← Back to Sendora

Privacy Policy

Version 1.3 · Effective 2026-07-29

This Privacy Policy explains how Sendora AI LLC ("Sendora", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information in connection with the Sendora platform, websites, applications, browser extension, and related services (collectively, the "Services").

Sendora is an AI-powered sales development (SDR) and outbound-communications platform. On behalf of our business customers, the Services send outreach across email, SMS and MMS, LinkedIn, and WhatsApp, and place AI-assisted voice calls, to the business prospects those customers choose to contact. Because of this, Sendora plays two different roles depending on whose data is involved, and this Policy describes both.

This Privacy Policy provides information about Sendora's processing practices. It does not itself constitute consent for processing requiring affirmative consent. Where applicable law requires consent, Sendora or the relevant Customer will obtain separate, specific, informed, and affirmative consent before processing begins.

Please read this Policy together with our Terms of Service, our Data Processing Addendum (DPA), our Acceptable Use Policy, our Cookie Policy, our Sub-processor List, our AI Transparency Notice, our Prospect Privacy Notice, and our Data Retention Schedule, each of which is available from the legal footer of our website. If you do not agree with this Policy, please do not use the Services.

1. Introduction and Scope

Sendora is a United States-based limited liability company organized under the laws of the State of Wyoming, with a registered business address at 30 N Gould St Ste R, Sheridan, Wyoming, US 82801-6317. We provide a business-to-business (B2B) software-as-a-service platform used by companies to run and manage multi-channel outbound sales and marketing outreach.

This Privacy Policy applies to Sendora's websites, platform, applications, browser extensions, APIs, customer-hosted domains, embedded forms, communication tools, integrations, and other services controlled by Sendora.

It covers: (a) individuals who create or administer a Sendora account, or who otherwise use the Services on behalf of a business customer ("Customers" and their authorized users); (b) visitors to our public websites and anyone who contacts us; and (c) individuals whose personal information is uploaded to, or generated within, the Services by a Customer for the purpose of outreach ("Prospects" or "data subjects").

This Policy does not apply to third-party websites, products, or services that we do not own or control, including the mailboxes, calendars, customer relationship management (CRM) systems, telephony providers, and social or messaging networks that Customers connect to Sendora. Your use of those third parties is governed by their own privacy policies. It also does not govern the independent privacy practices of our Customers; where Sendora acts as a processor, the Customer is the party responsible for its own privacy notices and lawful basis for outreach (see Section 3).

By accessing or using the Services, or by submitting information to us, you acknowledge the practices described in this Policy. Where required by law, we obtain consent or rely on another lawful basis before processing your personal information, as described in Section 6.

2. Definitions

The following terms are used throughout this Policy. Where a term is defined in an applicable data-protection law, that statutory meaning also applies.

  • "Personal information" or "personal data" means any information relating to an identified or identifiable natural person, such as a name, email address, phone number, or online identifier. It includes "personal data" under the EU and UK General Data Protection Regulation (GDPR), "personal information" under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and "personal data" under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
  • "Controller" (or "business" under the CCPA/CPRA, "data fiduciary" under the DPDP Act) means the entity that determines the purposes and means of processing personal information.
  • "Processor" (or "service provider" under the CCPA/CPRA, "data processor" under the DPDP Act) means the entity that processes personal information on behalf of, and under the instructions of, a controller.
  • "Customer" means a business or organization that has registered for and uses the Services, and its authorized administrators and users.
  • "Prospect" or "data subject" means an individual whose personal information a Customer uploads into, or generates through, the Services in order to conduct outreach.
  • "Sub-processor" means a third party engaged by Sendora to process personal information in connection with providing the Services. Our current sub-processors are listed on our Sub-processor List.
  • "Special Category Data" means personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data used for identification, health data, or information concerning sex life or sexual orientation.
  • "Sensitive Personal Information" means information treated as sensitive under applicable law, including account credentials, financial information, government identifiers, precise geolocation, communication contents, and other legally protected information. These two categories are not the same: GDPR special-category data differs from sensitive information under American privacy laws, and each carries its own obligations. Sendora does not seek to collect either, and Customers are prohibited from uploading either without Sendora's prior written approval and a lawful basis (see Section 4 and our Acceptable Use Policy).
  • "Processing" means any operation performed on personal information, whether or not by automated means, including collection, recording, storage, use, disclosure, transfer, and deletion.

