schedule or change in Senitix, so both sides stay in sync. - Basic profile (
userinfo.emailanduserinfo.profile). We identify the connected Google account and use the right sender address. The same information is used if you choose to sign in with Google.
How we use it
We use Google user data only to provide and improve the user-facing features described above. When you ask Senitix AI to work on a message or event, for example to summarize a thread, it processes that data to give you the result. We do not use Google user data for advertising, including retargeting or personalized ads, and we do not sell it. We do not use it to develop, improve or train generalized or non-personalized AI or machine-learning models.
How we share it
We do not transfer Google user data to anyone except: (a) as necessary to provide or improve the features you use, including to the service providers that host and run Senitix, such as AWS (and Amazon Bedrock when you use Senitix AI on that data), under contracts that limit their use of it; (b) within your organization’s workspace, according to the permissions its administrators set, for example when an email is linked to a shared CRM record; (c) to comply with applicable law; or (d) as part of a merger, acquisition or sale of assets, after telling you.
Human access
No one at Senitix reads Google user data unless you give us permission for specific messages or events (for example, when you ask our support team to look into a problem), it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized and is used for internal operations.
How we store and protect it
Google user data is stored on AWS in the European Union with the rest of the service and is encrypted in transit and at rest. The access tokens that let Senitix reach your Google account are stored encrypted, and only the people and systems that need them to run the feature can use them.
Retention and deletion
Synced messages are deleted after 365 days. When you disconnect a Gmail account in Senitix, we revoke our access and delete the messages and attachments we synced from it. When you disconnect Google Calendar, we stop syncing and revoke our access; meetings you scheduled in Senitix remain as activities in your organization’s workspace until it deletes them. You can also remove Senitix’s access at any time on your Google Account’s third-party access page, and you can ask us to delete Google user data we hold by writing to privacy@senitix.com. Deleted data can remain in our backups until they expire (section 13).
Limited Use
Senitix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Senitix’s use of information received from Google Workspace APIs will also adhere to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
11. Microsoft and other mail connections
Users can also connect a Microsoft Outlook mailbox and calendar, or any mailbox that supports IMAP and SMTP.
- Outlook mail (
Mail.ReadWriteandMail.Send). We read your messages and attachments so they appear next to the related CRM records, send the messages you write in Senitix, and apply the changes you make in Senitix, such as marking a message as read. - Outlook calendar (
Calendars.ReadWrite). We show your meetings in Senitix and keep the events you schedule in Senitix in sync with your calendar. - Basic profile (
User.Read). We identify the connected account and use the right sender address. The same information is used if you choose to sign in with Microsoft. - IMAP and SMTP. We store the server details and credentials you enter, encrypted, and use them only to sync and send your mail.
We handle this data under the same rules as Google user data in section 10: we use it only to provide the features you use; we do not sell it or use it for advertising; we do not use it to train AI models; people at Senitix read it only with your permission, for security or where the law requires; synced messages are deleted after 365 days; and disconnecting a mailbox revokes our access and deletes the messages we synced from it. You can also remove Senitix’s access in your Microsoft account’s app permissions.
12. International data transfers
Where the service runs. The Senitix application and its data are hosted on AWS in Frankfurt, Germany (region eu-central-1), with disaster-recovery copies in Ireland (region eu-west-1), and Senitix AI requests are processed in AWS Regions in the European Union. We do not host the service in the United States.
Where we work. Senitix is based in Türkiye. Our team operates, secures and supports the service from Türkiye and can access personal information from there when that work requires it. Your correspondence with us is handled there too.
Providers in other countries. Some of our service providers process information in the United States or on a global network, as listed in section 7 and on our Sub-processors page. If you accept analytics on our website, that includes Google: Google Ireland Limited processes it for visitors in the EEA, the UK and Türkiye, and Google LLC, based in the United States, for other visitors; transfers to the United States rely on the standard contractual clauses in Google’s data processing terms and, for Google LLC, its certification under the EU-U.S. Data Privacy Framework.
If you are in the United States, your personal information is transferred to and processed in the European Union and Türkiye, and in the United States by the providers named above. The data protection laws of those countries differ from the law of your state. This policy applies wherever your information is processed.
