Privacy and Data Governance

Privacy, data governance, and responsible AI notice

Santati handles relationship, customer, operational, and intelligence-layer data with governance controls designed for trust, accountability, and regulatory readiness.

Last updated: August 4, 2026. This notice explains Santati's public website and product data practices. Contract terms, data processing agreements, and customer-specific configurations may add more specific obligations.

1. Scope

This notice applies to santaticrm.com, demo requests, contact forms, and Santati product interactions where Santati acts as a controller or processor of personal data. It covers public website data, account data, customer relationship records, activity history, documents, communications metadata, organizational memory, AI-supported guidance, and operational logs.

2. Roles under privacy law

For website inquiries and direct business communications, Santati may act as a controller. For customer workspaces, Santati normally acts as a processor or service provider on behalf of the customer. The customer remains responsible for deciding what personal data is entered into its workspace, which users receive access, and which lawful basis applies to its processing.

3. Personal data we may process

4. Special category and sensitive data

Santati is not intended for unrestricted storage of special category data, regulated health data, payment card data, government identity numbers, criminal-offence data, or children's data unless a written agreement, configuration, and compliance basis specifically allow that use. Customers must avoid entering restricted data unless approved controls are in place.

5. How we use data

6. Lawful bases

Depending on context and jurisdiction, processing may rely on contract performance, legitimate interests, consent, compliance with legal obligations, or instructions from a customer controller. Where consent is required, it must be freely given and withdrawable. Where legitimate interests are used, Santati considers proportionality, transparency, data minimization, and user rights.

7. GDPR, UK GDPR, and international transfers

Santati is designed to support controller and processor obligations under GDPR and UK GDPR, including transparency, purpose limitation, data minimization, security, retention controls, access governance, auditability, and data subject rights. If data is transferred across borders, appropriate transfer safeguards should be used, such as standard contractual clauses, transfer risk assessment, hosting restrictions, or customer-approved subprocessor controls.

8. EU AI Act and responsible AI governance

Santati's intelligence features are designed to support human decision-making through source-linked observations and explainable guidance. Santati should not be used to make prohibited AI decisions, hidden scoring decisions, employment decisions, credit decisions, insurance eligibility decisions, or legally significant automated decisions unless a written assessment confirms the use case, risk classification, human oversight model, transparency duties, logging, accuracy controls, and customer obligations. Users remain responsible for reviewing outputs before acting.

9. Explainability and human oversight

AI-supported outputs should be treated as assistance. Santati aims to show source context, evidence, and operational history where available. Users should verify outputs against underlying records. Santati does not remove the need for human review, professional judgment, or compliance approval.

10. Data sharing and subprocessors

Santati may use hosting, security, communications, scheduling, analytics, database, storage, and AI infrastructure providers. Subprocessors should be limited to what is necessary to operate the service and should be governed by contractual confidentiality, security, and data protection obligations.

11. Security controls

Santati uses role-based access control, workspace isolation, authentication controls, operational logging, backup procedures, deployment controls, and access governance. No security program eliminates all risk, but Santati's control model is designed to reduce unauthorized access, data leakage, accidental exposure, and uncontrolled use of customer information.

12. Retention

Data is retained only as long as needed for the relevant purpose, customer instruction, contract requirement, audit obligation, legal obligation, backup cycle, dispute management, or security investigation. Customer workspace records may be deleted, exported, archived, or retained according to customer instructions and applicable agreements.

13. Your rights

Depending on location, individuals may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. Requests related to customer workspace data may need to be directed to the customer controller first.

14. Cookies and similar technologies

The santaticrm.com marketing website does not use advertising trackers, tracking pixels, remarketing, or third-party tools such as Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, or Hotjar. Advertising and personalization cookies are never enabled.

Neither analytics tool runs, and no identifier or event is stored or sent, unless you choose "Accept" in the cookie banner. Choosing "Essential only" keeps both fully off and clears any analytics identifiers already stored in your browser. You can change your choice at any time using the "Cookie preferences" link in the site footer.

15. Contact

Privacy, security, and data governance questions can be submitted through the contact page. Customers with a signed agreement should use their designated operational contact for data protection requests.