3. Our Two Roles: Controller and Processor

Understanding which role Sendora plays for a given category of data is essential, because it determines who is responsible for that data and to whom you should direct requests about it.

Sendora acts as a PROCESSOR where it processes Customer Data solely to provide Customer-configured services and follow documented Customer instructions. The prospect and lead records a Customer uploads, and the messages, calls, transcripts, and outreach content generated on the Customer's behalf, fall into this category. For that data the CUSTOMER is the controller, and the Customer is responsible for having a valid lawful basis to contact each Prospect and for providing any privacy notice those individuals are owed. Sendora acts as an independent CONTROLLER for account management, billing, security, fraud prevention, abuse prevention, legal compliance, corporate administration, service analytics, and the establishment or defence of legal claims. For that data this Policy is our direct notice to you.

Where Sendora acts as a processor, our handling of Prospect data is governed by our Data Processing Addendum (DPA) with the Customer, which is incorporated into the Terms of Service. In that role we do not decide who is contacted, what is said, or for what purpose; we execute the Customer's campaigns and provide tools such as the campaign builder, unified inbox, CRM sync, lead enrichment, knowledge base, and the LinkedIn browser extension.

If you are a Prospect and you want to exercise your rights over data a Customer holds about you, we will, where required, route your request to the relevant Customer (the controller) and assist them in responding. See Section 14 for how Prospects can contact us and opt out.

Sendora may also act as an independent Controller where it independently collects, combines, enriches, or uses personal data for Sendora's own purposes. Such processing will be separately disclosed and supported by an appropriate legal basis. For a limited set of operational activities that we carry out on our own behalf even for Prospect data (for example, securing our infrastructure, preventing fraud and abuse, maintaining audit logs, and meeting our own legal obligations), Sendora acts as an independent controller to the extent permitted by law, and limits such processing to what is necessary and compatible with the original purpose.

Where Sendora and a Customer jointly determine processing purposes or essential means, their respective responsibilities will be documented under applicable law. Legal roles depend on actual processing decisions, not on contractual labels alone; where our actual role differs from the description here for a specific activity, the actual role governs.

4. Information We Collect

We collect personal information in several ways: information you or your organization provide directly; information Customers upload or generate through the Services; information from connected third-party accounts and enrichment providers; and information collected automatically as you use the Services.

Account and profile data (Sendora as controller). When you register or use the Services, we collect your name, business email address, phone number, job title, organization name, authentication credentials, profile preferences, workspace and team membership, language, and time zone. We also record your role and permissions within a workspace.

Billing and payment data (Sendora as controller). We collect billing contact details, plan and subscription information, and transaction history. Card payments are processed by our payment processor, Stripe. Sendora does not receive or store full payment card numbers; Stripe provides us only with limited tokens and metadata (such as the card brand, last four digits, expiry, and billing country) needed to manage your subscription. Usage-based metering is calculated for invoicing.

Prospect Data may be received from Customers, connected CRM systems, email accounts, calendars, employers, company websites, public professional profiles, licensed data providers, enrichment providers, and communications initiated through the Service. Where Sendora independently determines the purpose of collecting such information, Sendora will disclose the relevant source categories, purposes, legal bases, recipients, transfers, retention periods, and available rights, as required by Article 14 GDPR. Our standalone Prospect Privacy Notice sets these out in full.

Customer-uploaded Prospect data (Sendora as processor). Customers upload or sync records about the business Prospects they wish to contact. This typically includes the Prospect's name, business email address, phone number, company, job title, LinkedIn profile URL, and Customer-defined custom fields. The Customer is the controller of this data and is responsible for its accuracy, its lawful collection, and its lawful use for outreach. Customers are contractually prohibited from uploading special-category, sensitive, or consumer data that they lack a lawful basis to process through the Services.

Communications content (Sendora as processor). To deliver and manage outreach, the Services store the content of messages exchanged with Prospects across channels, including email subject lines and bodies, SMS and MMS message bodies and attachments, LinkedIn connection notes and direct messages, and WhatsApp message bodies and media. Inbound replies from Prospects are ingested into the unified inbox so the Customer, and where enabled the Customer's configured AI reply agents, can respond.