If you are in the EEA or the UK. Neither the European Commission nor the United Kingdom has found that Türkiye provides an adequate level of data protection. When you give us information directly, for example by signing up, writing to us or visiting our website, the GDPR or the UK GDPR applies to our handling of it as this policy describes. When a customer in the EEA or the UK transfers Customer Data to us, our Data Processing Agreement incorporates the standard contractual clauses adopted by the European Commission and, for UK data, the UK International Data Transfer Addendum. When one of our providers outside the EEA and the UK handles personal information for us, we rely on the standard contractual clauses in that provider’s data processing terms. You can ask for a copy of the safeguards that apply to your information at privacy@senitix.com; we may remove commercially sensitive terms from the copy.
Transfers from Türkiye. Because we are established in Türkiye, transfers we make from Türkiye to other countries are made under Article 9 of the Turkish Personal Data Protection Law No. 6698 (KVKK), using the standard contracts issued by the Turkish Personal Data Protection Board.
13. How long we keep personal information
We keep personal information only as long as we need it for the purposes in this policy, and then delete or anonymize it. Most deletion runs automatically. The main periods are:
| Information | How long we keep it |
|---|---|
| Account and profile information | While your account exists. If an administrator removes you from a workspace, your membership record is deleted after 365 days. If you sign up but never verify your email address, we delete the account after 30 days, with reminders before we do. |
| Billing records, invoices and contracts | 10 years, as Turkish tax and commercial law requires. If you ask us to delete your information, we anonymize the personal information in these records and keep the records. |
| Audit and security logs | 7 years |
| Sign-in attempts and expired sessions | 30 days |
| Server and application logs | Generally 30 days |
| In-app notifications | 90 days after they are read; 180 days if unread |
| Data export files | 30 days |
| Analytics data (Google Analytics, only if you accept analytics on our website) | 14 months in Google Analytics. Your cookie consent choice itself (the sx_consent cookie) is kept for 180 days. |
| Senitix AI conversations | Deleted after 180 days without activity |
| Website inquiries, support requests and other correspondence | As long as we need them to answer you, follow up and keep a record of our dealings with you or your organization; then deleted |
| Marketing preferences | Until you withdraw your consent. We keep a record of your consent and of any opt-out so that we can prove and honor it. |
| Backups | Daily backups for 35 days and monthly backups for 365 days, after which they are overwritten |
We may keep information longer when the law requires it, to resolve a dispute or enforce an agreement, or while a legal hold applies. Once we have verified a deletion request, we complete it within 30 days. Information deleted from the live service can remain in backups until those backups expire; we use backups only to restore the service after an incident.
Customer Data
We keep Customer Data for as long as the customer’s subscription lasts and as the customer instructs. By default, deleted records stay in a recycle bin for 90 days (a workspace can choose anywhere from 30 days to 7 years) and deleted files stay in the file trash for 90 days; synced email is purged after 365 days. When a customer cancels or closes its workspace, the workspace stays available read-only for 30 days so the customer can export its data, and the data is then deleted as our Data Retention Policy describes.
14. How we protect personal information
We use administrative, technical and physical safeguards suited to the information we handle, including:
- encryption in transit with TLS 1.2 or higher (TLS 1.3 where your browser supports it), and HTTP Strict Transport Security on our websites;
- encryption at rest, plus field-level AES-256-GCM encryption, with a separate key for each workspace, for designated sensitive fields;
- passwords stored only as salted one-way hashes, and new passwords checked against known breached passwords by a method that never sends the password itself;
- multi-factor authentication with an authenticator app, or by SMS where it is enabled, which workspace administrators can make mandatory; Senitix staff must use multi-factor authentication to reach our administrative tools;
- role-based access control, with each customer’s workspace kept separate in the application, and audit logs of account activity;
- daily and monthly backups stored in the European Union, in Frankfurt with copies in Ireland; and
- traffic filtering and protection against denial-of-service attacks through Cloudflare.
No method of transmitting or storing information is completely secure, so we cannot guarantee absolute security. If we learn of a breach that affects your personal information, we will notify you and the relevant authorities as the law requires. Our security page describes our measures in more detail. To report a vulnerability, write to security@senitix.com.
