Privacy Center
Every form on this site is listed below with the data it collects, whether that data is encrypted at rest, how long we keep it, and how to have it removed. This page supplements our Privacy Policy.
Last updated: September 2, 2026
How we handle your data
Encrypted at rest
Personal fields in our database are stored as AES-256 encrypted values, not plain text.
Time-bound retention
Each record type has a defined retention period. We do not keep submissions indefinitely.
Deletion on request
You can ask us to delete your data at any time. We confirm in writing when it is done.
Form-by-form data inventory
| Form | What we collect | Storage & encryption | Retention |
|---|---|---|---|
| Intelligence Score / readiness assessment/assessment | Name, business email, company, role, phone (optional), assessment answers and resulting score | Encrypted at rest (AES-256) | Retained for 24 months after your last interaction, then deleted |
| Compliance readiness request/compliance/* and /request-readiness-check | Name, business email, company, phone, framework of interest, notes you provide | Encrypted at rest (AES-256) | Retained for 24 months after the request is closed |
| Contact form/contact | Name, email, phone (optional), message | Not stored in our database | Delivered to our sales inbox by email; retained in that mailbox per our email retention practice (24 months) |
| Pricing request/request-pricing | Name, business email, company, service interest, budget range if provided | Not stored in our database | Delivered by email to our sales team; retained in that mailbox for 24 months |
| Engagement intake/engagement-intake | Contact details, company profile, environment and scope answers | Not stored in our database | Delivered by email to our engagement team; retained for the life of the engagement plus 7 years where required for contracts and tax records |
| Gated guide / download form/resources and guide pages | Name, business email, company, the asset requested | Encrypted at rest (AES-256) | Retained for 24 months from download, or until you unsubscribe |
| Newsletter signupSite-wide newsletter blocks | Email address, subscription status, engagement events (opens and clicks) | Encrypted at rest (AES-256) | Retained while you are subscribed; removed within 30 days of unsubscribing |
| Investor inquiry/investors and /investor-deck | Name, email, firm, role, phone (optional), inquiry notes | Encrypted at rest (AES-256) | Retained for 36 months to support ongoing investor relations |
| On-site chatbotChat widget | Messages you type, and any contact details you choose to share in chat | Encrypted at rest (AES-256) | Conversation transcripts retained for 12 months |
| Client portal access request/auth and portal pages | Email address, requested organization, approval status | Encrypted at rest (AES-256) | Retained for the life of the account; 7 days after account deletion |
| Account registration & profile/auth and portal profile | Email, name, company details, phone, avatar, MFA enrollment state | Encrypted at rest (AES-256) | Retained while your account is active; deletion records kept for 7 days for recovery, then purged |
| Shop checkout & orders/shop | Name, email, billing details, order contents (card data handled by Stripe, never stored by us) | Encrypted at rest (AES-256) | Retained for 7 years to satisfy tax and accounting obligations |
Forms marked “Not stored in our database” are routed to a Senticit mailbox by email instead of being written to our application database. Payment card data is processed by Stripe and never reaches our systems.
Who can see your submission
- Access is limited to authorized Senticit staff who need the record to respond to you.
- Staff accounts with access to personal data must complete multi-factor authentication.
- Every decryption of a personal field is written to an internal, append-only access log.
- Row-level access rules prevent one client’s records from being visible to another.
Your rights
- Access — request a copy of the data we hold about you.
- Correction — ask us to fix inaccurate details.
- Deletion — ask us to erase your data, subject to records we must keep by law (for example invoices).
- Marketing opt-out — unsubscribe from any email using its one-click link, or via our opt-out instructions.
How to request deletion
- Email infosenticit.com with the subject line “Data deletion request”.
- Include the email address you used on the form, and which form or forms it applies to (or say “all”).
- We verify that the request comes from the address on file, then delete the matching records.
- We confirm completion in writing within 30 days. Records we are legally required to keep are listed in the reply.
If you have a portal account, you can also request deletion from your profile page — deleted accounts are recoverable for 7 days and then permanently purged.