Voice and call data (Sendora as processor). For AI-assisted voice calls, we process the Prospect's phone number, call metadata (such as time, duration, direction, and outcome), call recordings where the call is recorded, and machine-generated transcripts of the call. Sendora may process call audio, transcripts, synthetic voices, speaker information, and communication metadata. Sendora does not use voice characteristics for biometric identification unless separately disclosed, legally assessed, and expressly authorised.

Recording responsibilities are shared, not transferred. Customers must determine whether recording or transcription is lawful for each communication, and recording must not begin until any legally required notice or consent has been completed. Sendora provides configurable recording controls and disclosure mechanisms, and Sendora remains responsible for obligations arising from recording features, defaults, disclosures, or processing decisions that Sendora independently controls.

Connected-account credentials and tokens (Sendora as processor and, for the connection itself, controller). When a Customer connects a mailbox (for example via Gmail, Microsoft, or SMTP), a calendar, a CRM, or a messaging or telephony provider, we receive and store the OAuth access and refresh tokens or other credentials needed to send, receive, and sync on the Customer's behalf. User passwords are protected through appropriate one-way hashing by our authentication provider. OAuth tokens, API keys, integration credentials, and other recoverable secrets are encrypted at rest using authenticated symmetric encryption and are access-restricted; they are used only to operate the integration the Customer authorized, and are never included in any data export.

Enrichment and lead-sourcing data from third parties. When a Customer uses lead enrichment or lead sourcing, the Services retrieve additional business-contact and firmographic attributes about a Prospect (such as company size, industry, or corrected contact details) from third-party data providers and attach them to the Prospect record. Some of these data providers are engaged by Sendora on its own accounts and are identified in our Sub-processor List; others are enrichment providers the Customer connects as its own integration using its own credentials, in which case they act as the Customer's own third parties rather than Sendora sub-processors, as described in Section 7. In each case the enriched data is added to the Customer's workspace for the Customer's outreach, and the Customer, as controller, is responsible for the lawful use of that data.

Usage, device, and cookie data (Sendora as controller). We automatically collect information about how you interact with the Services, including IP address, device and browser type, operating system, pages and features viewed, actions taken, timestamps, referring URLs, and diagnostic and performance data. We use product-analytics tooling and cookies or similar technologies for these purposes, as described in our Cookie Policy at /privacy?doc=cookies.

Support and other communications (Sendora as controller). When you contact us for support, respond to a survey, or otherwise communicate with us, we collect the content of those communications and any information you choose to provide, along with metadata about the interaction.

We do not intentionally collect special categories of personal data (such as health, biometric, or precise-geolocation data) or data about children. Customers must not upload such data or any Prospect data they lack a lawful basis to process. If we become aware that prohibited data has been uploaded, we may remove it.

5. How We Use Information

As a controller of account data, we use personal information to operate, secure, and improve the Services and to run our business. As a processor of Prospect data, we use personal information only to provide the Services on the Customer's documented instructions and as permitted by our DPA.

  • Provide and operate the Services: create and manage accounts and workspaces, authenticate users, build and run campaigns, send and receive messages and calls across channels, sync with connected CRMs and calendars, power the unified inbox, and store the knowledge base a Customer configures.
  • Enable AI features: generate suggested and, where the Customer enables it, automated replies; classify call outcomes; personalize outreach using Customer-provided context; and summarize research and conversations. AI processing is performed to deliver features the Customer has turned on, and Customers may configure their own AI provider and model.
  • Billing and account administration: calculate usage, process subscription payments through Stripe, issue invoices, prevent payment fraud, and manage plan entitlements and limits.
  • Security, integrity, and abuse prevention: authenticate access, enforce tenant isolation, detect and prevent fraud, spam, and abuse, maintain audit logs, and protect the rights and safety of Sendora, our Customers, Prospects, and the public.
  • Support and service communications: respond to your requests, send administrative and transactional messages, and notify you of important changes to the Services or to legal terms.
  • Product analytics and improvement: understand how the Services are used, diagnose problems, measure performance, and develop new and improved features. We use aggregated or de-identified data for these purposes where feasible.
  • Legal and compliance: comply with applicable laws and regulations, respond to lawful requests, enforce our Terms of Service and Acceptable Use Policy, establish, exercise, or defend legal claims, and maintain records we are required to keep.
  • Marketing (account holders only, where permitted): send you information about features, offers, and events, subject to your consent where required and always with an option to opt out. We do not use Prospect data uploaded by Customers for our own marketing.

