Last updated: September 8, 2026
This policy explains what data Sendie collects, why we collect it, and what we do with it. We aim to collect as little as possible, and to keep what we do collect under your control.
- Overview
- Our role: processor, not controller
- What we collect
- How we use it
- Data contribution
- Sharing & disclosure
- Data retention
- Your rights
- Security
- Cookies & tracking
- Children
- Changes
- Contact
1. Overview
Sendie is an AI customer-engagement platform: it answers calls and web chats, replies across messaging channels, takes bookings, reservations and payments, hosts public pages (link-in-bio, shop, events, capture forms), and runs outbound outreach, all feeding one place. To do this on your behalf, we process information about you, the people who contact you or that you contact, the calls and messages exchanged, and the accounts and providers you connect. We do not sell personal data. We do not share your contacts, conversations, or content between accounts. Your data stays scoped to your account.
2. Our role: processor, not controller
This section explains who is legally responsible for the different categories of personal data the Service handles. The distinction matters under GDPR, the UK GDPR, CCPA/CPRA, and similar laws: the controller decides why and how data is processed, and bears most of the compliance obligations; the processor handles data on the controller's instructions and bears narrower obligations.
For contact data you upload, paste, import, or send to: we are a processor; you are the controller
When you upload a CSV of contacts, paste recipient addresses, import a list from another tool, or use Sendie to send messages, you are the data controller for those individuals' personal data. You decide whose data to upload, why you are contacting them, what to say, and on what lawful basis you process them. Sendie acts as your data processor: we store and transmit that data on your behalf and on your documented instructions (the actions you take inside the product).
As your processor for that data, we commit to:
- Process it only on your instructions, expressed through your use of the Service.
- Apply appropriate technical and organisational measures, including encryption of credentials at rest, access controls, and audit logging.
- Not transfer it to third parties except (i) the sub-processors listed below or on our website, (ii) where you direct us to (e.g. an SMTP provider you connect), or (iii) where required by law.
- Make available all information necessary to demonstrate compliance with Article 28 GDPR, and submit to audits as agreed in any Data Processing Addendum we sign with you.
- Notify you without undue delay of any personal-data breach affecting your contact data.
- Return or delete your data on termination, subject to the retention windows in section 7.
- Assist you with data-subject requests (access, deletion, rectification, objection) within a reasonable timeframe.
Because you are the controller for that data, you remain responsible for: choosing the lawful basis you rely on (GDPR Art. 6); making sure each recipient was lawfully obtained and is lawfully contactable; honoring opt-out, deletion, and objection requests from those recipients; providing a Privacy Notice to them where required; and any other controller obligation under applicable law. Sendie cannot, as a practical matter, verify the provenance of contact data you upload, and we are entitled to rely on the representations you make to us in our Terms of Service.
If your processing is subject to GDPR or UK GDPR and you require a written Data Processing Addendum (DPA), contact us at the address in section 13 and we will arrange one.
For account-holder data (you, the Sendie user): we are the controller
For data about you as our customer, your account email, password hash, billing information, support correspondence, and similar, Sendie is the controller. Sections 3-11 of this policy explain what we collect, why, and your rights. This dual-role structure is standard for B2B SaaS and is the same shape used by tools like Mailchimp, SendGrid, and similar services.
For aggregated or anonymized data we derive
Where we generate aggregated or de-identified statistics that cannot reasonably be linked back to a specific individual (e.g. "X% of campaigns from the Starter tier hit our deliverability heuristics"), that information is no longer personal data and we are free to use it to operate and improve the Service.
3. What we collect
Account information
- Email address (required) and password (stored as a bcrypt hash, never in plaintext).
- Display name and onboarding goal (optional).
- Account preferences such as theme and notification settings.
SMTP credentials
- The hostname, port, username, and password of the email server(s) you connect for sending. These are stored so we can send on your behalf. We are working to move all SMTP passwords to authenticated encryption at rest.
Contact & campaign data
- CSV files and contact lists you upload, including names, email addresses, company info, and any custom columns you map.
- Subject lines, body content, and any merge tags or templates you create.
- Send history, including timestamps, status (sent / failed / bounced), and per-recipient errors.
Usage data
- Basic request logs (IP address, browser user-agent, timestamp) used for security and abuse prevention.
- Demo-request and waitlist submissions, if you opt in.
Voice calls & concierge
- When you talk to a voice concierge, your microphone or phone audio and the conversation are processed in real time by our voice provider, ElevenLabs, so it can understand you and respond. Phone calls and text messages are carried by Twilio. Where a business enables our alternative voice pipeline, speech-to-text and text-to-speech may instead be handled by Deepgram, Cartesia and LiveKit. These providers act as our sub-processors.
