Privacy policy
What personal data SDEN collects, who processes it, why, for how long, and what you can ask us to do about it.
Last updated: August 18, 2026
Who is responsible
SDEN AI LLC, 254 Chapman Rd, Ste 208 #28196, Newark, DE 19702, United States, is the controller of the personal data described in this policy. You can reach us at info@sden.ai.
This policy covers sden.ai and the SDEN subdomains, the accounts area, the AI tools, the shop, the courses, and the support desk. It does not cover software we build for a client and run on that client's infrastructure: there the client is the controller and their own policy applies.
Where we act as a processor on a client engagement, we do so under a signed data processing agreement rather than under this policy.
What we collect and where it comes from
From forms you fill in: your name, email address, company, role, phone number where you give it, the content of your message, the project details you submit, and the country your request came from.
From your account: your email address, your name and profile image if your sign-in provider supplies them, and the billing details you enter (company name, VAT number, postal address, phone).
From purchases: what you bought, when, the amount, and identifiers from our payment processor. We never see or store your card number.
From support: the ticket you open, its category, the messages exchanged, and any email you send us, which is stored with its content so we can answer and keep a record.
From courses: your progress, quiz attempts, and the conversations you have with the course assistant.
From meetings: where a scheduled call is recorded, the recording, the transcript, a summary, and the names and email addresses of the participants.
From messaging: where you contact us on WhatsApp, the conversation and its messages.
Automatically: pages visited, referrer, UTM parameters and click identifiers, device and browser type, approximate country, and product events such as which step of a form you reached. Your IP address is used for rate limiting and abuse prevention, and is stored on a small number of records such as sign-in history, downloads and audit entries.
Why we use it, and on what legal basis
To answer you and to take steps at your request before entering into a contract, and to perform a contract once there is one. This covers enquiries, quotes, orders, deliveries, invoices, support and course access.
To comply with legal obligations, including tax and accounting records and responding to lawful requests.
On the basis of our legitimate interest in running and securing the business: preventing abuse and fraud, keeping audit and sign-in records, measuring how the site performs at an aggregate level, and contacting existing clients about services similar to ones we already provide them. You can object to any processing based on legitimate interest.
On the basis of your consent, where you gave it: analytics and advertising cookies, marketing emails to people who are not already clients, and call recording. You can withdraw consent at any time, and doing so does not affect processing that already happened.
We do not sell personal data, and we do not share it for cross-context behavioural advertising within the meaning of the CCPA/CPRA.
Artificial intelligence and your data
SDEN is an AI company and AI is used inside the product, not only in the tools you can see. This section exists because a generic privacy policy would hide that.
Content that may be sent to an AI provider includes: what you type into one of the public AI tools, the text of an email you send us and any reply we draft, support ticket content, the questions you ask a course assistant, and client records when a member of our team asks the internal assistant about an account.
Requests are routed to whichever provider is configured for that task. Any of the following may receive that content: Anthropic PBC (United States); OpenAI, L.L.C. (United States); Google LLC, Gemini models (United States); Mistral AI SAS (France); Groq, Inc. (United States); OpenRouter, Inc. (United States); Cloudflare, Inc., Workers AI (United States).
We also record prompts and responses in a self-hosted observability system on our own server, so we can debug quality and cost. That system is not a third party.
Two honest limits. We do not currently strip or mask personal data before sending it to a provider, and we do not currently hold a zero-retention agreement with every provider we route to. Please do not enter into our tools anything you are not permitted to disclose to a third-party AI service. If you need a written commitment on AI processing for an engagement, ask us and we will put it in the agreement.
We do not use your personal data to train our own models, and we do not sell it to anyone who does.
Who processes data on our behalf
We use the following sub-processors. Each one processes personal data only on our instructions and under a contract.
Cloudflare, Inc., United States, global edge network. Hosting, content delivery, object storage, bot protection and staff access control. Processes every request to the site.
Supabase, Inc., United States. The managed PostgreSQL database that stores the records described in this policy: enquiries, accounts, orders, support tickets, and client files.
Stripe, Inc., United States and Ireland. Payment processing. Card details are entered directly with Stripe and never reach our servers; we store only Stripe's customer and payment identifiers.
Resend, Inc., United States. Delivery of transactional email: sign-in links, order confirmations, download links, invoices and support replies.
PostHog, Inc., United States. Product analytics, loaded only after you accept analytics cookies. Some server-side events are recorded on a legitimate-interest basis and are described in the analytics section below.
Google LLC and Google Ireland Ltd, United States and Ireland. Analytics and advertising measurement, subject to your cookie choice. Separately, Google Workspace holds our mailbox, calendar and the document drive where client files are mirrored.