Sendora will not use Customer Content, Prospect Data, recordings, transcripts, prompts, embeddings, communication contents, or model outputs to train or fine-tune general-purpose artificial intelligence models without separate written Customer authorisation. Sendora may use irreversibly de-identified and aggregated operational statistics to maintain and improve the Service, provided such information cannot reasonably identify any Customer, user, Prospect, or communication. Sendora accesses each AI Provider under its business or API terms, which for most providers do not permit training on submitted data by default; where a provider trains by default, Sendora sets that provider opt-out on every request. Sendora does not opt in to any model-improvement program and does not authorise any AI Provider to use Customer Data for advertising, independent profiling, general model training, or unrelated product development. Per-provider detail is published on our Sub-processor List.

Sendora's AI features may generate communications, classify messages, summarise calls, rank leads, recommend actions, and automate Customer-configured workflows. Sendora does not use these features to determine eligibility concerning employment, credit, housing, insurance, healthcare, education, legal services, or essential public services, and Customers are prohibited from doing so under our Acceptable Use Policy.

We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you without a lawful basis and appropriate safeguards. Where AI features assist a Customer, a human user of the Customer retains control over campaigns and can review outputs. Our AI Transparency and Responsible Use Notice describes our AI functions, model providers, human oversight, and limitations in full.

Privacy-law compliance and marketing-law compliance are separate. Customers must establish both a lawful basis under applicable data-protection law and separate compliance with electronic-marketing, telemarketing, recording, sender-registration, consent, and suppression requirements. A lawful basis under privacy law does not by itself authorise a marketing communication.

7. How We Share Information

We share personal information only as described in this Policy. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We do not sell your personal data. Sendora does not sell personal information for money or other valuable consideration, and does not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding twelve months.

Sub-processors and service providers. We engage carefully vetted third parties to help us deliver the Services, such as cloud hosting and infrastructure, database and storage, payment processing (Stripe), email, SMS/MMS, LinkedIn and WhatsApp connectivity, voice telephony and transcription, AI model providers, product analytics, and error monitoring. These providers process personal information only on our instructions and under contractual confidentiality and security obligations. Our current sub-processors, and the categories of data each handles, are listed on our Sub-processor List at /privacy?doc=subprocessors, which we keep up to date.

Integrations at your direction. When a Customer connects a third-party mailbox, calendar, CRM, messaging network, or telephony provider, we exchange data with that service to perform the integration the Customer authorized (for example, sending an email from the connected mailbox, or writing an activity back to the connected CRM). Third-party recipients may act as Processors, Sub-processors, independent Controllers, or Customer-directed providers, depending upon their actual functions and contractual arrangements; a provider is not an independent controller merely because it is a third party. Sendora identifies the applicable role for each provider within its Sub-processor List or another appropriate notice.

Within a Customer workspace. Personal information within a workspace is accessible to the Customer's authorized users according to the roles and permissions the Customer configures. Sendora enforces strict tenant isolation so that one Customer's data is not accessible to another Customer.

Legal, safety, and compliance. We may disclose personal information if we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our Terms of Service or Acceptable Use Policy; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Sendora, our Customers, Prospects, or others. Unless legally prohibited, Sendora will notify the affected Customer before disclosing Customer Data to a public authority. Sendora will review each request for legal validity, challenge unlawful or disproportionate demands where reasonably available, and disclose only the minimum information legally required.

Business transfers. If Sendora is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this Policy or provide notice and choices consistent with applicable law before any personal information becomes subject to a materially different privacy policy.

Aggregated or de-identified data. We may create and share aggregated or de-identified information that cannot reasonably be used to identify you, for purposes such as analytics, benchmarking, and improving the Services. We maintain and use such information only in de-identified form and do not attempt to re-identify it except to test our de-identification.