- Calls may be recorded, transcribed and summarised so the business you contacted can answer, book you in and follow up. We keep the call summary and any details you share, such as your name, email, phone number, or a booking, and, where enabled, the recording and transcript. We also store a random, first-party visitor identifier (no IP address) so a returning caller can be recognised; see our Cookie Notice. Recording practice and consent are the responsibility of the business operating the concierge.
- The business operating the concierge is the controller of the details you provide; Sendie processes them on that business's behalf.
Messages & channels
- When you message a business through Sendie, SMS or WhatsApp (via Twilio), Telegram, or Instagram and Messenger (via the Meta platform), or through the web chat on its pages, we process the message content, your channel identifier (phone number, chat ID or social handle) and conversation history so the business can reply, and we store it in that business's inbox and Contacts. Where auto-reply is on, replies may be generated by AI (see below).
Payments & billing
- When you pay for a booking, ticket or product through a business on Sendie, payment is processed by Stripe (via Stripe Connect); card details are handled by Stripe and do not touch Sendie's servers. We record the transaction (amount, item, status) so the business and Sendie can reconcile it.
- For your own Sendie subscription and credit purchases, we process billing information through our payment providers (Stripe, Lemon Squeezy as merchant of record, and NOWPayments for crypto). We store invoices and billing metadata, not full card numbers.
AI processing
- To power the concierge, the Brain (lead scoring and next-best-action), auto-replies and AI writing, conversation and contact content is processed by our AI provider Anthropic (Claude). It is used to generate the response for your account and is not used by us to train models on your data.
Enrichment & lead data
- When you search for or enrich business contacts, we query our own database and third-party providers (People Data Labs, Apollo, Hunter) and verify deliverability (DeBounce). Results returned to you are stored in your account.
A full, current list of the providers we use is on our Subprocessors page.
4. How we use it
- Run the service. Authenticate you, store your contacts, conversations and content, answer calls and messages, take bookings and payments, and send your outreach.
- Improve the product. Understand which features are used, and find bugs. Aggregated, de-identified usage statistics may be used for product analytics and to train internal models that improve features like search, smart filtering, and deliverability heuristics.
- Communicate. Send transactional emails (password resets, send-status notifications) and, only with consent, occasional product updates.
- Security. Detect abuse, prevent unauthorized access, and protect both you and your recipients.
By default, we do not use the contents of your contact lists or campaign bodies for any purpose other than running your account. Section 5 describes two narrow, clearly-separated exceptions: an anonymized verification-outcomes contribution that is on by default under legitimate interest (you can switch it off any time), and an identifiable contact-record contribution that only ever happens when you deliberately submit records yourself.
5. Data contribution
Sendie operates a shared data pool that helps every user's deliverability and enrichment stay accurate. There are two entirely separate forms of contribution, with different scope, different defaults, and different lawful bases. We never contribute your campaign bodies, subject lines, SMTP credentials, billing data, account settings, unsubscribes, or manual blocks under either one, and contributions are never attributed to you.
5a. Anonymized verification outcomes (on by default)
When Sendie verifies an email address, the outcome of that check (deliverable, or bounced/undeliverable) is an objective deliverability signal. With this contribution on, those anonymized outcomes feed the shared pool so other users don't waste verifications on addresses already known to be dead, and so everyone's results stay fresh. This never includes the identity of your lists, who you are contacting, your campaign content, or any attribution to you: it is the deliverability status of an address, aggregated across everyone who has ever checked it, and it complements the cross-user verification cache in our Terms of Service (section 8), which stores one-way SHA-256 hashes rather than the original address.
- This contribution is on by default. You can switch it off any time in your account settings, and contribution stops immediately.
- Lawful basis: legitimate interest, Article 6(1)(f) GDPR / UK GDPR. Because the data is fully anonymized and aggregated (deliverability outcomes, not identifiable contact records or content) and you have a clear, standing opt-out, we rely on legitimate interest rather than consent. Our balancing assessment is available on request via the contacts in section 12.
5b. Identifiable contact records (only when you submit them)
Separately, you may choose to contribute identifiable contact records (email address, name, title, company and associated metadata) to our enrichment database via the deliberate Submit Lead flow. Records contributed this way can later be returned to other users as enrichment results, deduplicated across contributors.
- This never happens automatically. It only occurs for records you actively submit through Submit Lead; there is no background or default sharing of your uploaded lists or verified addresses.
- Lawful basis: your explicit consent, Article 6(1)(a) GDPR, given by the act of submitting the record. You may withdraw and request removal at any time. The contribution and reward rules in our Terms of Service (section 7) apply.
