Summary: We collect only what is needed to respond to your enquiry and to provide demos or proofs-of-concept. We never sell personal data. Marketing emails are sent only if you opt in. For enterprise customers, we act as a processor and follow the DPA below.
Special categories: we do not seek special category data. Because work tools may include free text, customers should apply minimization, blocklists, and retention.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Run/secure the site | device and usage data, logs | legitimate interests; security |
| Respond to enquiries & schedule demos | contact details, message | pre-contract steps or contract |
| Send product updates | contact, preferences | consent (opt-in only) |
| Provide & improve the product | account data, telemetry | contract; legitimate interests |
| Process end-user work signals | connected content & metadata | contract with customer |
| Security & legal compliance | logs, audit trails | legitimate interests; legal obligation |
We use service providers acting under contract as our processors to: host infrastructure; send emails; manage leads and scheduling; protect against bots; deliver analytics (consent-based); and provide CDN/WAF. We do not sell personal data. We may disclose data if required by law or to protect safety.
International transfers: if data moves outside the EEA/UK/Switzerland, we rely on EU Standard Contractual Clauses (2021) and relevant UK/Swiss addenda plus supplementary measures (encryption in transit/at rest, access controls).
Depending on your location, you may have rights to access, rectification, deletion, restriction, portability, object to processing, and withdraw consent.
SSO (SAML/OIDC) and least-privilege access for admins, MFA, encryption in transit and at rest, optional customer-managed keys, tenant isolation, private networking, IP allowlists, immutable audit logs, monitoring/alerting, vulnerability management and pen tests, disaster recovery with documented RPO/RTO.
This section forms a Data Processing Addendum between Customer (controller) and Colentia (processor) once you sign a service order or otherwise engage Colentia to process personal data on your behalf.
Processing personal data as necessary to provide the Colentia services (ingestion from connected systems; normalization/enrichment; knowledge graph; search/Q&A with citations; dashboards; support and security) for the term of your agreement and until deletion/return.
Customer is the controller; Colentia is the processor. We process only on documented instructions from Customer, including those given through product settings and APIs.
All personnel with access to personal data are bound by confidentiality and receive privacy/security training.
We implement appropriate technical and organizational measures proportionate to the risk, including SSO/SCIM, MFA, encryption in transit/at rest with cloud KMS, customer-managed key option, network isolation, Private Link/peering, IP allowlists, immutable audit logs, monitoring, secure SDLC, penetration tests, and business continuity/disaster recovery.
Customer authorizes Colentia to use sub-processors to provide the services. We impose the same data-protection obligations by contract and remain liable for them. Categories: cloud hosting & storage; key-management; email delivery; CRM/marketing automation; scheduling/meeting tools; CDN/WAF & anti-bot; analytics (consent-based only).
We assist Customer via appropriate technical and organizational measures to fulfill rights requests (access, rectification, erasure, restriction, portability, objection).
We will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer data.
At termination or upon request, we delete or return all personal data and then delete existing copies from active systems. Backups are purged on a rolling schedule.
For transfers outside the EEA/UK/Switzerland, the EU SCCs (2021) are incorporated (Module 2 for controller→processor and Module 3 for onward processor transfers) plus the UK Addendum and Swiss addendum as relevant.
All privacy and data requests: contact@colentia.com