8. International Data Transfers

Sendora is based in the United States, and we and our sub-processors may process personal information in the United States and other countries that may have data-protection laws different from those in your jurisdiction. When we transfer personal information across borders, we implement safeguards required by applicable law.

  • European Economic Area transfers: where we transfer personal data from the EEA to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs), together with any supplementary technical and organizational measures needed to protect the data.
  • United Kingdom transfers: for transfers from the UK, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as appropriate.
  • Swiss transfers: for transfers from Switzerland, we rely on the SCCs as recognized by the Swiss Federal Data Protection and Information Commissioner, with Switzerland-specific adaptations.
  • Data Privacy Framework: if and where Sendora certifies to the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework (DPF), we will state our certification and honor its principles; unless and until certified, we do not claim DPF participation and rely on the mechanisms above.
  • India transfers: personal data of individuals in India is transferred and processed consistent with the DPDP Act and any restrictions the Government of India may notify on transfers to particular countries.

Sendora will identify the relevant data exporter, importer, destination, transfer purpose, data categories, transfer mechanism, and supplementary safeguards before making a restricted international transfer. Where required, Sendora will complete transfer impact assessments or transfer risk assessments addressing government access, enforceable rights, onward transfers, and technical safeguards. Transfers involving Brazil will use a mechanism recognised under applicable LGPD transfer regulations. Optional processing within restricted or higher-risk jurisdictions will remain disabled unless the Customer knowingly selects such processing and the required safeguards are completed.

You may request a copy of the relevant transfer safeguards by contacting us using the details in Section 16. When Sendora acts as a processor, cross-border transfers of Prospect data are governed by the transfer terms in our DPA with the Customer.

9. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, to provide the Services, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Retention periods depend on the type of data and the role in which we process it. The periods below are our stated retention periods; they are extended only where a longer period is required by law, or where data is subject to a legal-preservation duty, in which case it is isolated and access-restricted until it can be deleted. Our full Data Retention Schedule is published alongside this Policy. You can ask us to delete your data as described in Section 11.

Data categoryStandard retention period
Prospect / lead personal information (as processor)Retained during the subscription term and for thirty (30) days following termination, unless deleted earlier. Customers can delete this data at any time.
Production copies after the export periodDeleted within thirty (30) days after the thirty-day post-termination export window closes.
Routine backupsDatabase backups are taken every six hours and retained on a rolling fourteen (14) day window locally, thirty (30) days off-box, so a deleted record leaves every backup set within thirty days and in any event within ninety (90) days of production deletion.
Voice call recordings and transcriptsRetained for the Customer-configured retention period, which is displayed before the recording feature is activated. Where no period is configured, recordings follow the Prospect-data period above.
Account and profile data (as controller)Retained for the life of the account and for thirty (30) days after closure, plus any period required by law.
Security and processing logsRetained for twelve (12) months, unless longer retention is legally required.
Support recordsRetained for twenty-four (24) months after the request is closed.
Billing, invoicing, and taxation recordsRetained for the period required by tax, accounting, and other legal obligations (commonly up to 7 years).
Consent, opt-out, and suppression recordsSuppression records are kept for as long as needed to give continued effect to the opt-out. Consent and legal-acceptance records are kept for applicable limitation periods, and are anonymised on workspace deletion - the IP address, user agent and user identifier are removed, leaving only the document, its version and the date.
Usage, analytics, and cookie dataRetained in identifiable form for twelve (12) months, then aggregated or de-identified.

When a retention period ends, we delete, anonymize, or aggregate the personal information, or if deletion is not immediately possible (for example, because data is stored in secure backups), we securely store it and isolate it from further processing until deletion is possible. Customers can also delete records and export data from within the Services at any time, subject to their plan and role.