15. Your choices
- Marketing email. Every marketing email we send includes an unsubscribe link and our postal address. You can also change your preference in the application under Settings › Privacy, or write to privacy@senitix.com. We act on an opt-out promptly, and always within 10 business days. We will still send you service messages about your account.
- Your profile. Update your details in the application’s settings, or ask your workspace administrator.
- A copy of your data. Export your account data under Settings › Privacy, or ask us for a copy.
- Connected services. Disconnect a mailbox or calendar in Senitix at any time, and remove Senitix’s access from your Google or Microsoft account.
- Cookies. On our website, use the “Cookie settings” link in the footer of every page to accept, reject or change analytics cookies at any time, or block or delete cookies in your browser. The application’s sign-in and security cookies are needed to use it, so blocking them will stop you from signing in.
- Browser signals. Section 8 explains how we respond to Do Not Track and Global Privacy Control.
16. U.S. state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon and a growing number of other states have rights under their state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA). Some of these laws apply only to businesses above certain thresholds, and some do not cover information about people acting in a business or employment capacity. We honor the requests below from residents of any U.S. state; the details and exceptions depend on the law where you live.
Your rights
- Know and access. Ask what personal information we have collected about you, the categories of its sources, why we use it, the categories of third parties to whom we disclose it, and the specific pieces of information we hold. Where your state provides for it, as Oregon and Minnesota do, you can also ask for a list of the specific third parties to which we have disclosed personal information.
- Portability. Receive your personal information in a portable, readily usable format.
- Correct. Ask us to correct personal information that is inaccurate.
- Delete. Ask us to delete personal information we collected from or about you, subject to exceptions the law allows, such as invoices we are required to keep.
- Opt out. Opt out of the sale or sharing of personal information, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do none of these; section 8 explains how we honor opt-out signals.
- Limit the use of sensitive personal information. See below.
- Non-discrimination. We will not deny you service, charge you a different price or give you a lower quality of service because you exercised any of these rights. We do not offer financial incentives in exchange for personal information.
Sensitive personal information
We collect account log-in credentials (your email address together with a password, which we store only as a one-way hash) and, when you pay by card, your card number and security code, which go to our payment processor. We use and disclose this information only to provide the service, secure your account and take payments, which are uses the CCPA permits without a right to limit, and never to infer characteristics about you. For that reason we do not offer a “Limit the Use of My Sensitive Personal Information” link.
How to make a request
Email privacy@senitix.com with “U.S. privacy request” in the subject line. Tell us your name, the email address you use with Senitix or used to contact us, your state of residence and the right you want to exercise. If you have an account, you can also export your account data under Settings › Privacy. We will confirm that we received your request within 10 business days and respond within 45 days. If we need more time, up to another 45 days, we will tell you why. Requests are free; if a request is manifestly unfounded or excessive, we may decline it or charge a reasonable fee, as the law allows.
How we verify requests
To protect your information, we verify your identity before we act on a request to know, correct or delete. If you have an account, we will ask you to confirm the request from the email address on the account or while signed in. If you do not, we will match details you give us, such as your name, email address and the date and subject of your inquiry, against our records. For a request for specific pieces of information or to delete sensitive information, we may ask for more. We use the information you give us for verification only for that purpose. An opt-out request does not need verification.
Authorized agents
You can use an authorized agent to make a request for you. The agent must give us proof that you signed a permission for the request, and we may ask you to verify your identity with us directly or to confirm that you gave the agent permission. We do not ask for this when the agent holds a power of attorney under California Probate Code sections 4121 to 4130 or a comparable law. A parent or legal guardian can make a request on behalf of a child.
Appeals
If we decline to act on your request, in whole or in part, we will explain why. You can appeal by replying to our decision or by emailing privacy@senitix.com with “Privacy request appeal” in the subject line. We will answer your appeal in writing within 45 days of receiving it, explaining what we did and why. If we deny your appeal, we will tell you how to contact your state’s Attorney General to submit a complaint.
Other state notices
- California “Shine the Light.” We do not disclose personal information to third parties for their own direct marketing purposes.
- Nevada. We do not sell covered information as Nevada law defines it. Nevada residents can still send an opt-out request to privacy@senitix.com.
- Job applicants. This policy does not cover job applications. If you apply for a job with us, we will tell you separately how we handle your application.
