Skip to content
Imsenta
Book a walkthrough

Privacy

What we hold, why we hold it, where it lives and who else is involved.

Last updated [date].

1. Who we are

[company legal name], of [registered address], provides Imsenta. For questions about this policy or about your data, write to [email protected].

2. Two different kinds of data

It matters which one is being discussed, because our role differs.

Account data is the information we hold to run the service for you: the names and email addresses of your users, your organisation details, billing information and our own logs. We decide how that is used, so we are the controller of it.

Your content is what you put into Imsenta: policies, drafts, comments, approvals and anything personal that happens to be inside them. We process that only on your instructions, in order to provide the service. You are the controller and we are the processor.

3. What we collect

For account data: name, work email address, the organisation you belong to, your role, and the identity provider you sign in with if you use single sign-on. We do not store a password when you sign in through your own provider.

We also record an audit log of activity in your organisation, including sign-ins and failed sign-in attempts, with the time, the account concerned and the network address the request came from. That log is part of what the product is for: it is the evidence trail our customers need, and it is available to your administrators and to your own security tooling.

We collect ordinary server logs for reliability and abuse prevention. We do not use advertising cookies and there is no third-party tracking on this website or in the application.

4. Why we process it, and on what basis

To provide the service under our contract with you. To keep it secure and to investigate abuse, which is our legitimate interest and yours. To bill you and to meet our legal obligations, such as keeping accounting records.

We do not sell personal data, and we do not use your content to train AI models.

5. Where it is held

On Amazon Web Services, in the region chosen when your organisation is set up: the United States, the United Kingdom, Germany or Australia. Your content and your audit log stay in that region.

Some account data and support correspondence may be handled by our staff and systems outside that region. Where that involves an international transfer we rely on the appropriate safeguards, including standard contractual clauses.

6. Who else is involved

We use a small number of providers to run the service. Amazon Web Services hosts it. Where you use the AI features, OpenAI processes the text involved. We also use providers for billing, email and error monitoring.

A current list of sub-processors is available on request, and we will tell you before adding one that processes your content.

7. The AI features

They are optional and are off until an administrator in your organisation turns them on.

When someone uses them, the text of the document concerned is sent to OpenAI for processing and the result is returned. Nothing is sent in the background, and nothing is sent when the features are off. If your organisation runs its own AI service we can use that instead, in which case the text goes there and not to OpenAI.

8. How long we keep it

Your content is kept for as long as your organisation exists. After termination it remains available for export for [30] days, after which we delete it, including from backups within our ordinary backup cycle.

Audit logs are retained for the life of the organisation, because their value is that they go back. Billing records are kept for as long as the law requires.

9. Security

Access is authenticated, roles are enforced on the server, organisations are separated in the data layer, and secrets are encrypted at rest. Our security overview describes how, in more detail than most policies of this kind would.

10. Your rights

If you are one of our customers’ users, the organisation you belong to controls your content, so ask them first. We will help them respond.

For the data we control, you have the right to ask for a copy, to have it corrected or deleted, to object to or restrict processing, and to ask us to move it. Write to [email protected] and we will respond within one month.

If you are not satisfied you may complain to your data protection authority. In the United Kingdom that is the Information Commissioner’s Office.

11. Cookies

This website sets no cookies at all. The application sets one, to keep you signed in. It is not used for analytics or advertising, and it is removed when you sign out.

12. Changes

We will update this page when what we do changes, and will tell customers before a material change takes effect.

Questions about this?

We would rather answer them before you sign than after.

Get in touch