10. Data Security

We maintain administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our measures include, without limitation:

  • Encryption in transit using TLS for data moving between your device, the Services, and our sub-processors.
  • Encryption at rest for sensitive stored data, with per-tenant credentials and vendor secrets protected using authenticated symmetric encryption (such as AES-256-GCM, or AES-128-CBC with HMAC-SHA256).
  • Strict multi-tenant isolation enforced at the database layer through row-level security, so that each Customer can access only its own workspace data.
  • Role-based access controls and the principle of least privilege for internal access, with administrative access limited to personnel who need it to operate the Services.
  • Comprehensive audit logging of security-relevant events, including authentication, permission changes, and administrative actions.
  • Secure software-development practices, dependency and vulnerability management, and monitoring and alerting for anomalous activity.
  • Secrets management that keeps credentials out of source code and logs, with redaction of sensitive values. Credentials and secrets are never included in a data export, in any form, including encrypted.
  • Privileged-access controls, SSH key-based authentication for production infrastructure, multi-factor authentication on the identity providers holding privileged access, and periodic access reviews.
  • Dependency vulnerability scanning, patch management, and dependency management. We do not claim an independent third-party penetration test; see our Security and Trust Centre for what we have and have not done.
  • Backup restoration testing, business-continuity controls, incident-response exercises, environment segregation, secure deletion, employee security training, and vendor security reviews.

Sendora will not claim any certification unless that certification remains valid and covers the relevant Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for using strong, unique passwords and available account-security features. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities as required by applicable law and, where Sendora is a processor, will notify the affected Customer without undue delay in accordance with our DPA.

11. Your Rights and Choices

Depending on where you live and the role in which we process your data, you may have rights over your personal information. Where Sendora is the controller (account data), you can exercise these rights directly with us. Where Sendora is a processor (Prospect data), we will refer your request to the relevant Customer, who is the controller, and assist them as required.

How to exercise your rights. Account holders can access, update, export, or delete much of their information, and manage consent, directly in the product under Settings then Privacy and Consent (including export, delete, and withdraw-consent controls). You may also email us at support@sendora.ai. We will respond within the timeframe required by applicable law (generally within 30 days under the GDPR and UK GDPR, and within 45 days under the CCPA/CPRA, each extendable where permitted). We may need to verify your identity before acting on a request, and we will not discriminate against you for exercising your rights.

11.1 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR). If you are in these regions, you have the rights to: access your personal data; rectify inaccurate or incomplete data; erase your data ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests or to direct marketing; and, where processing is based on consent, withdraw that consent at any time. You also have the right to lodge a complaint with your local data-protection supervisory authority. To exercise any of these rights, contact us at support@sendora.ai.

11.2 California (CCPA / CPRA). If you are a California resident, you have the rights to: know and access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; delete personal information we have collected from you, subject to exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information; and limit the use and disclosure of sensitive personal information. As noted in Section 7, we do not sell or share personal information and do not use sensitive personal information for purposes that trigger the right to limit. You have the right not to receive discriminatory treatment for exercising your CCPA/CPRA rights, and you may use an authorized agent to submit requests.

11.3 India (DPDP Act, 2023). If you are a Data Principal in India, you have the rights to: access a summary of your personal data and processing; correction, completion, updating, and erasure of your personal data; grievance redressal; nominate another individual to exercise your rights in the event of death or incapacity; and withdraw consent where processing is based on consent. India-specific statutory rights described within this Policy will apply from the date the relevant provisions of the DPDP Act and applicable Rules become legally effective. Before such commencement, Sendora may voluntarily honour equivalent requests, subject to verification and applicable law. To raise a grievance, contact us at support@sendora.ai; we will respond within the timeframe prescribed by the DPDP Act and its rules once they are in force.

11.4 Canada (PIPEDA and CASL). If you are in Canada, you have the right to access and request correction of your personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, and to withdraw consent subject to legal or contractual restrictions. Commercial electronic messages we send you are subject to Canada's Anti-Spam Legislation (CASL); you can unsubscribe from our marketing messages at any time using the link in the message or by contacting us. You may also complain to the Office of the Privacy Commissioner of Canada.

Other jurisdictions. Residents of other U.S. states and countries with comprehensive privacy laws may have similar rights, including rights to access, correct, delete, and opt out of certain processing. We honor applicable rights regardless of where you live; contact us using the details in Section 16 and we will apply the protections your law provides.

