Last updated: August 4, 2026. This notice explains Santati's public website and product data practices. Contract terms, data processing agreements, and customer-specific configurations may add more specific obligations.
1. Scope
This notice applies to santaticrm.com, demo requests, contact forms, and Santati product interactions where Santati acts as a controller or processor of personal data. It covers public website data, account data, customer relationship records, activity history, documents, communications metadata, organizational memory, AI-supported guidance, and operational logs.
2. Roles under privacy law
For website inquiries and direct business communications, Santati may act as a controller. For customer workspaces, Santati normally acts as a processor or service provider on behalf of the customer. The customer remains responsible for deciding what personal data is entered into its workspace, which users receive access, and which lawful basis applies to its processing.
3. Personal data we may process
- Identity and contact data, including name, email, company, role, phone, and message content.
- Workspace account data, including user role, permissions, authentication state, and audit history.
- CRM records, including contacts, companies, opportunities, activities, tasks, notes, documents, communications, and relationship context.
- Operational metadata, including timestamps, user actions, source references, browser data, security events, and error logs.
- AI governance data, including prompts or user requests submitted to approved intelligence features, generated observations, source links, evaluation markers, and human feedback.
4. Special category and sensitive data
Santati is not intended for unrestricted storage of special category data, regulated health data, payment card data, government identity numbers, criminal-offence data, or children's data unless a written agreement, configuration, and compliance basis specifically allow that use. Customers must avoid entering restricted data unless approved controls are in place.
5. How we use data
- Operate, secure, and improve Santati services.
- Respond to inquiries and demo requests.
- Authenticate users and enforce workspace permissions.
- Maintain CRM records, document references, organizational memory, and audit trails.
- Provide explainable guidance, summaries, observations, and workflow support where enabled.
- Detect misuse, investigate incidents, preserve service integrity, and comply with legal obligations.
6. Lawful bases
Depending on context and jurisdiction, processing may rely on contract performance, legitimate interests, consent, compliance with legal obligations, or instructions from a customer controller. Where consent is required, it must be freely given and withdrawable. Where legitimate interests are used, Santati considers proportionality, transparency, data minimization, and user rights.
7. GDPR, UK GDPR, and international transfers
Santati is designed to support controller and processor obligations under GDPR and UK GDPR, including transparency, purpose limitation, data minimization, security, retention controls, access governance, auditability, and data subject rights. If data is transferred across borders, appropriate transfer safeguards should be used, such as standard contractual clauses, transfer risk assessment, hosting restrictions, or customer-approved subprocessor controls.
8. EU AI Act and responsible AI governance
Santati's intelligence features are designed to support human decision-making through source-linked observations and explainable guidance. Santati should not be used to make prohibited AI decisions, hidden scoring decisions, employment decisions, credit decisions, insurance eligibility decisions, or legally significant automated decisions unless a written assessment confirms the use case, risk classification, human oversight model, transparency duties, logging, accuracy controls, and customer obligations. Users remain responsible for reviewing outputs before acting.
9. Explainability and human oversight
AI-supported outputs should be treated as assistance. Santati aims to show source context, evidence, and operational history where available. Users should verify outputs against underlying records. Santati does not remove the need for human review, professional judgment, or compliance approval.
10. Data sharing and subprocessors
Santati may use hosting, security, communications, scheduling, analytics, database, storage, and AI infrastructure providers. Subprocessors should be limited to what is necessary to operate the service and should be governed by contractual confidentiality, security, and data protection obligations.
11. Security controls
Santati uses role-based access control, workspace isolation, authentication controls, operational logging, backup procedures, deployment controls, and access governance. No security program eliminates all risk, but Santati's control model is designed to reduce unauthorized access, data leakage, accidental exposure, and uncontrolled use of customer information.
12. Retention
Data is retained only as long as needed for the relevant purpose, customer instruction, contract requirement, audit obligation, legal obligation, backup cycle, dispute management, or security investigation. Customer workspace records may be deleted, exported, archived, or retained according to customer instructions and applicable agreements.
13. Your rights
Depending on location, individuals may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. Requests related to customer workspace data may need to be directed to the customer controller first.
14. Cookies and similar technologies
The santaticrm.com marketing website does not use advertising trackers, tracking pixels, remarketing, or third-party tools such as Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, or Hotjar. Advertising and personalization cookies are never enabled.
- Essential. A first-party browser storage entry records your cookie preference itself (accepted or essential-only) so the banner does not reappear on every page. This is required for the preference to work and is not optional.
- Optional analytics (Santati Wisp). Some pages load a first-party analytics script we built ourselves ("Wisp") that records anonymous, first-party page views, clicks, and time on page to help us understand which content is useful.
- Optional analytics (Google Analytics, via Google Tag Manager). When enabled, standard web analytics -- page views, sessions, referrers, and similar aggregate usage patterns -- are also sent to Google Analytics. Names, email addresses, phone numbers, form contents, and CRM identifiers are never sent to Google.
Neither analytics tool runs, and no identifier or event is stored or sent, unless you choose "Accept" in the cookie banner. Choosing "Essential only" keeps both fully off and clears any analytics identifiers already stored in your browser. You can change your choice at any time using the "Cookie preferences" link in the site footer.
15. Contact
Privacy, security, and data governance questions can be submitted through the contact page. Customers with a signed agreement should use their designated operational contact for data protection requests.