Legal

Privacy Policy

This policy explains what data Sendie collects, why we collect it, and what we do with it.

Last updated: September 8, 2026

This policy explains what data Sendie collects, why we collect it, and what we do with it. We aim to collect as little as possible, and to keep what we do collect under your control.

  1. Overview
  2. Our role: processor, not controller
  3. What we collect
  4. How we use it
  5. Data contribution
  6. Sharing & disclosure
  7. Data retention
  8. Your rights
  9. Security
  10. Cookies & tracking
  11. Children
  12. Changes
  13. Contact

1. Overview

Sendie is an AI customer-engagement platform: it answers calls and web chats, replies across messaging channels, takes bookings, reservations and payments, hosts public pages (link-in-bio, shop, events, capture forms), and runs outbound outreach, all feeding one place. To do this on your behalf, we process information about you, the people who contact you or that you contact, the calls and messages exchanged, and the accounts and providers you connect. We do not sell personal data. We do not share your contacts, conversations, or content between accounts. Your data stays scoped to your account.

2. Our role: processor, not controller

This section explains who is legally responsible for the different categories of personal data the Service handles. The distinction matters under GDPR, the UK GDPR, CCPA/CPRA, and similar laws: the controller decides why and how data is processed, and bears most of the compliance obligations; the processor handles data on the controller's instructions and bears narrower obligations.

For contact data you upload, paste, import, or send to: we are a processor; you are the controller

When you upload a CSV of contacts, paste recipient addresses, import a list from another tool, or use Sendie to send messages, you are the data controller for those individuals' personal data. You decide whose data to upload, why you are contacting them, what to say, and on what lawful basis you process them. Sendie acts as your data processor: we store and transmit that data on your behalf and on your documented instructions (the actions you take inside the product).

As your processor for that data, we commit to:

Because you are the controller for that data, you remain responsible for: choosing the lawful basis you rely on (GDPR Art. 6); making sure each recipient was lawfully obtained and is lawfully contactable; honoring opt-out, deletion, and objection requests from those recipients; providing a Privacy Notice to them where required; and any other controller obligation under applicable law. Sendie cannot, as a practical matter, verify the provenance of contact data you upload, and we are entitled to rely on the representations you make to us in our Terms of Service.

If your processing is subject to GDPR or UK GDPR and you require a written Data Processing Addendum (DPA), contact us at the address in section 13 and we will arrange one.

For account-holder data (you, the Sendie user): we are the controller

For data about you as our customer, your account email, password hash, billing information, support correspondence, and similar, Sendie is the controller. Sections 3-11 of this policy explain what we collect, why, and your rights. This dual-role structure is standard for B2B SaaS and is the same shape used by tools like Mailchimp, SendGrid, and similar services.

For aggregated or anonymized data we derive

Where we generate aggregated or de-identified statistics that cannot reasonably be linked back to a specific individual (e.g. "X% of campaigns from the Starter tier hit our deliverability heuristics"), that information is no longer personal data and we are free to use it to operate and improve the Service.

3. What we collect

Account information

SMTP credentials

Contact & campaign data

Usage data

Voice calls & concierge

Messages & channels

Payments & billing

AI processing

Enrichment & lead data

A full, current list of the providers we use is on our Subprocessors page.

4. How we use it

By default, we do not use the contents of your contact lists or campaign bodies for any purpose other than running your account. Section 5 describes two narrow, clearly-separated exceptions: an anonymized verification-outcomes contribution that is on by default under legitimate interest (you can switch it off any time), and an identifiable contact-record contribution that only ever happens when you deliberately submit records yourself.

5. Data contribution

Sendie operates a shared data pool that helps every user's deliverability and enrichment stay accurate. There are two entirely separate forms of contribution, with different scope, different defaults, and different lawful bases. We never contribute your campaign bodies, subject lines, SMTP credentials, billing data, account settings, unsubscribes, or manual blocks under either one, and contributions are never attributed to you.

5a. Anonymized verification outcomes (on by default)

When Sendie verifies an email address, the outcome of that check (deliverable, or bounced/undeliverable) is an objective deliverability signal. With this contribution on, those anonymized outcomes feed the shared pool so other users don't waste verifications on addresses already known to be dead, and so everyone's results stay fresh. This never includes the identity of your lists, who you are contacting, your campaign content, or any attribution to you: it is the deliverability status of an address, aggregated across everyone who has ever checked it, and it complements the cross-user verification cache in our Terms of Service (section 8), which stores one-way SHA-256 hashes rather than the original address.

5b. Identifiable contact records (only when you submit them)

Separately, you may choose to contribute identifiable contact records (email address, name, title, company and associated metadata) to our enrichment database via the deliberate Submit Lead flow. Records contributed this way can later be returned to other users as enrichment results, deduplicated across contributors.

Your obligations to the people in your lists

When you submit identifiable contact data, you confirm that you have a lawful basis to do so (for example, business-purpose processing under GDPR Article 6(1)(f), or relevant authorisation in your jurisdiction). Sendie cannot verify the lawful basis behind every record and relies on you to make this assessment. We honour subject-access and erasure requests from individuals in our database regardless of who contributed them.

6. Sharing & disclosure

We share data only in the following limited cases:

7. Data retention

8. Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, contact us at the address in section 12. We will respond within 30 days.

9. Security

We protect your data using industry-standard practices:

No system is perfectly secure. If you believe your account has been compromised, contact us immediately.

10. Cookies & tracking

Sendie uses a small number of first-party cookies and no third-party advertising cookies, ad pixels, or cross-site trackers. We do not sell your data. The cookies we use:

CookieTypePurposeNeeds consent?
sessionEssentialKeeps you signed in. HttpOnly, Secure, SameSite=Lax, cryptographically signed.No (strictly necessary)
csrf_tokenEssentialSecurity, protects forms against cross-site request forgery.No (strictly necessary)
sendie_refFunctionalRemembers a referral link so the referrer is credited (30 days).No (functional)
sendie_consentFunctionalRemembers your cookie choice so we don't ask again (1 year).No (functional)
Visitor analyticsAnalytics (cookieless)A server-side page-view count using a salted-hashed IP (no raw IP stored), to understand traffic. No third parties.Yes, Decline turns it off

We also use your browser's local storage for app preferences (e.g. theme, sidebar state), functional only. The cookie banner on our site lets you Accept or Decline; choosing Decline switches off the optional visitor analytics. Essential and functional cookies remain, as they are required for the service to work. You can also clear cookies any time in your browser settings.

11. Children

Sendie is not directed at, and we do not knowingly collect data from, anyone under 16. If you believe a minor has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify active customers by email and update the "Last updated" date at the top. Continued use after a change constitutes acceptance.

13. Contact

Questions about this policy or your data? Email privacy@sendie.ai.

Sendie is operated by SENDIE AI LTD, a company registered in England (No. 17307184), registered office: 66 Paul Street, London, England, EC2A 4NA.