11.5 Right to appeal a decision. If we decline to act on a privacy request, and you are covered by a U.S. state privacy law that provides an appeal right (including Colorado, Connecticut, Virginia, Texas, Montana, Oregon, and other states with comparable laws), you may appeal our decision within a reasonable period by replying to our response or by emailing support@sendora.ai with the subject line "Privacy Request Appeal." We will review the appeal and inform you in writing of our decision, and the reasons for it, within the time your state law requires (generally within 45 to 60 days of receipt). If we deny your appeal, we will provide a method for you to contact your state Attorney General to submit a complaint.

12. Cookies and Tracking Technologies

We and our providers use cookies, local storage, pixels, and similar technologies to operate the Services, remember your preferences, keep you signed in, maintain security, and understand and improve how the Services are used (including through our product-analytics provider, PostHog).

Strictly necessary cookies are required for the Services to function and cannot be switched off in our systems. For non-essential cookies (such as analytics), we obtain consent where required and provide controls to manage your preferences. You can also control cookies through your browser settings, though disabling some cookies may affect functionality.

For a full description of the cookies and similar technologies we use, their purposes, and how to manage them, please see our Cookie Policy at /privacy?doc=cookies. Sendora recognises legally valid opt-out preference signals, including the Global Privacy Control (GPC), where applicable. Where Sendora does not conduct covered sale, sharing, or targeted-advertising processing, receipt of such a signal will not trigger additional processing, because there is no such processing to opt out of. Separately, Sendora does not presently respond to legacy Do Not Track signals, because no uniform legal interpretation of them applies.

13. Account Security and Abuse Prevention

To keep accounts secure and to stop the Services being used to send unwanted or harmful messages, we record information about how each account is accessed and used. This section explains exactly what that means, because monitoring you are not told about is not something we are willing to do.

What we record

  • Sign-in sessions: the IP address, browser, operating system and device type each session came from, and the approximate location that IP corresponds to, at country level and, where available, city level. We do not collect or store precise coordinates.
  • Activity records: significant actions taken in a workspace, such as changes to permissions, plans, sending limits, integrations, and exports of data, together with who took them, when, and from what IP address.
  • Sending behaviour: aggregate measures of how much a workspace sends and how recipients respond, including bounce, spam-complaint and opt-out rates.

Why we record it

To detect a compromised account and let you see and end your own sessions; to detect and stop abuse of the Services; and to protect the deliverability of every customer sharing our sending infrastructure. Our legal basis is our legitimate interests, and those of our customers, in a secure and non-abusive service. We have weighed those interests against your privacy: the data is limited to what the purpose requires, location is deliberately coarse, it is not used for advertising, profiling unrelated to security, or any automated decision other than the abuse checks described below, and it is deleted on the schedule published at /privacy?doc=retention-schedule.

Automated abuse checks, and your right to a human

We apply automated checks to the measures above. Where a check matches, the response is graduated: we first notify, then warn, and only then may we pause a workspace’s outbound sending. Pausing sending does not remove access to your inbox, contacts, campaigns or settings, so you can correct the cause and continue to reply to people who have already responded. Suspension is reserved for cases where continuing would cause serious and irreversible harm.

Every such message tells you what behaviour was detected, the actual figure we measured, what to do about it, and what has changed on your account. Every automated restriction is reviewed by a member of our team, and you can ask us to look again at any time by replying to the notification or emailing support@sendora.ai. You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, the right to obtain human intervention, to express your point of view, and to contest the decision. We will not restrict an account on a purely automated basis without that route being available to you.

What we do not do

We do not read the content of your messages for these checks; the measures used are counts and rates, not message contents. We do not use security or abuse-prevention data for advertising or to build a profile of you for any purpose unrelated to security. We do not sell or share it.

14. Children's Privacy

The Services are a business-to-business product intended solely for use by organizations and their authorized personnel. The Services are not directed to individuals below eighteen (18) years of age, in any jurisdiction. Customers must not upload information concerning minors or use the Services to contact minors. Sendora may suspend affected processing and securely delete such information upon discovery.

Customers must not upload data about children or use the Services to contact minors. If we learn that we have inadvertently collected personal information from a child without appropriate consent, we will take reasonable steps to delete it. If you believe a child has provided us with personal information, please contact us at support@sendora.ai.