Meta Platforms, Inc. and Meta Platforms Ireland Ltd, United States and Ireland. Advertising measurement and lead forms, and WhatsApp Business messaging where you contact us that way. Where we send conversion data, contact details are hashed before transmission.
Sentry (Functional Software, Inc.), United States. Error monitoring, configured not to attach personal data to reports.
Discord, Inc., United States. Internal notifications to our team when an enquiry, order or support ticket arrives, and client discussion threads where a client has one.
Fathom Video, Inc., United States. Recording, transcription and summarising of scheduled calls, where the meeting is recorded. Participants are told at the start of the call.
Cal.com, Inc., United States. Meeting scheduling when you book a call with us.
Backblaze, Inc., United States. Encrypted off-site backup copies of the database and stored documents.
GitHub, Inc., United States. Source control, and the repositories we provision for client engagements.
We also run some services on our own servers rather than at a vendor: our newsletter delivery system, our automation and AI observability tooling. These are not third parties, but they hold personal data and are covered by the same security measures.
This list is kept current. If a sub-processor changes and you are a client, we tell you under your data processing agreement.
Where your data goes
SDEN is established in the United States and most of our sub-processors are too, so personal data is transferred to and processed in the United States and, through Cloudflare's edge network, potentially at other locations worldwide.
For transfers out of the European Economic Area, the United Kingdom and Switzerland, we rely on the European Commission's Standard Contractual Clauses with the UK addendum where relevant, and on the EU-US Data Privacy Framework where the recipient is certified under it.
We do not currently offer region-locked storage for our own products. If data residency in a particular jurisdiction is a requirement for you, tell us before an engagement starts, because it changes how we build.
How long we keep it
Analytics page-view records are aggregated and deleted after 90 days.
Enquiries and leads that do not become clients are kept for 24 months after the last interaction, then deleted.
Client records, contracts, invoices and the documents attached to an engagement are kept for the life of the relationship and then for as long as tax, accounting and limitation periods require, which in practice is up to ten years for financial records.
Support tickets and the email history attached to an account are kept for 24 months after the ticket is closed.
Course progress and certificates are kept while your access lasts and for 24 months afterwards, so a certificate can be reissued.
Meeting recordings and transcripts are kept for 12 months unless the engagement they belong to requires longer.
Sign-in history, download logs and audit entries, which contain IP addresses, are kept for 12 months.
Backups roll on their own cycle, so a record you asked us to delete can persist in a backup until that backup ages out, normally within 30 days.
You can ask us to delete your data sooner. See your rights below.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct it if it is wrong, to delete it, to restrict how we use it, to object to processing based on legitimate interest, and to receive it in a portable format. You can withdraw consent at any time and you can opt out of marketing with one click in any marketing email.
If you are in California, you also have the right to know what we collect and disclose, to delete it, to correct it, to limit the use of sensitive information, and not to be discriminated against for exercising those rights. If you are in Canada, you have equivalent rights under PIPEDA and, in Quebec, under Law 25.
To exercise any of these, write to info@sden.ai from the address we hold for you, or tell us which address the request concerns. We answer within 30 days, and we tell you if we need longer and why. We may ask you to confirm your identity before acting, and we will not charge you unless a request is manifestly unfounded or excessive.
We handle these requests by hand today rather than through a self-service button in your account. That is slower for you than it should be and we are changing it.
If you think we have got it wrong, you can complain to your data protection authority: the CNIL in France, the Garante in Italy, the AEPD in Spain, the ICO in the United Kingdom, the OPC in Canada, or the authority where you live. We would appreciate the chance to fix it first.
If we hold data about you and you never contacted us
Two cases. If you took part in a call with us that was recorded, we hold your name, your email address and what was said, because you were a participant. If someone at a client organisation gave us your details as a contact for a project, we hold those details for that purpose.
In both cases the source is the person or organisation that gave them to us, we keep the data for the periods above, and you have the same rights as anyone else. Write to info@sden.ai and we will tell you what we hold and remove it if you want us to.
Children
Our products are for adults. We do not knowingly collect personal data from anyone under 18 and we do not direct any part of the service at children. If you believe a child has given us personal data, write to info@sden.ai and we will delete it.
Security
Traffic is encrypted in transit, data is encrypted at rest by the platforms that hold it, internal systems are behind single sign-on that fails closed, and the most sensitive records are held in a separate database with an additional layer of encryption. Our security page describes the controls in place and, just as importantly, the ones that are not.
If you find a vulnerability, write to security@sden.ai. We answer within one business day.
Changes to this policy
We may update this policy. Every version carries a date and the current one is always published here. Where a change materially affects how we use data we already hold, we will tell you before it takes effect.
Contact
SDEN AI LLC, 254 Chapman Rd, Ste 208 #28196, Newark, DE 19702, United States. Privacy questions and requests: info@sden.ai. Security reports: security@sden.ai.