17. Privacy rights in the EU, the UK and Türkiye
If you are in the European Economic Area (EEA) or the United Kingdom, the EU General Data Protection Regulation (GDPR) or the UK GDPR applies to the personal information we handle as a controller, and this section adds what those laws require us to tell you. Our GDPR and Data Protection page explains our roles and transfers in more detail.
Legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service, running your account, billing and support | Performance of our contract with you or your organization. For users an organization invites, our legitimate interest in providing the service the organization has bought. |
| Service messages | Performance of a contract; our legitimate interest in keeping users informed about their accounts |
| Answering inquiries sent through our forms or by email | Steps you ask us to take before entering into a contract; our legitimate interest in answering you |
| Security, fraud and abuse prevention, sign-in location checks, error monitoring and backups | Our legitimate interest in keeping Senitix and its users secure |
| Sanctions screening | Our legitimate interest in complying with the sanctions rules that apply to us and our providers; legal obligation where EU or UK law requires it |
| Tax, accounting and other records the law requires | Our legitimate interest in complying with Turkish law, which requires us to keep these records; legal obligation where EU or UK law applies |
| Improving the service using logs and error reports | Our legitimate interest in running and improving our products |
| Senitix AI and the services you connect | Performance of a contract: they are features you ask us to provide |
| Analytics cookies on our website | Your consent (Art. 6(1)(a)), which you can withdraw at any time in “Cookie settings” |
| Marketing email | Your consent, which you can withdraw at any time |
| Establishing, exercising or defending legal claims | Our legitimate interest in protecting our rights |
Where we rely on legitimate interests, we consider whether your rights and interests override them. You can ask us for details, and you can object.
What you need to give us
We need your name, email address, password and country to create an account, and billing details for a paid plan. Without them we cannot provide the service. Other fields are optional unless a form marks them as required.
Your rights
- Access the personal information we hold about you and receive a copy.
- Rectification of information that is inaccurate or incomplete.
- Erasure of your information where the law provides for it.
- Restriction of our use of your information while a concern is resolved.
- Portability of information you gave us, in a structured, machine-readable format.
- Objection to processing based on legitimate interests, and at any time to direct marketing.
- Withdrawal of consent at any time, without affecting what we did before you withdrew it.
- Human review of a decision based solely on automated processing, such as the sanctions check described in section 6.
To exercise a right, write to privacy@senitix.com. We will respond within one month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you why.
Complaints
You can complain to us about how we handle your personal information at privacy@senitix.com. We acknowledge a complaint within 30 days of receiving it, look into it without undue delay and tell you the outcome. You also have the right to complain to a supervisory authority: in the EEA, the authority in the country where you live or work or where you believe the infringement took place (the European Data Protection Board lists them); in the UK, the Information Commissioner’s Office.
Representative
We have not designated a representative in the EU or UK; you can reach us directly at privacy@senitix.com.
People in Türkiye
Because Senitix is established in Türkiye, the Turkish Personal Data Protection Law No. 6698 (KVKK) also applies to our processing. People in Türkiye can read our KVKK disclosure notice, in Turkish, on our Türkiye website, and can send an application under Article 11 of KVKK to privacy@senitix.com. We answer applications within 30 days.
18. Children
Senitix is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16, including children under 13 as defined by the U.S. Children’s Online Privacy Protection Act, and we do not sell or share the personal information of anyone under 16. If you believe a child has given us personal information, write to privacy@senitix.com and we will delete it.
19. Changes to this policy
We review this policy at least once a year and update it when our practices or the law change. The dates at the top of this page show when it was last updated and when the current version took effect. If we make a material change, we will tell account owners by email or in the application before the change takes effect, and we will not apply a material change to information we collected earlier without giving notice and, where the law requires, obtaining consent. You can ask us for an earlier version at privacy@senitix.com.
20. Contact us
- Privacy questions and requests, including U.S. state, GDPR and KVKK requests: privacy@senitix.com
- Legal notices: legal@senitix.com
- Security vulnerabilities: security@senitix.com
- Support and billing: support@senitix.com
- General questions: info@senitix.com or our contact form
- By mail: Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye
If you have a disability and need this policy in another format, write to privacy@senitix.com and we will provide it. You can also print this page.