15. Notice to Prospects and Data Subjects

If you received an email, SMS or MMS, LinkedIn message, WhatsApp message, or voice call that was delivered using Sendora, that outreach was sent by one of our Customers using our platform, not by Sendora itself. For that outreach, the Customer is the controller of your personal information: the Customer decided to contact you, chose the content, and is responsible for having a lawful basis to do so and for providing any privacy notice you are owed.

If you receive outreach delivered through Sendora, the identified Customer generally determines why you were contacted, the campaign content, and the communication channel. Your information may have been obtained from the Customer, its connected systems, your employer, company websites, public professional sources, licensed data providers, enrichment providers, or your communications with the Customer.

Sendora acts as a Processor when delivering Customer-configured outreach solely upon Customer instructions. Sendora acts as an independent Controller for security, abuse prevention, legal compliance, and other independently determined activities described within this Policy. Where required, information concerning data categories, sources, purposes, lawful bases, recipients, international transfers, retention, and rights will be provided within the legally prescribed period. Our standalone Prospect Privacy Notice sets all of this out in one place.

If you are speaking to an AI. Any AI voice or conversational agent operating through Sendora must disclose its artificial nature at the beginning of the interaction, unless that fact is already obvious. It must identify the Customer on whose behalf it is contacting you, state the purpose of the communication, and give you a way to end the interaction or ask for a human. If an AI agent using Sendora ever tells you it is a human being, that is a breach of our Acceptable Use Policy and we want to hear about it at support@sendora.ai.

The fastest way to stop receiving messages or to exercise your rights over your data is to respond to the Customer directly:

  • Email: use the unsubscribe or opt-out link included in the message, or reply asking to be removed.
  • SMS / MMS: reply STOP (or the opt-out keyword shown in the message) to stop further messages.
  • WhatsApp / LinkedIn: reply asking to stop, or block the sender within that app.
  • Voice calls: tell the caller or agent that you do not wish to be contacted, and you will be added to the do-not-contact list for that campaign.

When you opt out through any of these channels, Sendora records the request and suppresses further outreach for that Customer across the relevant channel. You may also contact us at support@sendora.ai; where we can identify the Customer that holds your data, we will route your request to that Customer (the controller) and assist them in responding, and we will honor any suppression we are able to apply on our side. Sendora will not use Prospect data for its own marketing.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the version number and the effective date shown at the top of this Policy and post the updated Policy in the legal section of our website.

If the changes are material, we will provide additional notice as required by law, such as by email or an in-product notice, and where appropriate we may require you to re-accept the Policy before continuing to use the Services. Updated privacy terms apply prospectively from their stated effective date. Continued use of the Services constitutes acknowledgment of the revised Policy, but will NOT constitute consent to materially different processing where applicable law requires separate affirmative consent; in that case we will ask you separately. We encourage you to review this Policy periodically.

17. How to Contact Us

If you have questions, requests, or complaints about this Policy or our handling of personal information, please contact us using the details below. We will do our best to resolve your concern, and where required we will cooperate with the relevant supervisory or data-protection authority.

  • Controller / legal entity: Sendora AI LLC, organized in Wyoming, with a registered address at 30 N Gould St Ste R, Sheridan, Wyoming, US 82801-6317.
  • Privacy contact / email: support@sendora.ai
  • Representatives and privacy contacts: where legally required, Sendora will publish the name, address, and contact details of its European Union representative, United Kingdom representative, Data Protection Officer, or designated privacy contact. Until such an appointment is published, all privacy enquiries should be directed to support@sendora.ai.
  • Governing law: this Policy is governed by the laws of the State of Wyoming, United States, without regard to its conflict-of-laws rules, except where mandatory local data-protection law applies to you.
  • Mandatory rights are preserved: nothing within this Policy limits any mandatory privacy right, regulatory jurisdiction, statutory remedy, or protection available under applicable law. Wyoming governing law does not displace mandatory international privacy protections.

If you are located in the EEA, the UK, Switzerland, India, Canada, or a U.S. state with a comprehensive privacy law and you are not satisfied with our response, you also have the right to lodge a complaint with your local supervisory or data-protection authority. We would, however, appreciate the opportunity to address your concerns before you approach a regulator.

© 2026 Sendora. This document is version 1.3, effective 2026-07-29.