- Records you submitted before withdrawing remain in the database until removed. You may request removal of specific records, or all of your historical contributions, via section 12; we action verified requests within 30 days.
Your obligations to the people in your lists
When you submit identifiable contact data, you confirm that you have a lawful basis to do so (for example, business-purpose processing under GDPR Article 6(1)(f), or relevant authorisation in your jurisdiction). Sendie cannot verify the lawful basis behind every record and relies on you to make this assessment. We honour subject-access and erasure requests from individuals in our database regardless of who contributed them.
6. Sharing & disclosure
We share data only in the following limited cases:
- Sub-processors. Service providers we use to operate Sendie, hosting, AI (Anthropic), telephony and voice (Twilio, ElevenLabs), messaging (Meta, Telegram), payments (Stripe, Lemon Squeezy, NOWPayments), email delivery (Resend), enrichment and verification, and error monitoring. These providers are contractually bound to use data only to deliver their service to us. The current list is on our Subprocessors page.
- Message & call delivery. To deliver your outreach and conversations, message content and the recipient's address or number are transmitted through the relevant channel: email via the SMTP server you configured or our delivery provider, and calls and texts via our telephony and messaging sub-processors.
- Legal compliance. If required by a valid legal request, and only to the extent required. We will notify you if legally permitted.
- Business transfer. If Sendie is acquired or merged, your data may transfer to the new entity under the same protections described here.
- Public Discover directory. If you publish a Sendie page and verify your email, your business's already-public information (name, tagline, location, category, what it offers such as bookings, reservations, events or shop, and public reviews) is listed in the public Sendie Discover directory at sendie.ai/discover and may be indexed by search engines, so customers can find you. Discover listing is a standard part of a published Sendie page. We never publish your account credentials or your own customers' data here.
7. Data retention
- Account data is retained while your account is active.
- Campaign history and send logs are retained for 12 months by default unless you delete them earlier.
- If you delete your account, we delete your personal data and uploaded contacts within 30 days, except where retention is required by law (e.g., financial records).
- Call recordings and transcripts: where the business operating the concierge keeps durable copies, these are retained for up to 120 days and then automatically deleted; otherwise the recording is streamed from our voice provider on demand and not separately stored by us. The call summary and any details you shared are retained in the business's CRM as above. Every call opens with a spoken notice that it may be recorded.
- Deleting your call data: to have your recording, transcript or call summary deleted, email privacy@sendie.ai from, or quoting, the phone number or email address you used on the call. Your data is keyed to that number/email, so we can locate and remove it; we action verified requests within 30 days.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct or update inaccurate data.
- Delete your data (the "right to be forgotten").
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
To exercise any of these rights, contact us at the address in section 12. We will respond within 30 days.
9. Security
We protect your data using industry-standard practices:
- Passwords are hashed with bcrypt, not stored in plaintext.
- All traffic to the application is served over HTTPS.
- Per-user data isolation: one account cannot read or write another account's contacts, campaigns, or settings.
- Regular dependency updates and a documented incident-response process.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately.
10. Cookies & tracking
Sendie uses a small number of first-party cookies and no third-party advertising cookies, ad pixels, or cross-site trackers. We do not sell your data. The cookies we use:
| Cookie | Type | Purpose | Needs consent? |
session | Essential | Keeps you signed in. HttpOnly, Secure, SameSite=Lax, cryptographically signed. | No (strictly necessary) |
csrf_token | Essential | Security, protects forms against cross-site request forgery. | No (strictly necessary) |
sendie_ref | Functional | Remembers a referral link so the referrer is credited (30 days). | No (functional) |
sendie_consent | Functional | Remembers your cookie choice so we don't ask again (1 year). | No (functional) |
| Visitor analytics | Analytics (cookieless) | A server-side page-view count using a salted-hashed IP (no raw IP stored), to understand traffic. No third parties. | Yes, Decline turns it off |
We also use your browser's local storage for app preferences (e.g. theme, sidebar state), functional only. The cookie banner on our site lets you Accept or Decline; choosing Decline switches off the optional visitor analytics. Essential and functional cookies remain, as they are required for the service to work. You can also clear cookies any time in your browser settings.
11. Children
Sendie is not directed at, and we do not knowingly collect data from, anyone under 16. If you believe a minor has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify active customers by email and update the "Last updated" date at the top. Continued use after a change constitutes acceptance.
Questions about this policy or your data? Email privacy@sendie.ai.
Sendie is operated by SENDIE AI LTD, a company registered in England (No. 17307184), registered office: 66 Paul Street, London, England, EC2A 4NA.